Komforty
UK GDPR & Data Protection Policy
Last updated: 23 August 2026.
This policy explains the principles Komforty Limited applies when handling personal data in connection with its website and business enquiries.
Our responsibilities
We aim to process personal data lawfully, fairly and transparently; collect it for specified and legitimate purposes; keep it adequate, relevant and limited to what is necessary; maintain reasonable accuracy; retain it no longer than necessary; and protect it with appropriate security.
Lawful processing
Before processing personal data, we consider the purpose and an appropriate lawful basis. Typical bases for website and commercial enquiries include steps requested before a contract, performance of a contract, legal obligations and legitimate interests. Consent is used where required and may be withdrawn.
Individual rights
Individuals may, where applicable, request access, rectification, erasure, restriction, portability, or object to certain processing. Rights are not absolute and may be limited by lawful exemptions.
Subject access requests
Requests may be sent to info@komforty.co.uk. We may request reasonable information to verify identity and locate records. Requests will be handled within applicable statutory time limits.
Data minimisation and accuracy
We seek to collect only information reasonably needed for the relevant enquiry, transaction or business relationship. Where inaccurate information is identified, we will take reasonable steps to correct it.
Retention
Retention periods depend on the purpose of the information, the nature of the relationship and any legal or accounting obligations. Information no longer required should be securely deleted or anonymised where appropriate.
Security and breaches
Reasonable technical and organisational safeguards should be used to protect personal data. Suspected personal-data breaches should be assessed promptly and reported to the Information Commissioner’s Office or affected individuals where law requires.
Processors
Where third-party processors handle personal data on our behalf, they should be selected with regard to security and data-protection obligations and used only for authorised purposes.
International processing
Where personal data is transferred outside the UK, an appropriate legal safeguard should be used where required.
Review
This policy should be reviewed when material processing activities or relevant legal requirements change.