Last updated: 19 June 2026
We are committed to protecting your personal data and respecting your privacy rights in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018. This statement outlines how we comply with data protection principles in our operations.
For the purposes of data protection legislation, the data controller is:
deft-mist
42 Buchanan Street
Glasgow G1 3HL
United Kingdom
Email: [email protected]
We process personal data in accordance with the following principles:
You have the following rights regarding your personal data:
You have the right to clear, transparent information about how we use your personal data. This statement and our Privacy Policy fulfill this obligation.
You can request confirmation of whether we process your personal data and obtain a copy of that data. We will respond to access requests within one month.
If your personal data is inaccurate or incomplete, you have the right to have it corrected or completed. We will make corrections within one month of your request.
You can request deletion of your personal data in certain circumstances, including:
Note that we may be required to retain certain information for legal or regulatory purposes.
You can request that we limit how we use your personal data in certain situations, such as when you contest data accuracy or object to processing.
Where processing is based on consent or contract and carried out by automated means, you can request your data in a structured, commonly used, machine-readable format and have it transmitted to another controller.
You can object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
You have the right not to be subject to decisions based solely on automated processing that produces legal or similarly significant effects. We do not currently employ automated decision-making processes.
To exercise any of these rights, contact us at [email protected] or write to our postal address. We will respond within one month, though this may be extended by two months for complex requests. We will inform you of any extension and the reasons for it.
We may request proof of identity to prevent unauthorized disclosure of personal data. This verification protects your privacy and security.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you without undue delay. We will also report the breach to the Information Commissioner's Office within 72 hours of becoming aware of it, where required by law.
For data protection inquiries or to exercise your rights, contact our data protection representative at [email protected]
We primarily store and process data within the United Kingdom. If we transfer your personal data outside the UK, we ensure appropriate safeguards are in place, such as:
Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will take steps to delete it promptly.
We may update this GDPR compliance statement periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated through website notices or direct contact.
If you believe we have not complied with data protection legislation, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: www.ico.org.uk
For questions regarding this GDPR compliance statement or our data protection practices, contact us at [email protected]