We use cookies to enhance your browsing experience. By continuing to use this site, you consent to our use of cookies.

mist-osprey
Home About Services Contact
Advertising Content

GDPR Compliance Statement

Last updated: June 16, 2026

Our Commitment to GDPR Compliance

mist-osprey is committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This statement outlines how we meet our obligations as a data controller.

Data Controller Information

mist-osprey acts as the data controller for personal information collected through our website and services.

Contact details:
mist-osprey
17 Broadwick Street
London, W1F 0DA
United Kingdom
[email protected]

Lawful Basis for Processing

We process personal data only when we have a lawful basis to do so. The lawful bases we rely on include:

Consent

When you provide personal information through enquiry forms or sign up for communications, you give explicit consent for us to process that data for the stated purposes.

Contractual Necessity

Processing is necessary to deliver services you have requested or entered into agreement for.

Legitimate Interests

We may process data where necessary for legitimate business interests, such as improving services, preventing fraud, or ensuring network security, provided these interests do not override your rights and freedoms.

Legal Obligation

We process data when required to comply with legal obligations, including tax reporting, record-keeping requirements, and regulatory compliance.

Your Rights Under GDPR

Right to Access

You have the right to request confirmation of whether we process your personal data and to receive a copy of that data.

Right to Rectification

You can request correction of inaccurate personal data and completion of incomplete data.

Right to Erasure

You may request deletion of your personal data in certain circumstances, including when data is no longer necessary for its original purpose or when you withdraw consent.

Right to Restrict Processing

You can request limitation of how we use your data in specific situations, such as when you contest data accuracy or object to processing.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used format and to transmit that data to another controller.

Right to Object

You may object to processing based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.

How to Exercise Your Rights

To exercise any of these rights, contact us at [email protected]. We will respond to your request within one month of receipt. If your request is complex or we receive multiple requests, we may extend this period by two additional months, and we will inform you of any such extension.

We may request specific information from you to confirm your identity before processing rights requests.

Data Protection Principles

We adhere to the following data protection principles:

  • Lawfulness, fairness, and transparency in all processing activities
  • Purpose limitation: data collected for specified, explicit purposes
  • Data minimisation: only collecting data necessary for stated purposes
  • Accuracy: keeping personal data accurate and up to date
  • Storage limitation: retaining data only as long as necessary
  • Integrity and confidentiality: ensuring appropriate security measures
  • Accountability: demonstrating compliance with these principles

Data Security Measures

We implement technical and organisational security measures appropriate to the risk, including:

  • Encryption of data in transit and at rest
  • Access controls limiting data access to authorised personnel
  • Regular security assessments and updates
  • Staff training on data protection obligations
  • Incident response procedures for data breaches

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.

International Data Transfers

Personal data is primarily stored and processed within the United Kingdom. If we transfer data outside the UK, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.

Third-Party Processors

When we engage third-party service providers who process personal data on our behalf, we ensure:

  • Written contracts are in place specifying data protection obligations
  • Processors provide sufficient guarantees of GDPR compliance
  • Processors only act on our documented instructions
  • Appropriate security measures are maintained

Children's Privacy

Our services are not directed at children under 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.

Complaints

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office:

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk

Updates to This Statement

We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Material changes will be communicated through our website.

mist-osprey

Professional grant application support across the United Kingdom

Quick Links

  • About
  • Services
  • Contact

Legal

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

Contact

[email protected]

United Kingdom

© 2026 mist-osprey. All rights reserved.