Our commitment to protecting your data under the General Data Protection Regulation.
Last updated: January 2024
blossom-moose is committed to ensuring compliance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. We take the protection of your personal data seriously and have implemented measures to ensure that we process personal data lawfully, fairly, and transparently.
blossom-moose acts as the data controller for personal data collected through our website and in connection with our services. As the data controller, we determine the purposes and means of processing personal data and are responsible for ensuring compliance with data protection laws.
Contact details for the data controller:
blossom-moose
47 Whiteladies Road
Bristol BS8 2NT
United Kingdom
Email: [email protected]
We process personal data only when we have a valid legal basis to do so. The legal bases we rely on include:
Under the GDPR, you have the following rights regarding your personal data:
To exercise any of your rights under the GDPR, please contact us using the contact details provided above. We will respond to your request within one month of receiving it. In certain circumstances, we may extend this period by two further months, in which case we will inform you of the extension and the reasons for it.
We may need to request specific information from you to help us confirm your identity and ensure your right to access the information or to exercise any of your other rights.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. The retention period may vary depending on the context and our legal obligations.
We primarily store and process personal data within the United Kingdom and the European Economic Area (EEA). If we transfer personal data outside of these areas, we ensure that appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing personal data. These measures include encryption, access controls, and regular security assessments.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
If you believe that we have not complied with your data protection rights, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: www.ico.org.uk
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this page periodically.