GDPR Compliance
Understanding your data protection rights under the General Data Protection Regulation
Our Commitment to GDPR
dazzora-polish is committed to complying with the General Data Protection Regulation (GDPR), which came into effect on 25 May 2018. This page provides information about how we handle personal data in accordance with GDPR requirements and explains your rights as a data subject.
Data Controller
For the purposes of GDPR, dazzora-polish is the data controller responsible for your personal data. Our contact details are:
Email: [email protected]
Address: 47 Clerkenwell Road, London EC1M 5RS, United Kingdom
Types of Personal Data We Process
We may process the following categories of personal data:
- Identity Data: First name, last name, title
- Contact Data: Email address, postal address
- Service Data: Information about services you request or receive
- Technical Data: IP address, browser type and version, time zone setting, operating system
- Usage Data: Information about how you use our website
- Marketing Data: Your preferences in receiving marketing communications from us
Lawful Bases for Processing
We only process your personal data when we have a lawful basis to do so. The lawful bases we rely on include:
- Consent: You have given clear consent for us to process your personal data for a specific purpose.
- Contract: Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
- Legitimate Interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, provided your fundamental rights do not override those interests.
- Legal Obligation: Processing is necessary for compliance with a legal obligation to which we are subject.
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right to be Informed
You have the right to be informed about how we collect and use your personal data. This GDPR page and our Privacy Policy fulfil this obligation.
Right of Access
You have the right to request a copy of the personal data we hold about you. This is commonly known as a "subject access request". We will respond to your request within one month.
Right to Rectification
You have the right to request that we correct any inaccurate personal data or complete any incomplete personal data we hold about you.
Right to Erasure
You have the right to request the deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose for which it was collected.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to Object
You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.
Rights Related to Automated Decision Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
Exercising Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month. In certain circumstances, we may extend this period by a further two months, in which case we will inform you of the extension and the reasons for it.
We will not charge a fee for processing your request unless it is manifestly unfounded or excessive. In such cases, we may charge a reasonable fee or refuse to act on the request.
Data Security
We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing your personal data. These measures include:
- Encryption of personal data where appropriate
- Regular security assessments
- Limiting access to personal data to authorised personnel
- Staff training on data protection
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
Complaints
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Website: ico.org.uk
Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Updates to This Page
We may update this GDPR compliance page from time to time. Any changes will be posted on this page with an updated revision date.
Last updated: June 2026