Our commitment to data protection under UK GDPR
Effective Date: September 1, 2026
Lagoon-lumen is committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines how we fulfill our obligations as a data controller and explains your rights as a data subject.
Lagoon-lumen
42 Stonegate
York YO1 8AS
United Kingdom
Email: [email protected]
We process personal data in accordance with the following principles:
We process personal data under the following legal bases:
When you provide explicit consent for specific processing activities, such as subscribing to communications. You may withdraw consent at any time by contacting us.
When processing is necessary to fulfill contractual obligations related to consulting services you have engaged.
When processing serves our legitimate business interests, such as improving services or preventing fraud, provided these interests do not override your fundamental rights and freedoms.
When processing is required to comply with legal or regulatory requirements.
You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data. We will provide this information within one month of your request.
You may request correction of inaccurate or incomplete personal data. We will make corrections within one month.
You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when you object to processing.
You may request that we limit how we use your data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
You may request transfer of your personal data to another service provider in a structured, commonly used, machine-readable format.
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we have compelling legitimate grounds that override your interests.
We do not engage in automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals.
To exercise any of these rights, submit a request to [email protected]. Please include:
We will respond to requests within one month. In complex cases, we may extend this period by two additional months and will inform you of such extensions.
We implement technical and organizational security measures appropriate to the risks presented by our processing activities, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. If the breach poses a high risk to you, we will also notify you directly without undue delay.
When we engage third-party service providers to process data on our behalf, we ensure they provide sufficient guarantees regarding technical and organizational security measures. We maintain written agreements with processors that specify their obligations under UK GDPR.
If we transfer personal data outside the United Kingdom, we ensure appropriate safeguards are in place, such as:
We retain personal data based on the following criteria:
If you believe we have not complied with UK GDPR requirements, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: ico.org.uk
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website or direct notification. Please review this page periodically to stay informed about how we protect your data.