Privacy Policy
Breezy Clubs OS Ltd (trading as Breezy Tech) · breezyclub.tech Effective date: 10 September 2026 · Version: 2.1
About This Policy
Breezy Clubs OS Ltd (trading as Breezy Tech) ("we", "us", "our") operates the camp management platform at breezyclub.tech (the "Platform"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights under UK data protection law.
We are registered in England and Wales (Company No. 17339734) with our registered office at 35 Grafton Way, London, W1T 5DB. We are registered with the Information Commissioner's Office under registration number ZC199357.
Data protection contact: privacy@breezyclub.tech
1. Who This Policy Applies To
| Who | Role | Primary Controller |
|---|---|---|
| Parents / guardians | Book camps for children, manage accounts | The Camp Operator (camp data); Breezy Clubs OS Ltd (trading as Breezy Tech) (platform account data) |
| Children | Attend camps; data entered by parents | The Camp Operator |
| Camp staff | Invited by operators; manage registers and attendance | The Camp Operator |
| Camp operators | Subscribe to the Platform to run their camps | Breezy Clubs OS Ltd (trading as Breezy Tech) |
| Website visitors | Browse breezyclub.tech | Breezy Clubs OS Ltd (trading as Breezy Tech) |
The multi-controller structure — read this first
The Platform is used by multiple independent camp operators. Each camp operator is an independent Data Controller for the personal data of their parents, children, and staff. Breezy Clubs OS Ltd (trading as Breezy Tech) acts as a Data Processor on behalf of each camp operator for that data, under a Data Processing Addendum.
Breezy Clubs OS Ltd (trading as Breezy Tech) is a Data Controller in its own right only for: operator account and subscription data, platform security and audit data, and our own marketing and business records.
For how a specific camp operator uses your data, refer to that operator's own privacy policy. The operator responsible for any camp is identified on its booking page.
2. What Personal Data We Collect
2.1 Parents and guardians
- Identity: first name, last name, date of birth (age verification)
- Contact: email address, mobile number, home address and postcode
- Emergency contacts: name, relationship, phone number
- Account: username, encrypted password, login timestamps, IP address
- Financial: payment method reference (card data is processed and stored by Stripe — it never touches our servers), booking history, credit balance, refund records
- Communications: records of emails and notifications sent, communication preferences
2.2 Children
- Identity: first name, last name, date of birth, gender
- Medical (special category): conditions, allergies, dietary requirements, medications, emergency medical instructions, relevant disabilities or SEN
- Attendance: bookings, daily attendance records, registration history
- Photograph: optional profile photo, uploaded by the parent, stored in private encrypted storage with no public URL
2.3 Camp staff
- Identity and contact: full name, date of birth, email, phone, home address
- Compliance: DBS certificate number and expiry, passport number, right-to-work status
- Emergency contact: name and phone number
- Medical: information voluntarily disclosed for safeguarding purposes
- Work records: availability, assignments, attendance
2.4 Camp operators
- Business: company name, registered address, company number, Ofsted/Childcare Register number where applicable
- Individuals: name and contact details of account holders and designated contacts
- Financial: Stripe Connect account ID, subscription billing records, platform fee records
- Compliance: legal document acceptance records (timestamp, IP address, user, document version)
2.5 Technical data (all users)
IP address, browser type and version, device type, operating system, pages visited, session data, and error logs — collected automatically for security, debugging, and performance.
3. Lawful Basis for Processing
| Processing activity | Lawful basis |
|---|---|
| Account creation and management | Contract |
| Processing bookings and payments | Contract |
| Children's medical data | Explicit consent (UK GDPR Art. 9(2)(a)); vital interests (Art. 9(2)(c)) in a genuine emergency |
| Staff DBS and compliance data | Legal obligation (Safeguarding Vulnerable Groups Act 2006); employment law basis under DPA 2018 Sch.1 Pt.1 |
| Transactional communications | Contract |
| Marketing communications | Consent (opt-in only; withdraw at any time) |
| Platform security, fraud prevention, audit logging | Legitimate interests |
| Retention of payment records | Legal obligation (HMRC — 7 years) |
| Platform improvement from our own aggregated usage logs | Legitimate interests (aggregated/pseudonymised) |
Where we rely on legitimate interests, we have conducted a balancing assessment weighing our interests against your rights and freedoms, with particular weight given to the fact that the Platform processes children's data. Details of these assessments are available on request.
4. Children's Data — Special Protections
Children's medical data is special category data under UK GDPR Article 9. We apply the following protections:
- Explicit, separate consent. Parents provide a specific, unticked, standalone consent to the processing of their child's medical information. It is never bundled with terms acceptance. Consent can be withdrawn at any time in account settings; withdrawal may affect the child's ability to attend camps where medical information is required for safe participation.
- Strict access control. Medical data is visible only to: the parent who entered it, the camp operator's authorised admins, and staff assigned to camps that child is booked onto. Access is technically enforced by row-level security.
- DBS gate. No staff member can access any child data until their DBS status has been verified in the Platform by the operator's admin.
- Access logging. Every access to a child's medical record is logged.
- Data minimisation. We collect only medical information relevant to safe participation.
- No profiling, no AI training, no advertising. Children's data is never used for automated profiling, model training, or marketing of any kind.
- Age Appropriate Design Code. The Platform is designed for use by adults (parents, staff, operators). Children do not hold accounts. We nonetheless apply the ICO's Children's Code standards to all processing of children's data, including default privacy settings and data minimisation.
- Photographs. Child profile photos are stored privately and encrypted, with no public URLs. Use of any child's photograph in camp marketing requires separate consent collected by the camp operator; Breezy Clubs OS Ltd (trading as Breezy Tech) never uses children's photographs for marketing.
- Emergencies. In a genuine medical emergency we may share a child's medical information with emergency services without prior consent, relying on the vital interests basis. This exception is applied narrowly.
5. Staff Compliance Data
- DBS certificate details are visible only to the relevant operator's admin users — never to parents or other staff.
- Passport and right-to-work data is encrypted and restricted to the relevant operator's admins and platform administrators.
- Staff medical disclosures are treated as special category data with equivalent controls to children's medical data.
6. How We Use Personal Data
Platform operation: account management; booking and payment processing via Stripe Connect; register generation and distribution to authorised staff; staff rota and availability management; credits, refunds, and payment records; transactional notifications.
Safety and compliance: making medical data available to authorised staff for booked camps; DBS verification gating; audit logging; legal document acceptance records.
Communication: booking confirmations and receipts; schedule change and credit expiry notifications; marketing only with opt-in consent.
Improvement and security: performance monitoring and error debugging; aggregated, anonymised usage figures from our own logs; fraud prevention and rate limiting. We do not use third-party analytics services.
We do not: sell personal data; share data with third parties for their marketing; use children's data for AI training or advertising; serve behavioural advertising.
7. Sub-Processors and Third Parties
| Provider | Purpose | Data location | Safeguard |
|---|---|---|---|
| Supabase | Database, authentication, file storage | UK/EU (London, eu-west-2) | DPA + SCCs |
| Stripe | Payment processing (Stripe Connect) | UK/EU | DPA; UK adequacy + SCCs |
| Vercel | Hosting and delivery | EU edge | DPA + SCCs |
| Resend | Transactional email | EU | DPA + SCCs |
| Sentry | Error monitoring (PII redaction configured) | EU data residency | DPA + SCCs |
| Upstash | Rate limiting / session cache | EU | DPA + SCCs |
We may disclose personal data to law enforcement or regulators where required by law, or where necessary in good faith to protect the rights, safety, or property of any person, including safeguarding referrals.
International transfers outside the UK/EU are protected by the UK International Data Transfer Agreement or Addendum, or Standard Contractual Clauses, as applicable.
8. Retention
| Data category | Retention | Reason |
|---|---|---|
| Parent account data | Active account + 2 years | Contract; legitimate interests |
| Children's data (incl. medical) | Last camp attended + 3 years | Safeguarding; liability |
| Payment records | 7 years | HMRC |
| Booking history | 6 years | Limitation Act 1980 |
| Staff compliance data | Last assignment + 1 year | Safeguarding; legal obligation |
| Audit logs | 3 years | Accountability; safeguarding |
| Marketing consent records | Withdrawal + 1 year | Proof of consent |
Data past its retention period is securely deleted from live systems, and from backups within 90 days.
9. Your Rights
You have the following rights over your data and your children's data (where you hold parental responsibility):
- Access — request a copy of your data (Subject Access Request); we respond within 30 days, free of charge
- Rectification — correct inaccurate data; most fields are self-service editable
- Erasure — delete your account via Account Settings (soft delete, 30-day recovery, then permanent deletion, subject to legal retention carve-outs)
- Restriction — restrict processing in defined circumstances
- Portability — receive your data in machine-readable format (JSON/CSV) via Account Settings
- Objection — object to legitimate-interests processing and to direct marketing (instant opt-out)
- Withdraw consent — at any time, without affecting prior processing
- Automated decisions — we do not make solely automated decisions with legal or similarly significant effects
To exercise any right: privacy@breezyclub.tech. We may need to verify your identity. If you are dissatisfied with our response, you may complain to the ICO: ico.org.uk/make-a-complaint · 0303 123 1113.
10. Security
Measures include: encryption in transit (TLS 1.2+) and at rest (AES-256); row-level security enforcing strict tenant isolation; role-based access control; MFA for admin accounts; private encrypted storage for all sensitive files; DBS-gated access to child data; audit logging of sensitive data access; rate limiting; automated secret scanning in CI/CD; continuous isolation testing; and error monitoring with PII redaction.
No system is perfectly secure. If a breach occurs that risks your rights and freedoms, we will notify the relevant controller within 48 hours and support notification to the ICO within 72 hours as required by UK GDPR Articles 33–34.
11. Cookies
See our Cookie Policy for full details. In summary: we currently set only strictly necessary cookies (no consent required); we use no analytics, functional, advertising, or tracking cookies. If that changes we will ask for consent first.
12. Changes to This Policy
We will update the effective date and notify registered users by email at least 14 days before material changes take effect. Material changes affecting children's special category data trigger fresh consent collection.
Breezy Clubs OS Ltd (trading as Breezy Tech) · Company No. 17339734 · 35 Grafton Way, London, W1T 5DB · ICO No. ZC199357 Version 2.1 · Effective 10 September 2026