brave-blossom is committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR). This statement outlines how we process personal data in accordance with GDPR requirements.
brave-blossom acts as the data controller for personal information collected through our website and services.
Contact details:
Email: [email protected]
Address: 142 Kensington High Street, London, W8 7RL, United Kingdom
We process your personal data based on the following legal grounds:
Under GDPR, you have the following rights regarding your personal data:
You have the right to request access to your personal data and obtain a copy of the information we hold about you.
You can request correction of inaccurate or incomplete personal data.
You have the right to request deletion of your personal data under certain circumstances, including when the data is no longer necessary for the purposes it was collected.
You can request restriction of processing your personal data in specific situations, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and transmit it to another controller.
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of your GDPR rights, please contact us at: [email protected]
We will respond to your request within one month of receipt. In complex cases, this period may be extended by up to two months, and we will inform you of any such extension.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
When personal data is no longer required, it will be securely deleted or anonymized.
Your personal data is primarily stored and processed within the United Kingdom. If data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will take steps to delete it promptly.
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your habitual residence, place of work, or place of alleged infringement.
UK supervisory authority:
Information Commissioner's Office (ICO)
Website: www.ico.org.uk
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. We will notify you of any material changes through our website or by email where appropriate.
If you have questions about our GDPR compliance or data protection practices, please contact us at:
Email: [email protected]
Address: 142 Kensington High Street, London, W8 7RL, United Kingdom