Last Updated: September 11, 2026
We are committed to complying with the General Data Protection Regulation and protecting the privacy rights of individuals in the European Economic Area and the United Kingdom. This statement outlines how we fulfill our obligations under GDPR when processing personal data.
For the purposes of GDPR, we act as the data controller for personal information collected through this website and our payment services. Our contact details are:
Email: [email protected]
Address: 142 Kensington High Street, London, W8 7RG, United Kingdom
We process personal data only when we have a lawful basis to do so under GDPR Article 6:
As a data subject, you have the following rights under GDPR:
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data along with information about how it is processed.
You have the right to request correction of inaccurate personal data and completion of incomplete personal data.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes it was collected or when you withdraw consent.
You have the right to request limitation of processing in specific situations, such as when you contest the accuracy of the data or object to processing.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, unless certain conditions are met.
To exercise any of your GDPR rights, please contact us at [email protected] with your request. We will respond within one month of receiving your request, though this period may be extended by two additional months in complex cases. We may require verification of your identity before processing your request.
We process the following categories of personal data:
We may share personal data with the following categories of recipients:
When we transfer personal data outside the EEA or UK, we ensure appropriate safeguards are in place, such as:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations. Our standard retention periods include:
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by law.
Our services are not directed at children under 16 years of age. We do not knowingly process personal data of children without parental consent where required by law.
You have the right to lodge a complaint with a data protection supervisory authority if you believe we have processed your personal data unlawfully. In the United Kingdom, the supervisory authority is the Information Commissioner's Office.
We may update this GDPR compliance statement to reflect changes in our data processing practices or legal requirements. We will notify you of significant changes through our website or direct communication where appropriate.
If you have questions about our GDPR compliance or data protection practices, please contact our privacy team at [email protected].