Legal
Data Protection
How Global SoLARK Limited meets UK data protection law: for our own records, and when we handle personal data on behalf of the organisations we work for.
1Our commitment
We design and build data platforms and AI systems, so handling personal data carefully is part of our work, not an add-on. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and follow the principles they set out:
- use personal data lawfully, fairly and transparently;
- collect it only for clear, specific purposes;
- collect no more than we need;
- keep it accurate;
- keep it no longer than necessary; and
- keep it secure.
2Controller and processor
As a controller, we decide how to use personal data for our own business: responding to enquiries, managing clients and suppliers, recruitment and our accounts. Our Privacy Policy explains this in full.
As a processor, we handle personal data on behalf of a client, for example when we build or support a system that holds its customers’ or students’ records. In that case the client decides how the data is used, and we act only on its documented instructions.
3When we work with your data
When we act as a processor, we:
- put a written data processing agreement in place that meets Article 28 of UK GDPR, before any personal data is shared;
- use the data only to deliver the agreed work, and never for our own purposes;
- work in systems and accounts that the client owns and controls wherever possible, so that data stays under the client’s control;
- use realistic test or anonymised data for development and demonstrations, rather than real personal data, wherever possible;
- make sure everyone who handles the data is bound by confidentiality;
- use other providers (sub-processors) only with the client’s agreement, and on equivalent terms;
- help the client respond to requests from individuals and meet its own obligations; and
- return or delete the data at the end of the work, as the client instructs.
4Personal data and AI systems
When a system we build uses AI, we agree with the client in writing:
- which AI models and providers will be used, and where they process data;
- that personal data is not used to train or improve AI models unless the client has explicitly instructed it and a lawful basis exists; and
- how the system will be tested for accuracy and fairness, as described in section 8 of our Gender Equality Plan.
We carry out, or help the client carry out, a data protection impact assessment (DPIA) where processing is likely to result in a high risk to individuals.
5Personal data breaches
If we become aware of a breach affecting personal data we process for a client, we will tell the client without undue delay, so that it can meet its own duty to report to the ICO.
For breaches affecting data we control, we will report to the ICO within 72 hours where the law requires it, and tell the people affected where the breach is likely to result in a high risk to them.
6Security
We use technical and organisational measures appropriate to the risk, including restricting access to people who need it, encrypting data in transit, keeping software up to date, and choosing providers that meet recognised security standards.
7International transfers
We transfer personal data outside the UK only where it is protected, either by UK adequacy regulations or by the ICO’s International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. For client data, we only do so with the client’s agreement.
8Making a request
If you want to use your data protection rights, email hello@globalsolark.co.uk. We will respond within one month. If we hold your data as a processor for a client, we will pass your request to that client and help it respond.
9Accountability
We are registered with the Information Commissioner’s Office under registration number ICO registration number. Our Chief Executive Officer (CEO) is responsible for data protection. We are not required to appoint a Data Protection Officer.
If you are unhappy with how we have handled personal data, contact us first. You can also complain to the Information Commissioner’s Office.
Rama Krishna Aditya Bharadwaj Kolluri
Chief Executive Officer (CEO), for and on behalf of Global SoLARK Limited
Approved 12 August 2026