Your data protection rights explained
misty-crag is committed to protecting the privacy and security of your personal information. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This page provides information about your rights under data protection law and how we fulfil our obligations.
misty-crag acts as the data controller for personal information collected through this website and our travel services. This means we determine the purposes and means of processing your personal data.
Contact Address:
misty-crag
47 Kensington High Street
London W8 5ED
United Kingdom
Email: [email protected]
The UK GDPR provides you with the following rights regarding your personal data:
You have the right to know how we collect and use your personal data. Our Privacy Policy provides this information in detail.
You can request a copy of the personal data we hold about you. This is known as a Subject Access Request (SAR). We will respond within one month of receiving your request.
If any personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected. Please contact us with the correct information.
Also known as the right to be forgotten, you can request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.
You can ask us to limit how we use your personal data while we verify its accuracy or consider your objection to its processing.
Where technically feasible, you can request that we transfer your personal data to another organisation in a commonly used, machine-readable format.
You have the right to object to processing of your personal data for direct marketing purposes. You can also object to processing based on legitimate interests.
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. We do not currently use automated decision-making in our services.
To exercise any of your data protection rights, please contact us at:
Email: [email protected]
We will respond to your request within one month. In complex cases, we may extend this by up to two additional months, in which case we will inform you within the first month.
We will not charge a fee for processing reasonable requests. However, we may charge a reasonable fee or refuse requests that are manifestly unfounded or excessive.
We adhere to the following principles when processing personal data:
When arranging international travel, we may need to transfer your personal data to countries outside the UK. When we do so, we ensure that appropriate safeguards are in place, which may include:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach poses a high risk, we will also notify affected individuals directly.
The Information Commissioner's Office (ICO) is the UK supervisory authority for data protection matters. If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the ICO.
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
This GDPR information page was last updated in January 2024. We may update this page periodically to reflect changes in our practices or legal requirements.