This Privacy Policy applies to all personal data collected and processed by Brushworks in connection with our services and operations.
Scope of this policy
Who this covers
- Customers and members
- Visitors to our facility
- Website users
- Participants in classes, coaching, or events
- Parents or guardians of under-18s
What this covers
This policy explains how we handle personal data when you:
- Create or use a Brushworks account
- Visit our climbing centre
- Make bookings or purchases
- Use our website
- Contact us or interact with our services
Where this applies
This policy applies across:
- Our physical premises
- Our website
- Our booking and membership systems
- Our communication platforms (email, marketing, and support)
What this does not cover
This policy does not apply to:
- Third-party websites or services not controlled by Brushworks
- External providers where you interact with them directly
We recommend reviewing the privacy policies of any third-party services you use alongside Brushworks.
Who we are
| Company name | The Brushworks Ltd |
| Trading name | Brushworks |
| Registered address | Suite I Windrush Court Abingdon Business Park Abingdon Oxfordshire England OX14 1SY |
| Contact | Email: [email protected] Telephone: 01417 240066 |
Data protection lead
Role: Data Protection Lead (internal)
Contact: [email protected]
About Brushworks
Brushworks is an indoor bouldering centre offering climbing facilities, coaching, and a welcoming community space for climbers of all abilities.
We are committed to providing a safe, inclusive, and high-quality environment for everyone — whether you’re trying climbing for the first time or training regularly.
What personal data we collect
We collect and process personal data to provide safe access to our facilities, manage memberships, and deliver our services effectively. The type of data we collect depends on how you interact with us.
Customer and membership data
When you register or use our services, we may collect:
- Name
- Date of birth
- Address
- Email address
- Phone number
- Emergency contact name and phone number
- Membership details and status
- Booking history (including classes and coaching sessions)
- Visit and check-in records (including time and date of entry)
Customers are checked in using our membership system (Rock Gym Pro), which may include barcode-based entry for efficient access to the facility.
Account profile data
- Profile photographs (for customers aged 18 and over only)
These are used to help staff identify customers and manage accounts safely and efficiently. We do not collect profile photos for anyone under the age of 18.
Safety and medical information
We may collect:
- Voluntarily provided medical information (e.g. asthma or relevant conditions) during registration
- Incident reports, including:
- details of accidents or injuries
- staff observations
- witness statements
- relevant medical information where necessary
This information is used solely to support safety, incident response, and safeguarding.
Children and young people’s data
For users under 18, we collect:
- Parent or guardian name and contact details
- Emergency contact information
- Consent records for participation
- Booking and attendance records for sessions and activities
- Incident records where applicable
Payments and transactions
We collect:
- Transaction records
- Purchase history (including café and retail purchases where linked to your account)
Payments are processed securely by our payment provider, Stripe, and we do not store full payment card details on our systems.
Café and retail data
Where purchases are linked to your account, we may store:
- Items purchased
- Transaction dates and times
This allows us to manage accounts, refunds, and business operations.
Website and technical data
When you use our website, we may collect:
- IP address
- Device and browser information
We do not currently use cookies on our website.
CCTV
We operate CCTV within our facilities for safety and security purposes.
Footage is accessed only by authorised staff or contractors where necessary for security, safety, investigating incidents, or responding to legal requests. We may share relevant footage with insurers, law enforcement, or emergency services where required or appropriate.
This may capture:
- video footage of customers, visitors, and staff within the premises
How we use your information
We use your personal information to run our climbing wall safely and smoothly, and to give you the best possible experience when visiting Brushworks.
In practice, this means we use your information to:
Provide our services
- Set up and manage your account
- Allow you to book sessions, classes, and coaching
- Give you access to the climbing wall
- Manage your membership
Keep you safe
- Record attendance so we know who is in the building
- Respond to accidents or incidents
- Contact your emergency contact if needed
- Maintain records to improve safety and prevent future incidents
Manage payments and purchases
- Process payments through our payment provider (Stripe)
- Keep records of purchases (including café and retail where linked to your account)
- Handle refunds and resolve payment issues
Communicate with you
- Respond to enquiries or support requests
- Send important service updates (e.g. booking confirmations or changes)
- Send marketing emails where you have agreed, or where allowed by law
You can opt out of marketing at any time.
Improve our services
- Understand how people use our facilities and website
- Improve our climbing offering, classes, and customer experience
- Maintain internal records to help run the business effectively
Keep our facilities secure
- Use CCTV to help keep customers, staff, and visitors safe
- Prevent and detect misuse of our services
Meet legal requirements
- Comply with health and safety obligations
- Meet financial and tax requirements
- Work with regulators, law enforcement, or insurers where required
Protect our business
- Prevent fraud or misuse of our services
- Support legal claims or investigations if needed
Lawful bases for processing
Data protection law requires us to have a valid reason (known as a “lawful basis”) for using your personal information. We rely on the following:
Contract
We use your information where it’s necessary to provide the services you’ve signed up for.
This includes:
- setting up your account
- managing your membership
- taking bookings and providing access to the climbing wall
- delivering classes and coaching sessions
Legal obligations
Sometimes we need to use your information to comply with the law.
This includes:
- health and safety requirements
- accident and incident reporting
- financial and tax obligations
Legitimate interests
We may use your information where it’s reasonably necessary to run our business, as long as this doesn’t unfairly affect your rights.
This includes:
- running and improving our services
- managing our day-to-day operations
- responding to enquiries and customer support requests
- keeping our facilities safe and secure (including CCTV)
- preventing fraud or misuse of our services
We always consider the impact on you and make sure this use is fair and proportionate.
Consent
In some cases, we rely on your permission (consent) to use your information.
This includes:
- sending marketing emails or messages (where required)
- collecting certain types of optional information
You can withdraw your consent at any time, and we will stop using your information for that purpose.
Vital interests
In rare situations, we may use your information to protect someone’s life or safety.
For example:
- contacting emergency services
- sharing relevant information in a medical emergency
Health information (special category data)
If we collect health-related information (for example, during an incident or if you choose to provide it), we only use it where necessary for:
- safety and incident management
- protecting the wellbeing of customers
This is handled in line with data protection laws that allow us to use this type of information for safety and legal reasons.
Marketing communications
We may use your contact details to keep you up to date with what’s happening at Brushworks, including:
- news and updates
- events and competitions
- offers and promotions
- new classes or services
How we send communications
We send emails using systems including:
- Mailchimp (for newsletters and marketing emails)
- SendGrid (for booking confirmations and service-related emails via Rock Gym Pro)
When we contact you
We will only send you marketing emails where:
- you have given your consent, or
- you have previously used our services and the law allows us to contact you (known as a “soft opt-in”)
Opting out
You can stop receiving marketing emails at any time by:
- clicking the “unsubscribe” link in any email, or
- contacting us directly at [email protected]
Once you opt out, we will stop sending marketing messages to you.
Service emails
Some emails are necessary for providing our services and are not marketing. These include:
- booking confirmations
- payment receipts
- important updates about your bookings or membership
You will continue to receive these even if you opt out of marketing emails.
Children’s data
We take children’s privacy and safety seriously and only collect the information needed to allow them to use our facilities safely.
Parental / guardian consent
Children cannot register independently.
For anyone under 18:
- a parent or legal guardian must provide consent
- we collect parent/guardian contact details as part of the registration process
Supervision and participation
- Children under 18 must be supervised in the centre by someone aged 18 or over
- Customers aged 14–17 may climb without direct supervision once they have completed a competency sign-off with our staff
We keep records of registrations, bookings, and sign-offs to manage this safely.
What information we collect
For children, we may collect:
- name and date of birth
- parent or guardian details
- emergency contact information
- booking and attendance records (including classes and coaching sessions)
- records of competency sign-offs
- incident records where applicable
Incidents involving children
If an incident involves a child, we may record:
- what happened
- actions taken by staff
- any relevant safety or medical information
These records are used to manage safety and improve our procedures.
Retention of children’s data
Some records relating to children, particularly incident reports, may be kept for longer than standard records.
This is to meet legal requirements and ensure we can respond appropriately to any future claims or safeguarding concerns. In practice, this can mean retaining incident-related records for longer periods for children (often up to age 21 in England, Wales and Northern Ireland, and up to age 19 in Scotland), depending on the circumstances.
Sharing your information
We do not sell your personal information to third parties.
However, we may share your information with trusted organisations where necessary to run our business, provide our services, and meet our legal obligations.
Service providers
We use third-party providers to help operate our business. These include:
- Membership and booking systems (Rock Gym Pro)
- Payment processing providers (Stripe)
- Email and communications platforms (Mailchimp and SendGrid)
- IT and cloud service providers
These providers only process your information on our behalf and are required to keep it secure.
Safety and industry bodies
All accidents and incidents are recorded using the Association of British Climbing Walls (ABC) incident reporting database.
This means relevant information about incidents may be shared with the ABC for:
- safety monitoring
- industry reporting
- improving safety standards across climbing walls
Insurers
Where necessary, we may share information with our insurers, particularly in relation to:
- accidents or incidents
- claims or potential claims
Legal and regulatory requirements
We may share your information where required to do so by law, including with:
- regulatory authorities
- law enforcement agencies
- government bodies
Emergency situations
In the event of an emergency, we may share relevant information with:
- emergency services
- healthcare professionals
to help protect someone’s health or safety.
Business changes
If we sell or transfer part of our business, your information may be shared with the new owner as part of that process.
Data retention
We only keep your personal information for as long as necessary to run our services, meet legal requirements, and manage safety.
General customer data
We typically keep customer and membership information for:
- 6 years after your last activity (such as a visit, booking, or account interaction)
This helps us manage accounts, resolve disputes, and meet legal requirements.
Incident reports
All accidents and incidents are recorded using the Association of British Climbing Walls (ABC) incident reporting database.
- Incident records are kept for at least 3 years
- For anyone under 18, incident records are usually kept until they reach 21 years of age (England, Wales and Northern Ireland)
- In Scotland, incident records involving children are usually kept until they reach 19 years of age (based on the usual time limit for raising personal injury actions)
This reflects the usual time limits for personal injury claims involving children (for example, in England, Wales and Northern Ireland the 3-year limitation period generally runs from a child’s 18th birthday; in Scotland it generally runs from a child’s 16th birthday). Exact time limits can vary depending on the circumstances and type of claim.
Please note:
- Incident data may also be retained by the ABC as part of their own safety monitoring and reporting systems.
CCTV
- CCTV footage is normally kept for up to 30 days
- It may be kept for longer if required for an investigation, an insurance matter, or a legal claim
Marketing data
- We keep your contact details for marketing until you unsubscribe or opt out
After this, we may keep a minimal record to ensure we respect your preference and do not contact you again.
Financial records
- Payment and transaction records are kept as required for accounting and tax purposes
When we delete data
We may delete your personal information sooner if:
- it is no longer needed
- you request deletion and we are able to comply
In some cases, we may need to retain certain information to meet legal, safety, or regulatory requirements.
Security of your data
We take the security of your personal information seriously and have measures in place to protect it from loss, misuse, or unauthorised access.
How we protect your data
We use a combination of technical and organisational measures, including:
- secure systems and password protection
- controlled access to personal data (only staff who need it can access it)
- use of trusted third-party providers
- regular staff awareness of data protection responsibilities
Access to your information
Your personal information is only accessible to:
- trained staff
- trusted contractors or service providers (where necessary)
All access is limited to what is needed to carry out specific tasks.
Data storage
Your data is stored securely using systems such as:
- Rock Gym Pro (membership and booking system)
- approved third-party providers for payments and communications
Security limitations
While we take appropriate steps to protect your information, no system can be completely secure.
Once we receive your data, we use strict procedures to reduce the risk of unauthorised access.
International data transfers
We are a UK-based business, and most of your personal information is processed within the UK.
However, some of the systems we use (such as payment, email, and membership platforms) may store or process data outside the UK.
When data is transferred
This may happen when we use trusted providers such as:
- Rock Gym Pro
- Stripe
- Mailchimp
- SendGrid
These providers may process data in countries such as the United States.
How we protect your data
When your data is transferred outside the UK, we make sure appropriate safeguards are in place to protect it.
This may include:
- using UK-approved transfer safeguards where required (for example, the UK International Data Transfer Agreement)
- requiring providers to meet recognised data protection standards
What this means for you
We take steps to ensure your personal information remains protected and handled securely, even when it is processed outside the UK.
Your rights
You have rights over your personal information. These allow you to understand and control how your data is used.
Access your data
You can ask us:
- what personal information we hold about you
- for a copy of that information
Correct your data
If any of your information is incorrect or out of date, you can ask us to update it.
Delete your data
You can ask us to delete your personal information.
We will do this where we can, but we may need to keep some information where:
- we have a legal obligation, or
- it is required for safety or legal reasons (for example, incident records)
Restrict or object to use
You can ask us to:
- stop using your data in certain ways, or
- object to how we are using it
This includes the right to object to marketing at any time.
Data portability
Where appropriate, you can ask us to provide your data in a format that can be transferred to another service provider.
Withdraw consent
If we rely on your consent (for example, for marketing), you can withdraw it at any time.
Automated decisions
We do not make decisions about you based solely on automated processing that have a significant effect on you.
How to make a request
To exercise any of your rights, please contact us at:
Email: [email protected]
We will respond within one month, as required by law.
Complaints
If you are not happy with how we use your data, you can contact us and we will do our best to resolve the issue.
You also have the right to complain to the Information Commissioner’s Office (ICO):
Website: www.ico.org.uk
Phone: 0303 123 1113
Updates to this policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or how we use personal information.
Where appropriate, we will:
- update the version on our website
- take reasonable steps to notify you of any significant changes
We recommend checking this page occasionally to stay informed.
Contact us
If you have any questions about this Privacy Policy or how we use your personal information, please contact us:
Contact details are listed in the “Who we are” section above. You can also reach us using the details below.
Email: [email protected]
Telephone: 01417 240066