Last updated: 17 June 2026
nimble-finch is committed to compliance with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Economic Area. This page outlines how we meet our obligations under GDPR and explains your rights as a data subject.
For the purposes of GDPR, nimble-finch acts as the data controller for personal information collected through our website and learning platform.
Contact details:
Email: [email protected]
Address: 42 Broadwick Street, London W1F 7AF, United Kingdom
We process personal data only when we have a lawful basis to do so under GDPR Article 6:
We process your personal information to fulfil our contractual obligations when you enrol in our courses, including:
We process certain data based on our legitimate business interests, which include:
We have conducted legitimate interest assessments to ensure these activities do not override your fundamental rights and freedoms.
We request explicit consent for:
You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
We process certain data to comply with legal obligations, including:
As a data subject, you have the following rights:
You have the right to obtain confirmation of whether we process your personal data and, if so, to access that data along with information about how it is processed. We will provide one free copy upon request.
You may request correction of inaccurate personal data or completion of incomplete data. We will make corrections promptly and notify relevant third parties where appropriate.
You may request deletion of your personal data in the following circumstances:
This right is not absolute. We may retain information where we have legal obligations to do so, such as financial records required for tax purposes.
You may request that we limit how we use your personal data in specific situations:
Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format. You may also request direct transmission to another controller where technically feasible.
You may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms.
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.
To exercise any of your rights under GDPR, contact us at [email protected]. Please include sufficient information to allow us to verify your identity and locate your data.
We will respond to requests within one month of receipt. In complex cases, this period may be extended by two additional months, about which we will inform you.
We will not charge a fee for processing requests unless they are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or refuse the request.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you without undue delay. Where required, we will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
While not legally required to appoint a Data Protection Officer, we have designated a privacy contact responsible for monitoring GDPR compliance. Questions about our data protection practices should be directed to [email protected].
We primarily process data within the European Economic Area. Where transfers to third countries occur, we ensure appropriate safeguards are in place through:
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting or reporting requirements. Specific retention periods are detailed in our Privacy Policy.
Where we engage third-party processors, we ensure they provide sufficient guarantees regarding technical and organisational security measures. Processor agreements comply with Article 28 requirements, including:
We do not knowingly process personal data of children under 16 years of age. Where we become aware of such processing, we will delete the data unless we have obtained consent from the holder of parental responsibility.
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR. In the United Kingdom, the relevant authority is:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Telephone: 0303 123 1113
We review our GDPR compliance regularly and update this page when our practices change or regulations evolve. Significant changes will be communicated through our standard notification channels.
For additional details about our data processing practices, please refer to our Privacy Policy. For specific questions about GDPR compliance, contact [email protected].