Information presented on this website is advertising in nature

Our Commitment to Data Protection

witty-cascade is committed to ensuring compliance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. We take our responsibilities as a data controller seriously and have implemented measures to protect your personal information.

Data Controller

For the purposes of data protection legislation, the data controller is:

witty-cascade
47 Chancery Lane
London WC2A 1PL
United Kingdom

Email: [email protected]

Your Rights Under GDPR

The GDPR provides you with specific rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal information we hold about you. This is known as a Subject Access Request (SAR). We will respond to such requests within one month of receipt.

Right to Rectification

If any personal information we hold about you is inaccurate or incomplete, you have the right to request correction. We will make necessary amendments promptly.

Right to Erasure

In certain circumstances, you have the right to request that we delete your personal data. This applies when the data is no longer necessary for the purpose it was collected, or when you withdraw consent.

Right to Restrict Processing

You may request that we limit how we use your personal data while we address concerns you have raised or verify the accuracy of information.

Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used format.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that significantly affect you. We do not currently engage in such automated decision-making.

Lawful Basis for Processing

We process personal data under the following lawful bases as defined by the GDPR:

Data Protection Principles

We adhere to the data protection principles set out in the GDPR:

International Data Transfers

When arranging travel services, your personal information may be shared with travel providers located outside the United Kingdom or European Economic Area. In such cases, we ensure that appropriate safeguards are in place, such as standard contractual clauses approved by relevant authorities.

Data Breach Procedures

In the event of a personal data breach that poses a risk to individuals, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.

Exercising Your Rights

To exercise any of your rights under the GDPR, please contact us using the details provided above. We may need to verify your identity before processing your request. There is generally no fee for exercising these rights, although we may charge a reasonable fee for manifestly unfounded or excessive requests.

Complaints

If you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF

Website: ico.org.uk

Updates to This Information

We may update this GDPR compliance information periodically. The date of the last revision will be indicated at the top of the page.

Last updated: July 2026