Our Commitment to Data Protection

iris-beaver is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take the protection of your personal data seriously and have implemented appropriate measures to ensure compliance with all applicable data protection laws.

Data Controller Information

Data Controller: iris-beaver
Registered Address: 27 Deansgate, Manchester M3 2FF, United Kingdom
Contact Email: info at iris-beaver.com

Your GDPR Rights Explained

1. Right to Be Informed

You have the right to be informed about the collection and use of your personal data. This notice, along with our Privacy Policy, explains how we collect, use, and protect your information.

2. Right of Access

You have the right to request access to the personal data we hold about you. This is commonly known as a "subject access request." We will provide you with a copy of your data free of charge within one month of your request.

3. Right to Rectification

If you believe any information we hold about you is inaccurate or incomplete, you have the right to request correction. We will update your records promptly upon verification.

4. Right to Erasure

Also known as the "right to be forgotten," you can request deletion of your personal data in certain circumstances, such as:

  • The data is no longer necessary for the purpose it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

Please note that we may need to retain certain information to comply with legal obligations or for the establishment, exercise, or defense of legal claims.

5. Right to Restrict Processing

You have the right to request restriction of processing your personal data in the following situations:

  • You contest the accuracy of the data
  • Processing is unlawful but you prefer restriction over erasure
  • We no longer need the data but you require it for legal claims
  • You have objected to processing pending verification of our legitimate grounds

6. Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format. You can also request that we transfer this data directly to another organization where technically feasible.

7. Right to Object

You have the right to object to processing of your personal data where we rely on legitimate interests as our legal basis. You also have an absolute right to object to processing for direct marketing purposes.

8. Rights Related to Automated Decision Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. We do not currently engage in automated decision-making processes.

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us using the following methods:

  • Email: info at iris-beaver.com
  • Post: iris-beaver, 27 Deansgate, Manchester M3 2FF, United Kingdom

We will respond to your request within one month. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension.

Verification Process

To protect your privacy and security, we may need to verify your identity before processing your request. We may ask you to provide additional information to confirm your identity, particularly for access or deletion requests.

No Fee Required

You will not usually have to pay a fee to access your personal data or exercise any of your other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

Lawful Basis for Processing

We process your personal data under the following lawful bases:

  • Contract: Processing is necessary to fulfill our contractual obligations for travel services
  • Legitimate Interests: We have a legitimate business interest in processing your data to improve our services, ensure website security, and prevent fraud
  • Legal Obligation: We must process certain data to comply with legal and regulatory requirements
  • Consent: For certain activities such as marketing communications, we rely on your explicit consent

Data Protection Principles

We adhere to the following data protection principles as outlined in UK GDPR:

  • Lawfulness, fairness, and transparency: We process data lawfully and inform you about our processing activities
  • Purpose limitation: We collect data for specific, legitimate purposes and do not use it in ways incompatible with those purposes
  • Data minimization: We only collect data that is necessary for our purposes
  • Accuracy: We take reasonable steps to ensure data is accurate and up to date
  • Storage limitation: We retain data only as long as necessary
  • Integrity and confidentiality: We implement appropriate security measures to protect your data
  • Accountability: We can demonstrate our compliance with these principles

Data Breach Notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach where required by law.

International Transfers

When we transfer your data outside the United Kingdom, we ensure appropriate safeguards are in place, such as:

  • Standard contractual clauses approved by the UK government
  • Transfers to countries with adequacy decisions
  • Other legally approved transfer mechanisms

Complaints and Supervisory Authority

If you are not satisfied with how we have handled your personal data or your request, you have the right to lodge a complaint with the supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Website: www.ico.org.uk
Helpline: 0303 123 1113

Updates to This Statement

We may update this GDPR compliance statement from time to time to reflect changes in our practices or legal requirements. The updated version will be posted on this page with a revision date.

Last Updated: August 4, 2026