Our Commitment to GDPR

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that governs how organizations process personal data of individuals within the European Union and European Economic Area. As a UK-based travel agency, misty-osprey is committed to full compliance with GDPR principles.

Legal Basis for Processing

We process your personal data based on the following legal grounds:

Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal information we hold about you. We will provide this information in a structured, commonly used, and machine-readable format.

Right to Rectification

If you believe any information we hold about you is inaccurate or incomplete, you have the right to request correction or completion of that data.

Right to Erasure

Also known as the "right to be forgotten," you can request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, subject to legal retention requirements.

Right to Restrict Processing

You have the right to request that we limit how we use your personal data in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability

You can request to receive your personal data in a structured format and have it transmitted to another organization where technically feasible.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

Data Protection Officer

For questions regarding data protection or to exercise your GDPR rights, please contact us at:

Email: [email protected]
Address: 42 Deansgate Avenue, Manchester M3 2FF, United Kingdom

Response Timeline

We will respond to requests to exercise your GDPR rights within one month of receipt. In complex cases, this period may be extended by up to two additional months, and we will inform you of any such extension.

Right to Lodge a Complaint

If you believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection.

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk

International Data Transfers

When booking travel services that involve destinations outside the UK or EU, your personal information may be transferred to service providers in those locations. We ensure appropriate safeguards are in place for such transfers in accordance with GDPR requirements.

Data Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk to you, we will also communicate the breach directly to you without undue delay.

Children's Privacy

Our services are not directed to children under 16 years of age. When processing travel arrangements for minors, we obtain consent from parents or legal guardians as required by applicable law.