GDPR Compliance

Range8 Digital's commitment to data protection under the General Data Protection Regulation

Our Commitment to GDPR

Range8 Digital (operating as bespokepermonth.com) is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page explains our GDPR compliance measures and your rights under the regulation.

1. Data Controller

Range8 Digital acts as the data controller for personal data collected through our website and services. We determine how and why your personal data is processed.

Contact: [email protected]

2. Legal Basis for Processing

We process your personal data under the following legal bases:

  • Consent: You have given clear consent for us to process your personal data for specific purposes (e.g., marketing communications)
  • Contract: Processing is necessary to fulfill our contractual obligations to you
  • Legal Obligation: Processing is necessary to comply with legal requirements
  • Legitimate Interests: Processing is necessary for our legitimate business interests (e.g., fraud prevention, improving services)

3. Your Rights Under GDPR

You have the following rights regarding your personal data:

3.1 Right to Access

You have the right to request copies of your personal data. We may charge a small fee for this service.

3.2 Right to Rectification

You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.

3.3 Right to Erasure

You have the right to request that we erase your personal data, under certain conditions (e.g., when data is no longer necessary for the purposes it was collected).

3.4 Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data, under certain conditions.

3.5 Right to Object

You have the right to object to our processing of your personal data, under certain conditions.

3.6 Right to Data Portability

You have the right to request that we transfer your data to another organization, or directly to you, under certain conditions.

3.7 Right to Withdraw Consent

Where we rely on consent to process your personal data, you have the right to withdraw that consent at any time.

4. How to Exercise Your Rights

To exercise any of your rights, please contact us at [email protected]. We will respond to your request within one month.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.

5. Data We Collect

We collect and process the following categories of personal data:

  • Identity Data: Name, business name
  • Contact Data: Email address, phone number, business address
  • Financial Data: Payment card details, billing information
  • Transaction Data: Details about payments and services subscribed
  • Technical Data: IP address, browser type, device information
  • Usage Data: Information about how you use our website and services
  • Marketing and Communications Data: Your preferences in receiving marketing communications

6. How We Use Your Data

We use your personal data for:

  • Providing and managing our services
  • Processing payments and managing subscriptions
  • Communicating with you about our services
  • Improving our website and services
  • Marketing communications (with your consent)
  • Complying with legal obligations
  • Fraud prevention and security

7. Data Retention

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

When determining the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process your data, and applicable legal requirements.

8. Data Security

We have implemented appropriate technical and organizational measures to secure your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

These measures include:

  • SSL/TLS encryption for data transmission
  • Encrypted data storage
  • Regular security audits and updates
  • Access controls and authentication
  • Employee training on data protection
  • Regular backups

9. Third-Party Data Processors

We may share your personal data with third-party service providers who process data on our behalf. These processors include:

  • Payment processors
  • Email service providers (Mailgun)
  • Hosting providers
  • Analytics services
  • Security services (Cloudflare)

All third-party processors are required to respect the security of your personal data and to treat it in accordance with the law. We only permit them to process your data for specified purposes and in accordance with our instructions.

10. International Data Transfers

Some of our service providers may be located outside the European Economic Area (EEA). When we transfer your personal data outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions recognizing equivalent data protection levels
  • Other appropriate safeguards as required by GDPR

11. Data Breach Notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.

12. Children's Privacy

Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

13. Automated Decision Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.

14. Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.

ICO Website: ico.org.uk
ICO Helpline: 0303 123 1113

15. Updates to This Policy

We may update our GDPR compliance information from time to time. We will notify you of any significant changes via email or through our website.

16. Contact Us

If you have any questions about our GDPR compliance or wish to exercise your rights, please contact us: