BlocHaus Climbing Ltd is committed to protecting personal data in accordance with the Data Protection Act 2018 (DPA 2018) and the UK General Data Protection Regulation (UK GDPR). This Privacy Policy explains how we collect, use, store, and share your personal data, and outlines your rights.
1. Why We Collect Personal Data
We collect personal data in order to:
Operate and administer our indoor climbing facilities safely and effectively
Manage memberships, bookings, waivers, and participation agreements
Communicate with you about bookings, events, updates, or emergencies
Process transactions and maintain accurate financial records
Send marketing communications (only with your consent)
Conduct recruitment and hiring activities
Collect feedback through surveys to improve our services
Some information (e.g., emergency contacts, medical/safety information) is required for safety and cannot be withheld. Other data, such as marketing preferences or voluntary survey responses, is collected only with your consent.
2. Legal Bases for Processing
We rely on one or more lawful bases under UK GDPR:
Contractual necessity: Memberships, bookings, participation in activities
SendGrid (US): Automated booking and confirmation emails (SCCs/UK Addendum)
Brevo (UK/EU): Marketing email platform
Wix (Israel): Website forms (UK adequacy decision)
Google Forms (EU/US): Surveys and feedback forms (SCCs/UK Addendum)
NICAS (UK): Only name and DOB for eligible youth participants
Indeed / recruitment platforms: Applicant data submission
We do not sell personal data. All third parties are contractually required to comply with UK GDPR.
7. Data Retention
Data is retained as follows:
Membership & account data: Retained for the duration of your membership and indefinitely thereafter for legal and safety purposes
Waivers & participation agreements: Retained indefinitely as evidence of consent
Transactions & billing records: Retained indefinitely for accounting and audit purposes
Medical/emergency information: Retained indefinitely or until consent is withdrawn
CCTV footage: 30 days unless required longer
Recruitment data: Retained indefinitely unless the applicant requests deletion or removes their information from third‑party recruitment platforms (e.g., Indeed). We may retain applications received via email or recruitment platforms for reference in future hiring unless a deletion request is made.
Marketing consent: Retained until withdrawn (suppression list maintained)
All data is stored securely with access restricted to authorised personnel.
8. Children & Youth Programmes
Parental/guardian consent required for under-18s
Medical and emergency details collected only as needed for safe participation
NICAS registration includes only name and date of birth
9. Your Rights Under UK GDPR
You have the right to:
Access your personal data
Request correction of inaccurate or incomplete information
Request erasure where appropriate
Restrict processing in certain circumstances
Object to processing (including marketing)
Withdraw consent at any time
Request data portability
Object to automated decision-making
Lodge a complaint with the ICO
Some requests may be limited by legal or contractual obligations.
10. Security
We apply appropriate technical and organisational measures, including:
Encrypted digital storage (via RGP and other providers)
Secure storage of paper documents (e.g., incident reports)
Role-based access for staff
Staff GDPR and data protection training
Regular security reviews
11. Cookies & Website Use
Our website uses cookies for:
Strictly necessary: Essential for functionality
Analytical / functional / marketing: Only used with consent
You may manage cookie settings through your browser or our website’s cookie banner.
12. Policy Updates
This policy is reviewed regularly by the DPO. Updates will be posted on our website or communicated where appropriate.