GDPR Compliance
Last updated: September 30, 2026
Our Commitment to Data Protection
Moon-verse is committed to full compliance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This page outlines how we meet our obligations and protect your rights as a data subject.
Data Controller
Moon-verse Environmental Consulting acts as the data controller for personal information collected through our website and client engagements.
Contact details:
42 Stokes Croft
Bristol BS1 3QD
United Kingdom
Email: [email protected]
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Consent: When you voluntarily provide information through forms or email correspondence
- Contract: When processing is necessary to fulfill service agreements
- Legitimate Interest: For business operations, website improvement, and communications with prospective clients
- Legal Obligation: To comply with accounting, tax, and professional regulations
Your Data Protection Rights
Under GDPR, you have the following rights:
Right to Access
You may request a copy of the personal data we hold about you. We will provide this within one month of your request.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Erasure
You may request deletion of your personal data when it is no longer necessary for the purposes collected, or when you withdraw consent. Note that legal obligations may require us to retain certain data.
Right to Restrict Processing
You can request we limit how we use your data in specific circumstances.
Right to Data Portability
You may request your data in a structured, commonly used format for transfer to another controller.
Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
We do not use automated decision-making or profiling systems that produce legal or similarly significant effects.
How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected] with:
- Your full name and contact information
- Clear description of your request
- Proof of identity (required for security purposes)
We will respond within one month. In complex cases, this may be extended by two additional months with notification.
Data Security
We implement appropriate technical and organizational measures including:
- Encrypted data transmission
- Access controls limiting data access to authorized personnel
- Regular security assessments
- Staff training on data protection practices
Data Breach Procedures
In the event of a data breach that poses risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and inform affected individuals without undue delay.
International Data Transfers
We primarily store and process data within the United Kingdom and European Economic Area. Any transfers outside these regions will be protected by appropriate safeguards such as Standard Contractual Clauses.
Children's Privacy
Our services are not directed at individuals under 16 years of age. We do not knowingly collect data from children. If you believe we have inadvertently collected such information, contact us immediately for removal.
Right to Lodge a Complaint
You have the right to lodge a complaint with the Information Commissioner's Office if you believe we have not complied with data protection laws:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
Policy Updates
This GDPR compliance statement may be updated to reflect changes in our practices or legal requirements. Material changes will be communicated through our website and, where appropriate, via direct communication to affected individuals.