Last Updated: August 4, 2026
cozy-leaf.com is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
The data controller responsible for your personal information is:
cozy-leaf.com
47 Victoria Street
Westminster, London SW1H 0EU
United Kingdom
Email: [email protected]
We process your personal data under the following lawful bases:
Under UK GDPR, you have the following rights regarding your personal data:
You can request a copy of the personal data we hold about you. We will provide this information free of charge within one month of your request.
You can request correction of inaccurate or incomplete personal data we hold about you.
You can request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purpose it was collected or if you withdraw consent.
You can request that we limit the processing of your personal data in specific situations, such as when you contest the accuracy of the data.
You can request to receive your personal data in a structured, commonly used, and machine-readable format, and have it transmitted to another controller where technically feasible.
You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: www.ico.org.uk
To exercise any of your GDPR rights, please contact us at [email protected] with the subject line "GDPR Request" and specify which right you wish to exercise.
We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of the extension.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach and will inform affected individuals without undue delay.
If we transfer your personal data outside the United Kingdom, we ensure appropriate safeguards are in place through mechanisms such as standard contractual clauses approved by the UK authorities.
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
When processing personal data of children under 16 in relation to our courses, we obtain consent from a parent or guardian where required by law.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Enrollment records are typically retained for seven years.
We may update this GDPR compliance notice periodically to reflect changes in our practices or applicable law. We will notify you of significant changes through our website.