Last updated: July 14, 2026
cliff-muse is committed to compliance with the General Data Protection Regulation (GDPR) and ensuring that your personal data is processed lawfully, fairly, and transparently. This document outlines how we comply with GDPR principles and your rights as a data subject.
For the purposes of GDPR, cliff-muse is the data controller responsible for your personal data. Our contact details are:
cliff-muse
47 Riverside Business Park
Eastwood Lane
Birmingham B12 4TG
United Kingdom
Email: [email protected]
We process your personal data under the following lawful bases as defined by GDPR:
Under GDPR, you have the following rights regarding your personal data:
You have the right to obtain confirmation of whether we process your personal data and, if so, to access that data along with information about how we use it.
You have the right to have inaccurate personal data corrected and incomplete data completed.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request restriction of processing your personal data in specific situations, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis for processing.
Where processing is based on consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before withdrawal.
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your habitual residence, place of work, or place of alleged infringement.
To exercise any of your GDPR rights, contact us using the details provided above. We will respond to your request within one month, though this may be extended by two additional months for complex requests. We will inform you of any extension within the first month.
We may request specific information from you to verify your identity before processing your request.
We process the following categories of personal data:
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for legal, accounting, or reporting requirements. Our standard retention periods are:
After these periods, data is securely deleted or anonymized.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 and 34 of GDPR.
If we transfer your personal data outside the UK or European Economic Area, we ensure appropriate safeguards are in place, such as:
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
We may update this GDPR compliance document from time to time to reflect changes in our practices or legal requirements. Changes will be posted on this page with an updated revision date.
For any questions or concerns regarding GDPR compliance or data protection, contact us at [email protected]