Our commitment to protecting your data under UK GDPR
Last updated: 1 September 2026
This page provides information about how quaint-point complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are committed to ensuring that your personal data is protected and processed lawfully, fairly, and transparently.
quaint-point is the data controller responsible for your personal data. Our contact details are:
quaint-point
47 Kensington High Street
London, W8 5ED
United Kingdom
Email: [email protected]
We adhere to the following data protection principles:
Under UK GDPR, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of receiving your request. There is no fee for this service unless the request is manifestly unfounded or excessive.
You have the right to request correction of any inaccurate personal data we hold about you. We will respond to such requests within one month.
You have the right to request deletion of your personal data in certain circumstances, including:
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or where processing is unlawful but you do not want the data erased.
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format.
You have the right to object to processing based on legitimate interests, direct marketing, or processing for research purposes.
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significant effects. We do not currently use automated decision-making in our services.
To exercise any of these rights, please contact us at [email protected] with the subject line "Data Protection Request". We may need to verify your identity before processing your request.
We will respond to all legitimate requests within one month. Occasionally, it may take longer if your request is particularly complex or you have made multiple requests, in which case we will notify you and keep you updated.
We process personal data under the following legal bases:
We conduct Data Protection Impact Assessments (DPIAs) when introducing new technologies or processing activities that may result in high risk to individuals' rights and freedoms.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.
Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as:
Given the nature and scale of our processing activities, we are not required to appoint a Data Protection Officer under UK GDPR. However, data protection queries should be directed to [email protected].
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: www.ico.org.uk
We would, however, appreciate the opportunity to address your concerns before you approach the ICO. Please contact us in the first instance.
We may update this GDPR compliance notice from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this notice periodically to stay informed about how we protect your data.