Skip to main content
Vermont Solutions

UK GDPR Privacy Notice

Supplemental privacy notice for users in the United Kingdom

⚠️ Draft pending legal review

This UK addendum is a working draft pending review by a UK GDPR / ICO specialist solicitor before being published as legally binding.

1. Introduction

This UK Addendum applies to users of vermont-solutions.com who access from the United Kingdom. It supplements our main Privacy Policy and explains how we comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Controller

Vermont Solutions S.L., NIF B66520446, with registered office at Agustín de Betancourt Street, 21 — 28003 Madrid, Spain.

Data Protection Officer: dpo@vermont-solutions.com

3. EU-UK data transfers

Vermont Solutions processes UK personal data on EU-based servers under the mutual EU-UK adequacy decisions in force since June 2021 (renewed 2024). No additional safeguards are required for routine transfers.

4. Lawful basis (UK GDPR Art. 6)

We rely on: consent for contact forms and newsletters; legitimate interests for analytics and B2B prospecting; performance of contract for active commercial relationships.

5. Your rights under UK GDPR

You have the rights of: information, access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making. Exercise them via dpo@vermont-solutions.com (30-day response, extendable by 60 days for complex cases).

6. Cookies and PECR

Our cookie practices comply with the Privacy and Electronic Communications Regulations 2003 (PECR) and ICO guidance: strictly necessary cookies require no consent; analytics and marketing cookies require prior, freely given, specific and informed consent.

7. Marketing under PECR

Marketing emails are sent only with explicit double opt-in. Each email contains a one-click unsubscribe link. We comply with PECR Regulation 22 and the ICO Direct Marketing Code of Practice.

8. Data breach notification

In the event of a breach likely to result in a high risk to your rights, we will notify the ICO within 72 hours (UK GDPR Art. 33) and inform you without undue delay (Art. 34).

9. Children's data

We do not knowingly process personal data of children under 13 years of age (UK threshold under DPA 2018 §9). Contact dpo@vermont-solutions.com for immediate deletion if a minor has provided data.

10. Right to complain — ICO

You can lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office — Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, UK — Phone: 0303 123 1113 — https://ico.org.uk/make-a-complaint/

11. ICO Data Protection Fee

Evaluation completed (2026-05-14): Vermont Solutions S.L. is established outside the UK with no UK office, no UK employees, and revenue below the GBP 632k threshold under the Data Protection (Charges and Information) Regulations 2018. Under the ICO Tier 1 self-assessment criteria, Vermont qualifies as a small organisation, fee approximately GBP 40/year. Vermont will register with the ICO as a foreign controller offering services to UK data subjects (UK GDPR Art. 3(2) targeting) once UK lead volume justifies registration; in the interim, EU-UK adequacy applies and Vermont processes UK data on EU servers under UK GDPR.

12. Updates

Last reviewed: 2026-05-14. Material changes will be communicated via the main Privacy Policy banner.