We use cookies to enhance your browsing experience and analyze our traffic. By continuing to use this site, you consent to our use of cookies.

wolf-wave
Home Our Story Experiences Visit Us Privacy Promotional Content

GDPR Compliance

Last updated: September 2026

Our Commitment to Data Protection

Wolf-wave is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection legislation. This page explains how we comply with GDPR requirements and what rights you have regarding your personal information.

Data Controller

For the purposes of GDPR, wolf-wave acts as the data controller. Our contact details are:

wolf-wave
42 Heritage Lane
Bath, BA1 5LR
United Kingdom
Email: [email protected]

Lawful Basis for Processing

We process personal data only when we have a lawful basis to do so under GDPR Article 6:

Consent

When you provide explicit consent for specific processing activities, such as receiving marketing communications or using optional website features. You may withdraw consent at any time.

Contractual Necessity

When processing is necessary to fulfill our contractual obligations, such as processing your tour booking and providing the services you requested.

Legal Obligation

When we must process data to comply with legal requirements, such as maintaining financial records for tax purposes.

Legitimate Interests

When we have legitimate interests in processing data, provided these interests do not override your fundamental rights. This includes improving our services, website functionality, and communicating with customers about bookings.

Your Rights Under GDPR

Right to Access

You have the right to request access to personal data we hold about you. We will provide a copy of your data in a commonly used electronic format within one month of your request.

Right to Rectification

If you believe personal data we hold is inaccurate or incomplete, you have the right to request correction. We will rectify the data within one month.

Right to Erasure

Under certain circumstances, you have the right to request deletion of your personal data. This right applies when:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • Deletion is required to comply with a legal obligation

Note that this right is not absolute, and we may retain data when required by law or for legitimate purposes.

Right to Restriction of Processing

You can request that we restrict processing of your personal data in specific situations:

  • When you contest the accuracy of the data, pending verification
  • When processing is unlawful but you prefer restriction over erasure
  • When we no longer need the data but you require it for legal claims
  • When you have objected to processing, pending verification of legitimate grounds

Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.

Right to Object

You have the right to object to processing based on legitimate interests or for direct marketing purposes. Upon receiving an objection to direct marketing, we will cease such processing immediately.

Rights Related to Automated Decision-Making

We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects on individuals.

How to Exercise Your Rights

To exercise any of your rights under GDPR, please contact us at [email protected] with your request. Include:

  • Your full name and contact information
  • A clear description of the right you wish to exercise
  • Any relevant details to help us locate your information
  • Proof of identity if requested to protect your data security

We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of the extension.

Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Pseudonymization and encryption of personal data where appropriate
  • Measures to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems
  • Procedures to restore availability and access to data in a timely manner after incidents
  • Regular testing and assessment of security measures

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by law.

International Data Transfers

We primarily process data within the United Kingdom and European Economic Area. If we transfer data outside these areas, we ensure appropriate safeguards are in place, such as:

  • Standard contractual clauses approved by the European Commission
  • Adequacy decisions confirming the recipient country provides adequate protection
  • Other mechanisms recognized under GDPR

Data Protection by Design and Default

We implement data protection principles into our processing activities and business practices from the design stage. We process only the data necessary for specific purposes and ensure that personal data is not accessible to an indefinite number of people without intervention.

Children's Data

Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately so we can delete the information.

Supervisory Authority

You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your residence, place of work, or place of alleged infringement if you believe our processing of your personal data violates GDPR.

In the United Kingdom, the relevant authority is:

Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
Website: ico.org.uk

Updates to This Statement

We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. We will post the updated version on this page with a revised date. We encourage you to review this page periodically.

Further Information

For comprehensive information about how we collect, use, and protect your personal data, please refer to our Privacy Policy.

wolf-wave

Connecting contemporary visitors with Britain's architectural legacy through thoughtfully designed heritage experiences.

Navigation

  • Our Story
  • Experiences
  • Visit Us

Legal

  • Privacy Policy
  • Terms of Use
  • GDPR
  • Cookies Policy

Contact

42 Heritage Lane
Bath, BA1 5LR
United Kingdom

[email protected]

The information provided on this website is for educational and promotional purposes. Individual experiences may vary. We recommend consulting specialized historical resources for academic research. All tours are subject to site availability and weather conditions.

© 2026 wolf-wave. All rights reserved.