Our commitment to protecting your personal data under UK data protection law
Last updated: July 2026
nebula-glow is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take your privacy seriously and have implemented measures to ensure that your personal data is processed lawfully, fairly, and transparently.
For the purposes of data protection law, nebula-glow is the data controller responsible for your personal data. This means we determine the purposes and means of processing your personal information.
We process personal data only when we have a valid legal basis to do so. The lawful bases we rely upon include:
Under the UK GDPR, you have the following rights:
You have the right to request copies of your personal data. We may charge a small fee for this service if the request is manifestly unfounded or excessive.
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
You have the right to request that we erase your personal data under certain conditions, such as when the data is no longer necessary for the purpose it was collected.
You have the right to request that we restrict the processing of your personal data under certain conditions.
You have the right to object to our processing of your personal data under certain conditions, particularly where we are relying on legitimate interests as our legal basis.
You have the right to request that we transfer the data we have collected to another organisation, or directly to you, under certain conditions.
If you wish to exercise any of your rights, please contact us using the details on our Contact page. We will respond to your request within one month. In certain circumstances, we may extend this period by up to two months, in which case we will inform you.
You will not have to pay a fee to exercise your rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
We have implemented appropriate technical and organisational measures to protect your personal data, including:
We do not routinely transfer personal data outside the United Kingdom. If any transfer becomes necessary, we will ensure that appropriate safeguards are in place to protect your data in accordance with UK GDPR requirements.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected and to satisfy any legal, accounting, or reporting requirements. Our standard retention periods are:
If you have concerns about our use of your personal data, you have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (ico.org.uk). We would, however, appreciate the opportunity to address your concerns before you approach the ICO, so please contact us in the first instance.
This GDPR compliance notice forms part of our overall privacy documentation. Please also refer to our Privacy Policy and Cookies Policy for comprehensive information about our data practices.