Last updated: 4 August 2026
We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This page explains how we comply with these regulations and what rights you have regarding your personal information.
For the purposes of GDPR, the data controller is:
meadow-loop
42 Park Square East
Leeds LS1 2NP
United Kingdom
Email: [email protected]
We process personal data only when we have a lawful basis to do so. The lawful bases we rely on include:
Under GDPR, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. This is commonly known as a subject access request.
You can ask us to correct any personal data that is inaccurate or incomplete.
Also known as the right to be forgotten, you can request deletion of your personal data in certain circumstances.
You can ask us to limit how we use your personal data in specific situations.
You can request to receive your personal data in a structured, commonly used format and transmit it to another controller.
You can object to processing of your personal data where we rely on legitimate interests as the lawful basis.
You have the right not to be subject to decisions based solely on automated processing that significantly affect you. We do not currently use automated decision-making processes.
To exercise any of your GDPR rights, please contact us via email at [email protected] with details of your request.
We will respond to your request within one month of receipt. In complex cases, we may extend this period by up to two months and will inform you of the extension and reasons.
We may need to verify your identity before processing certain requests to ensure personal data is disclosed only to authorised individuals.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected or to comply with legal obligations. Specific retention periods include:
We primarily store and process data within the United Kingdom and European Economic Area. If we transfer personal data outside these regions, we ensure appropriate safeguards are in place, such as:
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and accidental loss, destruction, or damage. These measures include:
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach where required by law.
We work with carefully selected third-party service providers who process personal data on our behalf. These processors are bound by contractual obligations to implement appropriate security measures and process data only as instructed by us.
We conduct due diligence on all processors to ensure they meet GDPR requirements.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Website: ico.org.uk
Helpline: 0303 123 1113
We encourage you to contact us first so we can address your concerns directly.
We may update this GDPR compliance information periodically to reflect changes in our practices or legal requirements. Please review this page regularly to stay informed about how we protect your data.