Last updated: August 4, 2026

This page provides information about how brave-petal complies with the General Data Protection Regulation (GDPR) and your rights as a data subject.

Data Controller

brave-petal is the data controller responsible for your personal data. We are committed to protecting your privacy and ensuring compliance with GDPR requirements.

Contact details:
brave-petal
47 Bold Street
Liverpool, L1 4EU
United Kingdom
Email: [email protected]

Legal Basis for Processing

We process your personal data based on the following legal grounds:

Your Rights Under GDPR

Right to Access

You have the right to request access to the personal data we hold about you. We will provide you with a copy of your data in a commonly used electronic format.

Right to Rectification

If your personal data is inaccurate or incomplete, you have the right to request that we correct or complete it.

Right to Erasure

You have the right to request deletion of your personal data under certain circumstances, including when the data is no longer necessary for the purposes for which it was collected.

Right to Restrict Processing

You can request that we limit the processing of your personal data in certain situations, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

Right to Object

You can object to our processing of your personal data based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Where we process your data based on consent, you have the right to withdraw that consent at any time.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe we have violated your data protection rights.

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

International Data Transfers

When we transfer personal data outside the European Economic Area, we ensure appropriate safeguards are in place, such as:

Exercising Your Rights

To exercise any of your GDPR rights, please contact us at [email protected] with the subject line "GDPR Request". We will respond to your request within one month, or inform you if we need additional time.

We may need to verify your identity before processing your request. We will not charge a fee for processing requests unless they are manifestly unfounded or excessive.

Updates to This Information

We may update this GDPR information from time to time to reflect changes in our practices or legal requirements. Please review this page periodically for the latest information.