GDPR & CCPA Data Rights
Your rights over the data we hold, and exactly how to exercise them.
1. Scope of this notice
This notice explains how The Peddler LLC handles personal data under the EU and UK GDPR, the California Consumer Privacy Act as amended by the CPRA, and comparable state privacy laws. It sits alongside our Privacy Policy, which describes the data we collect through this website.
2. Controller and processor roles
For our own marketing, hiring and website analytics, we act as a data controller and decide why and how data is used.
When we run campaigns, CRM work, email programmes or analytics inside your accounts, we act as a data processor and only act on your documented instructions. In that case you remain the controller and are responsible for the lawful basis of the data you supply.
3. Lawful bases we rely on
We process personal data only where one of these applies:
- Consent — for marketing emails and non-essential cookies, withdrawable at any time.
- Contract — to deliver services you have engaged us for.
- Legitimate interests — to run, secure and improve our business, balanced against your rights.
- Legal obligation — for tax, accounting and regulatory record keeping.
4. Your rights
Subject to local law, you can ask us to:
- Access the personal data we hold about you and receive a copy.
- Correct data that is inaccurate or incomplete.
- Delete data where we no longer have a lawful reason to keep it.
- Restrict or object to processing, including profiling for marketing.
- Receive your data in a portable, machine-readable format.
- Opt out of the sale or sharing of personal data — we do not sell personal data.
- Be free from discrimination for exercising any of these rights.
5. Making a request
Email hello@thepeddler.agency with the subject line "Privacy Request". We verify identity before acting, respond within 30 days for GDPR requests and 45 days for CCPA requests, and will tell you if we need a permitted extension. An authorised agent may submit a request with written proof of authority.
6. Sub-processors and international transfers
We use vetted sub-processors for hosting, analytics, email delivery, advertising and payments, and we keep a current list available to clients on request. Where data leaves the EEA or UK, transfers rely on Standard Contractual Clauses plus the UK Addendum, together with technical safeguards such as encryption in transit and at rest.
7. Retention and security
We keep personal data only as long as needed for the purpose it was collected, plus any statutory retention period. Access is limited to staff who need it, protected by multi-factor authentication and reviewed regularly. We notify affected parties and the relevant supervisory authority of a qualifying breach without undue delay.
8. Complaints
If you are unhappy with how we handled your data, tell us first and we will try to resolve it. You also have the right to complain to your supervisory authority — the ICO in the UK, your national authority in the EEA, or the California Privacy Protection Agency in California.