(Updated February 2025 to ensure UK GDPR and Data Protection Law Compliance)
1. Introduction
This Privacy Policy explains how Theatretrain collects, uses, and protects personal data under UK GDPR and the Data Protection Act 2018.
2. Data Protection Responsibility
Theatretrain Head Office follows UK data protection laws and guides Company Directors, but each Company Director is independently responsible for compliance.
3. Data Collection
We collect only necessary personal data provided voluntarily through website forms or registration processes, including names, contact details, dates of birth, and health information.
4. Lawful Basis for Processing
We process personal data under these lawful bases:
- Legitimate interests: Service delivery and customer support.
- Contractual necessity: Fulfilling agreements with students, parents, staff, and franchisees.
- Consent: Marketing and promotional media usage (with opt-in).
- Legal obligation: Compliance with UK laws (e.g., safeguarding and licensing).
5. Data Use
We use data solely for:
- Providing services and customer support.
- Ensuring health, safety, and compliance with legal obligations.
- Marketing communications with consent.
6. Data Security
We apply appropriate security measures for personal data protection. However, no online system is completely secure from unauthorised access.
7. Data Retention
We retain data as follows:
- Financial and Payment Records: 6 years (HMRC compliance).
- Safeguarding and Incident Reports: 25 years from student’s birth.
- Attendance and General Student Files: 3 years post-membership.
- Special Category Data (e.g., medical): 3 years post-membership (25 years if related to safeguarding).
- Marketing Data: Until consent is withdrawn.
- Teachers and Staff Records: Retained for 6 years post-employment.
- Franchisee Records: Retained for 6 years post-termination.
Secure digital deletion and shredding are used for disposal.
8. Sharing of Personal Data
We only share data when necessary:
- Local Authorities: Child performance licensing.
- Exam Bodies: For exam participation.
- New Franchise Owners: For continuity of service.
- Medical Professionals: In emergencies.
- Authorities: As required by law.
9. Your Rights (Under UK GDPR)
You have the right to:
- Access, correct, or delete your data (subject to legal obligations).
- Withdraw consent for marketing.
- Object to processing or request data portability. Submit requests to your local Theatre Company Director. Responses are provided within one calendar month.
10. Consent for Photos and Videos
We only use your child’s images with active opt-in consent, which can be withdrawn at any time.
11. Policy Changes
We may update this Privacy Policy and will post changes on our website with reasonable notification.
12. Complaints
To address data concerns, contact Theatretrain Head Office at admin@theatretrain.co.uk or the Information Commissioner’s Office (ICO) at www.ico.org.uk.
Effective from: February 2025.
Theatretrain Head Office