Frosty Spiral
  • Our Story
  • Programmes
  • Get in Touch

GDPR Compliance

Last updated: May 6, 2026

Our Commitment to GDPR

Frosty Spiral is committed to complying with the General Data Protection Regulation (GDPR) and protecting the rights of individuals whose personal data we process. This page outlines our GDPR compliance measures and your rights under the regulation.

Data Controller Information

Frosty Spiral acts as the data controller for personal data collected through our website and services.

Data Controller: Frosty Spiral
Address: 42 Cathedral Road, Cardiff CF11 9LJ, United Kingdom
Email: [email protected]

Lawful Basis for Processing

We process personal data only when we have a lawful basis to do so:

  • Consent: You have given clear consent for us to process your personal data for specific purposes (e.g., marketing communications)
  • Contract: Processing is necessary to fulfill a contract with you (e.g., delivering our educational programmes)
  • Legal obligation: Processing is necessary to comply with the law
  • Legitimate interests: Processing is necessary for our legitimate interests, provided these do not override your rights

Your Rights Under GDPR

You have the following rights regarding your personal data:

Right to Access

You have the right to request copies of your personal data. We may charge a small fee for this service.

Right to Rectification

You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.

Right to Erasure

You have the right to request that we erase your personal data, under certain conditions.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data, under certain conditions.

Right to Object to Processing

You have the right to object to our processing of your personal data, under certain conditions.

Right to Data Portability

You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.

Right to Withdraw Consent

Where we rely on consent to process your personal data, you have the right to withdraw that consent at any time.

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us at:

Email: [email protected]

We will respond to your request within one month of receipt. If your request is particularly complex or you have made multiple requests, we may extend this period by two additional months, and we will inform you.

Data Protection Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data
  • Regular security assessments and updates
  • Access controls and authentication procedures
  • Staff training on data protection
  • Confidentiality agreements with third-party processors

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.

International Data Transfers

We do not routinely transfer personal data outside the UK or EEA. If such transfers become necessary, we will ensure appropriate safeguards are in place in accordance with GDPR requirements.

Automated Decision-Making and Profiling

We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.

Children's Data

While our programmes include children, we collect personal data only from parents or guardians. We do not process personal data of children under 16 without verified parental consent.

Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the supervisory authority:

Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113

Updates to This Page

We may update this GDPR compliance information to reflect changes in our practices or legal requirements. Any changes will be posted on this page with an updated date.

Contact Us

For any questions about our GDPR compliance or to exercise your rights, contact us at:

Email: [email protected]
Address: 42 Cathedral Road, Cardiff CF11 9LJ, United Kingdom

Frosty Spiral

Building financial confidence across generations in Cardiff.

Quick Links

  • About Us
  • Programmes
  • Contact

Legal

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

© 2026 Frosty Spiral. All rights reserved.