GDPR Information
Last updated: June 19, 2026
Our commitment to data protection
We are committed to complying with the UK General Data Protection Regulation and ensuring that your personal data is processed lawfully, fairly, and transparently. This page provides detailed information about your rights and how we fulfill our obligations under GDPR.
Data controller information
For the purposes of data protection law, the data controller is:
amethyst-tundra
47 Chamberlain Square
Birmingham, B3 3AX
United Kingdom
Email: [email protected]
Your data protection rights
Right to access
You have the right to obtain confirmation that we are processing your personal data and to receive a copy of that data. This is commonly known as a subject access request. We will provide this information free of charge within one month of receiving your request.
Right to rectification
If your personal data is inaccurate or incomplete, you have the right to have it corrected. We will respond to rectification requests within one month and notify any third parties with whom we have shared your data.
Right to erasure
Also known as the right to be forgotten, you may request deletion of your personal data in certain circumstances, including:
- The data is no longer necessary for the purposes it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
This right is not absolute and may be limited by legal obligations to retain certain information.
Right to restrict processing
You can request that we restrict processing of your personal data in specific situations, such as when you contest the accuracy of the data or object to processing. During restriction, we may store your data but not actively process it.
Right to data portability
Where processing is based on consent or contract performance and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format. You may also request that we transmit this data directly to another controller where technically feasible.
Right to object
You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Rights related to automated decision making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. We do not currently engage in automated decision making of this nature.
How to exercise your rights
To exercise any of your data protection rights, please contact us at [email protected] with your request. We may need to verify your identity before processing your request to ensure we are disclosing information only to the rightful data subject.
Response timeframes
We will respond to requests without undue delay and within one month of receipt. In complex cases or where we receive multiple requests, this period may be extended by two additional months. We will inform you of any extension within the initial one-month period.
Complaints
If you believe we have not handled your personal data in accordance with GDPR requirements, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
Data processing principles
We process personal data in accordance with the following principles:
- Lawfulness, fairness, and transparency
- Purpose limitation: collected for specified, explicit, and legitimate purposes
- Data minimization: adequate, relevant, and limited to what is necessary
- Accuracy: kept accurate and up to date
- Storage limitation: retained only as long as necessary
- Integrity and confidentiality: processed securely
Data security measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
- Incident response procedures
Data breach notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also report qualifying breaches to the Information Commissioner's Office within 72 hours of becoming aware of the breach.
Updates to this information
We may update this GDPR information to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website or directly via email.