Our commitment to General Data Protection Regulation compliance
Last Updated: July 2026
turquoise-spring is committed to compliance with the General Data Protection Regulation and protecting the personal data of all individuals with whom we interact. This document outlines our approach to GDPR compliance and your rights under this regulation.
For the purposes of GDPR, turquoise-spring acts as a data controller when processing your personal information. We determine the purposes and means of processing your personal data in connection with our property rental services.
We process personal data only when we have a lawful basis to do so. Our processing activities are based on:
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data. We will provide this information free of charge within one month of your request.
If you believe personal data we hold about you is inaccurate or incomplete, you have the right to request correction or completion of that information.
Also known as the "right to be forgotten," you may request deletion of your personal data in certain circumstances, including:
You have the right to request that we restrict processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing based on legitimate interests.
Where technically feasible, you have the right to receive personal data you provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. We do not currently engage in automated decision-making of this nature.
To exercise any of your GDPR rights, please submit a request via email to [email protected]. We will respond to your request within one month, though this period may be extended by two additional months where necessary, considering the complexity and number of requests.
We may request specific information from you to help us confirm your identity and ensure your right to access your personal data or exercise your other rights. This is a security measure to ensure personal data is not disclosed to unauthorised persons.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you without undue delay and within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to your rights and freedoms.
We primarily process personal data within the United Kingdom and European Economic Area. If we transfer personal data outside these regions, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected and to comply with legal, accounting, or reporting requirements. When personal data is no longer needed, we securely delete or anonymise it.
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office, the UK supervisory authority for data protection issues.
Information Commissioner's Office
Website: www.ico.org.uk
Telephone: 0303 123 1113
We may update this GDPR compliance statement periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated through our website.
This GDPR compliance statement is provided for informational purposes and should not be considered legal advice. For specific questions about your data protection rights, we recommend consulting with a qualified data protection professional.