GDPR Compliance
Last updated: 1 September 2026
Our Commitment to GDPR Compliance
marsh-ferret.com is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Data Controller
For the purposes of GDPR, the data controller is:
marsh-ferret.com
42 Pembroke Street
Cambridge, CB2 3QY
United Kingdom
Email: [email protected]
Lawful Basis for Processing
We process personal data only when we have a lawful basis to do so. The lawful bases we rely on include:
- Consent: When you have given clear consent for us to process your personal data for specific purposes
- Contract: When processing is necessary for the performance of a contract with you
- Legal obligation: When we must process your data to comply with the law
- Legitimate interests: When processing is necessary for our legitimate interests or those of a third party, provided your rights do not override those interests
Your Rights Under GDPR
As a data subject, you have the following rights:
Right to Access
You have the right to request copies of your personal data. We may charge a reasonable fee for additional copies.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purposes it was collected.
Right to Restrict Processing
You have the right to request restriction of processing your personal data in certain circumstances.
Right to Object
You have the right to object to processing of your personal data in certain circumstances, particularly for direct marketing purposes.
Right to Data Portability
You have the right to request transfer of your personal data to another organization or directly to you in a commonly used, machine-readable format.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state where you live, work, or where an alleged infringement occurred.
How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month, though this may be extended by two additional months in complex cases.
We may ask you to verify your identity before processing your request to ensure we are disclosing information to the right person.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication measures
- Staff training on data protection principles
- Incident response procedures for data breaches
Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
International Data Transfers
If we transfer your personal data outside the European Economic Area, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions recognizing equivalent data protection standards
- Other legally approved transfer mechanisms
Data Protection Officer
For questions specifically related to GDPR compliance or to exercise your rights, you may contact our data protection contact at [email protected].
Updates to This Statement
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.