dune-side
Home Courses Our Story Connect Advertisement Content

GDPR Compliance

Last Updated: July 2026

Our Commitment to GDPR

dune-side is committed to complying with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Union and the United Kingdom. This page explains how we fulfill our GDPR obligations and how you can exercise your rights.

Data Controller Information

Entity Name: dune-side

Location: London, United Kingdom

Contact: [email protected]

As the data controller, we determine the purposes and means of processing your personal data.

Lawful Basis for Data Processing

We process personal data only when we have a lawful basis under GDPR Article 6:

  • Consent: You have given clear consent for us to process your personal data for specific purposes
  • Contract: Processing is necessary to fulfill a contract with you, such as delivering educational services
  • Legal Obligation: Processing is necessary to comply with legal requirements
  • Legitimate Interests: Processing is necessary for our legitimate interests, provided these do not override your rights and freedoms

Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

You have the right to request copies of your personal data. We may charge a reasonable fee for additional copies beyond the first request.

Right to Rectification

You have the right to request correction of any inaccurate personal data and to complete any incomplete data.

Right to Erasure

You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes collected or when you withdraw consent.

Right to Restrict Processing

You have the right to request restriction of processing your personal data in specific situations, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to request transfer of your personal data to another organization or directly to you, in a structured, commonly used, and machine-readable format.

Right to Object

You have the right to object to processing of your personal data when we rely on legitimate interests as the legal basis. You also have an absolute right to object to processing for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produces legal effects or similarly significantly affects you. We do not currently engage in such automated decision-making.

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us at [email protected] with:

  • Your full name and contact information
  • Specific right you wish to exercise
  • Details of your request

We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of the extension.

Data Protection Principles

We adhere to the GDPR data protection principles, ensuring personal data is:

  • Processed lawfully, fairly, and transparently
  • Collected for specified, explicit, and legitimate purposes
  • Adequate, relevant, and limited to what is necessary
  • Accurate and kept up to date
  • Kept only as long as necessary
  • Processed securely with appropriate safeguards

Data Security Measures

We implement appropriate technical and organizational measures to ensure data security, including:

  • Encryption of data in transit and at rest
  • Access controls limiting who can view personal data
  • Regular security assessments and updates
  • Staff training on data protection practices
  • Secure data backup and recovery procedures

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.

International Data Transfers

We primarily process data within the United Kingdom. If we transfer personal data outside the UK or EU, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission or transfers to countries with adequacy decisions.

Data Retention

We retain personal data only as long as necessary for the purposes outlined in our Privacy Policy. Specific retention periods include:

  • Enrollment records: 6 years after programme completion
  • Marketing communications consent: Until withdrawn
  • Website usage data: 24 months

Consent Withdrawal

Where we rely on your consent as the legal basis for processing, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. To withdraw consent, contact us at [email protected]

Supervisory Authority

You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with GDPR requirements. In the United Kingdom, the relevant authority is:

Information Commissioner's Office (ICO)

Website: ico.org.uk

However, we encourage you to contact us first so we can address your concerns directly.

Updates to GDPR Compliance

We regularly review our data protection practices to ensure ongoing GDPR compliance. This page will be updated to reflect any changes in our approach or legal requirements.

Questions and Contact

For questions about our GDPR compliance or data protection practices, please contact us at [email protected]

dune-side

Empowering financial confidence through education since our establishment in London.

Quick Links

Courses Our Story Connect

Legal

Privacy Policy GDPR Cookies Policy Terms of Use

Contact

[email protected]

London, United Kingdom

© 2026 dune-side. All rights reserved.