GDPR Compliance
Last updated: June 19, 2026
Our Commitment to GDPR
canyon-jay is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and UK data protection legislation. This page outlines how we comply with these regulations.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Contract: Processing necessary to fulfil our contract with you when you enrol in courses
- Consent: Where you have given explicit consent for specific processing activities
- Legitimate Interest: For improving our services and website functionality
- Legal Obligation: Where we must process data to comply with legal requirements
Your GDPR Rights
Under GDPR, you have the following rights:
Right to Access
You can request a copy of the personal data we hold about you. We will provide this information within one month of your request.
Right to Rectification
You can ask us to correct inaccurate or incomplete personal data.
Right to Erasure
You can request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purposes it was collected.
Right to Restriction
You can ask us to restrict processing of your personal data in specific situations.
Right to Data Portability
You can request your personal data in a structured, commonly used format and transfer it to another controller.
Right to Object
You can object to processing of your personal data where we rely on legitimate interests as the legal basis.
Right to Withdraw Consent
Where we process your data based on consent, you can withdraw that consent at any time.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Course enrolment data: retained for 7 years for accounting and legal purposes
- Marketing communications: until you unsubscribe or request deletion
- Website analytics: anonymised after 26 months
Data Transfers
We primarily store and process data within the United Kingdom and European Economic Area. If we transfer data outside these areas, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.
Data Protection Officer
For questions regarding GDPR compliance or to exercise your rights, you can contact us at:
42 Kensington Gardens
London, W2 4BH
United Kingdom
Complaints
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Tel: 0303 123 1113
Exercising Your Rights
To exercise any of your GDPR rights, please contact us with the following information:
- Your full name and email address used for enrolment
- Specific right you wish to exercise
- Any relevant details to help us locate your information
We will respond to your request within one month. In complex cases, we may extend this by two additional months and will inform you of any delay.
Data Security Measures
We implement appropriate technical and organisational measures to ensure data security, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication procedures
- Staff training on data protection
- Incident response procedures
Updates to This Page
We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. The date at the top indicates when this page was last revised.