Last updated: June 2026
cobalt-mesa is committed to complying with the General Data Protection Regulation (GDPR) and UK data protection laws. We respect your privacy rights and handle your personal data with care and transparency.
cobalt-mesa acts as the data controller for personal information collected through our website and travel services.
Contact details:
cobalt-mesa
27 Colmore Row
Birmingham B3 2EW
United Kingdom
Email: [email protected]
Under GDPR, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information in a commonly used electronic format within one month of your request.
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request correction. We will update your information promptly upon verification.
You may request deletion of your personal data in certain circumstances, including when the data is no longer necessary for the purposes it was collected, or when you withdraw consent for processing based on consent.
You can request that we limit how we use your personal data in specific situations, such as when you contest the accuracy of the data or object to processing.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
You may object to processing of your personal data when we rely on legitimate interests as the legal basis. This includes objecting to direct marketing communications at any time.
Where we process your data based on consent, you have the right to withdraw that consent at any time. This does not affect the lawfulness of processing before withdrawal.
If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority.
To exercise any of your GDPR rights, please contact us via email at [email protected] or by post at the address above. We will respond to your request within one month, though this may be extended by two additional months for complex requests.
We may need to verify your identity before processing your request to ensure we protect your personal data from unauthorised access.
We process your personal data under the following lawful bases:
We implement appropriate technical and organisational security measures to protect your personal data, including:
When providing international travel services, we may transfer your personal data outside the UK and European Economic Area. We ensure appropriate safeguards are in place through:
We retain personal data only as long as necessary for the purposes outlined in our Privacy Policy or as required by law. Retention periods vary based on data type:
Our services are not directed at children under 16. We do not knowingly collect personal data from children without parental consent. If we become aware of such collection, we will delete the information promptly.
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the ICO within 72 hours of becoming aware of the breach.
We may update this GDPR compliance statement to reflect changes in regulations or our data practices. Significant changes will be communicated via email to registered users.
If you wish to report a concern about our data practices, you can contact the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Tel: 0303 123 1113
Website: ico.org.uk