GDPR Compliance
Last Updated: July 21, 2026
indigo-gorge is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page explains your rights under GDPR and how we comply with these regulations.
Your Rights Under GDPR
As a data subject, you have the following rights:
- Right to Access: You have the right to request copies of your personal data.
- Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or incomplete.
- Right to Erasure: You have the right to request that we erase your personal data, under certain conditions.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
- Right to Object to Processing: You have the right to object to our processing of your personal data, under certain conditions.
- Right to Data Portability: You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: You have given clear consent for us to process your personal data for a specific purpose.
- Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract.
- Legal Obligation: Processing is necessary for us to comply with the law.
- Legitimate Interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, provided those interests are not overridden by your rights and interests.
Data Controller Information
The data controller responsible for your personal data is:
indigo-gorge
47 Thornbury Lane
Bristol, BS3 4QE
United Kingdom
Email: [email protected]
Data Protection Officer
For any questions or concerns regarding data protection, you can contact our data protection officer at: [email protected]
How We Collect Your Data
We collect data through:
- Direct interactions when you submit forms or contact us
- Automated technologies such as cookies when you interact with our website
- Third parties or publicly available sources when legally permitted
International Data Transfers
We primarily store and process your data within the European Economic Area (EEA). If we need to transfer your data outside the EEA, we ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.
Data Security
We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way. We limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know.
Data Retention
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Automated Decision Making
We do not use automated decision-making or profiling in ways that produce legal effects or significantly affect you.
How to Exercise Your Rights
If you wish to exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not complied with GDPR requirements.
Updates to This Notice
We may update this GDPR compliance notice from time to time. We will notify you of any significant changes by posting the updated notice on our website.