GDPR Compliance
Last updated: September 1, 2026
Our Commitment to Data Protection
Serene Marsh Ltd is committed to protecting your personal data in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018. This document explains how we comply with these regulations and your rights as a data subject.
Data Controller
Serene Marsh Ltd is the data controller responsible for your personal information. Our contact details are:
Serene Marsh Ltd
14 Wharfedale Court
Grassington, North Yorkshire
BD23 5LB
United Kingdom
Email: [email protected]
Lawful Basis for Processing
We process your personal data only when we have a lawful basis to do so. The lawful bases we rely on include:
Contract Performance
When you book a walking expedition, we process your information to fulfill our contractual obligations to provide the service you requested.
Legitimate Interest
We process certain information based on our legitimate business interests, such as:
- Responding to inquiries about our services
- Improving our website and services
- Maintaining business records and accounts
- Protecting against fraud and ensuring participant safety
Legal Obligation
We process and retain certain information to comply with legal requirements, including tax, accounting, and health and safety regulations.
Consent
For certain optional processing activities, such as sending marketing communications, we rely on your explicit consent. You can withdraw consent at any time.
Your Rights Under GDPR
You have the following rights regarding your personal data:
Right of Access
You have the right to obtain confirmation that we are processing your personal data and to receive a copy of that data. We will provide this information within one month of your request.
Right to Rectification
If your personal information is inaccurate or incomplete, you have the right to request that we correct or complete it.
Right to Erasure
In certain circumstances, you have the right to request deletion of your personal data. This right is not absolute and may be limited by legal retention requirements.
Right to Restriction of Processing
You can request that we restrict processing of your personal data in specific situations, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to Object
You can object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Rights Related to Automated Decision Making
You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you. We do not currently use automated decision-making processes.
How to Exercise Your Rights
To exercise any of your data protection rights, contact us at:
Email: [email protected]
When making a request, please provide:
- Your full name and contact information
- Details of the specific right you wish to exercise
- Any relevant information that helps us locate your data
We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of any such extension.
We will not charge a fee for processing requests unless they are manifestly unfounded, excessive, or repetitive.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of sensitive personal data
- Regular security assessments and updates
- Access controls limiting who can access personal data
- Staff training on data protection principles
- Secure backup and recovery procedures
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you without undue delay and within 72 hours of becoming aware of the breach, as required by law.
Data Transfers
Your personal data is processed and stored within the United Kingdom. If we need to transfer data internationally, we ensure appropriate safeguards are in place, such as:
- Adequacy decisions by the UK government
- Standard contractual clauses approved by the UK authorities
- Other legally recognized transfer mechanisms
Retention Periods
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal obligations.
Our standard retention periods are:
- Booking and expedition records: 7 years
- Financial records: 7 years
- General correspondence: 2 years
- Website analytics: Indefinitely in anonymized form
After these periods, we securely delete or anonymize personal data unless longer retention is required by law.
Cookies and Tracking
Our website uses cookies to improve functionality and analyze usage. You can control cookie preferences through our cookie banner or your browser settings. For detailed information about our cookie practices, please see our Cookie Policy.
Third-Party Links
Our website may contain links to external sites. We are not responsible for the privacy practices of third-party websites. We encourage you to review the privacy policies of any external sites you visit.
Updates to This Notice
We may update this GDPR compliance notice periodically to reflect changes in our practices or legal requirements. Significant changes will be communicated directly to affected individuals where possible.
Complaints
If you believe we have not handled your personal data in accordance with data protection law, you have the right to lodge a complaint with the supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: www.ico.org.uk
However, we would appreciate the opportunity to address your concerns directly before you contact the ICO. Please contact us first at [email protected].