Our Commitment to Data Protection
Russet Comet is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We respect your privacy and are dedicated to protecting your personal data.
This page explains how we comply with data protection legislation and outlines your rights as a data subject.
Data Controller
Russet Comet is the data controller responsible for your personal data. Our contact details are:
Russet Comet
47 Greenfields Lane
London, SW15 3QR
United Kingdom
Email: [email protected]
Lawful Basis for Processing
We process personal data only when we have a lawful basis to do so. The lawful bases we rely on include:
Contract
Processing necessary to perform our contract with you, including:
- Processing your course enrolment
- Providing access to course materials
- Handling payment transactions
- Providing customer support
Legitimate Interests
Processing necessary for our legitimate business interests, provided these do not override your rights:
- Improving our services and website
- Ensuring network and information security
- Preventing fraud
- Administrative purposes
Consent
Where we rely on your consent for processing:
- Marketing communications (where applicable)
- Non-essential cookies
You can withdraw consent at any time by contacting us.
Legal Obligation
Processing necessary to comply with legal requirements, such as tax and accounting obligations.
Your Rights Under UK GDPR
As a data subject, you have the following rights:
Right to Be Informed
You have the right to know how your personal data is collected and used. Our Privacy Policy provides this information.
Right of Access
You can request a copy of the personal data we hold about you. This is known as a Subject Access Request (SAR). We will respond within one month of receiving your request.
Right to Rectification
If you believe the personal data we hold about you is inaccurate or incomplete, you can request that we correct or complete it.
Right to Erasure
Also known as the "right to be forgotten", you can request deletion of your personal data in certain circumstances, including:
- The data is no longer necessary for its original purpose
- You withdraw consent (where processing was based on consent)
- You object to processing and there are no overriding legitimate grounds
- The data was unlawfully processed
Right to Restrict Processing
You can request that we limit how we use your personal data in certain circumstances, such as when you contest the accuracy of the data or have objected to processing.
Right to Data Portability
You can request to receive your personal data in a structured, commonly used, machine-readable format, and have the right to transmit that data to another controller.
Right to Object
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have rights related to automated decision-making and profiling. We do not currently use automated decision-making that produces legal or similarly significant effects.
Exercising Your Rights
To exercise any of your rights, please contact us at [email protected] with your request. We may need to verify your identity before processing your request.
We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by a further two months, but we will inform you within the first month.
There is no fee for exercising your rights in most circumstances.
Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
- Incident response procedures
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Our specific retention periods are:
- Account information: Duration of account plus 7 years
- Transaction records: 7 years for tax purposes
- Support communications: 3 years
- Marketing preferences: Until you withdraw consent
International Transfers
If we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the ICO
- Transfers to countries with adequate data protection
- Binding corporate rules where applicable
Complaints
If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve your concerns.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Website: ico.org.uk
Updates to This Information
We may update this GDPR information from time to time. We will notify you of significant changes through our website or by email.