Information on this site is advertising in nature

GDPR Compliance

cliff-path is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and UK data protection laws.

Data Controller

cliff-path acts as the data controller for personal information collected through our website and services. We are responsible for ensuring your data is processed lawfully and transparently.

Your Rights Under GDPR

Right to Access

You have the right to request access to the personal data we hold about you. We will provide a copy of your data in a commonly used electronic format within one month of your request.

Right to Rectification

If you believe any information we hold about you is inaccurate or incomplete, you have the right to request correction. We will update your information promptly upon verification.

Right to Erasure

You may request deletion of your personal data under certain circumstances, including when the data is no longer necessary for the purposes it was collected or when you withdraw consent.

Right to Restrict Processing

You can request that we limit how we use your data while we investigate concerns you have raised about its accuracy or our use of it.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used format and transmit it to another controller where technically feasible.

Right to Object

You may object to processing of your personal data where we rely on legitimate interests as the legal basis for processing.

Right to Withdraw Consent

Where we process your data based on consent, you have the right to withdraw that consent at any time.

How to Exercise Your Rights

To exercise any of these rights, please contact us at: [email protected]

We will respond to your request within one month. In some cases, we may need to verify your identity before processing your request.

Data Protection Principles

We process personal data in accordance with the following principles:

Legal Basis for Processing

We process your personal data under the following legal bases:

Data Security

We implement appropriate technical and organizational measures including:

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.

Third-Party Processors

When we engage third-party service providers to process data on our behalf, we ensure they provide sufficient guarantees of GDPR compliance through written agreements.

International Transfers

If we transfer your data outside the UK, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by UK authorities.

Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.

Children's Data

Our services are not directed at individuals under 18 years of age. We do not knowingly collect personal data from children.

Complaints

If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Tel: 0303 123 1113

Updates to GDPR Compliance

We regularly review our data protection practices to ensure ongoing compliance with GDPR requirements. This page was last updated in July 2026.