Last updated: June 19, 2026
stone-mongoose is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page explains how we comply with GDPR requirements and your rights under this regulation.
stone-mongoose acts as the data controller for personal information collected through our website and services. We are responsible for determining how and why your data is processed.
We process your personal data based on the following legal grounds:
Under the GDPR, you have the following rights:
You have the right to request access to the personal data we hold about you. We will provide a copy of your data in a commonly used electronic format.
If your personal data is inaccurate or incomplete, you have the right to request that we correct or complete it.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we restrict processing of your personal data in certain situations, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time.
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. Booking information is typically retained for seven years in accordance with financial record-keeping obligations.
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
We primarily process data within the United Kingdom and European Economic Area. If we transfer data outside these regions, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you.
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month. In some cases, we may extend this period by an additional two months if your request is complex.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection supervisory authority.
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Telephone: 0303 123 1113
We may update this GDPR compliance statement from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes.