GDPR & Data Protection
Last reviewed: June 2026
Brylo Ltd is committed to protecting personal data and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page summarises how we comply, our roles as a controller and a processor, and how we help our clients meet their own obligations. It complements our Privacy Policy.
1. Our commitment
We process personal data fairly, lawfully and transparently. We collect only what we need, keep it accurate, retain it no longer than necessary, and protect it with appropriate security. We are registered with the Information Commissioner's Office (ICO), registration number [ICO REGISTRATION NUMBER].
2. Controller and processor roles
- For data we collect about our own visitors, enquirers and clients, we are the data controller — see our Privacy Policy.
- When we host or manage a website, application or system for a client, any personal data within it is generally processed by us as a data processor on that client's instructions. The client is the controller and is responsible for its own privacy notice and lawful basis.
3. The data protection principles
We apply the UK GDPR principles, processing personal data:
- lawfully, fairly and transparently;
- for specified, explicit and legitimate purposes;
- limited to what is necessary (data minimisation);
- accurately and kept up to date;
- for no longer than necessary; and
- securely, with integrity and confidentiality.
4. Your rights as a data subject
You have the right to be informed, and to access, rectify, erase, restrict, port and object to the processing of your personal data, and to withdraw consent where we rely on it. Full details and how to exercise these rights are in our Privacy Policy.
5. Data Processing Agreements (for clients)
Where we act as your processor, we will enter into a written Data Processing Agreement (DPA) that meets the requirements of Article 28 of the UK GDPR. Under it, we commit to:
- process personal data only on your documented instructions;
- ensure personnel are bound by confidentiality;
- apply appropriate technical and organisational security measures;
- use only approved sub-processors and remain responsible for them;
- assist you with data subject requests, security, breach notification and impact assessments;
- delete or return personal data at the end of the engagement; and
- make available the information needed to demonstrate compliance and allow audits.
Contact us at info@brylo.co.uk to request a DPA.
6. Sub-processors
We use a small number of trusted sub-processors to deliver our services, including providers of hosting and infrastructure, databases, payments, business email, domain registration, and (with consent) analytics. We select providers that offer appropriate safeguards, and we keep a current list available on request.
7. Security measures
Our technical and organisational measures include encryption of data in transit (TLS), hashed passwords, two-factor authentication, role-based access controls, least-privilege access, reputable cloud infrastructure, and regular review of our security practices.
8. Personal data breaches
We maintain procedures to detect, investigate and respond to personal data breaches. Where a breach is likely to result in a risk to people's rights and freedoms, we will notify the ICO without undue delay and, where feasible, within 72 hours, and will inform affected individuals or our client controllers without undue delay where required.
9. International transfers
We aim to process personal data in the UK and EEA. Where data is transferred outside the UK, we rely on appropriate safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses with the UK Addendum.
10. Data retention
We keep personal data only as long as necessary for the purposes for which it was collected and to meet legal obligations. Retention periods for data we control are set out in our Privacy Policy; for data we process for clients, retention is governed by the relevant DPA.
11. Exercising your rights and contacting us
To exercise your rights or ask a data protection question, email info@brylo.co.uk (please mark it "Data Protection"). If we process your data on behalf of one of our clients, we may direct your request to that client as the controller.
12. Complaints
You can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would welcome the chance to address your concerns first.