Last Updated: September 8, 2026
zephyrmarsh is committed to protecting the privacy and security of personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This statement outlines how we fulfill our obligations as a data controller.
For the purposes of data protection legislation, the data controller is:
zephyrmarsh
42 Kelvingrove Street
Glasgow G3 7SA
United Kingdom
Email: [email protected]
We process personal data under the following lawful bases as defined by UK GDPR:
You have the following rights regarding your personal data:
You may request confirmation of whether we process your personal data and obtain a copy of that data along with supplementary information about how it is processed.
You may request correction of inaccurate personal data or completion of incomplete data.
You may request deletion of your personal data in certain circumstances, including where data is no longer necessary for the purposes for which it was collected or where you withdraw consent.
You may request that we restrict processing of your personal data in specific circumstances, such as when you contest data accuracy or object to processing.
Where processing is based on consent or contract and carried out by automated means, you may request to receive your data in a structured, commonly used format or have it transmitted to another controller.
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
To exercise any of your data protection rights, please contact us at [email protected]. We will respond to requests within one month, though this may be extended by two months for complex requests. We may request additional information to verify your identity before processing requests.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal obligations. Course enrollment records are maintained for seven years in accordance with educational record-keeping standards.
Personal data is primarily stored and processed within the United Kingdom. Any transfers outside the UK are conducted with appropriate safeguards in place, such as standard contractual clauses approved by regulatory authorities.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by UK GDPR.
We may engage third-party processors to assist with specific functions such as website hosting and email communications. All processors are carefully selected and bound by data processing agreements that ensure GDPR compliance.
While we provide educational services for children, enrollment is conducted through parents or guardians. We do not directly collect or process personal data of children under 16 without parental consent.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
This GDPR compliance statement may be updated periodically to reflect changes in our practices or legal requirements. The last updated date is indicated at the top of this document.
For questions or concerns regarding data protection and GDPR compliance, contact us at [email protected].