Your Data Protection Rights Under UK GDPR

View our Privacy Policy

Your Rights Overview

Under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018, you have specific rights regarding your personal data. MAINNET Limited is committed to upholding these rights.

Response Time: We respond to all valid requests within 30 days, free of charge.

Identity Verification: We may request proof of identity to protect your data.

Contact: Email admin@mainnet.uk or call 020 3488 4346 to exercise any of your rights.

1. Right to Access (Subject Access Request)

What this means:

You can request a copy of all personal data we hold about you.

We will provide:

  • Confirmation that we're processing your data
  • A copy of your personal data
  • Details about how we use your data
  • Who we share it with
  • How long we keep it
  • Your rights regarding the data

How to request:

Email admin@mainnet.uk with "Subject Access Request" in the subject line.

2. Right to Rectification

What this means:

You can ask us to correct any inaccurate or incomplete personal data.

Examples:

  • Incorrect name spelling
  • Old address after moving
  • Outdated phone number
  • Wrong company information

How to request:

Login to your account to update details, or email admin@mainnet.uk with corrections.

3. Right to Erasure ('Right to be Forgotten')

What this means:

You can request deletion of your personal data in certain circumstances.

When this applies:

  • Data is no longer needed for original purpose
  • You withdraw consent (where consent was the legal basis)
  • You object and we have no overriding legitimate grounds
  • Data was unlawfully processed
  • Legal obligation requires erasure

When we can't delete:

  • Legal obligations (e.g., 6-year tax records under UK law)
  • Defending legal claims
  • Public health interests
  • Freedom of expression

How to request:

Email admin@mainnet.uk with "Erasure Request" in the subject line.

4. Right to Restrict Processing

What this means:

You can limit how we use your data without deleting it.

When this applies:

  • You contest data accuracy (while we verify)
  • Processing is unlawful but you don't want erasure
  • We no longer need data but you need it for legal claims
  • You've objected (while we assess legitimate grounds)

What happens:

We can store the data but not use it (except with consent or for legal claims).

How to request:

Email admin@mainnet.uk with "Restriction Request" and specify what to restrict.

5. Right to Data Portability

What this means:

You can receive your data in a machine-readable format to transfer to another service.

What data is portable:

  • Account details (name, email, addresses)
  • Order history and invoices
  • Product reviews
  • Saved payment methods (tokenized, not full card details)
  • Communication preferences

Conditions for portability:

  • Only data you provided to us or we observed about you
  • Only where processing is automated
  • Only where legal basis is consent or contract

Format provided:

CSV or JSON format, commonly used and machine-readable.

How to request:

Email admin@mainnet.uk with "Portability Request" in the subject line.

6. Right to Object

What this means:

You can object to certain types of processing.

Absolute right to object to:

  • Direct marketing - We must stop immediately
  • Marketing profiling - No exceptions

Qualified right to object to:

  • Processing based on legitimate interests
  • Processing for research/statistics
  • Processing for public tasks

We must stop unless we demonstrate compelling legitimate grounds.

How to object:

Email admin@mainnet.uk or click "unsubscribe" in marketing emails.

7. Rights Related to Automated Decision-Making

What this means:

You have rights when decisions are made about you without human involvement.

Our automated processing:

  • Fraud prevention screening: Orders may be automatically declined if they trigger fraud indicators such as mismatched billing addresses, high-risk IP addresses, or unusual order patterns
  • Credit checks: B2B customers requesting credit terms

What happens if flagged:

Orders flagged for fraud will be automatically declined or held for manual review. You'll receive an email notification explaining the decision.

Your rights:

  • Request human intervention
  • Request manual review of declined orders
  • Express your point of view
  • Contest the decision
  • Request explanation of logic involved

How to request review:

Email admin@mainnet.uk with "Automated Decision Review" in the subject line.

8. Right to Withdraw Consent

What this means:

Where we rely on consent, you can withdraw it at any time.

Areas using consent:

  • Marketing emails (B2C customers)
  • Marketing cookies
  • Analytics cookies

How to withdraw:

  • Marketing: Click unsubscribe in any email
  • Cookies: Use cookie settings on website
  • General: Email admin@mainnet.uk

How Long We Keep Your Data

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or to comply with legal obligations.

Data Type Retention Period Reason
Order & invoice data 6 years Tax law (HMRC requirement)
Customer accounts Active + 6 years after last activity Contract & tax obligations
Marketing consent Until withdrawn + 2 years Consent management & suppression list
Website analytics 26 months Business insights
Warranty records Warranty period + 1 year Support & legal obligations
Support tickets 3 years Customer service quality

International Transfers

Some of our service providers process personal data outside the UK. We ensure appropriate safeguards are in place:

Third-party services we use:

  • Stripe (Payment Processing): Data processed in the UK and EEA. Stripe complies with UK GDPR and uses Standard Contractual Clauses (SCCs) for international transfers. Your payment data is encrypted and tokenized.
  • Google Analytics: Data processed in the EEA and US. Google complies with UK GDPR and EU-US Data Privacy Framework.
  • Firebase (Chat Widget): Data processed in the EEA and US. Google complies with UK GDPR and uses SCCs.
  • Amazon Web Services (Hosting): Data hosted in AWS EU-West-1 (Ireland). AWS complies with UK GDPR.

Safeguards in place: Standard Contractual Clauses (SCCs), data processing agreements, and encryption in transit and at rest.

How to Exercise Your Rights

1

Contact Us

Email admin@mainnet.uk with your request

2

Verification

We may ask for ID to protect your data

3

Processing

We process within 30 days

4

Response

We fulfill or explain why we cannot

Making a Complaint

If you're unhappy with how we handle your data or requests:

Step 1: Contact Us

Email: admin@mainnet.uk
Phone: 020 3488 4346
We'll try to resolve your concerns directly.

Step 2: Contact the ICO

You have the right to lodge a complaint with the Information Commissioner's Office:

  • Website: ico.org.uk/make-a-complaint
  • Phone: 0303 123 1113
  • Live chat: Available on ICO website
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Contact Information

Data Controller:
MAINNET Limited
86-90 Paul Street, 3rd Floor
London, EC2A 4NE

Data Protection Contact:
Email: admin@mainnet.uk
Phone: 020 3488 4346

MAINNET Support

We typically reply within minutes

👋 Welcome!

How can we help you today?

End Chat Session?

This will clear your chat history and end the conversation.