Privacy and GDPR Policy

Last Updated: July 2026

  1. Introduction

Staincross Apiaries is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, share and protect your personal information when you book an experience, attend an event, visit our website, contact us, or otherwise interact with us.

We process personal information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable data protection legislation.

  1. Data Controller

Staincross Apiaries is the Data Controller responsible for the personal information collected and processed in connection with our activities.

If you have any questions regarding this Privacy Policy or your personal information, please contact us:
Email: richard@staincross-apiaries.co.uk

Address: Coniston Farm, 38 Coniston Avenue, Staincross, Barnsley, S75 5BB

  1. Personal Information We Collect

We may collect and process the following categories of personal information:

  • Name
  • Postal address
  • Email address
  • Telephone number
  • Date of birth (where required)
  • Emergency contact details
  • Booking and attendance records
  • Payment and transaction information
  • Medical information relevant to participation, including allergies, medications and medical conditions
  • Photographs and video recordings where consent has been provided
  • Correspondence and communications with us
  • Information submitted through website contact forms
  • Information required for invoicing, accounting and insurance purposes

When you visit our website, we may also collect:

  • IP address
  • Browser type and version
  • Device information
  • Website usage information
  • Cookie and analytics information
  1. Special Category Data

Some information we collect, including medical information, allergies and health-related information, may constitute Special Category Personal Data under UK GDPR.

We collect and process this information solely where necessary to protect participant health and safety and to ensure the safe delivery of our activities.

This information will only be accessed by authorised persons and may be shared with healthcare professionals, first responders, or emergency services where necessary to protect an individual’s vital interests.

The processing of health-related information is carried out where necessary for health and safety purposes, to protect the vital interests of participants, and for the establishment, exercise or defence of legal claims where appropriate.

  1. How We Collect Information

We may collect information directly from you when you:

  • Book an experience or event
  • Complete registration forms
  • Contact us by email, telephone or social media
  • Subscribe to communications
  • Complete website forms
  • Provide information during participation in an activity

We may also receive information from booking platforms used to manage reservations.

Where a booking is made, relevant details (such as name, email address and experience date) may be transferred automatically between our booking platform and our customer communication system, in order to send booking-related reminders and information.

  1. Why We Use Your Information

We use personal information to:

  • Process bookings and reservations
  • Deliver experiences, events and services
  • Protect participant health, safety and welfare
  • Contact participants regarding bookings
  • Contact emergency contacts where necessary
  • Respond to enquiries and requests
  • Issue certificates and post-course materials
  • Maintain operational records
  • Manage accounts and finances
  • Comply with legal and regulatory obligations
  • Defend or pursue legal claims
  • Improve our services and customer experience
  • Send marketing communications where appropriate consent has been provided
  1. Lawful Bases for Processing

We process personal information under one or more of the following lawful bases:

Contract
Where processing is necessary to fulfil a booking or provide a service.

Legal Obligation
Where processing is necessary to comply with legal, regulatory, health and safety, accounting, taxation or insurance obligations.

Legitimate Interests
Where processing is necessary for the legitimate interests of Staincross Apiaries, provided those interests are not overridden by your rights and freedoms.

Consent
Where you have provided consent, including for photography, video recordings, and marketing communications.

Vital Interests
Where processing is necessary to protect the life or health of a participant or another person.

  1. How We Store Your Information

We take appropriate technical and organisational measures to protect personal information from unauthorised access, disclosure, alteration, loss or destruction.

Personal information may be stored and processed using:

  • Google Workspace services, including Google Drive, Google Sheets and Gmail, for document storage, participant records and communications.
  • Google Photos for the secure storage and management of photographs and video recordings.
  • Brevo (formerly Sendinblue) for customer communications, newsletters, certificates, marketing communications and customer relationship management.
  • TicketSource and other booking systems used to manage bookings and attendance.
  • Accounting software and financial record systems.
  • Secure paper records where required for operational, legal, insurance, health and safety, or accounting purposes.

These providers may process information on our behalf and are required to maintain appropriate security measures and comply with applicable data protection requirements.

  1. Sharing Your Information

We do not sell, rent or trade personal information.

Information may be shared:

  • With healthcare professionals, emergency services or first responders where necessary.
  • With service providers acting on our behalf.
  • With insurers, legal advisers or professional advisers where necessary.
  • Where required by law, regulation, court order or regulatory authority.
  • Where necessary to establish, exercise or defend legal claims.

Only information relevant to the purpose concerned will be shared.

  1. International Transfers

Some of our service providers may store or process personal information outside the United Kingdom.

Where this occurs, we will ensure appropriate safeguards are in place as required by UK data protection legislation, including adequacy regulations, approved contractual clauses, or other lawful transfer mechanisms.

  1. Data Security and Personal Data Breaches

We take reasonable steps to protect personal information from accidental loss, unauthorised access, misuse, alteration or disclosure.

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will comply with our legal obligations, including notifying the Information Commissioner’s Office and affected individuals where required by law.

  1. How Long We Keep Information

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected.

Retention periods may vary depending on legal obligations, health and safety requirements, insurance requirements, safeguarding responsibilities, accounting requirements and potential legal claims.

Participant registration forms, emergency contact details, medical information, booking records, incident records and associated correspondence will normally be retained for up to seven years following the date of the event.

Where records relate to participants under the age of 18, information may be retained until the participant reaches the age of 21 and for up to three years thereafter where reasonably necessary to establish, exercise or defend legal claims.

Photographs and video recordings for which consent has been provided may be retained until consent is withdrawn, unless we are legally required to retain them or they form part of materials already published before consent was withdrawn.

When personal information is no longer required, it will be securely deleted, anonymised or destroyed.

  1. Photography and Video Recordings

Where consent has been provided, photographs and video recordings may be stored securely using Google Photos and may be used for promotional, educational and business purposes.

This may include use on websites, social media platforms, printed publications, newsletters, certificates, advertising materials and other marketing communications.

Providing consent is entirely voluntary and separate from participation in any activity.

Photographs and video recordings may be published on Staincross Apiaries’ website, social media channels, printed materials and other promotional media.

Consent may be withdrawn at any time by contacting us. We will cease future use of images where reasonably practicable, although images already published or distributed may continue to appear in existing materials.

14. Marketing Communications

    Where you have consented, we may send you information about our services, events, experiences, products and offers.

    You may withdraw consent or unsubscribe from marketing communications at any time by following the unsubscribe instructions in our emails or by contacting us directly.

    15. Cookies and Website Analytics

    Our website uses cookies and similar technologies, including Google Analytics, to understand how visitors use our website, monitor website performance, and improve user experience.

    Google Analytics collects information such as pages visited, time spent on the website, approximate geographic location, device type, browser type, and interactions with website content. This information is generally aggregated and does not directly identify individual users.

    Where required by law, consent will be obtained before non-essential cookies, including Google Analytics cookies, are placed on your device.

    You can manage your cookie preferences through our cookie consent banner or through your browser settings. Disabling certain cookies may affect website functionality.

    16. Your Rights

    Under UK data protection law, you have the right to:

    • Request access to your personal information.
    • Request correction of inaccurate or incomplete information.
    • Request deletion of personal information in certain circumstances.
    • Request restriction of processing.
    • Object to certain processing activities.
    • Request transfer of your data where applicable.
    • Withdraw consent where processing is based on consent.
    • Lodge a complaint with the Information Commissioner’s Office (ICO).

    Requests will normally be dealt with free of charge unless they are manifestly unfounded or excessive.

    17. Complaints

    If you are unhappy with how we have handled your personal information, please contact us first so that we have the opportunity to resolve your concerns.

    You also have the right to complain to the Information Commissioner’s Office:

    Information Commissioner’s Office
    Wycliffe House
    Water Lane
    Wilmslow
    Cheshire
    SK9 5AF

    Website: www.ico.org.uk

    18. Changes to This Policy

    We may update this Privacy Policy from time to time to reflect changes in legal requirements, technology, business practices or the services we use.

    The most recent version will always be available upon request and on our website.