Last Updated: July 2026
dune-side is committed to complying with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Union and the United Kingdom. This page explains how we fulfill our GDPR obligations and how you can exercise your rights.
Entity Name: dune-side
Location: London, United Kingdom
Contact: [email protected]
As the data controller, we determine the purposes and means of processing your personal data.
We process personal data only when we have a lawful basis under GDPR Article 6:
Under GDPR, you have the following rights regarding your personal data:
You have the right to request copies of your personal data. We may charge a reasonable fee for additional copies beyond the first request.
You have the right to request correction of any inaccurate personal data and to complete any incomplete data.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes collected or when you withdraw consent.
You have the right to request restriction of processing your personal data in specific situations, such as when you contest the accuracy of the data.
You have the right to request transfer of your personal data to another organization or directly to you, in a structured, commonly used, and machine-readable format.
You have the right to object to processing of your personal data when we rely on legitimate interests as the legal basis. You also have an absolute right to object to processing for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produces legal effects or similarly significantly affects you. We do not currently engage in such automated decision-making.
To exercise any of your GDPR rights, please contact us at [email protected] with:
We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of the extension.
We adhere to the GDPR data protection principles, ensuring personal data is:
We implement appropriate technical and organizational measures to ensure data security, including:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.
We primarily process data within the United Kingdom. If we transfer personal data outside the UK or EU, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission or transfers to countries with adequacy decisions.
We retain personal data only as long as necessary for the purposes outlined in our Privacy Policy. Specific retention periods include:
Where we rely on your consent as the legal basis for processing, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. To withdraw consent, contact us at [email protected]
You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with GDPR requirements. In the United Kingdom, the relevant authority is:
Information Commissioner's Office (ICO)
Website: ico.org.uk
However, we encourage you to contact us first so we can address your concerns directly.
We regularly review our data protection practices to ensure ongoing GDPR compliance. This page will be updated to reflect any changes in our approach or legal requirements.
For questions about our GDPR compliance or data protection practices, please contact us at [email protected]