GDPR Compliance Statement
Last updated: September 11, 2026
Our Commitment to Data Protection
lagoon-kernel is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This statement outlines how we comply with these regulations.
Data Controller Information
lagoon-kernel is the data controller responsible for your personal data.
Contact details:
Email: [email protected]
Address: 42 Kensington Gardens, London, W2 4RU, United Kingdom
Lawful Basis for Processing
We process personal data only when we have a lawful basis to do so:
- Performance of a contract: Processing necessary to deliver travel guides you purchase
- Legitimate interests: Improving our services, sending updates about your purchased region
- Consent: Marketing communications, optional surveys, or newsletter subscriptions
- Legal obligation: Compliance with UK tax, accounting, and regulatory requirements
Your Rights Under UK GDPR
You have the following rights regarding your personal data:
Right to Access
You can request a copy of all personal data we hold about you. We will provide this within one month of your request.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure (Right to be Forgotten)
You can request deletion of your personal data when:
- The data is no longer necessary for the purposes it was collected
- You withdraw consent and there's no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
Right to Restriction of Processing
You can request that we limit how we use your data in certain circumstances, such as when you contest the accuracy of the data.
Right to Data Portability
You can request to receive your personal data in a structured, commonly used, and machine-readable format, or have it transmitted to another controller.
Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes at any time.
Rights Related to Automated Decision Making
We do not use automated decision-making or profiling that produces legal effects concerning you.
How to Exercise Your Rights
To exercise any of your rights, contact us at [email protected] with:
- Your full name and email address
- A clear description of your request
- Proof of identity (if necessary to verify your request)
We will respond within one month. In complex cases, this may be extended by two additional months, and we will inform you of the extension.
Data Processing Principles
We adhere to the following principles when processing personal data:
- Lawfulness, fairness, and transparency: We process data legally, fairly, and transparently
- Purpose limitation: We collect data for specific, explicit, and legitimate purposes
- Data minimisation: We collect only data that is necessary for our purposes
- Accuracy: We keep data accurate and up to date
- Storage limitation: We retain data only as long as necessary
- Integrity and confidentiality: We protect data with appropriate security measures
- Accountability: We demonstrate compliance with these principles
Data Retention
We retain personal data for the following periods:
- Customer data (name, email, purchases): Duration of service provision plus 6 years for legal and accounting purposes
- Marketing consent records: Until consent is withdrawn, then 3 years for proof of consent
- Website analytics: 26 months
- Correspondence: 3 years after the last interaction
Data Security
We implement appropriate technical and organisational measures including:
- Encryption of data in transit and at rest
- Access controls limiting who can view personal data
- Regular security assessments and updates
- Staff training on data protection
- Secure data backup procedures
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach
- Notify affected individuals without undue delay if the breach poses a high risk
- Provide information about the nature of the breach and steps being taken
Third-Party Processors
We work with third-party service providers who process data on our behalf. We ensure these processors:
- Provide sufficient guarantees of GDPR compliance
- Process data only on our instructions
- Implement appropriate security measures
- Have Data Processing Agreements in place
International Transfers
If we transfer data outside the UK, we ensure adequate safeguards are in place through:
- Adequacy decisions by the UK government
- Standard Contractual Clauses approved by the UK authorities
- Other legally recognised transfer mechanisms
Complaints
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
Updates to This Statement
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.