
Privacy Policy
1. Introduction
Castle Peak Limited ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website www.castle-peak.co.uk, in accordance with the UK GDPR, the Data Protection Act 2018, the DUAA 2025, and applicable international data protection laws including the EU GDPR.
​
2. Information We Collect
We may collect and process the following types of personal data:
-
Identity Data: Name, username, title, date of birth.
-
Contact Data: Email address, phone number, billing/shipping address.
-
Technical Data: IP address, browser type, operating system, device identifiers.
-
Usage Data: Pages visited, time spent, clickstream data.
-
Marketing Data: Preferences for receiving marketing communications.
​​
3. How We Collect Data
-
Direct interactions (e.g., forms, registrations, purchases).
-
Automated technologies (e.g., cookies, analytics).
-
Third-party sources (e.g., payment processors, advertising platforms).
​​
4. Legal Basis for Processing
We process your data under the following lawful bases:
-
Consent: When you opt-in to marketing or cookies.
-
Contract: To fulfill services or purchases.
-
Legal Obligation: For compliance with laws.
-
Legitimate Interests: For analytics, fraud prevention, and service improvement.
​​
5. How We Use Your Data
-
To provide and manage services.
-
To personalize user experience.
-
To process transactions.
-
To send administrative and promotional communications.
-
To comply with legal obligations.
​​
6. Cookies and Tracking Technologies
We use cookies for functionality, analytics, and advertising. Under DUAA 2025, consent is not required for certain functional and analytics cookies.
​
7. Data Sharing and Transfers
We may share your data with:
-
Service providers (e.g., hosting, payment processors).
-
Legal authorities (if required).
-
International partners (with appropriate safeguards under GDPR).
​​
8. International Data Transfers
Where data is transferred outside the UK or EU, we ensure appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
​
9. Data Retention
We retain personal data only as long as necessary for the purposes outlined or as required by law.
​
10. Your Rights
You have the right to:
-
Access your data.
-
Rectify inaccurate data.
-
Erase your data (“right to be forgotten”).
-
Restrict or object to processing.
-
Data portability.
-
Withdraw consent at any time.
To exercise these rights, contact us at enquires@castle-peak.co.uk.
​
11. Children’s Privacy
We do not knowingly collect data from children under 13. Enhanced protections apply under DUAA 2025 for children’s data.
​
12. Automated Decision-Making
We may use automated decision-making for service personalization. You can request human intervention or challenge decisions.
​
13. Data Security
We implement appropriate technical and organizational measures to protect your data, including encryption, access controls, and regular audits.
​
14. Data Breaches
In case of a breach, we will notify affected individuals and the ICO within 72 hours, as required by law.
​
15. Changes to This Policy
We may update this policy periodically. Changes will be posted on this page with a revised effective date.
​
16. Contact Us
If you have questions or concerns about this policy or your data, contact:
Castle Peak Limited
167-169 Great Portland Street
5th Floor
London
W1W 5PF