Your data protection rights under UK GDPR
glow-piston is committed to protecting the privacy and security of your personal data. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page explains your rights under these regulations and how we fulfil our obligations.
glow-piston acts as the data controller for personal information collected through this website. This means we determine how and why your personal data is processed. For any data protection enquiries, please contact us at [email protected].
Right to Access
You have the right to request a copy of the personal information we hold about you. This is known as a Subject Access Request (SAR). We will respond to your request within one month of receipt, though this may be extended by up to two months for complex requests.
Right to Rectification
If you believe that any personal information we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it. We will respond to your request within one month.
Right to Erasure
Also known as the "right to be forgotten," you may request deletion of your personal data in certain circumstances, including when the data is no longer necessary for its original purpose, when you withdraw consent, or when data has been unlawfully processed.
Right to Restrict Processing
You have the right to request that we limit how we use your personal data in certain circumstances, such as when you contest the accuracy of the data or object to our processing.
Right to Data Portability
Where we process your data based on consent or contract performance, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
Right to Object
You have the right to object to processing of your personal data where we rely on legitimate interests as our legal basis. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that produce legal effects or significantly affect you. We do not currently use automated decision-making in our services.
We process personal data under the following lawful bases as defined by UK GDPR:
We adhere to the data protection principles set out in UK GDPR:
To exercise any of your rights under UK GDPR, please contact us using the details on our contact page. We may need to verify your identity before processing your request. We will respond to valid requests within one month, or inform you if an extension is necessary.
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection. You can contact the ICO through their website at ico.org.uk.
We primarily store and process data within the United Kingdom. If we transfer personal data outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
This GDPR information page may be updated periodically to reflect changes in our practices or legal requirements. Please check back regularly for any updates.
Last updated: June 2026