brook-sparrow
  • Home
  • About
  • Services
  • Contact
Information on this site is advertising in nature

GDPR Compliance

Last updated: September 2026

1. Our Commitment to Data Protection

brook-sparrow Ltd is committed to ensuring the security and protection of the personal information that we process. We have a consistent approach to data protection and have implemented measures to comply with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.

2. Data Controller Information

brook-sparrow Ltd acts as the Data Controller for the personal information we process. Our contact details are:

brook-sparrow Ltd
47 Finsbury Square
London EC2A 1PQ
United Kingdom

Data Protection Contact: [email protected]

3. Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Contract: Processing necessary for the performance of a contract with you (e.g., providing our travel card services).
  • Legal Obligation: Processing necessary to comply with legal requirements (e.g., anti-money laundering regulations).
  • Legitimate Interests: Processing necessary for our legitimate business interests, provided these do not override your rights.
  • Consent: Where you have given explicit consent for specific processing activities (e.g., marketing communications).

4. Your Rights Under GDPR

Under the GDPR, you have the following rights regarding your personal data:

Right of Access

You have the right to request a copy of the personal information we hold about you. We will provide this information free of charge within one month of receiving your request.

Right to Rectification

You have the right to request that we correct any personal information you believe is inaccurate or complete any information you believe is incomplete.

Right to Erasure

You have the right to request that we erase your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to request that we transfer the personal data we have collected to another organisation, or directly to you, in a structured, commonly used, and machine-readable format.

Right to Object

You have the right to object to our processing of your personal data in certain circumstances, including processing for direct marketing purposes.

Rights Related to Automated Decision Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you.

5. How to Exercise Your Rights

To exercise any of your rights, please contact us using the details provided above. When submitting a request, please provide:

  • Your full name and contact details
  • A description of the right you wish to exercise
  • Any information that will help us identify you in our systems

We will respond to your request within one month. If your request is complex or you have made multiple requests, we may extend this period by a further two months, but we will inform you if this is the case.

6. Data Security Measures

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data where appropriate
  • Regular testing and evaluation of security measures
  • Access controls limiting who can access personal data
  • Staff training on data protection and security
  • Incident response procedures for data breaches

7. Data Breach Procedures

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the Information Commissioner's Office within 72 hours of becoming aware of the breach
  • Communicate the breach to you without undue delay if it is likely to result in a high risk to your rights and freedoms
  • Document all personal data breaches and the measures taken in response

8. International Data Transfers

Where we transfer personal data outside the UK or European Economic Area, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the relevant authorities
  • Transfers to countries with an adequacy decision
  • Other legally approved transfer mechanisms

9. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. When data is no longer needed, we securely delete or anonymise it.

10. Complaints

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom

Website: ico.org.uk

We would, however, appreciate the opportunity to address your concerns before you approach the ICO, so please contact us in the first instance.

11. Updates to This Notice

We may update this GDPR compliance notice from time to time. Any significant changes will be communicated to you through our website or by email where appropriate.

brook-sparrow

Smarter travel money for the modern explorer.

Company

  • About Us
  • Our Cards
  • Contact

Legal

  • Privacy Policy
  • Terms of Use
  • Cookie Policy
  • GDPR

© 2026 brook-sparrow. All rights reserved.

We use cookies to enhance your browsing experience and analyse site traffic. By continuing to use this site, you consent to our use of cookies.

Learn more