wise-lagoon is committed to protecting the privacy and security of personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines our approach to GDPR compliance and your rights as a data subject.
Data Controller
wise-lagoon acts as the data controller for personal information collected through our website and services. We determine the purposes and means of processing personal data related to vehicle rental services.
Contact details:
wise-lagoon
47 Castle Boulevard
Nottingham, NG7 1FE
United Kingdom
Email: [email protected]
Lawful Basis for Processing
We process personal data under the following lawful bases:
Contract Performance
Processing necessary for the performance of a rental agreement, including verifying your identity, processing payments, and managing your booking.
Legal Obligation
Processing required to comply with legal requirements, such as maintaining records for tax purposes and responding to lawful requests from authorities.
Legitimate Interests
Processing necessary for our legitimate business interests, such as improving our services, preventing fraud, and ensuring security, where these interests are not overridden by your rights.
Consent
Where we rely on consent for specific processing activities, such as marketing communications, you have the right to withdraw consent at any time.
Your Data Subject Rights
Under GDPR, you have the following rights regarding your personal data:
Right of Access
You have the right to obtain confirmation of whether we process your personal data and to access that data along with supplementary information about how it is processed.
Right to Rectification
You have the right to have inaccurate personal data corrected and incomplete data completed.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
Right to Restrict Processing
You have the right to request that we restrict processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
Exercising Your Rights
To exercise any of your data protection rights, please contact us using the details provided above. We will respond to your request within one month. In complex cases, this period may be extended by a further two months, and we will inform you of any such extension.
We may request verification of your identity before processing your request to ensure the security of your data.
Data Protection Officer
For any questions or concerns regarding our data protection practices, please contact us at the address above. We take all privacy concerns seriously and will respond promptly to any enquiries.
Supervisory Authority
If you are not satisfied with our response to a data protection concern, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk
International Data Transfers
We primarily process data within the United Kingdom. Where data is transferred outside the UK, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the Information Commissioner.
Data Security Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data where appropriate
- Regular security assessments and testing
- Access controls limiting data access to authorised personnel
- Staff training on data protection practices
- Incident response procedures for data breaches
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
Last updated: July 2026