GDPR Compliance
Last updated: September 1, 2026
General Data Protection Regulation
lotus-loop is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines our compliance practices and your rights under GDPR.
Data Controller
lotus-loop acts as the data controller for personal information collected through our website and services.
Contact: [email protected]
Address: 47 Cobblestone Lane, Bristol, BS1 2QR, United Kingdom
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: When you provide explicit consent for specific processing activities
- Contract: When processing is necessary to fulfill our contractual obligations
- Legitimate interests: When processing is necessary for our legitimate business interests
- Legal obligation: When processing is required to comply with legal requirements
Your Rights Under GDPR
You have the following rights regarding your personal data:
Right to Access
You have the right to request a copy of the personal data we hold about you.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
Right to Erasure
You have the right to request deletion of your personal data under certain circumstances.
Right to Restrict Processing
You have the right to request that we limit the processing of your personal data in specific situations.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format and transfer it to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements.
Data Transfers
We do not transfer personal data outside the European Economic Area. If such transfers become necessary, we will ensure appropriate safeguards are in place.
Exercising Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month.
Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection authority.
ICO Website: ico.org.uk
Data Security Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication procedures
- Staff training on data protection
Updates to This Information
We may update this GDPR compliance information from time to time. Material changes will be communicated through our website.