Last updated: June 25, 2026
Our commitment to GDPR
moon-reach is committed to protecting and respecting your privacy in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This page outlines how we comply with GDPR principles and your rights as a data subject.
Data controller
For the purposes of GDPR, the data controller is:
moon-reach
42 Clerkenwell Road
London EC1M 5PS
United Kingdom
Email: [email protected]
Lawful basis for processing
We process personal data only when we have a lawful basis to do so. The lawful bases we rely on include:
- Consent: You have given explicit permission for us to process your data for specific purposes
- Contract performance: Processing is necessary to fulfil a contract with you or to take steps before entering into a contract
- Legal obligation: We must process your data to comply with legal requirements
- Legitimate interests: Processing is in our legitimate business interests, provided this does not override your rights and freedoms
Your GDPR rights
Under GDPR, you have the following rights regarding your personal data:
Right to be informed
You have the right to clear, transparent information about how we use your personal data. This information is provided in our Privacy Policy and on this page.
Right of access
You have the right to request access to the personal data we hold about you. This is commonly known as a "subject access request." We will provide a copy of your data free of charge, with additional copies subject to a reasonable administrative fee.
Right to rectification
You have the right to request correction of inaccurate personal data we hold about you. You also have the right to have incomplete data completed.
Right to erasure
Also known as the "right to be forgotten," you can request that we delete your personal data in certain circumstances, including:
- The data is no longer necessary for the purpose it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- The data must be erased to comply with a legal obligation
Right to restrict processing
You have the right to request that we limit how we use your personal data in certain circumstances, such as:
- When you contest the accuracy of the data
- When processing is unlawful but you do not want the data erased
- When we no longer need the data but you need it for legal claims
- When you have objected to processing and verification of legitimate grounds is pending
Right to data portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to object
You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis. You also have the absolute right to object to processing for direct marketing purposes.
Rights related to automated decision-making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. We do not currently engage in automated decision-making or profiling.
How to exercise your rights
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month of receipt. If your request is particularly complex or you have made multiple requests, we may extend this period by two further months, and we will inform you of any such extension.
When making a request, please provide sufficient information to allow us to verify your identity and locate your data.
Data protection principles
We adhere to the following GDPR data protection principles:
- Lawfulness, fairness, and transparency: We process data lawfully, fairly, and in a transparent manner
- Purpose limitation: We collect data for specified, explicit, and legitimate purposes only
- Data minimisation: We collect only the data that is adequate, relevant, and necessary
- Accuracy: We take reasonable steps to ensure data is accurate and kept up to date
- Storage limitation: We keep data only as long as necessary for the purposes for which it was collected
- Integrity and confidentiality: We process data securely and protect it against unauthorised or unlawful processing and accidental loss
- Accountability: We are responsible for and can demonstrate compliance with these principles
Data security measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Pseudonymisation and encryption of personal data
- Ongoing confidentiality, integrity, availability, and resilience of processing systems
- Regular testing and evaluation of the effectiveness of security measures
- Staff training on data protection principles and practices
Data breach notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible.
International data transfers
When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
- Adequacy decisions by the European Commission
- Standard contractual clauses approved by the European Commission
- Binding corporate rules
Complaints
If you believe we have not complied with your data protection rights, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
Updates to this information
We may update this GDPR compliance information from time to time to reflect changes in our practices or legal requirements. We will post any changes on this page and update the "Last updated" date accordingly.