Our commitment to protecting your data under UK GDPR regulations
Last Updated: 9 December 2025
The UK General Data Protection Regulation (UK GDPR) is the United Kingdom's data protection framework following Brexit, based on the EU GDPR but adapted for UK law. It works alongside the Data Protection Act 2018 to regulate how organizations collect, use, and protect personal data.
At CrownSpinScout, we are fully committed to compliance with UK GDPR and ensuring your personal data is handled lawfully, fairly, and transparently.
We process personal data in accordance with UK GDPR principles: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.
Under UK GDPR, we are classified as a Data Controller for the personal information we collect and process through this website.
Data Controller: CrownSpinScout
Website: crownspinscout.co.uk
Contact Email: info@crownspinscout.co.uk
Data Protection Email: privacy@crownspinscout.co.uk
Phone: +44 20 7123 4567
Address: London, United Kingdom
We only process your personal data when we have a valid lawful basis under UK GDPR. We rely on the following legal grounds:
When you explicitly agree to our processing of your personal data for specific purposes, such as:
Your right: You can withdraw consent at any time by unsubscribing, adjusting cookie settings, or contacting us.
When processing is necessary for our legitimate business interests that do not override your rights and freedoms:
Balancing test: We regularly assess whether our interests are proportionate and respect your privacy rights.
When we must process data to comply with UK legal requirements:
When processing is necessary to fulfill our obligations or provide services you've requested:
UK GDPR grants you comprehensive rights regarding your personal data. We are committed to facilitating the exercise of these rights.
Request a copy of the personal data we hold about you, including details about processing activities.
Request correction of inaccurate or incomplete personal data.
Request deletion of your personal data ("right to be forgotten") in certain circumstances.
Request that we limit how we process your data while you contest accuracy or object to processing.
Receive your personal data in a structured, commonly used, machine-readable format.
Object to processing based on legitimate interests or for direct marketing purposes.
Request human intervention if decisions are made solely by automated processing.
Withdraw previously given consent at any time without affecting prior processing.
To exercise any of these rights, please contact us using the following methods:
Response time: We will respond to your request within 30 days (1 month) as required by UK GDPR. In complex cases, we may extend this by an additional 2 months and will inform you accordingly.
Free of charge: We do not charge fees for exercising your rights, unless requests are manifestly unfounded or excessive.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, or resolve disputes.
| Data Type | Retention Period | Reason |
|---|---|---|
| Newsletter Subscriptions | Until unsubscribe or deletion request | Ongoing consent |
| Contact Form Inquiries | 2 years from last communication | Customer service & follow-up |
| Website Analytics (Google Analytics) | 26 months (anonymized after) | Service improvement & insights |
| Cookie Consent Records | 12-24 months | Compliance evidence |
| Age Verification Records | Session duration only | Legal compliance (no storage) |
| Affiliate Tracking Data | 6 years | Financial & tax obligations |
| Legal/Compliance Records | 6-7 years (as required by law) | UK legal obligations |
Secure Deletion: When retention periods expire, we securely delete or anonymize personal data using industry-standard methods to prevent recovery or unauthorized access.
We implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage (UK GDPR Article 32).
In the event of a personal data breach that poses a risk to your rights and freedoms:
Your personal data is primarily processed and stored within the United Kingdom and European Economic Area (EEA).
If we transfer personal data to countries outside the UK/EEA, we ensure appropriate safeguards are in place as required by UK GDPR (Chapter V):
Third-Party Processors: We ensure all service providers handling your data on our behalf comply with UK GDPR through contractual agreements (Data Processing Agreements).
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you (UK GDPR Article 22).
We use automated tools for the following limited purposes only:
None of these activities involve decisions that legally or significantly affect individuals.
Our website is intended solely for individuals 18 years of age and older. We do not knowingly collect or process personal data from children under 18.
If you believe we have inadvertently collected information from someone under 18, please contact us immediately at privacy@crownspinscout.co.uk.
While not legally required to appoint a DPO under UK GDPR (as we are not a public authority and our processing activities do not meet the threshold), we have designated a Data Protection Team responsible for overseeing GDPR compliance.
Email: privacy@crownspinscout.co.uk
Phone: +44 20 7123 4567
Purpose: Data protection inquiries, rights requests, compliance questions
You have the right to lodge a complaint with the UK's data protection supervisory authority if you believe we have not complied with UK GDPR.
Website: https://ico.org.uk/
Helpline: 0303 123 1113
Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Online Complaints: https://ico.org.uk/make-a-complaint/
We Encourage Direct Contact First: While you have the right to complain directly to the ICO, we encourage you to contact us first so we can address your concerns promptly and effectively.
We regularly review and update our GDPR compliance practices to ensure ongoing adherence to UK data protection laws and best practices.
This page was last updated on 9 December 2025. Material changes will be communicated via our website and Privacy Policy.
Our Data Protection Team is here to help you exercise your UK GDPR rights and answer any compliance questions.
Contact Data Protection Team