Last Updated: August 14, 2026
thicket-verse is fully committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This statement outlines how we meet our obligations as a data controller when processing personal data.
Data Controller: thicket-verse
Address: 47 Finsbury Square, London EC2A 1PX, United Kingdom
Contact Email: [email protected]
We process personal data only when we have a lawful basis to do so:
As a data subject, you have the following rights:
You have the right to request a copy of the personal data we hold about you. This is known as a Subject Access Request (SAR).
You can request that we correct any inaccurate or incomplete personal data we hold about you.
Also known as the "right to be forgotten," you can request that we delete your personal data in certain circumstances.
You can ask us to limit how we use your personal data in specific situations.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
You can object to our processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that significantly affects you.
To exercise any of your GDPR rights, please submit a written request to [email protected]. We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you accordingly.
We adhere to the following data protection principles:
We implement technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.
Your personal data is processed and stored within the United Kingdom. We do not transfer personal data outside the UK unless appropriate safeguards are in place to ensure GDPR-level protection.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our standard retention periods are:
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children without appropriate parental or guardian consent.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Phone: 0303 123 1113
Website: www.ico.org.uk
We may update this GDPR Compliance Statement to reflect changes in our practices or legal requirements. We will notify you of any significant changes through our website.
For questions about our GDPR compliance or to exercise your data protection rights, please contact us at [email protected]