Our commitment to protecting your data rights
Muse-petal is committed to ensuring that we process all personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page provides information about how we fulfil our obligations under these regulations.
Muse-petal is the data controller for personal data collected through this website and in connection with our services. This means we determine why and how your personal data is processed.
Contact details:
Address: 47 Riverside Business Centre, Chapel Street, Manchester M3 5BN
Email: [email protected]
We only process personal data where we have a lawful basis to do so. The lawful bases we rely upon include:
When you engage our services, we process your personal data as necessary to perform our contract with you. This includes processing your financial information to conduct the fee analyses you have requested.
We may process personal data where it is necessary for our legitimate business interests, provided these are not overridden by your rights and freedoms. Our legitimate interests include:
Where we rely on consent as our lawful basis for processing, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
We may process personal data where necessary to comply with our legal obligations, such as maintaining business records or responding to lawful requests from authorities.
Under UK GDPR, you have the following rights in relation to your personal data:
You have the right to be informed about how we collect and use your personal data. This GDPR page, along with our Privacy Policy, fulfils this obligation.
You have the right to request a copy of the personal data we hold about you. This is commonly known as a "Subject Access Request." We will respond to such requests within one month.
You have the right to have inaccurate personal data corrected or completed if it is incomplete. Please contact us if you believe any information we hold about you is incorrect.
Also known as the "right to be forgotten," you can request the deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we limit how we use your personal data in certain circumstances, for example, while we are verifying the accuracy of data you have disputed.
Where we process your data based on consent or contract performance, and the processing is automated, you have the right to receive your personal data in a structured, commonly used, and machine-readable format.
You have the right to object to processing based on legitimate interests or for direct marketing purposes. If you object to processing for direct marketing, we will stop processing your data for that purpose immediately.
You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not currently engage in such automated decision-making.
To exercise any of your data protection rights, please contact us at [email protected]. We may need to verify your identity before processing your request.
We will respond to all legitimate requests within one month. Occasionally, it may take us longer if your request is particularly complex or you have made multiple requests, in which case we will notify you and keep you updated.
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk involved in our processing activities. These measures include:
We have procedures in place to detect, report, and investigate personal data breaches. Where a breach is likely to result in a high risk to the rights and freedoms of individuals, we will notify affected individuals without undue delay. We will also report relevant breaches to the Information Commissioner's Office within 72 hours of becoming aware of them.
We primarily process data within the United Kingdom and do not routinely transfer personal data internationally. Should circumstances require international transfer, we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK ICO.
Where we use third-party processors to handle personal data on our behalf, we ensure they provide sufficient guarantees to implement appropriate technical and organisational measures. We have written contracts with all processors that set out their obligations regarding data protection.
Given the nature and scale of our processing activities, we are not required to appoint a Data Protection Officer. However, data protection matters are taken seriously at every level of our organisation. For any data protection queries, please contact us at [email protected].
If you are unhappy with how we have handled your personal data, we would ask that you contact us first so we can try to resolve the issue. You also have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: www.ico.org.uk
We may update this GDPR compliance information periodically to reflect changes in our practices or regulatory requirements. The date of the last update will be noted at the top of this page.
Last updated: January 2024
The information provided on this website is for general informational purposes only and should not be construed as professional financial advice. Individual circumstances vary, and results may differ based on your specific banking arrangements and usage patterns. We recommend consulting with a qualified financial adviser before making significant changes to your banking setup. Muse-petal does not guarantee specific savings outcomes and is not affiliated with any banking institution mentioned in our analyses.