Last updated: September 2026
ash-plover is committed to complying with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This page explains how we meet our obligations under these laws and how you can exercise your rights as a data subject.
For the purposes of GDPR, ash-plover acts as the data controller for personal information collected through our website and services. Our contact details are:
Email: [email protected]
Address: 52 Wardour Street, London, W1D 6BX, United Kingdom
We process personal data only when we have a lawful basis to do so. The lawful bases we rely on include:
Under GDPR, you have the following rights regarding your personal data:
You have the right to request a copy of the personal information we hold about you. This is commonly known as a "subject access request." We will respond to your request within one month.
If you believe that any information we hold about you is inaccurate or incomplete, you have the right to request correction. We will make the necessary changes promptly.
Also known as the "right to be forgotten," you can request deletion of your personal data in certain circumstances, including:
You can request that we restrict how we use your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
Where we rely on consent as the lawful basis for processing, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing before consent was withdrawn.
To exercise any of your GDPR rights, please contact us at [email protected]. We may need to verify your identity before fulfilling your request. We will respond to all legitimate requests within one month, though this may be extended by two months in complex cases.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in high risk to you, we will also notify you directly without undue delay.
We primarily process data within the United Kingdom and European Economic Area. If we transfer personal data outside these regions, we ensure appropriate safeguards are in place, such as:
Where processing is likely to result in high risk to individuals, we conduct Data Protection Impact Assessments to identify and mitigate those risks before processing begins.
When we engage third parties to process personal data on our behalf, we ensure they:
Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority. In the United Kingdom, this is the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
We may update this GDPR compliance statement from time to time to reflect changes in our practices or legal requirements. Significant changes will be communicated to you via email or through a prominent notice on our website.