GDPR Compliance
Last updated: 8 May 2026
Our Commitment to Data Protection
arctwist is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page explains how we meet our obligations and your rights under these regulations.
Legal Basis for Processing
We process your personal data under the following legal bases:
Consent
When you provide information through our booking forms or sign up for communications, we rely on your explicit consent to process your data.
Contract Performance
When you book a programme with us, processing your information is necessary to fulfill our contractual obligations to deliver the service.
Legitimate Interests
We may process data based on legitimate interests, such as improving our services and website functionality, provided this does not override your rights and freedoms.
Legal Obligation
In some cases, we process data to comply with legal requirements, such as tax and accounting obligations.
Your GDPR Rights
Right to Access
You have the right to request a copy of the personal information we hold about you. We will provide this within one month of your request.
Right to Rectification
You can ask us to correct inaccurate or incomplete personal information.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, such as when it's no longer necessary for the purpose it was collected.
Right to Restrict Processing
You can ask us to limit how we use your data in specific situations, such as when you contest the accuracy of the data.
Right to Data Portability
You can request your personal data in a structured, commonly used, machine-readable format and have it transferred to another organisation.
Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Where we rely on consent, you can withdraw it at any time. This won't affect the lawfulness of processing before withdrawal.
Rights Related to Automated Decision-Making
We do not use automated decision-making or profiling in our processing of your personal data.
How to Exercise Your Rights
To exercise any of these rights, please contact us at:
Email: [email protected]
Address: arctwist Financial Education, 142 Kingsland Road, London E2 8DY, United Kingdom
We will respond to your request within one month. In complex cases, we may extend this by two additional months and will inform you if this is necessary.
Data Protection Officer
For questions specifically about data protection and GDPR compliance, you can contact our Data Protection Officer at [email protected]
Data Transfers
We primarily store and process data within the United Kingdom. If we transfer data outside the UK, we ensure appropriate safeguards are in place, such as:
- Adequacy decisions by the UK government
- Standard contractual clauses
- Binding corporate rules
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach.
Children's Data
We recognise that children's data requires additional protection. While our services are for children and teenagers, we only collect their personal information through parents or legal guardians who provide consent on their behalf.
Data Minimisation
We only collect personal data that is necessary for the specific purposes we've identified. We don't collect excessive information.
Storage and Security
We implement appropriate technical and organisational measures to ensure data security, including:
- Encryption of data in transit and at rest
- Access controls and authentication
- Regular security assessments
- Staff training on data protection
Retention Periods
We retain personal data only as long as necessary for the purposes for which it was collected:
- Programme participant data: Retained for the duration of the programme plus 3 years for record-keeping
- Enquiry data: Retained for 2 years unless you become a client
- Financial records: Retained for 7 years to comply with tax regulations
Third-Party Processors
When we use third-party service providers who process data on our behalf, we ensure they:
- Provide sufficient guarantees of GDPR compliance
- Process data only according to our instructions
- Implement appropriate security measures
- Have signed data processing agreements with us
Complaints
If you believe we have not handled your data in accordance with GDPR, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire
SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: ico.org.uk
Updates to This Information
We may update this GDPR compliance information to reflect changes in our practices or legal requirements. Significant changes will be communicated to active clients via email.
More Information
For detailed information about how we collect, use, and protect your data, please see our Privacy Policy.