Last Updated: July 13, 2026
We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This document outlines how we comply with these regulations and protect your rights.
For the purposes of GDPR, the data controller is river-den, located at 45 Deansgate, Manchester, M3 2AY, United Kingdom. We are responsible for deciding how we hold and use personal information about you.
We process your personal data based on the following lawful grounds:
Under GDPR, you have the following rights:
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements. When we no longer need your data, we securely delete or anonymize it.
We primarily process data within the United Kingdom. If we transfer your data outside the UK or EEA, we ensure appropriate safeguards are in place to protect your information in accordance with GDPR requirements.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform you without undue delay.
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month, though this may be extended in complex cases.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection.