Last updated: June 18, 2026
This page explains how isle-cypress complies with the General Data Protection Regulation (GDPR) and outlines your rights under this regulation.
isle-cypress acts as the data controller for personal information collected through our website and services. We are responsible for ensuring that your personal data is processed lawfully, fairly, and transparently.
We process personal data under the following legal bases:
As a data subject, you have the following rights:
You have the right to request confirmation of whether we process your personal data and to receive a copy of that data.
You can request correction of inaccurate personal data and completion of incomplete data.
Also known as the "right to be forgotten," you can request deletion of your personal data under certain circumstances.
You can request that we restrict processing of your personal data in specific situations.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month, though this period may be extended by two additional months for complex requests.
We may require verification of your identity before processing requests to protect your personal data from unauthorized access.
We adhere to the following data protection principles:
If we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission or other legally recognized transfer mechanisms.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.
Where we process your data based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted before withdrawal.
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR. In the United Kingdom, the relevant authority is the Information Commissioner's Office (ICO).
For questions about GDPR compliance or to exercise your rights, please contact us at:
Email: [email protected]