Effective Date: January 10, 2017
Last Updated: September 05, 2026
PRIVACY NOTICE
For students, parents and guardians, prospective members and website visitors
|
Data controller |
Blue Wave Taekwondo Ltd (company number 13941126), trading as Washington Taekwondo |
|
Address |
Arndale House, Victoria Road, Washington, Tyne and Wear NE37 2SW |
|
Privacy contact |
info@washingtontaekwondo.co.uk |
|
Effective date |
Immediately upon publication | ICO registration number: ZC228782 |
1. About this notice
Blue Wave Taekwondo Ltd is responsible for deciding how and why personal information is used. This notice explains what information we collect, why we use it, who we may share it with, how long we keep it and the rights available under UK data-protection law.
This notice applies to students, parents and guardians, prospective members, trial participants and visitors to our website and premises. Employees, instructors and volunteers are covered by a separate staff privacy notice.
We handle personal information under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where relevant, the Privacy and Electronic Communications Regulations (PECR).
2. Information we collect
Depending on your relationship with us, we may collect:
• names, dates of birth, addresses and contact details for students, parents, guardians and emergency contacts;
• membership, programme, class, belt, grading, attendance, progress and achievement records;
• enquiry, trial, communication, complaint, cancellation and customer-service records;
• membership agreements, invoices, payment status, transaction references, discounts and limited card information supplied by Stripe, such as card type and final digits;
• health conditions, injuries, disabilities, allergies, additional needs and reasonable-adjustment information needed to support safe participation;
• accident, incident, behaviour, disciplinary and safeguarding information;
• photographs, videos, livestream footage and related consent choices;
• CCTV images and audio recorded at our premises;
• website and device information, such as IP address, browser type, cookie identifiers, page visits, advertisement interactions and form submissions; and
• information supplied through Spark, email, telephone, WhatsApp, social media, the member app, our website or in person.
We do not write down or store full payment-card details. Card information is handled by Stripe through its secure payment systems.
3. How we obtain information
We usually obtain information directly from the student or their parent or guardian through enquiry, trial, starter-pack, induction, membership and consent forms; through communications with us; and while delivering classes, events and membership services.
We may also obtain information from payment providers, Spark, Website Dojo, the British Taekwondo Council (BTC), our website and advertising platforms, emergency services, insurers, professional advisers or another person acting with appropriate authority.
4. Why we use information and our lawful bases
We only use personal information when we have a lawful reason. Depending on the activity, we rely on one or more of the following:
• Contract: to take steps before membership, administer the membership agreement, provide classes and member services, take payments, manage cancellations and respond to service requests.
• Legal obligation: to meet tax, accounting, health and safety, safeguarding and other legal or regulatory duties.
• Legitimate interests: to operate and improve the club, keep accurate records, communicate with families, manage attendance and progress, protect the premises, prevent fraud, recover properly due fees and establish, exercise or defend legal claims. We balance these interests against the rights of students and families, especially children.
• Consent: for optional marketing and for specified photography, video and livestream uses. Consent can be withdrawn at any time without affecting the lawfulness of earlier use.
• Vital interests: in a genuine emergency where information is needed to protect someone's life and the person cannot give consent.
5. Health, additional-needs and safeguarding information
Health and some disability information is special-category data. We process it only where an Article 6 lawful basis and an additional Article 9 condition apply. Depending on the circumstances, these may include explicit consent, vital interests, legal claims, or substantial public interest for safeguarding children and individuals at risk.
This information is used to assess safe participation, provide reasonable support and adjustments, respond to emergencies, record accidents and fulfil safeguarding responsibilities. Within Spark, access is limited to Andrew Keogh and authorised instructors or administrative staff who need the information for safety or administration. Safeguarding records held in Google Drive are restricted to Andrew Keogh.
Safeguarding concerns may be shared with the BTC safeguarding team, the police, local authority safeguarding services, emergency services or other appropriate bodies where necessary. Safeguarding decisions are made by people and follow BTC safeguarding procedures; they are not delegated to artificial intelligence.
6. Payments and unpaid accounts
Stripe processes card payments and may apply security, fraud-prevention and bank-decline checks. Spark records membership and payment status, while relevant information may be reconciled through Stripe, QuickBooks and our accountant.
Where membership fees remain unpaid, we may use contact, agreement, payment and communication records to contact the payer, administer the account and recover sums properly due. If proportionate and necessary, information may be shared with an appointed solicitor, authorised debt-recovery provider, court or dispute-resolution service. We will not disclose more information than is reasonably required.
7. Photographs, video and livestreams
For children, parents or guardians are offered separate yes/no choices for public photographs and videos, livestreams such as Facebook Live, and internal training or progress images. Refusing consent does not affect membership or the student's ability to train.
Consent choices are recorded in Spark. Staff check the non-consent list before recording and take reasonable steps to keep those students outside the camera area. We normally avoid publishing a child's full name alongside an image. Consent may be withdrawn by emailing us, although withdrawal cannot remove material already lawfully printed or prevent third parties from retaining content they previously accessed on social media.
Where event or crowd photography is planned, we will provide reasonable notice and arrangements for anyone who does not wish to be included.
8. CCTV and live spectator viewing
Eight CCTV cameras operate continuously at the premises. Four dojang cameras also provide a live, video-only feed to screens in the parents' spectator room so parents can watch classes while physically present. Parents cannot access the feed remotely, download it or replay recordings.
The other cameras, including one external camera, are used for security, crime prevention, safety and incident investigation. Cameras do not operate in toilets or changing facilities and do not use facial recognition, identity matching or automatic number-plate recognition.
The CCTV system records video and audio. Audio is not played on the spectator-room feed. CCTV and audio recording are more intrusive than video alone; our use is subject to necessity and proportionality review and a Data Protection Impact Assessment. Appropriate signs identify the recording, its purpose and how to contact us.
Recordings are normally overwritten after 30 days. Relevant footage may be preserved for longer where needed for an accident, safeguarding concern, complaint, insurance matter, legal claim or police investigation. Stored recordings can be viewed or downloaded only by Andrew Keogh through the secure office system or authorised mobile app. Footage may be disclosed to the police, insurers, legal advisers, safeguarding authorities or an individual exercising a valid data right where lawful and proportionate.
9. Use of artificial intelligence
We may use business AI services, including ChatGPT Work provided by OpenAI, to support administrative and creative work. Uses may include drafting or improving communications, preparing policies and templates, producing lesson or educational ideas, summarising business information and improving routine administration.
AI is a support tool, not the final decision-maker. Important outputs are checked by a person. We do not use AI to make solely automated decisions with legal or similarly significant effects, and AI does not independently decide membership, cancellations, debt recovery, disciplinary action, safeguarding, grading, medical suitability or reasonable adjustments.
We apply data minimisation. Customer material should normally be anonymised by removing surnames, contact details, payment information and unnecessary health or safeguarding details before it is entered into AI. We do not intentionally enter full card details, passwords or unnecessary confidential information. Identifiable safeguarding information should not be entered unless strictly necessary, lawful and appropriately protected.
AI services may process information outside the UK. Where personal information is involved, we use business services and contractual or other transfer safeguards appropriate to the service and keep our use under review.
10. Who we share information with
Where necessary and lawful, we may share limited information with:
• Spark Membership, for customer relationship management, memberships, attendance, communications and member services;
• Stripe, for secure payment processing, payment retries, fraud prevention and disputes;
• the British Taekwondo Council, for annual membership, safeguarding, accident reporting and related administration;
• Website Dojo, website hosting, booking and form providers;
• Google Workspace services, including Gmail and Google Drive;
• WhatsApp and Meta/Facebook, where you communicate with us or consent to relevant media and marketing activities;
• OpenAI and other approved business AI providers, subject to the safeguards described above;
• QuickBooks, our accountant, insurers, banks and professional advisers;
• IT, CCTV, security and communications providers supporting our systems;
• HMRC, regulators, courts, law-enforcement and safeguarding authorities where required or permitted by law; and
• authorised legal and debt-recovery providers where reasonably necessary.
We do not sell personal information. Providers acting for us must process information only for agreed purposes and provide appropriate security and confidentiality.
11. International transfers
Some service providers, including technology, CRM, communications, social-media, payment and AI providers, may store or access information outside the United Kingdom. Where UK data-protection law requires it, we use an adequacy regulation, approved contractual protections such as the UK International Data Transfer Agreement or UK Addendum, or another lawful transfer mechanism. Further information may be requested using our privacy contact details.
12. Marketing
Prospective customers are asked to make a separate marketing choice. We may send marketing by email, text, WhatsApp or similar electronic message where you have consented or where the limited existing-customer rules permit it. Every electronic marketing message will identify us and provide a straightforward way to opt out.
Membership, payment, safety, timetable and service messages are not marketing and may still be sent where needed to administer the membership. If you object to marketing, we may keep minimal contact information on a suppression list so that we do not contact you again accidentally.
13. Website cookies and advertising
Our website may use essential cookies needed for security, forms and basic operation. With consent, it may also use analytics and advertising technologies such as Google Analytics, Google Ads and Meta/Facebook tools to understand website use, measure enquiries and improve advertising.
Non-essential cookies should not be activated until a visitor has made a valid choice. Visitors must be able to reject non-essential cookies and change their choice later. More detail, including cookie names, providers, purposes and durations, should be provided in our cookie notice or consent tool.
14. How long we keep information
We use the following standard periods, subject to earlier deletion where information is no longer required and longer retention where a legal claim, investigation, safeguarding matter or regulator requires it:
|
Record |
Standard retention |
|---|---|
|
Current membership records |
For the duration of membership. |
|
Former-member agreements, attendance and payment records |
Six years after membership ends. |
|
Enquiries and unsuccessful trials |
Three years after the last contact, unless the person remains validly subscribed to marketing. |
|
Marketing suppression records |
Minimal details for as long as reasonably necessary to honour the objection. |
|
CCTV and audio |
Normally 30 days; longer only for a preserved incident, claim or investigation. |
|
Adult accident records |
Six years from the incident. |
|
Children's accident records |
Until the child's 21st birthday, or longer where a claim, insurer or BTC requirement applies. |
|
Safeguarding records |
For the period required by BTC safeguarding policy, applicable safeguarding guidance and any continuing investigation. |
|
Accounting and tax records |
Normally six years or any longer period required by law. |
15. Information security
We use proportionate technical and organisational safeguards. These include individual user accounts, role-based access, restricted Drive folders, password protection, two-factor authentication where supported, secure payment processing through Stripe, access removal when roles end, controlled CCTV access and secure destruction of paper accident forms after scanning and checking.
No system is completely secure. We maintain procedures for identifying, containing, recording and, where legally required, notifying personal-data breaches.
16. Your data-protection rights
Depending on the circumstances, you may have the right to:
• be informed about how we use personal information;
• request access to personal information and receive a copy;
• ask us to correct inaccurate or incomplete information;
• request deletion where there is no continuing lawful reason to keep information;
• request restriction of processing in certain circumstances;
• object to processing based on legitimate interests and object absolutely to direct marketing;
• receive certain information in a portable format;
• withdraw consent at any time where consent is the basis used; and
• ask for human intervention where a qualifying solely automated decision is made. We do not currently make such membership decisions.
To exercise a right, email info@washingtontaekwondo.co.uk. We may ask for reasonable proof of identity and authority, particularly where a parent or guardian makes a request concerning a child. Rights are not absolute, and we will explain if an exemption or other lawful reason applies.
17. Complaints
Please contact us first so we can try to resolve your concern. You also have the right to complain to the Information Commissioner's Office (ICO), the UK data-protection regulator, at www.ico.org.uk or by calling 0303 123 1113.
18. Changes to this notice
We may update this notice to reflect changes in law, our services, technology or providers. The current version will be published on our website with its effective date. Where a change materially affects how we use information, we will take reasonable steps to bring it to the attention of affected people.
19. Contact us
Privacy enquiries and requests should be sent to:
Andrew Keogh, Blue Wave Taekwondo Ltd
Arndale House, Victoria Road, Washington, Tyne and Wear NE37 2SW
Email: info@washingtontaekwondo.co.uk
Company number: 13941126
ICO registration number: ZC228782