Last updated: July 2026
iris-ferret is committed to complying with the General Data Protection Regulation (GDPR) and UK data protection laws. This statement outlines how we fulfill our obligations and protect your rights as a data subject.
iris-ferret acts as the data controller for personal information collected through our website and services. We are responsible for determining how and why your data is processed.
Contact Details:
iris-ferret
12 Primrose Lane
Bath BA1 5NZ
United Kingdom
Email: [email protected]
As a data subject, you have the following rights:
You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of your request.
If your personal data is inaccurate or incomplete, you have the right to request that we correct or complete it.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You can request that we limit the way we use your data in specific situations, such as when you contest the accuracy of the data or object to processing.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significant effects on you.
To exercise any of these rights, please contact us at [email protected] with the following information:
We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of any such delay.
We process personal data only when we have a lawful basis to do so:
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
When we engage third-party service providers to process data on our behalf, we ensure they:
If we transfer your data outside the UK or European Economic Area, we ensure appropriate safeguards are in place, such as:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, considering:
If you believe we have not complied with GDPR or UK data protection laws, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Website: ico.org.uk
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. The updated version will be posted on our website with a revised date.