Our commitment to protecting your data under UK GDPR regulations.
Last updated: September 2026
moss-loft is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines how we handle your personal data in accordance with these regulations.
moss-loft acts as the data controller for personal information collected through this website. This means we determine the purposes and means of processing your personal data.
Contact details:
moss-loft
47 Chancery Lane
London WC2A 1PL
United Kingdom
Email: [email protected]
We process personal data only when we have a lawful basis to do so. Our processing activities rely on:
When you submit enquiry forms or sign up for our courses, you provide consent for us to process your data for the specified purposes. You may withdraw consent at any time by contacting us.
When you enrol in a course, we process your data as necessary to fulfil our contractual obligations to you, including course administration and communication.
We may process data based on our legitimate business interests, such as improving our services and website functionality, provided these interests do not override your fundamental rights.
Under UK GDPR, you have the following rights:
You have the right to request a copy of the personal data we hold about you. We will respond to such requests within one month.
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
You have the right to request the deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes it was collected.
You have the right to request that we limit how we use your personal data in certain circumstances.
You have the right to receive the personal data you provided to us in a structured, commonly used, machine-readable format.
You have the right to object to processing of your personal data in certain circumstances, including processing for direct marketing purposes.
We implement appropriate technical and organisational measures to protect personal data, including:
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected and to comply with legal obligations. Specific retention periods are outlined in our Privacy Policy.
We do not routinely transfer personal data outside the United Kingdom. If such transfers become necessary, we will ensure appropriate safeguards are in place.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and, where required, inform affected individuals without undue delay.
To exercise any of your data protection rights, please contact us at [email protected]. We will respond to your request within one month. There is no fee for most requests, though we may charge a reasonable fee for unfounded, repetitive, or excessive requests.
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk
We may update this GDPR information periodically. Any changes will be posted on this page with an updated revision date.