Hound Performance Studio Back

Hound Performance Studio

Privacy Policy

Effective date: 20 July 2026

This Privacy Policy explains what personal information Hound Performance Studio collects, how it is used, the lawful bases relied upon, who receives it, how long it is kept and your rights.

HOUND PERFORMANCE LTD, company number 17328701, registered in England and Wales and trading as Hound Performance Studio, is the data controller for the personal information described in this policy, except where a service provider acts as a separate controller.

The Company does not store full payment card details. Stripe processes payment information through its secure systems.

1. Scope

This policy applies to Members, applicants, trainers, coaches, therapists, clients, guests, visitors, contractors, website users and people who contact the Company.

It explains what personal information is collected, how it is used, the lawful bases relied upon, who receives it, how long it is retained and your rights.

2. Personal information we may process

Identity and contact information: name, email address, telephone number, organisation or professional role, age confirmation, emergency contact details where provided, and correspondence details.

Membership and transaction information: membership type, start and end dates, subscription status, billing frequency, payment status, refunds, failed payment status, Stripe customer or subscription identifiers and records of accepted terms. Stripe may collect payment card details, billing address and other checkout information. The Company may receive limited payment and subscription information but does not store full card numbers or card security codes.

Booking and attendance information: booking dates and times, attendance, cancellations, the identity or category of approved attendees and records used to manage capacity and access.

Access and security information: Yale access code assignments, entry timestamps, access events, failed entry attempts, security alerts and records concerning suspected code sharing or unauthorised entry.

CCTV information: images, video footage, timestamps and incident extracts recorded by Ring or any replacement security system. CCTV may record continuously. It is not used for routine audio recording or automated facial recognition.

Health, safety and incident information: confirmation that the Health Declaration was accepted, information voluntarily disclosed about a health limitation, accident and injury reports, near misses, first aid information, complaints, equipment faults, damage and insurance or legal claim records.

Technical and website information: internet protocol address, device and browser information, website security logs, cookie or local-storage identifiers, consent preferences and basic usage information where the website or service providers collect it.

Marketing information: marketing preferences, consent records, campaign engagement and suppression records used to respect an opt-out.

3. How we obtain information

Information may come directly from you, from Stripe, the Booking System, Yale, Ring, a trainer or approved organisation, website and email providers, witnesses, insurers, professional advisers or public authorities.

4. Purposes and lawful bases

The Company processes personal information to set up and administer Membership (performance of a contract), to process payments and manage subscriptions (performance of a contract and legal obligation), to manage bookings and provide access (performance of a contract and legitimate interests), to protect people, premises and equipment (legitimate interests and legal obligation where applicable), to investigate misuse, disputes, accidents or claims (legitimate interests, legal claims and legal obligation), to meet accounting, tax and company obligations (legal obligation and legitimate interests), to respond to enquiries and complaints (legitimate interests and performance of a contract), to send direct marketing (consent or legitimate interests, as permitted by law), and to maintain website and system security (legitimate interests and legal obligation where applicable).

Legitimate interests include protecting Members and visitors, securing the Studio, preventing fraud and unauthorised access, managing capacity, enforcing agreements, establishing legal claims and operating the business efficiently. The Company considers the impact on individual rights before relying on legitimate interests.

5. Health information and other special category data

The Company does not require detailed medical records as a condition of ordinary Membership. If you voluntarily provide health information, it may be special category data under UK data protection law.

The Company will normally process such information with your explicit consent. In limited circumstances it may also be processed to protect vital interests, meet employment or health and safety obligations, or establish, exercise or defend legal claims, where the law permits.

You may withdraw consent, but this does not affect processing that was lawful before withdrawal or information that must be retained for another lawful reason.

6. CCTV

CCTV is used for safety, security, access verification, prevention and detection of crime, incident review, fraud prevention and enforcement of the Policies.

The lawful basis is the Company's legitimate interests in protecting people, property and the integrity of the private access model. CCTV is not used in toilets or changing areas. Clear signage should be displayed at entrances and within the Studio.

CCTV may be compared with booking and Yale access timestamps to verify authorised entry. The Company does not use automated facial recognition.

CCTV access is restricted to authorised persons and relevant service providers. Footage may be shared with insurers, legal advisers, law enforcement, courts, regulators or affected individuals where lawful and necessary.

Footage is normally retained for no longer than 90 days and may be overwritten sooner. Specific footage may be preserved for longer where it relates to an incident, complaint, investigation, insurance matter, legal claim or legal obligation.

7. Yale access records and bookings

Access records and bookings are used to provide entry, manage capacity, identify technical faults, investigate unauthorised access and protect the Studio.

The Company may link a credential to a Member and compare the recorded entry time with the booking and CCTV record.

8. Service providers and disclosures

The Company may use or disclose personal information to the following categories of recipient:

The Company does not sell personal information.

Stripe and some other providers may act as separate data controllers for parts of their processing. Their own privacy notices apply to that processing.

9. International transfers

Some service providers may store or access information outside the United Kingdom. Where UK data protection law requires safeguards, the Company will rely on an adequacy regulation, approved contractual safeguards, the UK International Data Transfer Agreement, the UK Addendum to standard contractual clauses, or another lawful transfer mechanism.

10. Retention

The Company retains personal information only for as long as reasonably necessary for the purpose collected, legal obligations, safety, insurance and the establishment or defence of claims.

These periods are reviewed and may be shortened or extended where the purpose, law, system settings, an incident or a legal hold requires it.

11. Security

The Company uses proportionate technical and organisational measures, including restricted access, strong account controls, provider security features, access logging and secure deletion processes.

No system is completely secure. You must protect your access credentials and notify the Company promptly if you suspect a compromise.

12. Marketing and service communications

Service communications about payments, bookings, access, safety, incidents and policy changes are necessary to administer Membership and are not marketing.

Marketing is sent only where permitted by law. You may opt out at any time. The Company may retain a minimal suppression record to ensure the opt-out is respected.

13. Cookies and similar technology

The website and third-party services may use strictly necessary cookies or local storage for security, checkout, authentication and preferences. Non-essential analytics or marketing technologies should be used only with the consent required by law.

Further details should be provided in the website Cookie Notice and consent interface.

14. Your rights

Depending on the circumstances, you may have the right to:

Rights are not absolute. The Company may need to verify identity and may withhold or redact information where the law requires or permits, including to protect another person's rights.

15. CCTV access requests

You may request CCTV footage containing your personal information. Provide the date, approximate time, location and identifying information needed to locate the footage.

The Company may need to obscure other people, withhold material covered by an exemption, or refuse a manifestly unfounded or excessive request. Make requests promptly because footage may be overwritten within the retention period.

16. Children

A person under 18 may use the Studio only under supervision. The Company may process identity, consent, booking, access, CCTV and incident information concerning that person where necessary for safety and access administration.

A parent or legal guardian should contact the Company before providing detailed information about a child.

17. Automated decision-making

The Company does not make decisions with legal or similarly significant effects solely by automated means. Automated payment retries, security alerts and access events may support decisions that are reviewed by a person where appropriate.

18. Data breaches

The Company will assess suspected personal data breaches and will notify the Information Commissioner's Office and affected individuals where required by law.

19. Changes to this policy

This policy may be updated to reflect legal, operational, security or service changes. Material changes will be communicated where appropriate. The current version will be made available through the website or membership process.

20. Contact and complaints

Data controller: HOUND PERFORMANCE LTD, company number 17328701, trading as Hound Performance Studio.

Email: info@houndperformance.com

You may also complain to the Information Commissioner's Office. The Company encourages you to contact it first so the concern can be investigated.