GDPR Compliance
Our commitment to protecting your data under European privacy law
The General Data Protection Regulation (GDPR) establishes comprehensive data protection standards for individuals within the European Union and European Economic Area. We are committed to full compliance with GDPR requirements.
Legal Basis for Processing
We process personal data based on the following legal grounds:
- Consent: You have explicitly agreed to our processing of your personal data for specific purposes
- Contractual necessity: Processing is necessary to fulfill our obligations when you register for workshops
- Legitimate interests: Processing is necessary for our legitimate business interests, such as improving services and preventing fraud
- Legal obligations: Processing is required to comply with applicable laws and regulations
Your GDPR Rights
Under GDPR, you have comprehensive rights regarding your personal data:
Right to Access
You may request confirmation of whether we process your personal data and obtain a copy of that data.
Right to Rectification
You may request correction of inaccurate personal data and completion of incomplete data.
Right to Erasure
You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when there is no legal ground for processing.
Right to Restriction
You may request restriction of processing under certain circumstances, such as when you contest the accuracy of data or object to processing.
Right to Data Portability
You may request that we provide your personal data in a structured, commonly used, machine-readable format and transmit it directly to another controller where technically feasible.
Right to Object
You may object to processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.
Exercising Your Rights
To exercise any of these rights, submit a request to [email protected]. We will respond within one month of receiving your request. In complex cases, we may extend this period by two additional months and will inform you of such extension.
We may request additional information to verify your identity before processing requests. This ensures we do not disclose personal data to unauthorized parties.
Data Protection Officer
For matters specifically related to data protection, you may contact our data protection officer at:
Email: [email protected]
Address: 47 Marylebone Lane, London W1U 2NT, United Kingdom
International Data Transfers
We primarily process and store data within the European Economic Area. If data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission or transfers to countries with adequacy decisions.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law. Retention periods vary based on the type of data and purpose:
- Workshop registration data: Retained for the duration of service provision plus seven years for accounting and legal purposes
- Marketing communications: Retained until you withdraw consent or object to processing
- Website analytics data: Typically retained for 26 months
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the appropriate supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR. In the United Kingdom, the relevant authority is:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Updates to This Statement
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Material changes will be communicated through prominent notice on our website or direct communication to registered users.