Our commitment to data protection under UK GDPR
Last updated: September 2026
mist-vector is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take our responsibilities as a data controller seriously and have implemented measures to ensure that personal data is processed lawfully, fairly, and transparently.
For the purposes of UK data protection law, the data controller is:
mist-vector
47 Broadcast House
Media Quarter
London, EC2A 4NE
United Kingdom
Email: [email protected]
We adhere to the following data protection principles:
Under UK GDPR, you have the following rights regarding your personal data:
You have the right to request confirmation of whether we process your personal data and to receive a copy of that data. We will respond to access requests within one month of receipt.
If you believe that personal data we hold about you is inaccurate or incomplete, you have the right to request correction. We will respond to rectification requests promptly.
In certain circumstances, you have the right to request that we delete your personal data. This right applies when the data is no longer necessary for its original purpose, when consent is withdrawn, or when processing is unlawful.
You may request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or when processing is unlawful but you do not want the data erased.
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format.
You have the right to object to processing based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will stop processing your data for this purpose.
You have rights in relation to automated decision-making, including profiling. We do not currently engage in automated decision-making that produces legal effects or similarly significant effects on individuals.
To exercise any of these rights, please contact us using the details provided above. We may need to verify your identity before processing your request. We will respond to requests within one month, though this period may be extended by two months for complex requests.
Where processing is likely to result in a high risk to individuals' rights and freedoms, we conduct Data Protection Impact Assessments to identify and minimise data protection risks.
In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk, affected individuals will also be notified.
Where we transfer personal data outside the United Kingdom, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions, to protect your data.
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire, SK9 5AF
Website: ico.org.uk
We may update this GDPR compliance information periodically. Changes will be posted on this page with an updated revision date.