GDPR Compliance

Our commitment to protecting your personal data under UK data protection law

Last updated: July 2026

Our Commitment

nebula-glow is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take your privacy seriously and have implemented measures to ensure that your personal data is processed lawfully, fairly, and transparently.

Data Controller

For the purposes of data protection law, nebula-glow is the data controller responsible for your personal data. This means we determine the purposes and means of processing your personal information.

Lawful Basis for Processing

We process personal data only when we have a valid legal basis to do so. The lawful bases we rely upon include:

Your Data Protection Rights

Under the UK GDPR, you have the following rights:

Right to Access

You have the right to request copies of your personal data. We may charge a small fee for this service if the request is manifestly unfounded or excessive.

Right to Rectification

You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.

Right to Erasure

You have the right to request that we erase your personal data under certain conditions, such as when the data is no longer necessary for the purpose it was collected.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data under certain conditions.

Right to Object

You have the right to object to our processing of your personal data under certain conditions, particularly where we are relying on legitimate interests as our legal basis.

Right to Data Portability

You have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions.

Exercising Your Rights

If you wish to exercise any of your rights, please contact us using the details on our Contact page. We will respond to your request within one month. In certain circumstances, we may extend this period by up to two months, in which case we will inform you.

You will not have to pay a fee to exercise your rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.

Data Security Measures

We have implemented appropriate technical and organisational measures to protect your personal data, including:

International Transfers

We do not routinely transfer personal data outside the United Kingdom. If any transfer becomes necessary, we will ensure that appropriate safeguards are in place to protect your data in accordance with UK GDPR requirements.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected and to satisfy any legal, accounting, or reporting requirements. Our standard retention periods are:

Complaints

If you have concerns about our use of your personal data, you have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (ico.org.uk). We would, however, appreciate the opportunity to address your concerns before you approach the ICO, so please contact us in the first instance.

This GDPR compliance notice forms part of our overall privacy documentation. Please also refer to our Privacy Policy and Cookies Policy for comprehensive information about our data practices.