GDPR Compliance
Our commitment to protecting your personal data under UK GDPR
Our commitment to protecting your personal data under UK GDPR
For the purposes of UK GDPR, the data controller is:
rustic-cove.com
47 Pemberton Gardens
Islington, London N19 5RR
United Kingdom
Email: [email protected]
As a data subject, you have the following rights regarding your personal data:
You have the right to obtain confirmation as to whether we process your personal data and, where that is the case, access to that data and information about how it is processed.
You have the right to obtain correction of inaccurate personal data and to have incomplete personal data completed.
In certain circumstances, you have the right to request deletion of your personal data. This right is not absolute and is subject to legal retention requirements applicable to legal service providers.
You have the right to request restriction of processing of your personal data in specific circumstances, such as when you contest the accuracy of the data or object to processing.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
You have the right to object to processing of your personal data based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
We do not use automated decision-making or profiling that produces legal effects or significantly affects you.
To exercise any of your GDPR rights, submit a request to [email protected] with the following information:
We will respond to your request within one month of receipt, or within two months for complex requests. We will inform you if we need to extend the response period.
We process personal data based on the following legal grounds under GDPR:
We may process special category data (health information) for disability benefit applications. This processing is based on:
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay in accordance with Article 34 GDPR.
We do not transfer personal data outside the United Kingdom. All data processing occurs within UK jurisdiction.
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Client files are retained for seven years after case closure in accordance with professional standards for legal services.
When we engage third-party service providers who process personal data on our behalf, we ensure they provide appropriate guarantees regarding data protection and security through written contracts as required by Article 28 GDPR.
You have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement.
For the UK, the supervisory authority is:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
We regularly review our data processing activities to ensure ongoing GDPR compliance. This page will be updated to reflect any significant changes to our data protection practices.
Last updated: August 4, 2026