Last Updated: June 2026
Introduction
We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines our data protection practices and your rights under GDPR.
Data Controller
For the purposes of GDPR, the data controller is:
frosty-otter
42 Colmore Row
Birmingham B3 2BS
United Kingdom
Email: [email protected]
Legal Basis for Processing
We process personal data under the following legal bases:
- Contractual Necessity: Processing necessary to fulfill our service obligations
- Legitimate Interest: Processing necessary for business operations and service improvement
- Legal Obligation: Processing required to comply with legal and regulatory requirements
- Consent: Where you have provided explicit consent for specific processing activities
Your Rights Under GDPR
Right to Access
You have the right to request access to the personal data we hold about you. We will provide a copy of your data in a commonly used electronic format within 30 days of your request.
Right to Rectification
You can request correction of inaccurate or incomplete personal data. We will update our records promptly upon verification of the corrected information.
Right to Erasure
You may request deletion of your personal data under certain circumstances, including:
- The data is no longer necessary for the purposes collected
- You withdraw consent and no other legal basis exists
- You object to processing and no overriding legitimate grounds exist
- The data has been unlawfully processed
Note that some data must be retained to comply with legal obligations.
Right to Restriction of Processing
You can request that we restrict processing of your personal data when:
- You contest the accuracy of the data
- Processing is unlawful but you oppose erasure
- We no longer need the data but you require it for legal claims
- You have objected to processing pending verification of legitimate grounds
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format. You may also request that we transmit this data directly to another controller where technically feasible.
Right to Object
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time. This does not affect the lawfulness of processing conducted prior to withdrawal.
Right to Lodge a Complaint
If you believe we have violated your data protection rights, you may lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Data Protection Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and vulnerability testing
- Access controls limiting data access to authorized personnel
- Data protection training for all staff handling personal information
- Incident response procedures for data breaches
- Regular backups with secure storage
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Booking and service records: 7 years (for accounting and legal purposes)
- Communication records: 3 years
- Marketing consent records: Until consent is withdrawn
- Website analytics data: 26 months
International Data Transfers
We process and store data primarily within the United Kingdom. If data is transferred outside the UK or European Economic Area, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions confirming adequate protection in the recipient country
- Binding corporate rules for intra-group transfers
Automated Decision Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.
Third-Party Processors
We work with third-party service providers who process personal data on our behalf. All processors are contractually bound to implement appropriate security measures and process data only according to our instructions.
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
Exercising Your Rights
To exercise any of your rights under GDPR, contact us at [email protected]. Please include:
- Your full name and contact information
- The specific right you wish to exercise
- Details of the data or processing in question
We will respond to your request within 30 days. In complex cases, this may be extended by an additional 60 days with notification.
Updates to This Policy
We may update this GDPR compliance page to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website or via email.