General Data Protection Regulation (GDPR) & UK Data Protection Compliance
Statement
1. Introduction This GDPR Compliance Statement outlines how Advanced Histopathology Laboratory Ltd, (“we,” “our,” “us”) collects, processes, and protects personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the UK General Data Protection Regulation (UK GDPR), and the Data Protection Act 2018 (DPA 2018).
2. Data We Collect We collect and process the following types of personal data:
- Contact details (e.g., name, email, phone number)
- Demographic information
- Payment details (if applicable)
- Website usage data (e.g., IP address, cookies, analytics tracking)
- Data collected via Google Analytics tags and LinkedIn Insight tag
- Information submitted through contact us forms
- Any other information required for business operations
We use cookies and tracking technologies to analyse website traffic and improve user experience. See our [Cookie Policy] for more details and how to manage your preferences.
3. Purpose of Data Collection We process personal data for the following purposes:
- Contact details → To respond to inquiries, provide customer support, manage client relationships, and send marketing communications where consent has been given.
- Website usage data → To analyse visitor behaviour, improve website performance, and enhance user experience.
- Form submissions → To process requests, provide relevant services, communicate with users, and send marketing communications where consent has been given.
4. Legal Basis for Processing Data We process personal data based on one or more of the following legal bases:
- Consent from the data subject
- Performance of a contract
- Compliance with legal obligations
- Legitimate interests pursued by our organization
5. Data Subject Rights Under GDPR and UK GDPR, individuals have the following rights:
- Right to access personal data
- Right to remove consent at any time
- Right to rectification of incorrect data
- Right to erasure (“right to be forgotten”)
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right not to be subject to automated decision-making
6. Data Security Measures We implement appropriate technical and organizational measures to ensure data security, including:
- Encryption and secure storage
- Access controls and authentication
- Regular data audits and assessments
- Staff training on data protection
7. Data Transfers Outside the UK & EU If we transfer personal data outside the UK or the
EU (e.g., to the US via Google Analytics or LinkedIn), we ensure that such transfers comply with:
- UK adequacy decisions
- Standard Contractual Clauses (SCCs)
- Other lawful data transfer mechanisms as required under UK GDPR and GDPR
8. Data Retention We retain personal data only as long as necessary to fulfill the purposes for which it was collected, in compliance with applicable laws.
9. Data Sharing and Third Parties We do not sell personal data. However, we may share data with:
- Service providers processing data on our behalf
- Regulatory authorities if required by law
- Business partners with explicit consent
10. Data Breach Notification In the event of a data breach, we will notify the relevant authorities (such as the ICO for UK-based data subjects) and affected individuals as required by GDPR and UK GDPR.
11. Complaints If you are not satisfied with how we process your data, you also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO).
12. Contact Information For any questions regarding this GDPR and UK GDPR policy or to exercise your data protection rights, please contact us at:
Company: Advanced Histopathology Laboratory Ltd
Address: 47A Devonshire Street, London, UK, W1G 7AW
Email: [email protected]
Website: www.ahlab.co.uk
Last reviewed: March 2025