

Data Protection
Version: 1.0
Effective Date: 5 August 2026
Review Date: 5 August 2027
1. Policy Statement
Grey Tide Ltd is committed to protecting the privacy, confidentiality and security of personal information entrusted to us by clients, suppliers, business partners, employees and other stakeholders.
We recognise our responsibilities under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 and will ensure personal information is processed lawfully, fairly and transparently.
This policy establishes the principles and standards that Grey Tide Ltd follows when collecting, storing, using and disposing of personal data.
2. Scope
This policy applies to:
-
All directors, employees, contractors and associates of Grey Tide Ltd.
-
All personal data processed by Grey Tide Ltd.
-
Information held in digital or physical form.
-
Data obtained through our website, business activities, contracts, communications and professional engagements.
3. Data Protection Principles
Grey Tide Ltd will ensure personal data is:
Lawful, Fair and Transparent
Personal data will only be collected and processed where there is a legitimate legal basis for doing so.
Collected for Specified Purposes
Information will be collected only for legitimate business purposes and will not be used in ways incompatible with those purposes.
Adequate and Limited
Only information necessary for the intended purpose will be collected and retained.
Accurate
Reasonable steps will be taken to keep data accurate and up to date.
Secure
Appropriate technical and organisational measures will be implemented to protect data against loss, unauthorised access, disclosure, alteration or destruction.
Retained Appropriately
Data will only be retained for as long as necessary for legal, contractual or operational purposes.
4. Types of Personal Data
Grey Tide Ltd may process:
-
Names
-
Business contact details
-
Email addresses
-
Telephone numbers
-
Employer or organisational details
-
Contractual information
-
Customer and supplier records
-
Professional correspondence
Grey Tide Ltd does not knowingly collect or process special category data unless explicitly required for a lawful business purpose.
5. Lawful Bases for Processing
Personal data will be processed only where one or more of the following applies:
-
Consent
-
Performance of a contract
-
Compliance with legal obligations
-
Protection of vital interests
-
Legitimate business interests
Where consent is used as the lawful basis, individuals may withdraw consent at any time.
6. Information Security
Grey Tide Ltd will implement appropriate security measures which may include:
-
Password-protected devices and accounts
-
Multi-factor authentication where available
-
Regular software updates and patching
-
Secure cloud storage solutions
-
Anti-malware and endpoint protection
-
Controlled access to information
-
Encrypted communications where appropriate
Personnel are responsible for taking reasonable care of information and reporting any security concerns immediately.
7. Data Sharing
Personal data will only be shared where:
-
Necessary to deliver contracted services.
-
Required by law.
-
Required for legitimate business operations.
-
Appropriate safeguards are in place.
Grey Tide Ltd will never sell personal data.
Third-party suppliers processing personal data on behalf of Grey Tide Ltd will be expected to apply appropriate security and privacy controls.
8. Data Retention
Personal information will be retained only for as long as necessary to:
-
Deliver services.
-
Meet contractual obligations.
-
Maintain business records.
-
Satisfy legal and regulatory requirements.
Data no longer required will be securely deleted, destroyed or anonymised.
9. Individual Rights
Individuals may exercise their rights under UK GDPR, including:
-
Right of access.
-
Right to rectification.
-
Right to erasure.
-
Right to restrict processing.
-
Right to object.
-
Right to data portability where applicable.
Requests should be submitted to Grey Tide Ltd using the contact details below.
10. Data Breach Management
Any actual or suspected personal data breach must be reported to the Director of Grey Tide Ltd as soon as possible.
Grey Tide Ltd will:
-
Assess the impact of the breach.
-
Contain and mitigate risks where possible.
-
Record relevant details.
-
Determine whether notification is required.
-
Notify affected individuals and regulatory authorities where legally required.
11. Responsibilities
The Director of Grey Tide Ltd is responsible for:
-
Ensuring compliance with this policy.
-
Reviewing data protection practices.
-
Ensuring appropriate security controls are maintained.
-
Managing any data protection incidents or complaints.
All personnel who process personal data are responsible for complying with this policy.
12. Contact Information
Questions regarding this policy or data protection matters should be directed to:
Grey Tide Ltd
Email: info@greytide.co.uk
© 2026 Grey Tide Ltd. All Rights Reserved | Registered in England and Wales | Company No. 17037454