Last updated: August 2026
We are committed to complying with the General Data Protection Regulation (GDPR) and UK data protection legislation in all aspects of our data processing activities. This page provides detailed information about how we fulfill our obligations under these regulations.
For the purposes of data protection legislation, we are the data controller responsible for your personal information. Our contact details are:
47 West George Street
Glasgow G2 1BP
United Kingdom
Email: [email protected]
We process personal data only when we have a lawful basis to do so. The specific lawful bases we rely upon include:
You have the right to obtain confirmation of whether we process your personal data and, if so, to access that data along with information about how we use it.
You may request correction of inaccurate personal data and completion of incomplete personal data we hold about you.
In certain circumstances, you have the right to request deletion of your personal data, including when:
You may request restriction of processing in specific situations, such as when contesting data accuracy or objecting to processing.
Where technically feasible, you have the right to receive your personal data in a structured, commonly used format and transmit it to another controller.
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
We do not currently use automated decision-making or profiling that produces legal or similarly significant effects. Should this change, we will provide appropriate information and safeguards.
To exercise any of your GDPR rights, contact us at [email protected] with sufficient detail to identify you and specify which right you wish to exercise. We will respond within one month, though complex requests may require up to three months with notification.
We do not charge fees for rights requests unless they are manifestly unfounded, excessive, or repetitive.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the appropriate supervisory authority within 72 hours of becoming aware. If the breach poses a high risk, we will also notify affected individuals without undue delay.
When we engage third-party service providers who process personal data on our behalf, we ensure they provide sufficient guarantees regarding security and confidentiality through appropriate contractual arrangements.
We primarily process personal data within the United Kingdom. Any international transfers comply with GDPR requirements, utilizing appropriate transfer mechanisms such as adequacy decisions or standard contractual clauses.
Our services are not directed at individuals under 16 years of age. We do not knowingly collect personal data from children without parental consent.
If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
We encourage you to contact us first so we can address your concerns directly.
We regularly review our data protection practices to ensure ongoing compliance with GDPR requirements. Material changes to how we process personal data will be communicated through our website and privacy policy updates.