Our commitment to data protection and your rights
Merry-thicket is fully committed to complying with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. We take your privacy seriously and have implemented measures to ensure your personal data is handled responsibly and securely.
Merry-thicket acts as the data controller for personal information collected through this website. We determine the purposes and means of processing your personal data and are responsible for ensuring compliance with data protection legislation.
The GDPR provides you with specific rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of receiving your request.
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request correction. We will respond to such requests within one month.
In certain circumstances, you have the right to request that we delete your personal data. This right applies when the data is no longer necessary for the purpose it was collected, or when you withdraw consent.
You may request that we limit how we use your personal data in certain situations, such as when you contest the accuracy of the data or object to our processing.
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used format.
You have the right to object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.
We process personal data only when we have a lawful basis to do so. The bases we rely on include:
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the Information Commissioner's Office.
We have procedures in place to detect, report, and investigate personal data breaches. Where a breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.
To exercise any of your rights under GDPR, please contact us at: [email protected]
We will respond to your request within one month. If your request is complex, we may extend this period by a further two months, but we will inform you of any extension within the initial one-month period.
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.