Last updated: August 2026
true-reed is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This page outlines our compliance measures and your rights under GDPR.
For the purposes of GDPR, the data controller is:
true-reed
47 George Street
Edinburgh EH2 2HT
United Kingdom
Email: [email protected]
We process personal data only when we have a lawful basis to do so. Our processing activities rely on the following legal grounds:
When you provide explicit consent for specific processing activities, such as subscribing to marketing communications or accepting cookies on our website. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
Processing necessary to fulfill our contractual obligations when you book travel services with us. This includes coordinating accommodations, transportation, and other elements of your travel experience.
Processing necessary for our legitimate business interests, provided these interests do not override your fundamental rights and freedoms. This includes:
Processing required to comply with legal obligations, such as maintaining financial records for tax purposes or responding to lawful requests from authorities.
GDPR grants you specific rights regarding your personal data. We respect these rights and have established procedures to facilitate their exercise.
You have the right to obtain confirmation of whether we process your personal data and, if so, to access that data along with specific information about the processing. We will provide a copy of your personal data free of charge upon request.
You have the right to request correction of inaccurate personal data and to have incomplete personal data completed. We will respond to rectification requests within 30 days.
Also known as the "right to be forgotten," you may request deletion of your personal data when:
Note that certain legal obligations may require us to retain specific data even after an erasure request.
You may request that we restrict processing of your personal data when:
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller when processing is based on consent or contract and is carried out by automated means.
You may object to processing of your personal data when:
We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for legal claims.
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. We do not currently engage in automated decision-making that would trigger this right.
To exercise any of your GDPR rights, please contact us at:
Email: [email protected]
We will respond to your request within 30 days. In complex cases, we may extend this period by an additional 60 days and will inform you of any such extension.
You will not be charged a fee for exercising your rights unless your request is clearly unfounded, repetitive, or excessive, in which case we may charge a reasonable administrative fee or refuse to act on the request.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal obligations:
When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay. We will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.
We conduct Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in high risk to individuals' rights and freedoms. These assessments help us identify and minimize data protection risks.
When we engage third-party processors to handle personal data on our behalf, we ensure they:
Our services are not directed to children under 16 years of age. We do not knowingly collect or process personal data from children. If we become aware that we have collected data from a child without appropriate parental consent, we will take steps to delete that information promptly.
You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement, if you believe our processing of your personal data violates GDPR.
For complaints in the United Kingdom, the relevant authority is:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Website: ico.org.uk
We may update this GDPR compliance statement periodically to reflect changes in our practices, legal requirements, or regulatory guidance. Material changes will be communicated through our website with an updated "Last updated" date.
For questions or concerns regarding our GDPR compliance or data protection practices, please contact:
Email: [email protected]
Address: 47 George Street, Edinburgh EH2 2HT, United Kingdom