Your data protection rights under UK GDPR
Last updated: July 2026
dificcatec is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take your privacy seriously and ensure that all personal data we process is handled lawfully, fairly, and transparently.
dificcatec acts as the data controller for personal information collected through this website and in connection with our educational services.
Contact details:
dificcatec
15 Cathedral Road
Cardiff, CF11 9HA
United Kingdom
Email: [email protected]
We process personal data based on one or more of the following lawful bases:
As a data subject, you have the following rights:
You have the right to know how your data is being collected and used. This GDPR notice and our Privacy Policy provide this information.
You can request a copy of the personal data we hold about you. This is known as a Subject Access Request (SAR). We will respond within one month of receiving your request.
If you believe the data we hold is inaccurate or incomplete, you have the right to request correction. We will respond within one month.
Also known as the "right to be forgotten", you can request deletion of your personal data in certain circumstances, including:
You can request that we limit how we use your data while concerns are investigated or resolved.
You have the right to receive your personal data in a structured, commonly used format and to transmit it to another controller.
You can object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds.
You have the right not to be subject to decisions based solely on automated processing that significantly affects you. We do not currently use automated decision-making.
To exercise any of your data protection rights, please contact us at [email protected]. We may request verification of your identity before processing your request. There is no fee for most requests, though we may charge a reasonable fee for manifestly unfounded or excessive requests.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
We implement appropriate technical and organisational measures to protect personal data, including:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours. Where the breach is likely to result in high risk to you, we will also notify you directly without undue delay.
Where we use third-party service providers to process data on our behalf, we ensure appropriate data processing agreements are in place that require them to meet UK GDPR standards.
Where personal data is transferred outside the UK, we ensure adequate safeguards are in place, such as standard contractual clauses approved by the Information Commissioner's Office.
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
We may update this GDPR notice periodically. The "Last updated" date at the top indicates when changes were last made.