Last updated: June 7, 2026
We are committed to complying with the General Data Protection Regulation (GDPR) and protecting your personal data. This page explains how we fulfill our obligations under GDPR and outlines your rights as a data subject.
We process your personal data under the following legal bases:
Under GDPR, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information in a commonly used electronic format.
You can request that we correct any inaccurate or incomplete personal data we hold about you.
You have the right to request deletion of your personal data in certain circumstances, including when the data is no longer necessary for the purpose it was collected.
You can request that we limit the processing of your personal data in specific situations, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
You can object to our processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produces legal effects concerning you.
To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month, though this may be extended by two additional months in complex cases.
The data controller responsible for your personal data is:
spectra-engine
42 Westbourne Grove
Notting Hill, London W2 5SH
United Kingdom
For questions specifically related to data protection, you may contact our data protection representative at [email protected].
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce agreements.
We primarily process data within the United Kingdom and European Economic Area. If we transfer data outside these regions, we ensure appropriate safeguards are in place.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and report to the relevant supervisory authority within 72 hours of becoming aware of the breach.
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
For the United Kingdom, the relevant authority is the Information Commissioner's Office (ICO).
We may update this GDPR compliance information from time to time. Any changes will be posted on this page with an updated revision date.