Your data rights
Eight rights. Here's how to use them.
UK GDPR gives you real control over your data. Exercising it costs nothing, needs no special form, and we answer within a month.
Last updated: June 2026
01Plain-English summary
Email info@glebetech.com, say what you want, and we'll do it. You don't need to quote article numbers or use the word "GDPR" — a plain sentence is a valid request in law and we'll treat it as one.
One thing worth reading first: section 08. If your data sits inside a system we built for one of our clients, the request has to go to them, not us.
02Your rights in full
Be informed. To know what we collect and why. That's what the privacy policy is for.
Access. To get a copy of the personal data we hold about you, plus an explanation of what we do with it. This is often called a subject access request.
Rectification. To have inaccurate data corrected and incomplete data filled in.
Erasure. To have your data deleted — the "right to be forgotten". It isn't absolute; where we must keep records by law, section 07 explains.
Restrict processing. To have us keep your data but stop using it, for instance while we investigate a dispute about accuracy.
Data portability. To receive data you gave us in a structured, machine-readable format, and to have it sent straight to another provider where technically feasible.
Object. To object to processing based on legitimate interests. If you object to direct marketing we must stop immediately, with no balancing test.
Rights around automated decisions. Not to be subject to a decision made purely by automated means that has a legal or similarly significant effect. For the record, we don't make any such decisions about you — no automated profiling, scoring or filtering of enquiries.
Separately, where we rely on your consent, you can withdraw it whenever you like. Withdrawing doesn't undo processing that was lawful beforehand.
03How to make a request
Email info@glebetech.com with:
- what you'd like us to do — access, correct, delete, stop;
- enough detail to find you, such as the email address or company name you used when you contacted us;
- roughly when you were in touch, if you remember.
A verbal request is equally valid. If you'd rather phone, we'll write down what you asked for and confirm it back to you in writing.
04What we'll ask you for
Before handing over personal data we need to be confident you are who you say you are — otherwise a subject access request becomes a way to steal someone else's information.
Usually replying from the email address we already hold is enough. If we can't match your request to anything, we may ask one or two verifying questions. We won't demand ID documents unless there's a genuine doubt, and the clock in section 05 pauses only until we've verified you.
Acting for someone else? Send written authority from them.
05How long we take
One calendar month from the day we receive the request, or from the day we verify your identity if that's later.
If a request is unusually complex we can extend by up to two further months, but we'll tell you inside the first month and explain why. In practice, for a business of our size, a website enquiry request is a same-week job.
06What it costs
Nothing. We may only charge a reasonable fee if a request is manifestly unfounded or excessive — for example, the same request repeated over and over. We would tell you before charging anything, and we'd rather just answer.
07When we might not be able to say yes
The rights above have limits, and we'd rather be straight about them:
- We must keep invoices and accounting records for seven years, so erasure doesn't reach them.
- We may keep the minimum needed to defend a legal claim.
- We won't disclose data that would reveal someone else's personal information.
- Portability applies only to data you gave us that we process by consent or contract, not to our own notes about a project.
If we refuse part of a request we'll tell you which part, why, and how to challenge it.
08When we're not the right people to ask
Much of our work is building and running software for clients. The personal data inside those systems belongs to the client: they decide what happens to it and we act on their written instructions. In UK GDPR terms they are the controller and we are the processor.
That means if you're a customer of one of our clients, your rights are exercised against them, not us — they're the ones who can lawfully decide. Send a request to us by mistake and we won't ignore it: we'll forward it to the client without delay and tell you we've done so, so your one-month clock starts with the right organisation.
09Complaining
If we get something wrong, tell us first — email info@glebetech.com and we'll try to put it right.
You also have the right to complain to the Information Commissioner's Office at any time, and you don't have to come to us first. The ICO can be reached at ico.org.uk/make-a-complaint or on 0303 123 1113. Complaining to the ICO doesn't affect your right to a legal remedy.
10Changes
If the way we handle requests changes, we'll update this page and the date at the top.
Ready to make a request? Email info@glebetech.com