GDPR & Your Data Rights
Last updated: 5 June 2026
AutoSter is committed to UK GDPR compliance. This page explains your rights regarding personal data and how to exercise them. For full details on our data practices, see our Privacy Policy.
Your Rights Under UK GDPR
Under the UK General Data Protection Regulation (UK GDPR), you have the following rights:
1. Right to Access (Subject Access Request)
You have the right to request a copy of the personal data we hold about you, along with information about how we process it. This is known as a Subject Access Request (SAR). We will respond within one month of receiving your request.
To make a Subject Access Request, email privacy@autoster.co.uk with the subject line "Subject Access Request". We may ask you to verify your identity before processing your request.
2. Right to Rectification
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct it. You can update your account information directly through your profile settings, or contact us for assistance.
3. Right to Erasure (Right to Be Forgotten)
You can request that we delete your personal data in certain circumstances, such as:
- The data is no longer necessary for the purpose we collected it.
- You withdraw your consent and we have no other legal basis for processing.
- You object to processing and there are no overriding legitimate grounds.
- The data has been unlawfully processed.
To request deletion, email privacy@autoster.co.uk with the subject line "Data Erasure Request". Note that we may need to retain certain data to comply with legal obligations.
4. Right to Restrict Processing
You have the right to request that we limit how we use your personal data in certain situations — for example, while we verify the accuracy of data you have contested, or if you have objected to processing.
5. Right to Data Portability
You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format (such as CSV or JSON). You can also request that we transmit this data directly to another data controller where technically feasible.
To request data portability, email privacy@autoster.co.uk with the subject line "Data Portability Request".
6. Right to Object
You have the right to object to our processing of your personal data when that processing is based on legitimate interests. Upon receiving your objection, we will stop processing unless we can demonstrate compelling legitimate grounds that override your rights.
7. Rights Related to Automated Decision-Making
AutoSter does not use your personal data for automated decision-making (including profiling) that produces legal effects or significantly affects you.
How to Exercise Your Rights
Response Times
We will respond to all data rights requests within one month of receipt. If your request is particularly complex, we may extend this period by up to two additional months — we will notify you of any such extension within the first month.
There is no charge for exercising your data rights unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.
Our Data Protection Officer
AutoSter has appointed a Data Protection Officer (DPO) who oversees our compliance with UK GDPR. You can contact the DPO at dpo@autoster.co.uk.