Our commitment to data protection
Last updated: July 2026
spire-orbit is committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. We have implemented this GDPR Compliance Statement to provide information about how we collect and process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
spire-orbit acts as a Data Controller for personal information collected through our website and service enquiries. As a Data Controller, we determine the purposes and means of processing personal data.
Contact details:
spire-orbit
42 Charlotte Square
Edinburgh EH2 4HQ
United Kingdom
Email: [email protected]
We process personal data under the following lawful bases:
Under the UK GDPR, you have the following rights regarding your personal data:
You have the right to be informed about the collection and use of your personal data. This GDPR statement and our Privacy Policy provide this information.
You have the right to request a copy of the personal data we hold about you. We will respond to your request within one month of receipt.
You have the right to request that we correct any personal data that is inaccurate or incomplete.
You have the right to request the deletion of your personal data where there is no compelling reason for its continued processing. This right is not absolute and may be subject to legal obligations requiring us to retain certain data.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as while we verify the accuracy of contested data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. We do not currently engage in automated decision-making processes.
To exercise any of these rights, please contact us at [email protected]. We may request specific information from you to help us confirm your identity and ensure your right to access the information or exercise your other rights.
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
We primarily process personal data within the United Kingdom. Where data is transferred outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach, where feasible. Affected individuals will be notified directly where the breach is likely to result in a high risk to their rights and freedoms.
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
We may update this GDPR Compliance Statement from time to time. Any changes will be posted on this page with an updated revision date.