Our commitment to protecting your data rights under UK GDPR.
Last updated: July 2026
mist-ocelot is fully committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take your privacy seriously and have implemented comprehensive measures to ensure your personal data is handled responsibly and transparently.
mist-ocelot acts as the data controller for the personal information we collect. Our registered address is 47 Charter Row, Sheffield, S1 4EG, United Kingdom. For all data protection matters, please contact us at [email protected].
We only process personal data when we have a valid legal basis to do so. Our processing activities rely on the following lawful bases:
As a data subject, you have the following rights which we are committed to upholding:
You have the right to know how your personal data is being used. Our Privacy Policy provides transparent information about our data processing activities.
You can request a copy of the personal data we hold about you. We will respond to such requests within one month of receipt.
If any personal data we hold about you is inaccurate or incomplete, you have the right to request correction.
Also known as the "right to be forgotten", you may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.
You can request that we limit how we use your personal data while concerns about accuracy or lawfulness are being resolved.
Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used format.
You can object to processing based on legitimate interests or for direct marketing purposes at any time.
You have rights concerning decisions made solely by automated processing that significantly affect you. We do not currently use automated decision-making processes.
To exercise any of your data protection rights, please submit a request to [email protected]. We may need to verify your identity before processing your request. We will respond to valid requests within one month, though this may be extended by two further months for complex requests.
We have implemented appropriate technical and organisational measures to ensure the security of your personal data, including:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours. Where the breach is likely to result in high risk, we will also inform affected individuals without undue delay.
When arranging international travel, your data may be transferred outside the UK. We ensure such transfers are protected by appropriate safeguards, including adequacy decisions and standard contractual clauses approved by the relevant authorities.
Where we engage third parties to process personal data on our behalf, we ensure they provide sufficient guarantees regarding their data protection practices and enter into appropriate data processing agreements.
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
We review and update this GDPR statement periodically to ensure continued compliance. Material changes will be communicated through our website.
The information provided on this website is for general informational purposes only. Travel packages are subject to availability and terms and conditions. Prices may vary based on seasonality, accommodation choices, and group size. Individual experiences may differ. We recommend reviewing all package details carefully before booking. This website does not constitute professional travel advice; please consult with our team for personalised guidance suited to your specific requirements.