GDPR Compliance
Last updated: September 2026
Our Commitment
stormy-fjord is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take our responsibilities regarding the protection of personal data seriously.
Data Controller
stormy-fjord acts as the data controller for personal information collected through this website. This means we determine the purposes and means of processing your personal data.
Contact details:
Email: [email protected]
Address: 47 Chancery Lane, London, WC2A 1PL, United Kingdom
Lawful Basis for Processing
We only process personal data when we have a lawful basis to do so. The legal bases we rely on include:
- Consent: You have given clear consent for us to process your personal data for a specific purpose.
- Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract.
- Legitimate interests: Processing is necessary for our legitimate interests or those of a third party, unless there is a good reason to protect your personal data which overrides those interests.
- Legal obligation: Processing is necessary for us to comply with the law.
Your Rights Under UK GDPR
You have the following rights regarding your personal data:
Right to Be Informed
You have the right to know how your personal data is being used. Our Privacy Policy provides this information.
Right of Access
You can request a copy of the personal data we hold about you. We will respond to such requests within one month.
Right to Rectification
If your personal data is inaccurate or incomplete, you have the right to have it corrected.
Right to Erasure
You can request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.
Right to Restrict Processing
You can request that we limit the way we use your personal data in certain circumstances.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
Right to Object
You can object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.
Rights Related to Automated Decision Making
You have rights relating to automated decision making and profiling. We do not currently use automated decision-making processes.
Exercising Your Rights
To exercise any of your rights, please contact us using the details provided above. We will respond to your request within one month. In exceptional circumstances, we may extend this period by up to two months, but we will inform you if this is necessary.
We may need to verify your identity before processing your request. There is no fee for making a request unless the request is manifestly unfounded or excessive.
Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data where appropriate
- Regular security assessments
- Access controls and authentication measures
- Staff training on data protection
International Transfers
We primarily store and process data within the United Kingdom. If we transfer data outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and, where required, inform affected individuals without undue delay.
Complaints
If you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Website: ico.org.uk