We use cookies to enhance your browsing experience and analyze site traffic. By continuing to use this site, you consent to our use of cookies.

birch-point
Advertising Content Home About Services Contact

GDPR Compliance

Last Updated: June 2026

Our Commitment to Data Protection

birch-point is committed to protecting your personal data and respecting your privacy rights under the UK General Data Protection Regulation (UK GDPR). This page outlines how we comply with GDPR requirements and explains your rights as a data subject.

Data Controller

For the purposes of UK GDPR, the data controller is:

birch-point
15 Castle Street
Liverpool L2 4SU
United Kingdom
Email: [email protected]

Lawful Basis for Processing

We process personal data only when we have a lawful basis to do so. The legal bases we rely on include:

Consent

When you provide explicit, informed consent for us to process your personal data for specific purposes, such as receiving marketing communications or storing optional information.

Contract Performance

When processing is necessary to fulfill our contractual obligations to you, such as providing property analysis services you have commissioned.

Legitimate Interests

When we have legitimate business interests that do not override your fundamental rights and freedoms. Examples include:

  • Improving our website and services
  • Detecting and preventing fraud
  • Ensuring network and information security
  • Responding to inquiries and providing customer support

Legal Obligation

When processing is necessary to comply with legal or regulatory requirements.

Your Rights Under GDPR

As a data subject, you have the following rights:

Right to Access

You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data, along with information about how it is being used.

Right to Rectification

You have the right to request correction of inaccurate personal data and to have incomplete data completed.

Right to Erasure

In certain circumstances, you have the right to request deletion of your personal data. This right applies when:

  • The data is no longer necessary for the purposes it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • Erasure is required to comply with a legal obligation

Right to Restriction of Processing

You have the right to request restriction of processing in certain circumstances, such as when:

  • You contest the accuracy of the personal data
  • Processing is unlawful but you oppose erasure
  • We no longer need the data but you require it for legal claims
  • You have objected to processing pending verification of legitimate grounds

Right to Data Portability

When processing is based on consent or contract performance and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.

Right to Object

You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

Right Not to Be Subject to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. We do not currently engage in automated decision-making.

Exercising Your Rights

To exercise any of your GDPR rights, please contact us at [email protected] with your request. We will:

  • Verify your identity to protect your personal data
  • Respond to your request within one month (extendable by two additional months for complex requests)
  • Provide the requested information free of charge unless the request is manifestly unfounded or excessive
  • Explain any reasons if we refuse your request

Data Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit and at rest
  • Access controls and authentication mechanisms
  • Regular security assessments and vulnerability testing
  • Staff training on data protection and security
  • Incident response procedures
  • Regular backups and disaster recovery plans

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the Information Commissioner's Office within 72 hours of becoming aware of the breach
  • Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms
  • Document the breach, including its effects and the remedial action taken

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Service delivery and customer relationship management
  • Compliance with legal, tax, and accounting obligations
  • Establishment, exercise, or defense of legal claims

When data is no longer required, we securely delete or anonymize it in accordance with our data retention schedule.

International Data Transfers

If we transfer your personal data outside the United Kingdom, we ensure appropriate safeguards are in place, such as:

  • Standard contractual clauses approved by the ICO
  • Adequacy decisions recognizing equivalent data protection
  • Binding corporate rules where applicable

Third-Party Processors

When we engage third-party processors to handle personal data on our behalf, we:

  • Ensure they provide sufficient guarantees of compliance with GDPR
  • Implement formal data processing agreements
  • Conduct due diligence on their security measures
  • Monitor their compliance with contractual obligations

Children's Data

Our services are not directed at children under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will take steps to delete it promptly.

Updates to This Notice

We may update this GDPR compliance notice to reflect changes in our practices or legal requirements. Material changes will be communicated through our website with an updated revision date.

Complaints and Supervisory Authority

If you believe we have not complied with your data protection rights or GDPR requirements, you have the right to lodge a complaint with the Information Commissioner's Office:

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: www.ico.org.uk

Contact Us

For questions about our GDPR compliance or to exercise your rights, please contact us:

Email: [email protected]
Address: 15 Castle Street, Liverpool L2 4SU, United Kingdom

birch-point

Independent property analysis and advisory services for Liverpool's luxury real estate market.

Quick Links

  • About Us
  • Services
  • Contact

Legal

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

Contact

15 Castle Street
Liverpool L2 4SU
United Kingdom

[email protected]

Disclaimer: The information and analysis provided by birch-point are for informational purposes only and should not be considered as financial or legal advice. Property investment carries risks, and past performance does not guarantee future results. We recommend consulting with qualified legal and financial professionals before making any property purchase decisions. Individual results may vary based on market conditions, property selection, and personal circumstances.

© 2026 birch-point. All rights reserved.