aurora-kernel
Home Services About Contact Advertising Content

GDPR Compliance

Effective Date: 4 August 2026

Our Commitment to GDPR

aurora-kernel is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and your rights under this regulation.

Lawful Basis for Processing

We process your personal data based on the following lawful grounds:

  • Consent: When you provide explicit consent for us to process your data for specific purposes
  • Contract Performance: When processing is necessary to fulfill our contractual obligations to provide travel services
  • Legitimate Interests: When we have a legitimate business interest that does not override your rights and freedoms
  • Legal Obligation: When we must process data to comply with legal requirements

Your GDPR Rights

Under GDPR, you have the following rights:

Right to Access

You may request confirmation of whether we process your personal data and obtain a copy of such data.

Right to Rectification

You can request correction of inaccurate or incomplete personal data we hold about you.

Right to Erasure

You may request deletion of your personal data under certain circumstances, including when the data is no longer necessary for the purposes it was collected.

Right to Restrict Processing

You can request that we limit how we use your personal data in specific situations.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used format and transmit it to another controller.

Right to Object

You may object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw that consent at any time.

Data Protection Measures

We implement appropriate technical and organizational security measures to protect your personal data, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls limiting who can view personal data
  • Staff training on data protection principles
  • Secure data backup and recovery procedures

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law. When data is no longer needed, we securely delete or anonymize it.

International Data Transfers

When we transfer personal data outside the European Economic Area, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions.

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.

Exercising Your Rights

To exercise any of your GDPR rights, please contact us at:

[email protected]
42 Princes Street
Edinburgh, EH2 2BY
United Kingdom

We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by two additional months and will inform you accordingly.

Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection.

Updates to This Policy

We may update this GDPR compliance page to reflect changes in regulations or our practices. The effective date indicates when this page was last revised.

aurora-kernel

Edinburgh's premier travel experience curator, connecting you with Scotland's soul and Europe's wonders.

Quick Links

  • Services
  • About Us
  • Contact

Legal

  • Privacy Policy
  • Terms of Use
  • Cookies Policy
  • GDPR

Connect

[email protected]

© 2026 aurora-kernel. All rights reserved. This website contains advertising content.