Last updated: July 10, 2026
We process personal data in accordance with the UK General Data Protection Regulation and Data Protection Act 2018. This document explains how we meet our obligations under these regulations.
We process personal data under the following legal bases:
The data controller responsible for personal information collected through this website is shimmer-foam, operating at the business address listed on our contact page. For data protection inquiries, contact [email protected].
You have the following rights regarding your personal data:
You may request a copy of all personal data we hold about you. We will provide this information in a structured, commonly used format within one month of receiving your request.
If personal information we hold is inaccurate or incomplete, you have the right to request correction. We will update records promptly upon verification of corrected information.
You may request deletion of your personal data in circumstances where there is no compelling reason for continued processing. This right is subject to legal record-keeping obligations that may require retention of certain information.
You can request that we temporarily restrict processing of your data in specific circumstances, such as while we verify accuracy of disputed information.
Where technically feasible and legally applicable, you may request transfer of your data to another service provider in a machine-readable format.
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease such processing unless we demonstrate compelling legitimate grounds that override your interests.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal obligations. Service records are typically retained for seven years in accordance with business record-keeping requirements.
Personal data collected through our services is processed and stored within the United Kingdom. We do not routinely transfer data outside the UK. Any international transfers that become necessary will be conducted using appropriate safeguards in compliance with GDPR requirements.
In the event of a data breach that poses risk to your rights and freedoms, we will notify affected individuals within 72 hours of becoming aware of the breach, as required by GDPR.
To exercise any of your GDPR rights, send a written request to [email protected] with "GDPR Request" in the subject line. Include sufficient information to verify your identity and specify which right you wish to exercise.
If you believe our data processing practices violate GDPR requirements, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection matters.