Our approach
Awab Textiles Limited is committed to handling personal information fairly, lawfully and transparently. We aim to collect information for clear purposes, limit it to what is relevant, keep it accurate, retain it no longer than necessary and protect it with proportionate safeguards.
Responsibility and lawful processing
The company is responsible for deciding why and how personal information is used in its business. Before processing, we consider an appropriate lawful basis. This may include contract, legal obligation, legitimate interests, consent or another basis recognised under UK law. Where special-category information is ever relevant, an additional legal condition would be required; we do not ask website visitors to submit such information through the enquiry form.
Individual rights
You may ask whether we hold information about you and request a copy. You may also ask us to correct inaccurate information, complete incomplete information, erase information in relevant circumstances, restrict its use, object to processing based on legitimate interests or direct marketing, or receive certain information in a portable format. Rights are not absolute and may be limited by lawful exemptions or the need to protect another person's rights.
Requests and identity checks
Requests can be sent to zalayed@awabtextiles.co.uk or to our registered office. Please describe what you are asking for and provide enough information for us to identify the relevant records. We may request reasonable evidence of identity before disclosing information. We normally respond within the period required by law and will explain if a request is refused or requires additional time.
Automated decisions
We do not use the public website to make solely automated decisions about individuals that produce legal or similarly significant effects. If that position changes, appropriate information and safeguards will be provided.
Retention, accuracy and access
Business records are reviewed in line with their purpose, contractual relevance and legal retention requirements. Access is limited to people and providers who need the information for authorised work. We take reasonable steps to correct information when an inaccuracy is identified.
Security and incidents
Measures may include access controls, maintained systems, secure service providers, backup arrangements and staff awareness appropriate to the size and nature of the business. Suspected personal-data incidents should be reported promptly so they can be contained, assessed and documented. Where the law requires notification to the Information Commissioner's Office or affected people, we will act within the applicable timescale.
Processors and accountability
Providers processing personal information on our behalf should act only on documented instructions, maintain confidentiality, use suitable security and assist with relevant data-protection duties. We keep appropriate records of important decisions and review arrangements when services or risks materially change.