GDPR Policy
Last Updated: 31 July 2026
Creatricx is committed to handling personal information responsibly and in accordance with applicable data protection laws, including the UK GDPR and EU GDPR where they apply to our operations and clients.
Our Approach to Data Protection
We apply the following principles across all our services and operations:
- Collect only the personal information needed for a clear, defined purpose.
- Clearly explain how information is collected, used, and stored.
- Process information on an appropriate lawful basis.
- Protect information using reasonable technical and organisational security measures.
- Limit access to authorised individuals and vetted service providers only.
- Retain information only for as long as necessary.
- Respect and support applicable individual data protection rights.
Lawful Basis for Processing
Depending on the situation, we process personal information on one or more of the following lawful bases:
- Contract — to deliver services agreed with a client.
- Legitimate Interests — to operate and improve our business.
- Legal Obligation — to comply with applicable laws and regulations.
- Consent — where you have given us clear permission to do so.
Your Rights
Depending on applicable law, individuals have the right to:
- Access — request a copy of the personal information we hold about you.
- Correction — request correction of inaccurate or incomplete information.
- Deletion — request that we delete your personal information.
- Restriction — ask us to limit how we use your information.
- Objection — object to certain types of processing.
- Portability — receive your information in a structured, machine-readable format.
- Withdraw Consent — where processing is based on your consent.
To submit a request, email us at info@creatricx.com. We will respond within the timeframe required by applicable law (typically 30 days).
Service Providers
Where third-party service providers process personal information on our behalf, we aim to put in place appropriate data processing agreements and safeguards to ensure your information is protected.
Where Creatricx processes personal information on behalf of a client, we are willing to enter into a Data Processing Agreement (DPA) upon request.
Data Security
We implement reasonable organisational and technical measures to protect personal information from unauthorised access, accidental loss, misuse, or disclosure. These measures are reviewed and updated as appropriate.
No internet-based system can be guaranteed to be completely secure. In the unlikely event of a data incident, we will take prompt action and notify relevant parties in accordance with our legal obligations.
Data Breach Notification
Where required by applicable law, we will notify the relevant supervisory authority and affected individuals of qualifying personal data breaches within the required timeframe.
Supervisory Authority
If you are located in the UK, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
If you are located in the EU, you may contact your local data protection authority.
Contact Our Data Contact Point
- Business: Creatricx
- Email: info@creatricx.com
- Phone / WhatsApp: +44 7882 744463
Disclaimer
This page describes our general approach to data protection. It is not a regulatory certification or a guarantee of compliance in every jurisdiction.