Last Updated: September 1, 2026
sapphire-tide is committed to complying with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals within the European Economic Area and the United Kingdom. This statement outlines how we fulfill our obligations under GDPR.
For the purposes of GDPR, sapphire-tide acts as the data controller for personal information collected through our website and services.
Contact details:
Email: [email protected]
Address: 42 Wellington Street, Leeds, LS1 4AB, United Kingdom
We process personal data only when we have a lawful basis to do so:
Under GDPR, you have the following rights regarding your personal data:
You may request confirmation of whether we process your personal data and obtain a copy of that data.
You can request correction of inaccurate personal data or completion of incomplete data.
You may request deletion of your personal data in certain circumstances, such as when it's no longer necessary for the purposes it was collected.
You can request that we limit how we use your personal data in specific situations.
You have the right to receive your personal data in a structured, commonly used format and transmit it to another controller.
You may object to processing based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you can withdraw that consent at any time.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) or your local supervisory authority if you believe we've violated your data protection rights.
To exercise any of these rights, please contact us using the details provided above. We will respond to your request within one month, though this period may be extended for complex requests.
We may require verification of your identity before processing certain requests to protect your personal information.
We collect only the personal data necessary to provide our services and fulfill the purposes outlined in our Privacy Policy. We do not process data excessively or retain it longer than required.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
When we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions by relevant authorities.
In the event of a data breach that poses a risk to individuals' rights and freedoms, we will notify the relevant supervisory authority within 72 hours. If the breach poses a high risk, we will also notify affected individuals without undue delay.
We do not use automated decision-making or profiling that produces legal or similarly significant effects concerning individuals.
Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly.
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.
If you have questions about our GDPR compliance or data protection practices, please contact us at [email protected].