GDPR Compliance

Last updated: July 21, 2026

Our Commitment to GDPR

misty-leaf is committed to complying with the General Data Protection Regulation (GDPR). This page outlines how we process your personal data in accordance with GDPR requirements.

Legal Basis for Processing

We process your personal data under the following legal bases:

  • Contract Performance: To provide the services you have requested
  • Legitimate Interests: To improve our services and communicate relevant information
  • Consent: For marketing communications, where we have obtained your explicit consent
  • Legal Obligation: To comply with applicable laws and regulations

Your Rights Under GDPR

Under GDPR, you have the following rights:

  • Right to Access: You can request a copy of the personal data we hold about you
  • Right to Rectification: You can request correction of inaccurate or incomplete data
  • Right to Erasure: You can request deletion of your personal data in certain circumstances
  • Right to Restrict Processing: You can request that we limit how we use your data
  • Right to Data Portability: You can request your data in a structured, commonly used format
  • Right to Object: You can object to processing based on legitimate interests or for direct marketing
  • Rights Related to Automated Decision Making: You have rights regarding automated decisions including profiling

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Service delivery and customer support
  • Legal and regulatory compliance requirements
  • Resolving disputes and enforcing our agreements

When personal data is no longer needed, we will securely delete or anonymize it.

Data Sharing

We do not sell your personal data to third parties. We may share your data with:

  • Service providers who assist in delivering our services
  • Professional advisors including lawyers and accountants
  • Law enforcement or regulatory authorities when legally required

All third parties are required to maintain the confidentiality and security of your data.

International Data Transfers

Your data is primarily processed within the United Kingdom. If we transfer data outside the UK, we ensure appropriate safeguards are in place to protect your information in accordance with GDPR requirements.

Security Measures

We implement appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:

  • Encryption of sensitive data
  • Regular security assessments
  • Access controls and authentication
  • Staff training on data protection

Exercising Your Rights

To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month of receipt. In some cases, we may extend this period by two additional months if necessary, taking into account the complexity of your request.

Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.

Contact Information

For any questions regarding GDPR compliance or to exercise your rights, please contact us at [email protected].