Last updated: 18 June 2026
valley-echo operates in full compliance with the General Data Protection Regulation (GDPR) and UK data protection law. We recognize the importance of protecting your personal information and have implemented appropriate technical and organizational measures to ensure data security.
We process your personal data under the following legal bases:
Under GDPR, you have the following rights regarding your personal data:
To exercise any of these rights, please submit a written request to [email protected] or send postal mail to our business address. We will respond within one month of receiving your request.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not handled your data appropriately. Contact details for the ICO can be found at ico.org.uk.
We retain client information for seven years after service completion to comply with business record requirements. After this period, personal data is securely deleted unless we have a legal obligation to retain it longer.
Marketing consent can be withdrawn at any time, and we will remove you from our marketing lists within 48 hours of receiving your request.
We employ industry-standard security measures to protect your data from unauthorized access, alteration, disclosure, or destruction. These measures include:
We do not transfer personal data outside the United Kingdom. All data processing occurs within the UK using servers and facilities subject to UK data protection law.
We may engage third-party service providers to assist with business operations, such as email hosting or appointment scheduling. These processors are carefully selected and contractually required to handle your data in accordance with GDPR requirements.
For questions about GDPR compliance or to exercise your data protection rights, contact us at [email protected]. Please include "Data Protection Request" in the subject line.