GDPR Compliance

How SlotFixer complies with the UK General Data Protection Regulation.

Our Commitment

SlotFixer is fully committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We process personal data lawfully, fairly, and transparently.

Lawful Basis for Processing

We process personal data under the following lawful bases:

Contract

Processing necessary to provide the SlotFixer service (account management, job scheduling, invoicing).

Legitimate interest

Analytics, security, fraud prevention, and product improvement.

Consent

Marketing communications, GPS location tracking (employee app), and optional cookies.

Legal obligation

Financial record keeping as required by UK tax law.

Your Rights Under GDPR

As a data subject, you have the following rights:

Right of access

Request a copy of your personal data at any time.

Right to rectification

Correct inaccurate or incomplete data we hold.

Right to erasure

Request deletion of your personal data.

Right to restrict processing

Limit how we use your data.

Right to data portability

Receive your data in a machine-readable format.

Right to object

Object to processing based on legitimate interests.

Right to withdraw consent

Withdraw consent at any time without affecting prior processing.

Data Protection Measures

All data encrypted in transit using TLS 1.3
Database encryption at rest
Passwords hashed using bcrypt with salt rounds
Session tokens validated against IP address and user agent
Personal data automatically anonymised upon account deletion
Access controls limit data visibility to authorised personnel
Regular security audits and vulnerability assessments

Data Processing Agreements

We maintain Data Processing Agreements (DPAs) with all third-party processors including Supabase (database hosting), Vercel (application hosting), and Stripe (payment processing).

Data Breach Notification

In the event of a personal data breach, we will notify the Information Commissioner's Office (ICO) within 72 hours where required, and affected individuals without undue delay.

Data Protection Officer

For GDPR-related enquiries, data access requests, or to exercise your rights, contact our Data Protection Officer.

privacy@slotfixer.co.uk

Supervisory Authority

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated.

Visit ico.org.uk