[CONFIRM WITH VAY] This is a tailored draft, not legal advice. Please fill in every bracketed item and confirm the processor list matches what the site actually uses. The items needing your input are listed at the bottom. Last updated: to be set on publish.
This policy explains what personal data Custom Canine Training collects when you use our website, buy a course or membership, or book in-person training, why we collect it, who we share it with, and the rights you have. We are committed to handling your data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are (the data controller)
Custom Canine Training is the controller of your personal data. Run by Vay [surname], based in Stafford, England. Trading status: [sole trader or limited company, to confirm]. Contact for any privacy question or request: vay@customcanine.co.uk, or by post at [address].
2. The data we collect
- Account data: your name, email address, and a securely hashed password when you register. We never store your password in readable form.
- Purchase and billing data: what you bought, when, and the amount. Card payments are processed by Stripe. We do not see or store your full card number. We keep records of transactions for accounting and tax.
- Membership data: your membership level, status, and renewal dates.
- Booking data: when you book in-person training, your booking details are handled through our booking provider, Bookwhen (name, contact details, the session booked, and anything you tell us about your dog).
- Information you give us: messages you send through our contact form or by email, including anything you tell us about your dog’s health, behaviour or training needs.
- Usage and technical data: your internet protocol (IP) address, browser and device information, and how you use the site, collected through cookies and analytics (see section 6).
- Email engagement: whether our service emails were delivered and, where applicable, opened, via our email provider (Postmark).
We do not knowingly collect special-category data. Anything you choose to tell us about your dog is about the animal, not a person, so it is not your special-category data.
3. How and why we use your data, and our lawful basis
- To provide what you bought (give you course or membership access, run your account, deliver in-person sessions): basis is performance of a contract with you.
- To take payment and keep accounting records: contract and legal obligation (tax law).
- To manage bookings and contact you about them: contract.
- To answer your enquiries: legitimate interests (responding to people who contact us).
- To keep the site secure and working (login security, firewall, fraud prevention, fixing problems): legitimate interests (protecting our site and users).
- To understand and improve the site through analytics: consent for non-essential analytics cookies (see section 6).
- To send marketing (for example a newsletter or news of new courses): consent, which you can withdraw at any time.
Where we rely on legitimate interests, we have considered your rights and only do this where it is fair and you would reasonably expect it.
4. Who we share your data with
We do not sell your data. We share it only with service providers who help us run the business, and only as far as needed. Our main processors are:
- Stripe, payment processing.
- Bunny.net, hosting and delivering our training videos.
- Bookwhen, booking in-person sessions and events.
- Postmark, sending account and service emails.
- [Hosting provider], hosting the website and its database on our server.
- Analytics, website analytics, only with your consent. [CONFIRM WITH VAY: which analytics the new site uses, for example Google Analytics or Microsoft Clarity, or none.]
- Wordfence, website security.
We may also disclose data if the law requires it, or to protect our rights, property or safety.
5. International transfers
Some of our providers are based outside the UK, for example in the United States. Where your data is transferred outside the UK, we rely on the safeguards the law allows, such as UK adequacy regulations or the International Data Transfer Agreement or Standard Contractual Clauses, so your data stays protected.
6. Cookies and analytics
- Essential cookies keep the site working, for example keeping you logged in and securing your session. These do not need consent.
- Analytics and non-essential cookies help us understand how the site is used. We only set these with your consent, which you give through our cookie banner and can change or withdraw at any time.
7. How long we keep your data
- Account and membership data: for as long as you have an account, then deleted or anonymised within [retention period] of closure.
- Transaction and tax records: at least 6 years, as required by UK tax law.
- Booking data: [retention period] after the session.
- Enquiries: [retention period] after the matter is closed.
- Analytics: per the provider’s retention settings.
8. Your rights
Under UK data protection law you have the right to: be informed, access your data, have it corrected, have it erased, restrict or object to how we use it, data portability, and to withdraw consent at any time (without affecting earlier processing). You also have rights in relation to automated decision-making (we do not make decisions about you by automated means). To exercise any right, email vay@customcanine.co.uk. We will respond within one month.
9. Marketing
If you opt in, we may email you news, offers and new course information. Every marketing email has an unsubscribe link, and you can opt out at any time by clicking it or emailing us. Opting out of marketing does not stop essential account or transaction emails.
10. Children
Our services are intended for adults. We do not knowingly collect data from children under 16. If you believe a child has given us their data, contact us and we will delete it.
11. Security
We protect your data with appropriate measures, including encryption in transit (HTTPS), a hardened and firewalled website, secure password storage, two-factor authentication on admin accounts, and limiting who can access data. No system is completely secure, but we take reasonable steps to keep your data safe and will tell you and the regulator about a breach where the law requires.
12. Complaints
If you are unhappy with how we have handled your data, please contact us first so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK regulator, at ico.org.uk or by calling 0303 123 1113.
13. Changes to this policy
We may update this policy from time to time. The current version is always on this page, with the last updated date at the top. Significant changes will be made clear on the site.
14. Contact us
Custom Canine Training, email vay@customcanine.co.uk, phone 07810 836906, [address].
Vay needs to confirm before this goes live
- Trading status and the address to publish.
- Whether to register with the ICO (most businesses processing personal data must pay the data protection fee unless exempt, worth checking on ico.org.uk).
- The exact analytics in use on the new site (Google Analytics, Microsoft Clarity, or none) so sections 4 and 6 are accurate.
- The hosting provider name to list as a processor.
- Retention periods for account, booking and enquiry data.
- Whether a cookie banner or consent tool is installed on the new site (the policy assumes one; it needs to exist for the consent basis to hold).
