This page explains how we comply with the General Data Protection Regulation and your rights under this legislation.
For the purposes of data protection legislation, snow-logic is the data controller responsible for processing your personal information.
We process your personal data under the following lawful bases:
The GDPR provides you with several rights regarding your personal data:
You have the right to request a copy of the personal information we hold about you. We will provide this information within one month of your request, free of charge.
If you believe any information we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it.
You have the right to request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purposes it was collected or if you withdraw consent.
You can request that we limit how we use your personal data in certain situations, such as while we verify the accuracy of data you have disputed.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis for processing.
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently use automated decision-making processes.
To exercise any of your GDPR rights, please contact us using the email address provided on our contact page. We will respond to your request within one month.
If you are not satisfied with how we have handled your request, you have the right to lodge a complaint with the Information Commissioner's Office, the UK supervisory authority for data protection issues.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. For enquiry data, this typically means:
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing personal data. This includes:
We do not transfer your personal data outside the United Kingdom. If this changes in the future, we will ensure appropriate safeguards are in place as required by GDPR.
In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
Last updated: June 2026