GDPR Compliance Statement
Last Updated: August 4, 2026
Our Commitment
ash-grouse is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws in the United Kingdom.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: When you provide explicit consent for specific processing activities, such as marketing communications.
- Contract Performance: To fulfil our contractual obligations when you enroll in our programmes.
- Legitimate Interests: For administrative purposes and improving our services, provided your rights are not overridden.
- Legal Obligation: When required to comply with legal or regulatory requirements.
Your GDPR Rights
Under the GDPR, you have the following rights:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data in certain circumstances.
- Right to Restrict Processing: Request limitation of how we use your data.
- Right to Data Portability: Request your data in a structured, commonly used format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month.
Data Protection Officer
For data protection enquiries, you can reach our Data Protection Officer at [email protected].
International Data Transfers
We process your data primarily within the United Kingdom. If data is transferred outside the UK or European Economic Area, we ensure appropriate safeguards are in place.
Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the United Kingdom.
Security Measures
We implement appropriate technical and organisational security measures including encryption, access controls, and regular security assessments to protect your personal data.
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects.