This GDPR Privacy Notice supplements our Privacy Statement and applies specifically to individuals who reside in the European Union and United Kingdom. For comprehensive information about our data practices, security measures, and general privacy policies, please refer to our Privacy Statement.
This notice provides the specific information required under Articles 13 and 14 of the General Data Protection Regulation (GDPR) and UK GDPR, ensuring full transparency and compliance with European data protection law.
Data Controller: SureFlow Ltd
Registration: Company incorporated in England and Wales
Address: SureFlow Ltd, 1 Old Street Yard, London EC1Y 8AF, United Kingdom.
Contact: privacy@sureflow.com
1. About This Notice
This GDPR Privacy Notice supplements our Privacy Statement and applies specifically to individuals who reside in the European Union and United Kingdom. For comprehensive information about our data practices, security measures, and general privacy policies, please refer to our Privacy Statement.
This notice provides the specific information required under Articles 13 and 14 of the General Data Protection Regulation (GDPR) and UK GDPR, ensuring full transparency and compliance with European data protection law.
Data Controller: SureFlow Ltd
Registration: Company incorporated in England and Wales
Address: SureFlow Ltd, 1 Old Street Yard, London EC1Y 8AF, United Kingdom.
Contact: privacy@sureflow.com
2. GDPR Transparency Information (Articles 13 & 14)
Personal Data We Process
Data Category | Specific Information | Legal Basis | Purpose |
---|---|---|---|
Internet Activity Data | • Anonymized page views using cryptographic hashes • Session duration and user engagement metrics • Bounce rate analysis and navigation patterns • Browser type, version, and compatibility information • Device category and screen resolution data | Article 6(1)(f) Legitimate Interests | Website analytics and performance optimization, security monitoring, user experience enhancement |
Geolocation Data | • General geographic location at country/region level • Derived from IP address through geolocation services • No precise location or movement tracking | Article 6(1)(f) Legitimate Interests | Regional analytics for content localization, compliance with regional regulations |
Source of Data: Information is collected directly from your device through automated means when you visit and interact with our website. No data is obtained from third-party sources, data brokers, or external databases.
Data Recipients: No personal data is disclosed to external recipients. All processing is conducted internally by SureFlow Ltd personnel under strict confidentiality and security obligations.
Detailed Retention Periods:
- Visitor Identification Hashes: Automatically and permanently deleted within 24 hours using secure deletion protocols
- Aggregated Analytics Data: Retained for maximum 25 months in fully anonymized form for trend analysis and performance measurement
- Technical Server Logs: Maintained for 12 months maximum for security monitoring, system troubleshooting, and regulatory compliance
- Error and Security Logs: Retained for 6 months for technical support and incident response purposes
International Transfer Safeguards: Personal data may be processed in the United Kingdom, European Union, and United States under the following protective measures:
- UK-EU Transfers: Covered by adequacy regulations and mutual recognition agreements
- EU-US Transfers: Protected by Standard Contractual Clauses (SCCs) with supplementary technical safeguards
- Additional Protections: End-to-end encryption, access controls, and regular transfer impact assessments
3. Comprehensive Legitimate Interests Assessment
3.1 Our Identified Legitimate Interests
Primary Business Interests:
- Website Operation: Maintaining a secure, functional, and continuously available online presence for business communications and information sharing
- Security Protection: Detecting and preventing cybersecurity threats, malicious activities, and unauthorized access attempts
- Service Improvement: Understanding aggregate user behavior to enhance website functionality, accessibility, and user experience
- Business Development: Analyzing traffic patterns and engagement metrics for strategic planning and resource allocation
Technical and Operational Interests:
- Performance Optimization: Ensuring optimal website loading speeds, cross-browser compatibility, and responsive design effectiveness
- Error Detection: Identifying and resolving technical issues, broken links, and system malfunctions
- Capacity Planning: Understanding usage patterns for infrastructure scaling and resource allocation
- Compliance Monitoring: Ensuring website accessibility and adherence to technical standards
3.2 Detailed Necessity Assessment
Proportionality Analysis:
- Data Minimization: Collection limited to essential technical information required for stated purposes
- Anonymization Priority: Implementation of cryptographic hashing prevents individual identification while enabling aggregate analysis
- Purpose Limitation: Data used exclusively for disclosed purposes with no secondary processing for unrelated activities
- Alternative Methods Evaluation: No less intrusive methods identified that would achieve equivalent business objectives
Technical Necessity:
- Security Monitoring: Essential for detecting and preventing malicious activities that could compromise user safety and data integrity
- Performance Analysis: Required for identifying bottlenecks, errors, and optimization opportunities that directly impact user experience
- Compatibility Assurance: Necessary for ensuring website functionality across diverse browsers, devices, and operating systems
3.3 Comprehensive Balancing Test
Privacy Impact Assessment:
- Minimal Intrusion: Data collection involves only technical metadata with no personal identifiers or behavioral profiling
- Temporal Limitations: Individual tracking limited to 24-hour periods with automatic deletion of identifying information
- Aggregation Focus: Analysis conducted at aggregate level preventing individual identification or targeting
- No Cross-Site Tracking: Data collection confined exclusively to SureFlow website interactions
Individual Rights Protection:
- Transparency Measures: Comprehensive disclosure of all data processing activities through detailed privacy documentation
- Control Mechanisms: Multiple opt-out methods including browser settings, "Do Not Track" signals, and direct contact options
- Rights Exercise: Full GDPR rights available with clear procedures and responsive support
- Ongoing Monitoring: Regular assessment of privacy impact and balancing test validity
Legitimate Expectations Analysis:
- Industry Standards: Data collection practices consistent with standard website analytics and security monitoring
- User Awareness: Clear notification of data processing through privacy policies and website notices
- Reasonable Expectations: Processing aligns with typical user expectations for website functionality and security
3.4 Conclusion of Balancing Test
Our comprehensive analysis demonstrates that our legitimate interests in website operation, security, and improvement do not override the fundamental rights and freedoms of data subjects, given:
- The minimal, anonymized nature of data collection
- Strong technical and organizational safeguards
- Clear transparency and control mechanisms
- Alignment with reasonable user expectations
4. Your Comprehensive Rights Under GDPR
4.1 Right of Access (Article 15)
Scope of Access: You may request comprehensive information about our processing of your personal data, including:
- Confirmation of Processing: Whether we are processing personal data concerning you
- Data Categories: Specific categories of personal data being processed
- Processing Purposes: Detailed explanation of all purposes for which data is processed
- Recipient Information: Categories of recipients to whom data has been or will be disclosed
- Retention Periods: Specific or criteria-based retention periods for different data categories
- Data Source: Information about the source of personal data if not collected directly from you
- Automated Decision-Making: Details of any automated decision-making or profiling (not applicable to SureFlow)
- Transfer Safeguards: Information about international transfers and applicable safeguards
Access Request Process:
- Submit detailed written request specifying information sought
- Provide identity verification as required by law
- Receive comprehensive response within 30 days of verified request
4.2 Right to Rectification (Article 16)
Rectification Scope: Request correction or completion of inaccurate or incomplete personal data, including:
- Data Accuracy: Correction of factually incorrect information
- Data Completeness: Supplementation of incomplete data relevant to processing purposes
- Supporting Evidence: Provision of documentation supporting requested corrections
Implementation Process:
- Assessment of rectification request validity and supporting evidence
- Communication of corrections to all recipients where technically feasible
- Notification of actions taken within required timeframes
4.3 Right to Erasure - "Right to be Forgotten" (Article 17)
Erasure Grounds: Request deletion of personal data in the following circumstances:
- Purpose Fulfillment: Data no longer necessary for original collection and processing purposes
- Consent Withdrawal: Withdrawal of consent where processing was based on consent
- Unlawful Processing: Processing has been determined to be unlawful
- Legal Compliance: Erasure required for compliance with legal obligations
- Child Protection: Data was collected from a child without proper consent
Erasure Limitations: Right subject to overriding considerations including:
- Legal Obligations: Compliance with legal retention requirements
- Public Interest: Processing necessary for public interest or official authority exercise
- Legal Claims: Establishment, exercise, or defense of legal claims
4.4 Right to Restrict Processing (Article 18)
Restriction Grounds: Request limitation of processing activities when:
- Accuracy Disputes: Contesting data accuracy during verification period
- Unlawful Processing: Processing is unlawful but deletion is not desired
- Data Retention: SureFlow no longer needs data but you require it for legal claims
- Objection Assessment: Pending verification of legitimate grounds following objection
Restriction Implementation: Limited processing to storage and specific authorized activities with your consent.
4.5 Right to Data Portability (Article 20)
Portability Conditions: Receive personal data in structured, machine-readable format when:
- Consent Basis: Processing based on consent or contract performance
- Automated Processing: Data processed through automated means
- Technical Feasibility: Transfer technically feasible without affecting others' rights
Important Note: Given our anonymized data collection methods, data portability rights have limited practical application to SureFlow processing activities.
4.6 Right to Object (Article 21)
Objection Scope: Object to processing based on legitimate interests, including:
- General Objection: Object to any processing based on legitimate interests
- Specific Circumstances: Object based on particular situation affecting your rights
- Direct Marketing: Absolute right to object to direct marketing (not applicable to SureFlow)
Response Obligations: Upon objection, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or processing is necessary for legal claims.
4.7 Right to Withdraw Consent (Article 7)
Consent Withdrawal: Where processing is based on consent, you may withdraw consent at any time with the same ease as providing consent. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.
Important Limitation: Due to our anonymized hash-based visitor identification system, we may have limited technical ability to identify and act upon requests relating to specific individuals in our analytics data.
Note on Global Privacy Control (GPC): While GPC signals are primarily recognized under CCPA, SureFlow applies similar transparency measures globally by respecting browser-based privacy settings such as 'Do Not Track' where feasible.
5. How to Exercise Your Rights
5.1 Contact Information
Primary Contact Methods:
- Email: privacy@sureflow.com
- Subject Line: "GDPR Rights Request - [Specify Right Type]"
- Postal Mail: SureFlow Ltd, 1 Old Street Yard, London EC1Y 8AF, United Kingdom, Attention: Data Protection Officer
- Telephone: +447449457293 (specify GDPR inquiry during business hours)
5.2 Required Information for Rights Requests
Essential Details:
- Full Name: Your complete name and any alternative names used
- Contact Information: Current email address and telephone number
- Specific Right: Clear identification of which GDPR right you wish to exercise
- Relationship Description: Your relationship with SureFlow (typically "website visitor")
- Timeframe Information: Approximate dates or periods of website visits if known
- Supporting Documentation: Any additional information supporting your request
5.3 Verification and Response Process
Identity Verification:
- Reasonable Measures: Implementation of appropriate identity verification procedures
- Proportionate Verification: Verification methods proportionate to privacy risks and request nature
- Documentation Requirements: Acceptable forms of identity verification including government-issued identification
Response Timeline and Commitments:
- Standard Requests: Comprehensive response within 30 calendar days of verified request receipt
- Complex Requests: Extension up to 90 days total with detailed explanation of delay reasons
- Cost Structure: All requests processed free of charge unless manifestly unfounded or excessive
- Interim Communications: Regular updates on request processing status for complex cases
For complete operational details about our data practices, security measures, international transfers, and retention policies, please refer to our Privacy Statement.
This notice complies with the General Data Protection Regulation (GDPR) and UK GDPR.