Last updated: July 13, 2026
cristfigli is committed to complying with the General Data Protection Regulation (GDPR) and protecting the rights of individuals whose personal data we process. This document outlines how we meet our obligations under GDPR and how you can exercise your rights.
cristfigli acts as the data controller for personal information collected through our website and in the course of providing our services. We determine the purposes and means of processing your personal data.
We process personal data only when we have a lawful basis to do so:
Under the GDPR, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information in a commonly used electronic format within one month of your request.
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request correction or completion of that data.
In certain circumstances, you have the right to request deletion of your personal data. This applies when the data is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when processing is unlawful.
You can request that we restrict the processing of your personal data in specific circumstances, such as when you contest the accuracy of the data or object to processing.
Where technically feasible, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis for processing.
Where we process your data based on consent, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing conducted before withdrawal.
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection.
To exercise any of your GDPR rights, please contact us at [email protected] with the following information:
We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of any such extension.
We adhere to the following data protection principles:
We process and store personal data within the United Kingdom. If we transfer data outside the UK or European Economic Area, we ensure appropriate safeguards are in place to protect your information in accordance with GDPR requirements.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach poses a high risk, we will also notify affected individuals without undue delay.
For questions about GDPR compliance or to exercise your rights, please contact us at [email protected].