top of page

GDPR and Data protection Policy

1. Purpose of this Policy

Balfour Swimming School is committed to protecting the privacy and security of all personal data we collect.

This policy explains:

what personal data we collect

why we collect it

how we store and protect it

your rights under UK GDPR

We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

 

 2. Data Controller

Balfour Swimming School is the Data Controller for all personal data processed in connection with our activities.

Contact:

Data Protection Lead 

Balfour Swimming School

Email: balfourswimmingschool@gmail.com

 

3. What Personal Data We Collect

We collect only the information necessary to run safe, effective swimming lessons.

 

3.1 For children/swimmers

Name, date of birth, gender

Parent/guardian contact details

Medical information (e.g., asthma, allergies)

Swimming ability and lesson history

Emergency contact details

 

3.2 For parents/guardians

Name and contact details

Payment information (processed securely by third‑party providers)

 

3.3 For staff/volunteers

Name and contact details

DBS information

Qualifications and training records

Emergency contact details

 

3.4 Website or digital data

Contact form submissions

Cookies (if applicable)

IP address (for security)

 

 4. Why We Collect Personal Data (Lawful Basis)

We process data under the following lawful bases:

Contract — to provide swimming lessons

Legal obligation — safeguarding, health & safety, DBS checks

Vital interests — medical emergencies

Legitimate interests — running and improving the swim school

Consent — photography, marketing communications

We only collect what is necessary.

 5. How We Use Personal Data

We use personal data to:

manage lesson bookings

communicate with parents

ensure swimmer safety

respond to medical needs

maintain safeguarding standards

manage staff and volunteers

process payments

comply with legal requirements

We never sell personal data.

 

 6. How We Store and Protect Data

We take data security seriously. Measures include:

password‑protected systems

encrypted storage where possible

restricted access for staff only

secure payment processors

regular policy reviews

Paper records (if used) are stored in locked cabinets and destroyed securely.

 

 7. Sharing Personal Data

We only share data when necessary, such as with:

pool operators (for emergency or safety reasons)

insurers (for incident reporting)

emergency services

DBS checking services

payment processors

We do not share data with third parties for marketing.

 

 8. Photography & Video

We will only take or use photographs/videos of swimmers if:

explicit written consent is given by a parent/guardian

images are used safely and appropriately

no child is identified by full name without consent

Parents must follow our Photography & Social Media Policy.

 

 9. Data Retention

We keep personal data only as long as necessary:

Swimmer records: up to 3 years after leaving

Incident reports: 3–7 years depending on severity

Safeguarding records: indefinitely, as required

Staff records: 6 years after employment/volunteering ends

Data is securely deleted or shredded when no longer needed.

 

 10. Your Rights Under UK GDPR

You have the right to:

Access your data

Correct inaccurate data

Request deletion (where legally allowed)

Restrict processing

Object to certain uses

Withdraw consent at any time

Data portability (where applicable)

Requests will be handled within 30 days.

 

11. Data Breaches

If a data breach occurs:

We will assess the risk immediately

Inform affected individuals if there is a high risk

Report serious breaches to the ICO within 72 hours

We maintain an internal breach log.

 

 12. Changes to This Policy

This policy will be reviewed annually or sooner if:

legislation changes

our operations change

new risks are identified

bottom of page