Privacy Policy

Last Updated: 24/6/2025
1. Introduction
This Privacy Policy explains how [Company Name] (“we”, “us”, or “our”) collects, uses, stores, and protects your personal information when you use our website, services, or interact with us. We are committed to protecting your privacy and ensuring compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data Controller Information
Company Name: Balstreet Limited
Registered Address: C/O Holder Blackthorn LLP
50-54 St Pauls Square
Birmingham
B3 1QS
Contact Email: sales@stormmaster.co.uk
Phone Number: 0333 3220 190
2. Information We Collect
2.1 Personal Information You Provide
We may collect the following personal information that you voluntarily provide to us:
Contact Information: Name, email address, phone number, postal address
Account Information: Username, password, profile information
Communication Data: Information contained in communications you send to us
Transaction Information: Payment details, billing address, purchase history
Marketing Preferences: Your preferences regarding marketing communications
Technical Information: IP address, browser type, device information
Usage Data: How you use our website and services
2.2 Information We Collect Automatically
When you visit our website or use our services, we may automatically collect:
Cookies and Similar Technologies: Information stored on your device
Log Files: Server logs containing IP addresses, browser information, and page requests
Analytics Data: Website usage statistics and user behaviour patterns
Device Information: Hardware model, operating system, unique device identifiers
3. Legal Basis for Processing
We process your personal data under the following legal bases:
Consent: Where you have given clear consent for us to process your data
Contract: Where processing is necessary for the performance of a contract
Legal Obligation: Where we need to comply with legal requirements
Legitimate Interests: Where we have legitimate business interests that don’t override your rights
Vital Interests: Where processing is necessary to protect someone’s life
Public Task: Where processing is necessary for the performance of a public task
4. How We Use Your Information
4.1 Primary Purposes
We use your personal information for the following purposes:
Service Provision: To provide, maintain, and improve our services
Account Management: To create and manage your account
Communication: To respond to your enquiries and provide customer support
Transaction Processing: To process payments and fulfill orders
Legal Compliance: To comply with legal obligations and protect our rights
Security: To maintain the security and integrity of our systems
4.2 Marketing Communications
With your consent, we may use your information to:
Send you promotional materials and offers
Provide you with information about products and services
Conduct market research and surveys
You can opt out of marketing communications at any time by:
Clicking the unsubscribe link in our emails
Contacting us directly at [Insert Email]
Updating your preferences in your account settings
5. Data Sharing and Disclosure
5.1 Third-Party Service Providers
We may share your personal information with trusted third-party service providers who assist us in:
Payment processing
Website hosting and maintenance
Email delivery services
Analytics and marketing tools
Customer support systems
All third-party providers are contractually bound to protect your data and only use it for specified purposes.
5.2 Legal Requirements
We may disclose your personal information if required to:
Comply with legal obligations
Respond to lawful requests from authorities
Protect our rights, property, or safety
Prevent fraud or illegal activities
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal information may be transferred to the new entity, subject to the same privacy protections.
6. Data Retention
6.1 Retention Periods
We retain your personal information for as long as necessary to fulfill the purposes outlined in this policy:
Account Information: Retained while your account is active plus 7 years after closure
Transaction Records: Retained for 7 years for accounting and legal purposes
Marketing Data: Retained until you withdraw consent or 3 years of inactivity
Website Analytics: Typically retained for 26 months
Communications: Retained for 3 years unless longer retention is required
6.2 Automated Deletion
We have implemented automated systems to delete personal data when retention periods expire, unless there are legal reasons to retain the information longer.
6.3 Factors Affecting Retention
Retention periods may be extended if:
Legal proceedings are ongoing
Regulatory investigations are in progress
Contractual obligations require longer retention
Your consent extends the retention period
7. Data Security
7.1 Security Measures
We implement appropriate technical and organisational measures to protect your personal information:
Encryption: Data is encrypted in transit and at rest
Access Controls: Strict access controls and authentication procedures
Regular Updates: Systems and software are regularly updated
Staff Training: Regular training on data protection and security
Monitoring: Continuous monitoring for security threats

Incident Response: Procedures for responding to data breaches
7.2 Data Breach Notification
In the event of a personal data breach, we will:
Notify the Information Commissioner’s Office (ICO) within 72 hours
Inform affected individuals without undue delay if there is a high risk
Take immediate steps to contain and remedy the breach
Conduct a thorough investigation to prevent future incidents
8. International Transfers
8.1 Transfers Outside the UK
If we transfer your personal data outside the UK, we ensure adequate protection through:

Adequacy Decisions: Transfers to countries with adequate data protection
Standard Contractual Clauses: Approved contractual protections
Binding Corporate Rules: Internal data protection standards
Certification Schemes: Recognised data protection certifications
8.2 Safeguards
All international transfers include appropriate safeguards to protect your rights and ensure your data receives equivalent protection.
9. Your Rights Under UK GDPR
9.1 Individual Rights
You have the following rights regarding your personal data:
Right of Access
You can request confirmation of whether we process your personal data and obtain a copy of your data.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure (Right to be Forgotten)
You can request deletion of your personal data in certain circumstances.
Right to Restrict Processing
You can request that we limit how we use your personal data.
Right to Data Portability
You can request your data in a structured, machine-readable format.
Right to Object
You can object to processing based on legitimate interests or for direct marketing.
Rights Related to Automated Decision-Making
You have rights regarding automated decision-making and profiling.
9.2 Exercising Your Rights
To exercise any of these rights, please contact us using the details provided in Section 12.
10. Subject Access Requests (SAR)
10.1 Making a Request
You can request access to your personal data by:
Email: Send a request to sales@stormmaster.co.uk
Post: Write to us at StormMaster, C/O Holder Blackthorn LLP, 50-54 St Pauls Square, Birmingham B3 1QS

10.2 Information Required
To process your request, please provide:
Your full name and contact details
Proof of identity (copy of passport, driving licence, or utility bill)
Specific information about the data you’re requesting
Preferred format for receiving the information
10.3 Response Timeline
We will respond to your request:
Within one month of receiving a valid request
Extended to three months for complex requests (we’ll explain why)
Free of charge unless the request is excessive or repetitive
10.4 What We’ll Provide
Our response will include:
Confirmation of whether we process your personal data
Categories of personal data we hold
Purposes of processing
Recipients or categories of recipients
Retention periods
Your rights regarding the data
A copy of your personal data in an accessible format
11. Permanent Data Deletion
11.1 Deletion Process
When you request deletion of your personal data, we will:
Verify your identity to prevent unauthorised deletion requests
Assess the request against legal and contractual obligations
Confirm deletion scope and timeline with you
Execute secure deletion from all systems and backups
Provide confirmation once deletion is complete
11.2 Secure Deletion Methods
We use industry-standard methods to ensure permanent deletion:
Cryptographic erasure for encrypted data
Multi-pass overwriting for unencrypted data
Physical destruction for hardware containing data
Certificate of destruction for sensitive data disposal
11.3 Deletion Limitations
We may not be able to delete your data if:
Legal obligations require retention
Ongoing legal proceedings involve the data
Contractual obligations prevent deletion
Other individuals’ rights would be affected
The data has been anonymised
11.4 Partial Deletion
If complete deletion isn’t possible, we may:
Delete what we legally can
Anonymise remaining data
Restrict processing of retained data
Explain why complete deletion isn’t possible
12. Cookies and Similar Technologies
12.1 Types of Cookies
We use the following types of cookies:
Essential Cookies: Necessary for website functionality
Performance Cookies: Help us improve website performance
Functional Cookies: Remember your preferences
Marketing Cookies: Used for advertising and marketing
12.2 Managing Cookies
You can control cookies through:
Browser settings to block or delete cookies

13. Children’s Privacy
We do not knowingly collect personal information from children under 13 years of age. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information immediately. Parents or guardians who believe their child has provided personal information should contact us immediately.
14. Changes to This Privacy Policy
14.1 Policy Updates
We may update this Privacy Policy from time to time to reflect:
Changes in our practices
Legal or regulatory requirements
New features or services
Feedback from users or regulators
14.2 Notification of Changes
When we make significant changes, we will:
Update the “Last Updated” date at the top of this policy
Notify you by email if you have an account with us
Display a prominent notice on our website
Obtain fresh consent where required by law
14.3 Continued Use
Your continued use of our services after changes take effect constitutes acceptance of the updated Privacy Policy.
15. Contact Information and Complaints
15.1 Data Protection Contact
For questions about this Privacy Policy or our data practices:
Email: sales@stormmaster.co.uk
Phone: 0333 3220 190
Post: StormMaster, C/O Holder Blackthorn LLP, 50-54 St Pauls Square Birmingham B3 1QS

15.2 Response Time
We aim to respond to all enquiries within:
5 working days for general enquiries
1 month for formal rights requests
72 hours for urgent security matters
15.3 Complaints Process
If you’re not satisfied with our response:
1. Internal Escalation: Contact our senior management team
2. External Complaint: Contact the Information Commissioner’s Office (ICO)
ICO Contact Details:
Website: https://ico.org.uk
Phone: 0303 123 1113
Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
15.4 Right to Lodge a Complaint
You have the right to lodge a complaint with the ICO if you believe we have not handled your personal data in accordance with UK GDPR. This right is in addition to any other legal remedies you may have.

Appendix: Definitions
* Data Controller: The entity that determines the purposes and means of processing personal data
* Data Processor: The entity that processes personal data on behalf of the data controller
* Data Subject: The individual to whom personal data relates
* Personal Data: Any information relating to an identified or identifiable natural person
* Processing: Any operation performed on personal data
* Consent: Freely given, specific, informed agreement to the processing of personal data
* Legitimate Interests: The lawful basis for processing when it’s necessary for legitimate business purposes
* Special Categories: Sensitive personal data requiring additional protection