GDPR Compliance Statement
Last updated: September 1, 2026
cobalt-cliff is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This statement outlines how we comply with these regulations.
Data Controller
cobalt-cliff acts as the data controller for personal information collected through our website and services. We are responsible for deciding how we hold and use personal information about you.
Our contact details are:
cobalt-cliff
42 Kensington Gardens
London, W2 4RB
United Kingdom
Email: [email protected]
Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: You have given clear consent for us to process your personal data for a specific purpose
- Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract
- Legal obligation: Processing is necessary for us to comply with the law
- Legitimate interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests
Your Rights Under GDPR
You have the following rights regarding your personal data:
Right to Access
You have the right to request copies of your personal data. We may charge a small fee for this service.
Right to Rectification
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data, under certain conditions.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data, under certain conditions.
Right to Object to Processing
You have the right to object to our processing of your personal data, under certain conditions.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
How to Exercise Your Rights
If you wish to exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month of receiving it. We may need to verify your identity before processing your request.
Data Protection Officer
While we are not required by law to appoint a Data Protection Officer, we have designated a privacy contact point for all GDPR-related inquiries. Please direct all data protection questions to [email protected].
Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach.
International Data Transfers
We do not transfer your personal data outside the United Kingdom. If this changes in the future, we will ensure that appropriate safeguards are in place and that the transfer complies with UK GDPR requirements.
Automated Decision-Making
We do not use automated decision-making or profiling in our processing of your personal data.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Complaints
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: www.ico.org.uk
Changes to This Statement
We may update this GDPR compliance statement from time to time. Any changes will be posted on this page with an updated revision date.
Contact Us
If you have any questions about our GDPR compliance or how we handle your personal data, please contact us at [email protected].