Last updated: 18 June 2026
seed-raven is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This document outlines how we comply with data protection legislation and safeguard your rights.
seed-raven acts as the data controller for personal information collected through our website and business operations. We determine the purposes and means of processing your personal data.
Contact: [email protected]
We process personal data only when we have a lawful basis to do so:
We process the following categories of personal data:
We do not process special category data (sensitive personal information such as health data, racial or ethnic origin, political opinions, religious beliefs) unless specifically required for service delivery and with your explicit consent.
Under UK GDPR, you have the following rights:
You may request confirmation of whether we process your personal data and obtain a copy of that data. This is commonly known as a Subject Access Request (SAR).
You may request correction of inaccurate or incomplete personal data.
You may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes it was collected or when you withdraw consent.
You may request that we restrict processing of your personal data in certain situations, such as when you contest the accuracy of the data.
You may request transfer of your personal data to another organisation in a structured, commonly used, and machine-readable format.
You may object to processing of your personal data based on legitimate interests or for direct marketing purposes.
We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month, though this may be extended in complex cases. We will inform you of any extension and the reasons for delay.
We may request proof of identity before fulfilling certain requests to ensure data is disclosed only to the appropriate individual.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected or to comply with legal obligations. Specific retention periods include:
We implement appropriate technical and organisational measures to protect personal data, including:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. If the breach poses a high risk to you, we will also notify you directly without undue delay.
We do not sell or rent personal data to third parties. We may share data with trusted service providers who assist in delivering our services, such as accounting or legal advisors, under strict confidentiality agreements and only to the extent necessary.
We do not routinely transfer personal data outside the United Kingdom. Should such transfer become necessary, we will ensure appropriate safeguards are in place as required by UK GDPR.
Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such information, please contact us immediately.
If you believe we have not handled your personal data in accordance with data protection law, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
We may update this GDPR compliance statement periodically to reflect changes in our practices or legal requirements. Material changes will be communicated through our website.