This content is promotional

Last updated: October 2026

Our Commitment

lagoon-sparrow is committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take our responsibilities regarding the protection of personal data seriously and have implemented measures to ensure we meet our obligations.

Data Controller

lagoon-sparrow acts as the data controller for personal information collected through this website. This means we determine the purposes and means of processing personal data.

Contact details:

lagoon-sparrow
47 Clerkenwell Road
London, EC1M 5RS
United Kingdom

Email: [email protected]

Lawful Basis for Processing

We process personal data only when we have a valid legal basis to do so. The lawful bases we rely upon include:

Consent

Where you have given clear consent for us to process your personal data for a specific purpose. For example, when you submit an inquiry form, you consent to us using your contact details to respond to your request.

You may withdraw consent at any time by contacting us.

Contractual Necessity

Where processing is necessary for the performance of a contract with you or to take steps at your request prior to entering into a contract. This includes processing required to deliver our consulting services.

Legitimate Interests

Where processing is necessary for our legitimate business interests, provided these do not override your rights and freedoms. Examples include improving our website, maintaining security, and managing our business operations.

Legal Obligation

Where processing is necessary to comply with a legal obligation to which we are subject, such as responding to lawful requests from authorities.

Your Rights Under UK GDPR

Under UK GDPR, you have the following rights regarding your personal data:

Right to Be Informed

You have the right to know how we collect and use your personal data. This information is provided in our Privacy Policy and this GDPR page.

Right of Access

You can request a copy of the personal data we hold about you. This is commonly known as a Subject Access Request (SAR). We will respond within one month of receiving your request.

Right to Rectification

If your personal data is inaccurate or incomplete, you have the right to have it corrected. We will respond to requests for rectification within one month.

Right to Erasure

Also known as the 'right to be forgotten', you can request deletion of your personal data in certain circumstances, including:

  • The data is no longer necessary for its original purpose
  • You withdraw consent and no other legal basis applies
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

Right to Restrict Processing

You can request that we limit how we use your personal data in certain circumstances, such as while we verify the accuracy of your data or consider your objection to processing.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.

Right to Object

You can object to processing based on legitimate interests, direct marketing, or processing for research purposes. We will cease processing unless we can demonstrate compelling legitimate grounds.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently use automated decision-making that falls within this category.

Exercising Your Rights

To exercise any of your rights under UK GDPR, please contact us:

Email: [email protected]

We will respond to your request within one month. If your request is complex or you have made multiple requests, we may extend this period by up to two months, but we will inform you of any extension within the first month.

We may need to verify your identity before processing your request to ensure we are providing personal data to the correct individual.

Data Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit
  • Access controls to limit who can view personal data
  • Regular review of security practices
  • Staff training on data protection responsibilities

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

International Transfers

We primarily process personal data within the United Kingdom. If we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.

Complaints

If you are dissatisfied with how we handle your personal data or respond to your rights requests, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF

Website: ico.org.uk

Updates to This Information

We may update this GDPR compliance information periodically. Any changes will be posted on this page with an updated revision date.