Privacy Notice - Substation Bouldering Ltd.
All data subjects whose personal data is collected, is in line with the GDPR.
The Data Protection Officer (DPO) is responsible for ensuring that this notice is made available to all customers prior to the collection of their personal data.
All employees of Substation Bouldering Limited that interact with data subjects are responsible for ensuring that this notice is drawn to the data subject’s attention and their consent to the processing of their data is secured.
Who are we?
Substation Bouldering Limited is a Macclesfield based company that provides a state-of-the-art bouldering and yoga centre. We aim to provide the best for our customers in terms of experience whilst maintaining our environmentally conscious ethos and giving back to the community in various ways.
Our Data Protection Officer and protection representatives can be contacted directly here: 01625 440 144
The Personal Data we would like to process on your behalf is:
Personal Data Types
Type: Type of Data Being Taken
Source: (Where Substation Bouldering Limited obtains the personal data from)
Source: Provided by the customer when registering to use Substation Bouldering Limited operated centre, via a digital registration form
Date of Birth*
Date of Birth*
Emergency Contact Name*
Emergency Contact Phone Number*
Signatures & Initials On Waiver*
Relevant Medical Conditions*
Photographs (Unsupervised 14+ Year Olds)*
Under 18 Year Olds
Source: Provided by the customer when registering to use Substation Bouldering Limited operated centre, via a digital registration form.
Parent/Guardian Phone Number*
Visit Log Including Dates & Times**
*These details are for system functionality
** Some information is required when partaking in other offerings for Substation.
The personal data that we collect, depending on the role, will be used for the following purposes:
Registration at the Centre
Identification of the Customer upon visiting the centre.
Contacting participants in regard to bookings made at Substation, Macclesfield.
Contacting named emergency contacts in the event of an emergency
Marketing from Substation Bouldering Limited (where permission has been given)
Verifying identity for payments processed by Stripe (www.stripe.com) on our behalf. This happens once permission has been given by the customer.
Our legal basis for processing data for the personal data (Article 6(1b));
Processing is necessary for the performance of a contract to which the customer has agreed when registering to climb at the centre.
We are required to collect the information in the form of a waiver showing consent and understanding before allowing anyone to participate in activities in the centre.
Article 6(1f) – Necessary for the purposes of the legitimate interests pursued by the controller.
The regulatory reform (Fire Safety) Order 2005 England and Wales – Requires an emergency evacuation plan that includes ensuring all those on site are safe and accounted for.
You are giving Substation Bouldering Ltd permission to process the personal data supplied specifically for the purposes identified. Substation Bouldering Limited collects data under the terms identified in Article 6 ‘Lawfulness of processing’ of the General Data Protection Regulation.
Where consent is required for Substation Bouldering Ltd to process personal data, it must be explicitly given.
You may withdraw consent at any time by contacting the Data Protection Officer at Substation Bouldering Limited using the contact details provided above.
Substation Bouldering Ltd will not release the information to any third party unless the request is subject to legal obligation without obtaining express written authority of the partner who provided the information.
We retain your personal information for as long as necessary to provide the services you have requested, or for other essential purposes such as complying with our legal obligations, resolving disputes and enforcing our policies.
For more information on storage and processing security, please contact Substation Bouldering Ltd. using the details provided above.
Your Rights as a Data Subject
At any point while we are in possession of or processing of your personal data, you, the data subject have the following rights:
Right of Access – You have the right to request a copy of the personal data we hold about you
Right of Rectification – You have a right to correct data that we hold about you that is inaccurate or incomplete
Right to be Forgotten – in certain circumstances you can request that all the data we hold about you is erased from our records.
Right to Restriction of Processing – where certain conditions apply you have the right to restrict the processing of the data.
Right of portability – You have the right to have the data we hold about you transferred to another organisation.
Right to object – You have the right to object to certain types of processing such as direct marketing.
Right to object to automatic processing, including profiling – You also have the right to object to the automated processing or profiling of your data.
Right to judicial review: if Substation Bouldering Ltd refuse your request under rights of access, we will provide you with a reason why. You have the right to complain as outlined in clause 3.6 below.
All of the above requests will be dealt in line with Substation Bouldering Limited’s Subject Access Procedure and will be shared with the customer should a request come directly from a data subject.
How Do We Protect Your Personal Information?
We protect your information using technical and administrative security measures to reduce the risks of loss, misuse, unauthorised access, disclosure and alteration. Some of the safeguards we use are firewalls and encryptions
Substation Bouldering Ltd is committed to keeping your personal data safe and secure and we have appropriate and proportionate security policies and organisational and technical measures in place to protect your information.
Your personal information is only accessible by appropriately trained staff, volunteers and contractors and stored on Rock Gym Pro’s database. This information is only available to Substation Bouldering Limited.
We use several third parties to process and administer customer information. We only use companies who show full compliancy to the GDPR legislation.
Source - What We Use Them For - GDPR Compliant
Rock Gym Pro - Entry system and storage on US servers - Yes, US Privacy Shield
Stripe - Online and RGPro Connect Booking as well as e-billing monthly payments - Yes, US Privacy Shields
Sendgrid - Automated E-mails from Rock Gym Pro - Yes, US Privacy Shield
MailChimp - Marketing (with permission) about upcoming events, products - Yes, US Privacy Shield
Outlook - @substation.co.uk e-mail addresses for company use - Yes, US Privacy Shield
Worldpay - PDQ terminal transactions within the centre - Yes, US Privacy Shield
Information Collected Automatically
We currently do not collect any data as an automatic function, although in future this may become something that we do.
If you wish to make a complaint about how your data is being processed by Substation Bouldering Limited, or about how your complaint has been handled, you have the right to lodge a complaint directly with the supervisory authority and schools/organisation’s data protection representatives.
The details for each of these contacts are as follows:
Supervisory authority contact details
Contact Name: Information Commissioners Office
Address line 1: Wycliffe House
Address line 2: Water Lane
Address line 3: Wilmslow
Address line 4: Cheshire
Address line 5: SK9 5A
Telephone: 0303 123 1113
Data Protection Officer contact details:
Substation Bouldering Limited.
Substation Climb And Yoga Centre
01625 440 144
Document Owner And Approval
The Data Protection Officer is the owner of this document and is responsible for ensuring that this record is reviewed in line with the requirements of GDPR
Signature: Dominic Pearce Date: 11/06/19
Change History Record
1. Initial Issue - Approval by Dominic Pearce - Date of Issue 11/06/19