Le- Gro Leisure GDPR policy
26/6/2020
This policy is made with reference to “The data protection act 2018” and guidance published 22nd March 2018 from the Information Commissioners Office (CMO)
For the purposes of this policy the Controller’s will be Phillip & Tracy Barre or any person authorised to by the controller to process data in accordance with the policy as it applies on the date of this policy. The client is any person who shares information with the controller or his or her business in the way of carrying out business either in person or remotely across electronic media.
Types of data stored:
- Names
2.Addresses
- Age
- Financial details
- Dates of financial details
- Analytic data from website
- Images from either CCTV or promotional images
- Sensitive information
Why this data is Processed:
- Data is processed for contractual, accounting and legal reasons.
- Data is processed for Marketing and promotional reasons
How data is Handled, stored or processed:
- Contractual data
This data would include the names, addresses dates and amounts of money needed to confirm a contractual obligation to or by either the Business (Le-Gro Leisure) or the client.
Contractual data is stored securely by either encryption or secure portals requiring passwords or biometrics to access the data. Any Physical data is secured in locked room with no pubic access and for sensitive information secured within a further safe.
Contractual information is stored for as long as it is required by the contract or where government bodies or third party underwriters or insurance companies require the business to keep and store such information as part of the businesses obligations to do so as required by law to fulfil the obligations as imposed on the Business.
- Marketing data
Marketing data is stored by cookies on and by electronic processors and media software where it is required for analytics or for marketing purposes by the business. Marketing data is never sold to third parties but is shared where the business has an obligation to the third parties to fulfil its contractual obligations to such third parties.
All data is shared or transferred via either secure portals, encryption or secure recorded mail or parcel services.
For the purposes of data sharing email is not considered by the business as secure. Any information shared by the client or business over email is done so with regards to this policy on the understanding that the business can hold no responsibility for secure transmission via email.
Sensitive information
No information is stored on minors or vulnerable adults who cannot consent to the sharing or storing of information either by themselves or the person responsible for there welfare and legal rights. Where vulnerable individuals information is stored or processed it will by the express grant of the person who has authority to act for the vulnerable persons on their behalf.
Third parties responsibilities for data.
Where a person or client consents to share information with a third party it is then the responsibility of the third party to process and store the data in line with the above stated legislation and guidance.
Types of consent.
- Data that is processed for contractual, accounting and legal reasons.
The business will ask for and require that the client will consent to the business or any third party who in offering a paid for service, permission to process any data required.
- Data that is processed for Marketing and promotional reasons.
Clients can opt out of at the time of contract without affecting the contractual obligations of the contact between the business and the client.
- Sensitive information and vulnerable adults and children. Sensitive information is gathered where knowing that information would place an obligation or burden on the company in its duties in carrying out the contract. Where information of this type is needed to be processed for the purposes of carrying out the responsibilities of the business to fulfil its legal obligations in carrying out that business, failure to grant consent to the business or sharing this information will void the contract and any liability that the business may carry if the information would have affected or placed an obligation on the business had the business known such information at the time the business entered into such a contract. Sensitive information will not be shared with third parties who have not been given express grant to do so by the client and the Business. Sensitive information will be stored only long enough to enable the business to complete its obligations and duties and shall then be destroyed as soon as this period of obligation has expired.
CCTV images and images where a person can be identified.
- Le-Gro Barns has CCTV running and recording constantly 24 hour per day, All cameras are on the outside of the building facing away from the buildings. All images are stored on a separate hard drive that is a closed system stored in a secure room. The images are stored for 28 days then overwritten unless they are needed for contractual or legal purposes. CCTV are never shared with third party processors.
Images used in marketing or advertising that identify a person are either by consent of the person represented or from a source where the third party has sought and been granted consent prior to Le-Gro Barns processing them.
Right to information
The client has the right to access any information stored or processed by the business in line with chapter 3 of the Data protection act 2018 http://www.legislation.gov.uk/ukpga/2018/12/contents/enacted

