Last Updated: July 13, 2026
marsh-myth is committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This document outlines our approach to data protection and your rights as a data subject.
marsh-myth acts as the data controller for personal information collected through our website and services. We determine the purposes and means of processing your personal data.
Data Controller:
marsh-myth
47 Berkeley Square
Mayfair
London W1J 5AT
United Kingdom
Email: [email protected]
We process personal data only when we have a lawful basis to do so. The primary legal bases we rely on are:
Processing is necessary to perform our contract with you, including:
Processing is necessary for our legitimate business interests, such as:
We obtain your explicit consent for specific processing activities, including:
Processing required to comply with legal requirements, such as:
You have the right to request a copy of the personal data we hold about you. We will provide this information in a commonly used electronic format within one month of your request.
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request correction. We will respond to such requests within one month.
You may request deletion of your personal data in the following circumstances:
You may request that we restrict processing of your personal data in certain situations:
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller where technically feasible.
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease such processing unless we can demonstrate compelling legitimate grounds that override your interests.
Where processing is based on consent, you may withdraw that consent at any time. This does not affect the lawfulness of processing based on consent before withdrawal.
To exercise any of your GDPR rights, please submit a request to [email protected] with the following information:
We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will notify you of any such extension.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in risk to individuals.
We primarily store and process data within the United Kingdom. Any transfers outside the UK are conducted in accordance with GDPR requirements, utilizing appropriate safeguards such as:
We engage carefully selected third-party processors to assist with our operations. All processors are required to:
We incorporate data protection principles into our operations from the design stage, implementing measures such as:
Our services are not directed at children under 18 years of age. We do not knowingly collect or process personal data from children. If we become aware of such collection, we will take immediate steps to delete the information.
We do not employ automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.
If you believe we have not handled your personal data in accordance with GDPR requirements, you have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Website: ico.org.uk
We review and update this GDPR compliance statement regularly to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website with an updated "Last Updated" date.