GDPR Information
Last updated: July 10, 2026
flickering-screw is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page provides information about how we comply with GDPR requirements and your rights under this regulation.
Data controller
flickering-screw acts as the data controller for the personal information we collect through our website and services. We determine the purposes and means of processing your personal data.
Contact details:
flickering-screw
27 Elmridge Avenue
Bristol BS6 7QT
United Kingdom
Email: [email protected]
Legal basis for processing
We process your personal data based on the following legal grounds:
- Contract performance: Processing necessary to fulfill our service agreement with you
- Legitimate interests: Processing necessary for our business operations, such as improving services and preventing fraud
- Consent: Processing based on your explicit consent for specific purposes
- Legal obligation: Processing necessary to comply with legal requirements
Your rights under GDPR
Under the GDPR, you have the following rights regarding your personal data:
Right to access
You have the right to obtain confirmation as to whether we are processing your personal data and, if so, to access that data along with certain information about how it is being processed.
Right to rectification
You have the right to have inaccurate personal data corrected and incomplete personal data completed.
Right to erasure
Also known as the "right to be forgotten," you have the right to request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purposes for which it was collected.
Right to restriction of processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to our processing.
Right to data portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to object
You have the right to object to processing of your personal data based on our legitimate interests or for direct marketing purposes.
Right to withdraw consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
How to exercise your rights
To exercise any of your rights under GDPR, please contact us at [email protected]. We will respond to your request within one month, though this period may be extended by two additional months if necessary, taking into account the complexity of your request.
When you submit a request, we may ask you to provide additional information to verify your identity and ensure we are disclosing information to the correct person.
Data retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Retention periods vary depending on the type of data and purpose of processing:
- Customer inquiry data: 2 years from last contact
- Project and transaction data: 7 years for accounting and legal purposes
- Marketing consent data: Until consent is withdrawn
- Website analytics data: 26 months
International data transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place, such as:
- EU Commission adequacy decisions
- Standard contractual clauses approved by the EU Commission
- Binding corporate rules
- Certification schemes
Data security measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments and penetration testing
- Access controls and authentication measures
- Employee training on data protection
- Incident response procedures
Data breach notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible.
Automated decision-making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
Children's data
We do not knowingly collect or process personal data from individuals under 16 years of age without parental consent. If we become aware that we have collected data from a child without proper consent, we will take steps to delete that information.
Updates to this information
We may update this GDPR information from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated information on this page.
Contact and questions
If you have questions about how we process your personal data under GDPR or wish to exercise your rights, please contact us at [email protected].