GDPR POLICY
StoneLark Group Limited · Version 1.1 · Last updated: June 2026
This policy sets out how StoneLark Group Limited (trading as StoneLark, company number 16834095, registered office: 22 Court Farm House, Court Lane, Bratton, United Kingdom, BA13 4RF) meets its obligations as a data controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It should be read alongside our Privacy Notice, available at stonelark.co.uk/privacy.
1. OUR COMMITMENT
StoneLark is committed to handling personal data lawfully, transparently and with respect for the people whose data we process. We collect only what we need, we use it only for the purpose for which it was obtained, and we protect it appropriately. This is not simply a legal obligation — it reflects how we operate across everything we do.
2. THE SIX PRINCIPLES OF UK GDPR
StoneLark processes personal data in accordance with the six principles set out in UK GDPR.
| Principle | How StoneLark applies it |
| Lawfulness, fairness and transparency | We process data only where we have a lawful basis and are open about what we do and why. |
| Purpose limitation | We collect data for specific, explicit purposes and do not use it for anything incompatible with those purposes. |
| Data minimisation | We collect only what is necessary. We do not gather data speculatively. |
| Accuracy | We take reasonable steps to keep personal data accurate and up to date. |
| Storage limitation | We do not retain data longer than necessary. Retention periods are set out in our Privacy Notice. |
| Integrity and confidentiality | We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss or destruction. |
3. LAWFUL BASES FOR PROCESSING
Depending on the nature of the processing, StoneLark relies on one or more of the following lawful bases:
– Contract — where processing is necessary to deliver services the individual has engaged us to provide.
– Legitimate interests — where we have a genuine business reason that is not overridden by the individual’s rights. We assess this before relying on it.
– Consent — where we have received clear, specific consent. This can be withdrawn at any time.
– Legal obligation — where we are required by law to process or retain certain data.
4. HOW WE PROTECT PERSONAL DATA
Personal data is held on password-protected devices and within the business platforms we use day to day. We protect it by:
– Limiting access to those who need it to perform their role.
– Using reputable service providers who maintain appropriate security standards and, where required, have data processing agreements in place.
– Requiring associates and subcontractors to be bound by confidentiality obligations before being given access to any personal data.
– Not retaining physical records beyond what is necessary.
5. AI-ASSISTED TOOLS
StoneLark uses AI-assisted tools as part of its working practice. These are used responsibly. We will not input personal data or client confidential information into any AI tool in a way that would cause it to be retained or shared beyond the immediate purpose for which it is needed.
6. DATA BREACHES
In the event of a personal data breach, StoneLark will assess the risk without undue delay. Where a breach is likely to result in a risk to individuals’ rights and freedoms, we will notify the ICO within 72 hours and, where the risk is high, notify affected individuals directly. Any suspected breach should be reported immediately to hello@stonelark.co.uk.
7. INDIVIDUAL RIGHTS
StoneLark respects the rights of individuals under UK GDPR, including the right to access, correct, erase, restrict or port their data, and to object to processing. To exercise any of these rights, contact us at hello@stonelark.co.uk. We will respond within one calendar month. You also have the right to complain to the ICO (registration reference: ZC042538) at ico.org.uk or on 0303 123 1113.
8. POLICY REVIEW
This policy will be reviewed annually or following any significant change to our operations, the tools we use, or applicable data protection law. The current version is always available at stonelark.co.uk/privacy. For questions, contact hello@stonelark.co.uk.
