Last Updated: August 4, 2026
We are committed to protecting your personal data and respecting your privacy rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines how we comply with these regulations.
For the purposes of UK data protection law, we are the data controller responsible for your personal information. Our contact details can be found on our contact page.
We only process your personal data when we have a lawful basis to do so. The legal bases we rely on include:
Under UK GDPR, you have the following rights regarding your personal data:
You can request a copy of the personal data we hold about you. This is known as a Subject Access Request (SAR).
You can ask us to correct any inaccurate or incomplete personal data we hold about you.
In certain circumstances, you can request that we delete your personal data. This right is not absolute and only applies in specific situations.
You can request that we limit how we use your personal data in certain circumstances.
You can request a copy of your personal data in a structured, commonly used, and machine-readable format.
You can object to our processing of your personal data where we are relying on legitimate interests as the legal basis.
We do not use automated decision-making or profiling in our service provision.
To exercise any of your data protection rights, please contact us at: [email protected]
We will respond to your request within one month, although this period may be extended by two additional months where necessary, taking into account the complexity and number of requests.
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.
ICO Contact Details:
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
We primarily process and store data within the United Kingdom. If we transfer personal data outside the UK, we ensure appropriate safeguards are in place to protect your data in accordance with UK GDPR requirements.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law. Our retention periods are based on business needs and legal requirements.
We may update this GDPR compliance statement from time to time to reflect changes in our practices or legal requirements. Please check this page periodically for updates.
If you have any questions about our GDPR compliance or data protection practices, please contact us at: [email protected]