Privacy Policy
1. Introduction
2. What personal data we collect
3. How we collect your data
4. How we use your personal data
5. Our lawful bases for processing
6. Sharing your data
7. Transfers outside the UK
8. Data retention
9. Security of data
10. Cookies and analytics
11. Behavioural marketing
12. Your data protection rights
13. How to contact us
14. Updates to this policy
15. Definitions
1. Introduction
Brighton Forest School Ltd (“we”, “us”, “our”) is a private limited company running weekly outdoor Forest School sessions at Stanmer Park, Brighton — Tuesday sessions for home-educated children and Saturday sessions open to children aged 5–11.
We are committed to protecting and respecting the privacy of our website visitors, programme participants, parents, guardians, and partners. This Privacy Policy explains what personal data we collect, from whom, why we collect it, our legal bases, and how long we keep it.
2. What personal data we collect
We collect and process various types of personal data depending on your relationship with us:
• Child data: Full names, dates of birth, and which sessions your child attends.
• Parent and carer data: Full names, relationships to the child, and the outward part of your postcode (e.g. “BN1”), used to understand the general area our families travel from.
• Emergency contact data: Names and phone numbers of anyone nominated by a parent or carer as a backup or emergency contact.
• Contact details: Mobile numbers and email addresses.
• Special category data: Relevant medical histories, allergies, conditions, and necessary medications (including EpiPens or inhalers).
• Authorised collector data: Names of adults specifically authorised to collect children from our sessions.
• Enquirer and prospective participant data: Names and contact details of people who get in touch to ask about sessions or join our mailing list, whether or not they go on to book.
• Staff and volunteer data: Employment, qualification and DBS/background check details used for internal team management, training and safeguarding compliance. Staff and volunteers are also covered by a separate, more detailed internal privacy notice.
• Technical details: IP addresses and browsing behaviour collected when you visit our website. Most of this is optional and controlled through our cookie banner — see Section 10.
3. How we collect your data
We gather personal data directly at the point of enquiry or booking, and through standard digital interactions:
• Direct forms: Information submitted by parents/carers through our registration sheets, enquiry forms, or online booking software.
• Communications: Email correspondence, phone calls, or physical paperwork regarding cancellations, weather updates, and emergency contacts.
• Automated tools: Standard cookies and analytics utilities used when you browse our website.
4. How we use your personal data
Your data is used to deliver safe, effective outdoor learning environments:
• Session administration: Managing registrations, tracking attendance, and ensuring age-appropriate group placement.
• Health and safety: Accessing medical profiles during live sessions to protect children and fulfil our duty of care.
• Emergency communication: Reaching booking parents or designated backup contacts regarding unexpected cancellations or emergencies.
• Safeguarding: Verifying authorised adult names to ensure children are only released to approved individuals.
• Keeping in touch: Sending updates about upcoming sessions, availability, or news to people who have opted in to our mailing list.
5. Our lawful bases for processing
We process personal data under the following legal frameworks defined by UK GDPR:
• Legitimate interests: Required for managing day-to-day operations, including child names, parent relationships, contact details, general (outward) postcode data used to understand the area we serve, and alternative emergency contacts.
• Legal obligation / Duty of care: Necessary to maintain physical safety, handle vital medical data, and verify authorised pickup adults for safeguarding purposes.
• Consent: Relied on for optional activities such as non-essential website cookies and photography/media use — see Sections 8, 10 and 11.
6. Sharing your data
We do not sell or trade your personal data. We only share information with trusted parties under strict conditions:
• Service providers: Web hosts, booking systems, or communication platforms that support our operations.
• Emergency services: Medical personnel or local authorities in the event of an urgent health or safeguarding incident during a session.
• Regulatory bodies: Oversight organisations or inspectors when legally required.
7. Transfers outside the UK
If any of our service providers (for example, cloud storage, email marketing, or booking platforms) store data outside the UK, we only allow this where one of the following applies:
• The destination country has a UK “adequacy” decision, meaning the UK government has confirmed it offers a comparable standard of data protection; or
• The provider is a US organisation certified under the UK-US Data Bridge (the UK's extension of the EU-US Data Privacy Framework); or
• We (or the provider, on our behalf) have put in place a UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU's Standard Contractual Clauses.
We keep a simple internal record of which providers process data outside the UK and which of the above safeguards applies to each.
8. Data retention
We only retain personal information for as long as necessary to fulfil the purposes we collected it for, including satisfying any statutory legal, accounting, or safe youth programme reporting requirements. We keep different types of personal information for different lengths of time, depending on the reason it was collected and any legal or safeguarding requirements.
• Booking and payment records are kept for 6 years, in line with HMRC requirements.
• Child medical, emergency contact and consent records are kept until the child turns 25. This is a standard retention period used across children's services, reflecting how long a claim could still be brought and the possibility of a much later safeguarding disclosure.
• Accident and incident records relating to children are kept until the child turns 21. For adults, these records are kept for a minimum of 3 years.
• Safeguarding records are kept until the child turns 25. Where a record relates to a looked-after child, or to child sexual abuse, records may be kept until the child turns 75.
• Staff records are kept for 6 years after the staff member's engagement with us ends. DBS certificate information is handled differently: in line with the DBS Code of Practice, we do not keep full certificate content beyond around 6 months after a recruitment decision, though a basic record (date, reference number, outcome) may be kept for longer for audit purposes.
• Photography and media consent is kept until you withdraw it or your child leaves the programme, whichever is sooner.
• Marketing email list information (your name, email address, and how and when you signed up) is kept until you unsubscribe.
• Website analytics data is retained no longer than 14 months, in line with our Google Analytics settings.
9. Security of data
We have put appropriate safety measures in place to prevent personal data from being lost, altered, or accessed in an unauthorised way. Access to sensitive participant data — especially children's medical profiles and staff DBS/background check information — is strictly restricted to our designated data lead and active session staff.
10. Cookies and analytics
Our website uses cookies and similar technologies. Some are strictly necessary for the site to work (for example, remembering items in a booking basket) and don't require your consent. Others are optional:
• Analytics cookies: help us understand how visitors use our site. Analytics cookies: help us understand how visitors use our site, including which pages they visit and, where available, which channel referred them (for example a search engine or a shared link). These are optional and only run once you've given consent through our cookie banner. If we ever use analytics in a way that identifies or tracks individuals, rather than aggregate statistics, we ask for consent in the usual way.
• All other optional cookies, including anything related to advertising (see Section 11), only run if you actively consent through our cookie banner.
You can manage your cookie preferences at any time using the banner on our website, or through your browser settings. For more detail on the specific cookies we use, see our separate Cookie Policy.
11. Behavioural marketing
If we run social media or search advertising (for example, to reach local families through Instagram or Facebook), we may use tracking pixels that record how visitors from those ads interact with our website, so we can measure and improve our campaigns. Unlike the basic analytics described in Section 10, this always requires your active, opt-in consent through our cookie banner before it runs. You can withdraw this consent at any time via the banner or your ad platform's own preference settings.
12. Your data protection rights
Under UK data protection law, parents, guardians, and individuals hold the following rights:
• Right of access: Request a copy of the personal data we hold about you or your child.
• Right to rectification: Ask us to correct any inaccurate, outdated, or incomplete information.
• Right to erasure: Request the deletion of your data where we have no continuing legal or safeguarding obligation to keep it.
• Right to object/restrict: Object to processing we carry out under legitimate interests, or ask us to restrict how we use your data.
• Right to withdraw consent: Where we rely on your consent (for example, cookies or photo use), withdraw it at any time.
We aim to respond to any request within one calendar month; this can be extended by up to two further months for complex requests, and we will let you know if that applies. To exercise any of these rights, contact us using the details in Section 13.
13. How to contact us
If you have any questions about this privacy policy, wish to exercise your rights, or need to update your file, contact our designated data lead:
Data Lead: Harry Neale-Smith, Brighton Forest School Ltd
Email: hello@brightonforestschool.co.uk
If you have a complaint about how we've handled your personal data, please contact us first using the details above — we aim to acknowledge complaints within 30 days. If you remain unsatisfied, you also have the right to lodge a complaint directly with the Information Commissioner's Office (ICO).
14. Updates to this policy
We review and update this privacy policy periodically to reflect operational changes at Stanmer Park, staffing adjustments, or evolving UK safeguarding and data laws. The latest revision date is shown at the top of this policy and on our website.
15. Definitions
• Personal Data: Any information relating to an identified or identifiable living individual.
• Special Category Data: Sensitive personal information, including details regarding health, medical conditions, and allergies.
• UK GDPR: The United Kingdom General Data Protection Regulation.
• International Data Transfer Agreement (IDTA): A standard contract, approved by the ICO, that provides legal safeguards when personal data is transferred outside the UK to a country without its own adequacy decision.