Legal
GDPR Compliance
Helios Trade Ltd is committed to protecting personal data in line with the UK GDPR, EU GDPR and the Data Protection Act 2018.
1. Our commitment
We handle personal data lawfully, fairly and transparently. Every partner, supplier and customer interaction is designed to respect the rights of data subjects and to comply with applicable data protection regulations.
2. Data controller and contact
Helios Trade Ltd is the data controller for personal data collected through its operations. Data protection enquiries can be sent to info@heliostradeltd.com.
3. Principles we follow
- Lawfulness, fairness and transparency.
- Purpose limitation — data collected for specified, explicit purposes.
- Data minimisation — only what is necessary.
- Accuracy and up-to-date records.
- Storage limitation aligned to legal retention periods.
- Integrity, confidentiality and accountability.
4. Rights of data subjects
Under UK/EU GDPR, individuals have the right to:
- Be informed about how their data is used.
- Access their personal data.
- Request correction or erasure of inaccurate data.
- Restrict or object to certain processing.
- Data portability where technically feasible.
- Withdraw consent at any time (where consent is the lawful basis).
- Lodge a complaint with a supervisory authority (ICO in the UK).
Requests are handled within one calendar month.
5. Data processors and safeguards
We work with vetted third-party processors (accounting, IT, logistics, marketplace platforms). Every processor is bound by a written Data Processing Agreement (DPA) that mirrors GDPR requirements, including confidentiality, security and sub-processor controls.
6. International transfers
Where personal data leaves the UK or EEA, we rely on adequacy decisions, UK International Data Transfer Agreements (IDTA), or the EU Standard Contractual Clauses with the UK Addendum, as appropriate.
7. Security measures
- Access controls and role-based permissions.
- Encryption of data in transit and at rest where appropriate.
- Regular backups and business continuity procedures.
- Staff training on data protection responsibilities.
8. Breach notification
Any personal data breach that poses a risk to individuals will be reported to the ICO within 72 hours of becoming aware, in line with Article 33 UK GDPR, and to affected individuals where required.
9. Records of processing
We maintain a Record of Processing Activities (ROPA) documenting the purposes, categories of data, recipients, retention periods and safeguards for each processing activity.
10. Contact
For access requests, questions or complaints under GDPR, email info@heliostradeltd.com.