Last updated: September 2026
Frost-astral is committed to full compliance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. This statement outlines how we meet our obligations under these regulations when processing personal data.
Frost-astral acts as the data controller for personal information collected through our website and business activities. We determine the purposes and means of processing your personal data.
Contact details:
Frost-astral
14 Belgrave Square
London SW1X 8PS
United Kingdom
Email: [email protected]
We process personal data only when we have a lawful basis to do so:
Under GDPR, you have comprehensive rights regarding your personal data:
You have the right to clear information about how we collect and use your data, provided through this statement and our privacy policy.
You may request confirmation of what personal data we hold about you and receive a copy of that data.
You can request correction of inaccurate or incomplete personal data we hold about you.
Also known as the "right to be forgotten", you may request deletion of your personal data in specific circumstances.
You can request that we limit how we use your personal data in certain situations.
You can request to receive your personal data in a structured, commonly used format and transmit it to another controller.
You may object to processing based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that significantly affects you. We do not engage in automated decision-making or profiling.
To exercise any of your GDPR rights, submit a request to [email protected]. We will respond within one month of receiving your request. In complex cases, we may extend this period by two additional months and will inform you of any extension.
We adhere to GDPR's fundamental data protection principles:
If we experience a data breach that poses risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses high risk to you, we will also communicate it directly without undue delay.
When transferring personal data outside the UK or EEA, we ensure adequate safeguards are in place, such as standard contractual clauses approved by regulatory authorities.
We integrate data protection considerations into our business processes and system design from the outset. Privacy settings are configured to the highest level by default.
Where we engage third parties to process personal data on our behalf, we ensure they provide sufficient guarantees of GDPR compliance through contractual arrangements.
Our services are not directed at children under 16. We do not knowingly collect personal data from minors without appropriate parental consent.
You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with data protection law. In the UK, the relevant authority is:
Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Material changes will be communicated prominently on our website.