GDPR Compliance
Last Updated: July 21, 2026
Overview
The General Data Protection Regulation (GDPR) is a European Union regulation on data protection and privacy. crater-drift is committed to full compliance with GDPR requirements for all individuals within the European Economic Area.
Data Controller
crater-drift acts as the data controller for personal information collected through our website and services. We determine the purposes and means of processing your personal data.
Contact Details:
crater-drift
42 Kensington Gardens
London, W2 4RB
United Kingdom
Email: [email protected]
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access
You have the right to request confirmation of whether we process your personal data and to receive a copy of that data. We will provide this information within one month of your request.
Right to Rectification
If your personal data is inaccurate or incomplete, you have the right to request correction or completion. We will respond to rectification requests within one month.
Right to Erasure
Also known as the "right to be forgotten," you may request deletion of your personal data in certain circumstances, including:
- The data is no longer necessary for the purposes it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
Right to Restriction of Processing
You may request that we restrict processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your residence, workplace, or where an alleged infringement occurred.
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Consent: You have given clear consent for processing for specific purposes
- Contract: Processing is necessary to fulfil a contract with you
- Legal obligation: Processing is necessary to comply with the law
- Legitimate interests: Processing is necessary for our legitimate interests or those of a third party, unless overridden by your fundamental rights
Data Processing Activities
We process personal data for the following purposes:
- Programme enrolment and administration
- Delivery of training services
- Communication regarding programmes and services
- Payment processing and financial record-keeping
- Website analytics and improvement
- Marketing communications (with consent)
- Legal compliance and protection of rights
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements. Our standard retention periods are:
- Enrolment and programme records: 7 years after programme completion
- Financial records: 7 years as required by UK tax law
- Marketing consent records: Until consent is withdrawn or 3 years of inactivity
- Website analytics: 26 months
Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication mechanisms
- Staff training on data protection
- Incident response procedures
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.
International Data Transfers
If we transfer your data outside the European Economic Area, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions recognising equivalent data protection standards
- Binding corporate rules for intra-group transfers
Exercising Your Rights
To exercise any of your GDPR rights, please contact us at [email protected] with your request. We may need to verify your identity before processing your request. We aim to respond to all requests within one month.
Updates to This Information
We may update this GDPR compliance information periodically. Changes will be posted on this page with an updated revision date.