Last updated: July 21, 2026
frost-serval is committed to complying with the General Data Protection Regulation (GDPR) and respecting your data protection rights. This page outlines how we ensure compliance and protect your personal information.
frost-serval acts as the data controller for personal information collected through our website and services.
Contact details:
Email: [email protected]
Address: 142 Kensington High Street, London W8 7RL, United Kingdom
We process personal data only when we have a lawful basis under GDPR:
You have the following rights regarding your personal data:
You can request a copy of the personal data we hold about you. We will provide this information in a commonly used electronic format within one month of your request.
If personal data we hold is inaccurate or incomplete, you have the right to have it corrected or completed.
You can request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or if you withdraw consent and no other legal basis exists for processing.
You can request that we limit how we use your data in certain circumstances, such as while we verify data accuracy.
You can request to receive your personal data in a structured, commonly used format and have it transmitted to another controller where technically feasible.
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us at [email protected] with your request. We will respond within one month and may require verification of your identity before processing requests.
Please provide:
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.
Personal data is primarily stored and processed within the United Kingdom and European Economic Area. If data is transferred outside these regions, we ensure appropriate safeguards are in place in accordance with GDPR requirements.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
Our services are not directed at individuals under 16 years of age. We do not knowingly collect personal data from children without parental consent.
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR.
UK supervisory authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Material changes will be communicated through our website.
If you have questions about our GDPR compliance or data protection practices, please contact us at [email protected]