GDPR Compliance
Last updated: 11 September 2026
Our Commitment to GDPR
delta-caribou is committed to complying with the General Data Protection Regulation (GDPR) and protecting the rights of individuals within the European Economic Area and the United Kingdom.
Data Controller
For the purposes of GDPR, delta-caribou acts as the data controller for personal information collected through our website and services.
Contact: [email protected]
Your GDPR Rights
Under GDPR, you have the following rights:
Right to Access
You can request a copy of the personal data we hold about you. We will provide this information within one month of your request.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure
You can request deletion of your personal data when it is no longer necessary for the purposes it was collected, or when you withdraw consent.
Right to Restriction of Processing
You can request that we limit how we use your data in certain circumstances.
Right to Data Portability
You can request a copy of your data in a structured, commonly used format that can be transferred to another service provider.
Right to Object
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Where processing is based on consent, you can withdraw that consent at any time.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary to fulfill a contract with you
- Legal obligation: Processing is necessary to comply with the law
- Legitimate interests: Processing is necessary for our legitimate interests, provided your rights do not override those interests
Data Protection Measures
We implement appropriate technical and organisational measures, including:
- Encryption of data in transit and at rest
- Access controls and authentication requirements
- Regular security assessments
- Staff training on data protection
- Incident response procedures
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements.
Typical retention periods:
- Course enrolment records: 7 years
- Marketing consent records: until consent is withdrawn
- Website analytics data: 26 months
- Email correspondence: 3 years
International Data Transfers
When we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions confirming the recipient country provides adequate protection
- Binding corporate rules
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
Exercising Your Rights
To exercise any of your GDPR rights, contact us at [email protected]. Please include:
- Your full name and contact details
- Details of your request
- Proof of identity (if required for security purposes)
We will respond to your request within one month. In complex cases, this may be extended by two additional months, and we will inform you of any delay.
Contact
For questions about our GDPR compliance or to exercise your rights, contact us at [email protected].