Last updated: January 2024
garnet-river is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page provides detailed information about how we handle your personal data in accordance with these regulations.
garnet-river acts as the data controller for personal information collected through this website and our travel services. As the data controller, we determine the purposes and means of processing your personal data.
Contact details:
garnet-river
47 Portland Street
Manchester, M1 3LF
United Kingdom
Email: [email protected]
Under the UK GDPR, you have the following rights regarding your personal data:
You have the right to obtain confirmation as to whether we process your personal data and, if so, to access that data along with supplementary information about how it is processed.
You have the right to have inaccurate personal data corrected and incomplete data completed.
Also known as the "right to be forgotten", you may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.
You may request that we restrict the processing of your personal data in specific situations, such as when you contest the accuracy of the data.
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format.
You have the right to object to processing based on legitimate interests, direct marketing, or processing for research purposes.
You have rights relating to automated decision-making, including profiling, that produces legal or similarly significant effects. We do not currently engage in such automated decision-making.
To exercise any of these rights, please contact us using the details provided above. We will respond to your request within one month, though this may be extended by two further months for complex requests.
We may request proof of identity before processing your request to ensure data security.
We maintain records of our processing activities as required under Article 30 of the UK GDPR. Our processing activities include:
We conduct Data Protection Impact Assessments (DPIAs) when introducing new processes or technologies that may result in high risk to individuals' rights and freedoms.
We have procedures in place to detect, investigate, and respond to personal data breaches. Where required, we will notify the Information Commissioner's Office within 72 hours and affected individuals without undue delay.
When arranging international travel, personal data may be transferred outside the United Kingdom. Such transfers are conducted in compliance with Chapter V of the UK GDPR, using appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
We review our GDPR compliance regularly and may update this page to reflect changes in our practices or legal requirements.