GDPR Compliance
Protecting privacy, ensuring transparency, and maintaining trust across every system we manage.
Our Commitment to Data Protection
CaminhoIT fully complies with the UK General Data Protection Regulation (UK GDPR) and the EU GDPR. As both a data controller (for our own business operations) and a data processor (for client systems and services), we uphold the principles of fairness, transparency, and accountability in all data handling activities.
1. Lawful, Fair & Transparent Processing
All data collected and processed by CaminhoIT is done lawfully, with a clear purpose and communicated transparently to individuals. We ensure that users are informed of how their data will be used at the time of collection.
2. Purpose Limitation
We process personal data only for legitimate business functions — such as account management, service delivery, or compliance with legal obligations — and never for unrelated purposes.
3. Data Minimisation
CaminhoIT collects only the minimum personal data required to provide services effectively. We avoid excessive or irrelevant data collection and regularly review stored data for necessity.
4. Accuracy & Integrity
Clients and users can update their data at any time. CaminhoIT maintains internal review processes to ensure that personal data remains accurate and up-to-date across all systems.
5. Storage Limitation
Personal data is retained only for as long as required to deliver services or meet regulatory requirements. When no longer needed, data is securely deleted or anonymized according to GDPR Article 5(1)(e).
6. Confidentiality & Security
CaminhoIT implements technical and organizational measures to protect personal data from unauthorized access, alteration, or destruction. This includes encryption, network monitoring, access logging, and restricted administrative permissions.
7. Data Subject Rights
Under GDPR, you have the right to:
- Access your personal data
- Request correction or deletion
- Restrict or object to processing
- Request data portability
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
8. Data Processing Roles
CaminhoIT acts as:
- Data Controller – for our own website, customer management, and operational data
- Data Processor – for client systems where we manage or host data under contract
9. Third-Party Processors
Where external service providers are used (e.g., Microsoft for 365 or Azure services), CaminhoIT ensures appropriate data protection agreements (DPAs) are in place. We only engage vendors that demonstrate GDPR compliance and provide adequate safeguards.
10. Data Transfers
CaminhoIT’s infrastructure is located within the UK and EU. Any transfer of personal data outside these regions occurs only when necessary and with approved mechanisms such as Standard Contractual Clauses (SCCs).
11. Breach Notification
In the unlikely event of a personal data breach, CaminhoIT will promptly notify affected clients and relevant authorities in accordance with GDPR Articles 33 and 34.
12. Data Protection Officer
CaminhoIT’s appointed Data Protection Lead oversees compliance and privacy strategy. For GDPR-related enquiries, contact privacy@caminhoit.com.
13. Accountability & Governance
CaminhoIT maintains internal policies, staff training, and technical documentation to ensure GDPR compliance is embedded across all levels of operation.
14. Continuous Improvement
Our GDPR practices are reviewed regularly to adapt to new legal interpretations, client requirements, and technological developments.
CaminhoIT — Powering Smarter IT, Sustainably.
For any GDPR or data protection concerns, please contact privacy@caminhoit.com.