Our commitment to data protection under the General Data Protection Regulation
branch-den is committed to full compliance with the General Data Protection Regulation (GDPR) and UK data protection legislation. We recognize the importance of protecting personal data and respecting the privacy rights of individuals.
branch-den acts as the data controller for personal information collected through our website and services. We are responsible for determining how and why your data is processed.
We process personal data only when we have a lawful basis to do so. Our processing activities are based on:
Under GDPR, you have comprehensive rights regarding your personal data:
You can request confirmation of whether we process your personal data and obtain a copy of that data. We will provide this information in a commonly used electronic format upon request.
If your personal data is inaccurate or incomplete, you have the right to request correction or completion. We will update your information promptly upon verification.
Also known as the "right to be forgotten," you can request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purposes for which it was collected.
You can request that we limit how we use your data in specific situations, such as when you contest the accuracy of the data or object to processing.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.
Where processing is based on consent, you can withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted before withdrawal.
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month, though this period may be extended by two additional months for complex requests.
For questions specifically related to data protection and GDPR compliance, you may contact our data protection representative at [email protected].
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and communicate with affected individuals without undue delay.
We primarily process data within the United Kingdom. If we transfer data outside the UK, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection.
ICO Contact Information:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: www.ico.org.uk
We regularly review our data protection practices to ensure ongoing GDPR compliance. Any significant changes to our compliance approach will be reflected in updates to this page and our Privacy Policy.
Last Updated: August 4, 2026