top of page

Privacy Policy

1. Introduction

Castle Peak Limited ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website www.castle-peak.co.uk, in accordance with the UK GDPR, the Data Protection Act 2018, the DUAA 2025, and applicable international data protection laws including the EU GDPR.

​

2. Information We Collect

We may collect and process the following types of personal data:

  • Identity Data: Name, username, title, date of birth.

  • Contact Data: Email address, phone number, billing/shipping address.

  • Technical Data: IP address, browser type, operating system, device identifiers.

  • Usage Data: Pages visited, time spent, clickstream data.

  • Marketing Data: Preferences for receiving marketing communications.

​​

3. How We Collect Data

  • Direct interactions (e.g., forms, registrations, purchases).

  • Automated technologies (e.g., cookies, analytics).

  • Third-party sources (e.g., payment processors, advertising platforms).

​​

4. Legal Basis for Processing

We process your data under the following lawful bases:

  • Consent: When you opt-in to marketing or cookies.

  • Contract: To fulfill services or purchases.

  • Legal Obligation: For compliance with laws.

  • Legitimate Interests: For analytics, fraud prevention, and service improvement.

​​

5. How We Use Your Data

  • To provide and manage services.

  • To personalize user experience.

  • To process transactions.

  • To send administrative and promotional communications.

  • To comply with legal obligations.

​​

6. Cookies and Tracking Technologies

We use cookies for functionality, analytics, and advertising. Under DUAA 2025, consent is not required for certain functional and analytics cookies.

​

7. Data Sharing and Transfers

We may share your data with:

  • Service providers (e.g., hosting, payment processors).

  • Legal authorities (if required).

  • International partners (with appropriate safeguards under GDPR).

​​

8. International Data Transfers

Where data is transferred outside the UK or EU, we ensure appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.

​

9. Data Retention

We retain personal data only as long as necessary for the purposes outlined or as required by law.

​

10. Your Rights

You have the right to:

  • Access your data.

  • Rectify inaccurate data.

  • Erase your data (“right to be forgotten”).

  • Restrict or object to processing.

  • Data portability.

  • Withdraw consent at any time.

To exercise these rights, contact us at enquires@castle-peak.co.uk.

​

11. Children’s Privacy

We do not knowingly collect data from children under 13. Enhanced protections apply under DUAA 2025 for children’s data.

​

12. Automated Decision-Making

We may use automated decision-making for service personalization. You can request human intervention or challenge decisions.

​

13. Data Security

We implement appropriate technical and organizational measures to protect your data, including encryption, access controls, and regular audits.

​

14. Data Breaches

In case of a breach, we will notify affected individuals and the ICO within 72 hours, as required by law.

​

15. Changes to This Policy

We may update this policy periodically. Changes will be posted on this page with a revised effective date.

​

16. Contact Us

If you have questions or concerns about this policy or your data, contact:

Castle Peak Limited 

167-169 Great Portland Street

5th Floor

London

W1W 5PF

bottom of page