GDPR Compliance
Last updated: August 2024
Our Commitment to Data Protection
We are committed to protecting your personal data in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018.
Data Controller
For the purposes of data protection legislation, the data controller is:
misty-nebula
47 Cathedral Road
Cardiff, CF11 9HD
United Kingdom
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Contract: Processing necessary to fulfill our contractual obligations when you enroll in courses
- Legitimate Interest: Processing necessary for our legitimate business interests in providing educational services
- Consent: Processing based on your explicit consent for marketing communications
- Legal Obligation: Processing required to comply with legal or regulatory requirements
Your GDPR Rights
You have the following rights regarding your personal data:
Right to Access
You can request a copy of the personal data we hold about you.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure
You can request deletion of your personal data in certain circumstances.
Right to Restriction
You can request that we restrict processing of your personal data in specific situations.
Right to Data Portability
You can request transfer of your data to another organisation or directly to you in a structured, commonly used format.
Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
How to Exercise Your Rights
To exercise any of these rights, contact us at:
We will respond to your request within one month. In complex cases, we may extend this by two additional months and will inform you accordingly.
Data Retention
We retain personal data only as long as necessary for the purposes outlined in our Privacy Policy or as required by law.
International Data Transfers
We do not routinely transfer personal data outside the United Kingdom. If such transfers become necessary, we will ensure appropriate safeguards are in place.
Data Security
We implement appropriate technical and organisational security measures to protect personal data against unauthorised access, loss, or destruction.
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
Complaints
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Tel: 0303 123 1113
Website: www.ico.org.uk
Updates to This Notice
We may update this GDPR compliance notice periodically to reflect changes in our practices or legal requirements. Material changes will be communicated appropriately.