Last Updated: July 13, 2026
mist-gate complies with the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018 in all data processing activities. This document explains how we meet our obligations and respect your rights.
Data Controller: mist-gate
Address: Unit 7, Broad Street Business Park, Birmingham B1 2HF, United Kingdom
Contact: [email protected]
We process personal data under the following lawful bases:
Processing necessary to execute and manage vehicle rental agreements, including:
Processing required to comply with:
Processing for our business operations, including:
You may request a copy of the personal data we hold about you. We will provide this within one month of receiving a valid request.
If personal information is inaccurate or incomplete, you have the right to request correction. We will update records promptly upon verification.
You may request deletion of your personal data in certain circumstances, including:
This right is subject to legal obligations requiring retention, such as financial record-keeping requirements.
You may request we limit processing of your data when:
For data processed based on consent or contract, you have the right to receive your data in a structured, commonly used format and transmit it to another controller.
You may object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
To exercise any data protection right:
We will respond within one month. For complex requests, we may extend this by two months and will inform you if this is necessary.
We implement appropriate technical and organizational measures to ensure data security:
In the event of a data breach likely to result in risk to your rights and freedoms:
We process and store data within the United Kingdom. If data transfers outside the UK become necessary, we will ensure appropriate safeguards are in place as required by UK GDPR.
When engaging third-party processors, we ensure:
We conduct data protection impact assessments for processing activities that pose high risks to individual rights and freedoms.
If you believe we have not complied with data protection law, you may:
We review and update this GDPR compliance statement regularly to reflect changes in our practices or legal requirements. Significant changes will be highlighted on this page.