General Data Protection Regulation Information
ash-caribou complies with the General Data Protection Regulation (GDPR) and related UK data protection legislation. We process personal data lawfully, fairly, and transparently.
This page explains your rights as a data subject and how we fulfill our obligations as a data controller.
We process personal data under the following legal bases:
Under GDPR, you have the following rights:
You may request a copy of all personal data we hold about you. We will provide this within one month of your request.
If personal information is inaccurate or incomplete, you may request corrections. We will update records promptly.
You may request deletion of your data. However, we must retain certain information for legal and insurance purposes for up to seven years following your last booking.
You may request that we limit how we use your data while we investigate a dispute or verify accuracy.
You may request a machine-readable copy of your data to transfer to another service provider.
You may object to processing based on legitimate interests or for marketing purposes. We will cease such processing unless we can demonstrate compelling legal grounds.
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
To submit a data subject access request or exercise any of the rights listed above, send an email to [email protected] with "GDPR Request" in the subject line.
Include the following information:
We will respond within one month. In complex cases, we may extend this by two additional months and will notify you of the reason for delay.
In the event of a data breach that poses a high risk to your rights and freedoms, we will notify you within 72 hours of becoming aware of the breach. Notification will include the nature of the breach, likely consequences, and measures taken to address it.
If you believe we have not handled your data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
ICO contact information: ico.org.uk
Personal data is stored within the European Economic Area. If transfers outside the EEA become necessary, we will ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.