Overview
Ginkgo is operated by [PLACEHOLDER: Company name], which is subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page explains our approach to compliance and summarises your rights.
For full details of how we process personal data, see our Privacy Policy. For cookie-specific information, see our Cookie Policy.
Data protection principles
We process personal data in accordance with the principles set out in UK GDPR Article 5. In practice, this means:
- Lawfulness, fairness and transparency: We only collect data we have a lawful basis for, and we tell you how we use it.
- Purpose limitation: Data collected for one purpose is not used for unrelated purposes without your consent.
- Data minimisation: We collect only the data we need to provide the Service.
- Accuracy: We take reasonable steps to keep your data accurate. You can update your data at any time.
- Storage limitation: We retain data only as long as necessary. See our Privacy Policy for retention periods.
- Integrity and confidentiality: We use appropriate security measures to protect your data.
- Accountability: We maintain records of our processing activities and regularly review our data practices.
Lawful basis for processing
We rely on the following lawful bases under UK GDPR Article 6:
- Contract (Article 6(1)(b)): Processing necessary to provide the Service you have signed up for, including storing your inventory and managing your account.
- Legitimate interests (Article 6(1)(f)): Processing for purposes of app improvement, security, and fraud prevention, where our interests are not overridden by your rights.
- Consent (Article 6(1)(a)): For marketing communications and optional features such as our AI improvement programme. You may withdraw consent at any time.
- Legal obligation (Article 6(1)(c)): Where we are required by law to process data.
Your rights under UK GDPR
You have the following rights in relation to your personal data:
- Right of access (Article 15): You can request a copy of the personal data we hold about you. Use the export function in Settings, or contact us.
- Right to rectification (Article 16): You can correct inaccurate or incomplete data, either through the app or by contacting us.
- Right to erasure (Article 17): You can request deletion of your data. See Requesting data deletion.
- Right to restriction of processing (Article 18): In certain circumstances, you can ask us to limit how we use your data.
- Right to data portability (Article 20): You can receive your data in a machine-readable format. Use the export function in Settings.
- Right to object (Article 21): You can object to processing based on legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds.
- Rights related to automated decision-making (Article 22): We do not make solely automated decisions that have significant legal or similarly significant effects on you.
Making a data subject request
To exercise any of your rights, contact us at hello@ginkgo.app with the subject line "Data subject request".
Please include:
- Your name and the email address associated with your account
- The right you wish to exercise
- Any relevant details
We will respond within one calendar month. In complex cases we may extend this by a further two months, in which case we will notify you.
We may ask you to verify your identity before processing a request.
Data Protection Impact Assessments
We carry out Data Protection Impact Assessments (DPIAs) where processing is likely to result in a high risk to individuals' rights and freedoms, as required by UK GDPR Article 35. This includes our AI processing features and any new high-risk processing activities we introduce.
Data breaches
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it, as required by UK GDPR Article 33.
Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
If you believe your Ginkgo account has been compromised, contact us immediately at hello@ginkgo.app.
Complaints and the ICO
If you are not satisfied with how we have handled your personal data or a data subject request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
We would ask that you contact us first, as we are usually able to resolve concerns more quickly than the ICO. But you always have the right to go directly to the regulator.