Privacy Policy

This Privacy Policy applies to all personal data collected and processed by Brushworks in connection with our services and operations. 

Scope of this policy 

Who this covers 

  • Customers and members  
  • Visitors to our facility  
  • Website users  
  • Participants in classes, coaching, or events  
  • Parents or guardians of under-18s  

What this covers 

This policy explains how we handle personal data when you: 

  • Create or use a Brushworks account  
  • Visit our climbing centre  
  • Make bookings or purchases  
  • Use our website  
  • Contact us or interact with our services  

Where this applies 

This policy applies across: 

  • Our physical premises  
  • Our website  
  • Our booking and membership systems  
  • Our communication platforms (email, marketing, and support)  

What this does not cover 

This policy does not apply to: 

  • Third-party websites or services not controlled by Brushworks  
  • External providers where you interact with them directly  

We recommend reviewing the privacy policies of any third-party services you use alongside Brushworks. 

  

Who we are 
Company name The Brushworks Ltd 
Trading name Brushworks 
Registered address Suite I Windrush Court 
Abingdon Business Park 
Abingdon 
Oxfordshire 
England 
OX14 1SY 
Contact Email: [email protected] 
Telephone: 01417 240066 

  

Data protection lead 

Role: Data Protection Lead (internal) 

Contact: [email protected] 

  

About Brushworks 

Brushworks is an indoor bouldering centre offering climbing facilities, coaching, and a welcoming community space for climbers of all abilities. 

We are committed to providing a safe, inclusive, and high-quality environment for everyone — whether you’re trying climbing for the first time or training regularly. 

What personal data we collect 

We collect and process personal data to provide safe access to our facilities, manage memberships, and deliver our services effectively. The type of data we collect depends on how you interact with us. 

Customer and membership data 

When you register or use our services, we may collect: 

  • Name  
  • Date of birth  
  • Address  
  • Email address  
  • Phone number  
  • Emergency contact name and phone number  
  • Membership details and status  
  • Booking history (including classes and coaching sessions)  
  • Visit and check-in records (including time and date of entry)  

Customers are checked in using our membership system (Rock Gym Pro), which may include barcode-based entry for efficient access to the facility. 

Account profile data 

  • Profile photographs (for customers aged 18 and over only)  

These are used to help staff identify customers and manage accounts safely and efficiently. We do not collect profile photos for anyone under the age of 18. 

Safety and medical information 

We may collect: 

  • Voluntarily provided medical information (e.g. asthma or relevant conditions) during registration  
  • Incident reports, including:  
  • details of accidents or injuries  
  • staff observations  
  • witness statements  
  • relevant medical information where necessary  

This information is used solely to support safety, incident response, and safeguarding. 

Children and young people’s data 

For users under 18, we collect: 

  • Parent or guardian name and contact details  
  • Emergency contact information  
  • Consent records for participation  
  • Booking and attendance records for sessions and activities  
  • Incident records where applicable  

Payments and transactions 

We collect: 

  • Transaction records  
  • Purchase history (including café and retail purchases where linked to your account)  

Payments are processed securely by our payment provider, Stripe, and we do not store full payment card details on our systems. 

Café and retail data 

Where purchases are linked to your account, we may store: 

  • Items purchased  
  • Transaction dates and times  

This allows us to manage accounts, refunds, and business operations. 

Website and technical data 

When you use our website, we may collect: 

  • IP address  
  • Device and browser information  

We do not currently use cookies on our website. 

CCTV 

We operate CCTV within our facilities for safety and security purposes. 

Footage is accessed only by authorised staff or contractors where necessary for security, safety, investigating incidents, or responding to legal requests. We may share relevant footage with insurers, law enforcement, or emergency services where required or appropriate. 

This may capture: 

  • video footage of customers, visitors, and staff within the premises 
How we use your information 

We use your personal information to run our climbing wall safely and smoothly, and to give you the best possible experience when visiting Brushworks. 

In practice, this means we use your information to: 

Provide our services 

  • Set up and manage your account  
  • Allow you to book sessions, classes, and coaching  
  • Give you access to the climbing wall  
  • Manage your membership  

Keep you safe 

  • Record attendance so we know who is in the building  
  • Respond to accidents or incidents  
  • Contact your emergency contact if needed  
  • Maintain records to improve safety and prevent future incidents  

Manage payments and purchases 

  • Process payments through our payment provider (Stripe)  
  • Keep records of purchases (including café and retail where linked to your account)  
  • Handle refunds and resolve payment issues  

Communicate with you 

  • Respond to enquiries or support requests  
  • Send important service updates (e.g. booking confirmations or changes)  
  • Send marketing emails where you have agreed, or where allowed by law  

You can opt out of marketing at any time. 

Improve our services 

  • Understand how people use our facilities and website  
  • Improve our climbing offering, classes, and customer experience  
  • Maintain internal records to help run the business effectively  

Keep our facilities secure 

  • Use CCTV to help keep customers, staff, and visitors safe  
  • Prevent and detect misuse of our services  

Meet legal requirements 

  • Comply with health and safety obligations  
  • Meet financial and tax requirements  
  • Work with regulators, law enforcement, or insurers where required  

Protect our business 

  • Prevent fraud or misuse of our services  
  • Support legal claims or investigations if needed  

Lawful bases for processing 

Data protection law requires us to have a valid reason (known as a “lawful basis”) for using your personal information. We rely on the following: 

Contract 

We use your information where it’s necessary to provide the services you’ve signed up for. 

This includes: 

  • setting up your account  
  • managing your membership  
  • taking bookings and providing access to the climbing wall  
  • delivering classes and coaching sessions  

Legal obligations 

Sometimes we need to use your information to comply with the law. 

This includes: 

  • health and safety requirements  
  • accident and incident reporting  
  • financial and tax obligations  

Legitimate interests 

We may use your information where it’s reasonably necessary to run our business, as long as this doesn’t unfairly affect your rights. 

This includes: 

  • running and improving our services  
  • managing our day-to-day operations  
  • responding to enquiries and customer support requests  
  • keeping our facilities safe and secure (including CCTV)  
  • preventing fraud or misuse of our services  

We always consider the impact on you and make sure this use is fair and proportionate. 

Consent 

In some cases, we rely on your permission (consent) to use your information. 

This includes: 

  • sending marketing emails or messages (where required)  
  • collecting certain types of optional information  

You can withdraw your consent at any time, and we will stop using your information for that purpose. 

Vital interests 

In rare situations, we may use your information to protect someone’s life or safety. 

For example: 

  • contacting emergency services  
  • sharing relevant information in a medical emergency  

Health information (special category data) 

If we collect health-related information (for example, during an incident or if you choose to provide it), we only use it where necessary for: 

  • safety and incident management  
  • protecting the wellbeing of customers  

This is handled in line with data protection laws that allow us to use this type of information for safety and legal reasons. 

Marketing communications 

We may use your contact details to keep you up to date with what’s happening at Brushworks, including: 

  • news and updates  
  • events and competitions  
  • offers and promotions  
  • new classes or services  

How we send communications 

We send emails using systems including: 

  • Mailchimp (for newsletters and marketing emails)  
  • SendGrid (for booking confirmations and service-related emails via Rock Gym Pro)  

When we contact you 

We will only send you marketing emails where: 

  • you have given your consent, or  
  • you have previously used our services and the law allows us to contact you (known as a “soft opt-in”)  

Opting out 

You can stop receiving marketing emails at any time by: 

  • clicking the “unsubscribe” link in any email, or  

Once you opt out, we will stop sending marketing messages to you. 

Service emails 

Some emails are necessary for providing our services and are not marketing. These include: 

  • booking confirmations  
  • payment receipts  
  • important updates about your bookings or membership  

You will continue to receive these even if you opt out of marketing emails. 

Children’s data 

We take children’s privacy and safety seriously and only collect the information needed to allow them to use our facilities safely. 

Parental / guardian consent 

Children cannot register independently. 

For anyone under 18: 

  • a parent or legal guardian must provide consent  
  • we collect parent/guardian contact details as part of the registration process  

Supervision and participation 

  • Children under 18 must be supervised in the centre by someone aged 18 or over  
  • Customers aged 14–17 may climb without direct supervision once they have completed a competency sign-off with our staff  

We keep records of registrations, bookings, and sign-offs to manage this safely. 

What information we collect 

For children, we may collect: 

  • name and date of birth  
  • parent or guardian details  
  • emergency contact information  
  • booking and attendance records (including classes and coaching sessions)  
  • records of competency sign-offs  
  • incident records where applicable  

Incidents involving children 

If an incident involves a child, we may record: 

  • what happened  
  • actions taken by staff  
  • any relevant safety or medical information  

These records are used to manage safety and improve our procedures. 

Retention of children’s data 

Some records relating to children, particularly incident reports, may be kept for longer than standard records. 

This is to meet legal requirements and ensure we can respond appropriately to any future claims or safeguarding concerns. In practice, this can mean retaining incident-related records for longer periods for children (often up to age 21 in England, Wales and Northern Ireland, and up to age 19 in Scotland), depending on the circumstances. 

Sharing your information 

We do not sell your personal information to third parties. 

However, we may share your information with trusted organisations where necessary to run our business, provide our services, and meet our legal obligations. 

Service providers 

We use third-party providers to help operate our business. These include: 

  • Membership and booking systems (Rock Gym Pro)  
  • Payment processing providers (Stripe)  
  • Email and communications platforms (Mailchimp and SendGrid)  
  • IT and cloud service providers  

These providers only process your information on our behalf and are required to keep it secure. 

Safety and industry bodies 

All accidents and incidents are recorded using the Association of British Climbing Walls (ABC) incident reporting database. 

This means relevant information about incidents may be shared with the ABC for: 

  • safety monitoring  
  • industry reporting  
  • improving safety standards across climbing walls  

Insurers 

Where necessary, we may share information with our insurers, particularly in relation to: 

  • accidents or incidents  
  • claims or potential claims  

Legal and regulatory requirements 

We may share your information where required to do so by law, including with: 

  • regulatory authorities  
  • law enforcement agencies  
  • government bodies  

Emergency situations 

In the event of an emergency, we may share relevant information with: 

  • emergency services  
  • healthcare professionals  

to help protect someone’s health or safety. 

Business changes 

If we sell or transfer part of our business, your information may be shared with the new owner as part of that process. 

Data retention 

We only keep your personal information for as long as necessary to run our services, meet legal requirements, and manage safety. 

General customer data 

We typically keep customer and membership information for: 

  • 6 years after your last activity (such as a visit, booking, or account interaction)  

This helps us manage accounts, resolve disputes, and meet legal requirements. 

Incident reports 

All accidents and incidents are recorded using the Association of British Climbing Walls (ABC) incident reporting database. 

  • Incident records are kept for at least 3 years  
  • For anyone under 18, incident records are usually kept until they reach 21 years of age (England, Wales and Northern Ireland) 
  • In Scotland, incident records involving children are usually kept until they reach 19 years of age (based on the usual time limit for raising personal injury actions) 

This reflects the usual time limits for personal injury claims involving children (for example, in England, Wales and Northern Ireland the 3-year limitation period generally runs from a child’s 18th birthday; in Scotland it generally runs from a child’s 16th birthday). Exact time limits can vary depending on the circumstances and type of claim. 

Please note: 

  • Incident data may also be retained by the ABC as part of their own safety monitoring and reporting systems.  

CCTV 

  • CCTV footage is normally kept for up to 30 days  
  • It may be kept for longer if required for an investigation, an insurance matter, or a legal claim  

Marketing data 

  • We keep your contact details for marketing until you unsubscribe or opt out  

After this, we may keep a minimal record to ensure we respect your preference and do not contact you again. 

Financial records 

  • Payment and transaction records are kept as required for accounting and tax purposes  

When we delete data 

We may delete your personal information sooner if: 

  • it is no longer needed  
  • you request deletion and we are able to comply  

In some cases, we may need to retain certain information to meet legal, safety, or regulatory requirements. 

Security of your data 

We take the security of your personal information seriously and have measures in place to protect it from loss, misuse, or unauthorised access. 

How we protect your data 

We use a combination of technical and organisational measures, including: 

  • secure systems and password protection  
  • controlled access to personal data (only staff who need it can access it)  
  • use of trusted third-party providers  
  • regular staff awareness of data protection responsibilities  

Access to your information 

Your personal information is only accessible to: 

  • trained staff  
  • trusted contractors or service providers (where necessary)  

All access is limited to what is needed to carry out specific tasks. 

Data storage 

Your data is stored securely using systems such as: 

  • Rock Gym Pro (membership and booking system)  
  • approved third-party providers for payments and communications  

Security limitations 

While we take appropriate steps to protect your information, no system can be completely secure. 

Once we receive your data, we use strict procedures to reduce the risk of unauthorised access. 

International data transfers 

We are a UK-based business, and most of your personal information is processed within the UK. 

However, some of the systems we use (such as payment, email, and membership platforms) may store or process data outside the UK. 

When data is transferred 

This may happen when we use trusted providers such as: 

  • Rock Gym Pro  
  • Stripe  
  • Mailchimp  
  • SendGrid  

These providers may process data in countries such as the United States. 

How we protect your data 

When your data is transferred outside the UK, we make sure appropriate safeguards are in place to protect it. 

This may include: 

  • using UK-approved transfer safeguards where required (for example, the UK International Data Transfer Agreement) 
  • requiring providers to meet recognised data protection standards  

What this means for you 

We take steps to ensure your personal information remains protected and handled securely, even when it is processed outside the UK. 

Your rights 

You have rights over your personal information. These allow you to understand and control how your data is used. 

Access your data 

You can ask us: 

  • what personal information we hold about you  
  • for a copy of that information  

Correct your data 

If any of your information is incorrect or out of date, you can ask us to update it. 

Delete your data 

You can ask us to delete your personal information. 

We will do this where we can, but we may need to keep some information where: 

  • we have a legal obligation, or  
  • it is required for safety or legal reasons (for example, incident records)  

Restrict or object to use 

You can ask us to: 

  • stop using your data in certain ways, or  
  • object to how we are using it  

This includes the right to object to marketing at any time. 

Data portability 

Where appropriate, you can ask us to provide your data in a format that can be transferred to another service provider. 

Withdraw consent 

If we rely on your consent (for example, for marketing), you can withdraw it at any time. 

Automated decisions 

We do not make decisions about you based solely on automated processing that have a significant effect on you. 

How to make a request 

To exercise any of your rights, please contact us at: 

Email: [email protected] 

We will respond within one month, as required by law. 

Complaints 

If you are not happy with how we use your data, you can contact us and we will do our best to resolve the issue. 

You also have the right to complain to the Information Commissioner’s Office (ICO): 

Website: www.ico.org.uk 
Phone: 0303 123 1113 

Updates to this policy 

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or how we use personal information. 

Where appropriate, we will: 

  • update the version on our website  
  • take reasonable steps to notify you of any significant changes  

We recommend checking this page occasionally to stay informed. 

Contact us 

If you have any questions about this Privacy Policy or how we use your personal information, please contact us: 

Contact details are listed in the “Who we are” section above. You can also reach us using the details below. 

Email: [email protected] 
Telephone: 01417 240066