Hound Performance Studio
Privacy Policy
Effective date: 20 July 2026
This Privacy Policy explains what personal information Hound Performance Studio collects, how it is used, the lawful bases relied upon, who receives it, how long it is kept and your rights.
HOUND PERFORMANCE LTD, company number 17328701, registered in England and Wales and trading as Hound Performance Studio, is the data controller for the personal information described in this policy, except where a service provider acts as a separate controller.
The Company does not store full payment card details. Stripe processes payment information through its secure systems.
1. Scope
This policy applies to Members, applicants, trainers, coaches, therapists, clients, guests, visitors, contractors, website users and people who contact the Company.
It explains what personal information is collected, how it is used, the lawful bases relied upon, who receives it, how long it is retained and your rights.
2. Personal information we may process
Identity and contact information: name, email address, telephone number, organisation or professional role, age confirmation, emergency contact details where provided, and correspondence details.
Membership and transaction information: membership type, start and end dates, subscription status, billing frequency, payment status, refunds, failed payment status, Stripe customer or subscription identifiers and records of accepted terms. Stripe may collect payment card details, billing address and other checkout information. The Company may receive limited payment and subscription information but does not store full card numbers or card security codes.
Booking and attendance information: booking dates and times, attendance, cancellations, the identity or category of approved attendees and records used to manage capacity and access.
Access and security information: Yale access code assignments, entry timestamps, access events, failed entry attempts, security alerts and records concerning suspected code sharing or unauthorised entry.
CCTV information: images, video footage, timestamps and incident extracts recorded by Ring or any replacement security system. CCTV may record continuously. It is not used for routine audio recording or automated facial recognition.
Health, safety and incident information: confirmation that the Health Declaration was accepted, information voluntarily disclosed about a health limitation, accident and injury reports, near misses, first aid information, complaints, equipment faults, damage and insurance or legal claim records.
Technical and website information: internet protocol address, device and browser information, website security logs, cookie or local-storage identifiers, consent preferences and basic usage information where the website or service providers collect it.
Marketing information: marketing preferences, consent records, campaign engagement and suppression records used to respect an opt-out.
3. How we obtain information
Information may come directly from you, from Stripe, the Booking System, Yale, Ring, a trainer or approved organisation, website and email providers, witnesses, insurers, professional advisers or public authorities.
4. Purposes and lawful bases
The Company processes personal information to set up and administer Membership (performance of a contract), to process payments and manage subscriptions (performance of a contract and legal obligation), to manage bookings and provide access (performance of a contract and legitimate interests), to protect people, premises and equipment (legitimate interests and legal obligation where applicable), to investigate misuse, disputes, accidents or claims (legitimate interests, legal claims and legal obligation), to meet accounting, tax and company obligations (legal obligation and legitimate interests), to respond to enquiries and complaints (legitimate interests and performance of a contract), to send direct marketing (consent or legitimate interests, as permitted by law), and to maintain website and system security (legitimate interests and legal obligation where applicable).
Legitimate interests include protecting Members and visitors, securing the Studio, preventing fraud and unauthorised access, managing capacity, enforcing agreements, establishing legal claims and operating the business efficiently. The Company considers the impact on individual rights before relying on legitimate interests.
5. Health information and other special category data
The Company does not require detailed medical records as a condition of ordinary Membership. If you voluntarily provide health information, it may be special category data under UK data protection law.
The Company will normally process such information with your explicit consent. In limited circumstances it may also be processed to protect vital interests, meet employment or health and safety obligations, or establish, exercise or defend legal claims, where the law permits.
You may withdraw consent, but this does not affect processing that was lawful before withdrawal or information that must be retained for another lawful reason.
6. CCTV
CCTV is used for safety, security, access verification, prevention and detection of crime, incident review, fraud prevention and enforcement of the Policies.
The lawful basis is the Company's legitimate interests in protecting people, property and the integrity of the private access model. CCTV is not used in toilets or changing areas. Clear signage should be displayed at entrances and within the Studio.
CCTV may be compared with booking and Yale access timestamps to verify authorised entry. The Company does not use automated facial recognition.
CCTV access is restricted to authorised persons and relevant service providers. Footage may be shared with insurers, legal advisers, law enforcement, courts, regulators or affected individuals where lawful and necessary.
Footage is normally retained for no longer than 90 days and may be overwritten sooner. Specific footage may be preserved for longer where it relates to an incident, complaint, investigation, insurance matter, legal claim or legal obligation.
7. Yale access records and bookings
Access records and bookings are used to provide entry, manage capacity, identify technical faults, investigate unauthorised access and protect the Studio.
The Company may link a credential to a Member and compare the recorded entry time with the booking and CCTV record.
8. Service providers and disclosures
The Company may use or disclose personal information to the following categories of recipient:
- Stripe for checkout, billing, subscriptions, payment recovery and refunds.
- Yale or another access-control provider.
- Ring or another CCTV and security provider.
- Booking, membership, website, hosting, analytics, email and communications providers.
- Accountants, insurers, banks, solicitors, consultants and other professional advisers.
- Landlords, maintenance providers, emergency services and contractors where access or incident information is necessary.
- Courts, regulators, law enforcement and public authorities where disclosure is required or lawful.
- A buyer, investor or successor in connection with a genuine sale, restructure or transfer of the business, subject to appropriate confidentiality and data protection safeguards.
The Company does not sell personal information.
Stripe and some other providers may act as separate data controllers for parts of their processing. Their own privacy notices apply to that processing.
9. International transfers
Some service providers may store or access information outside the United Kingdom. Where UK data protection law requires safeguards, the Company will rely on an adequacy regulation, approved contractual safeguards, the UK International Data Transfer Agreement, the UK Addendum to standard contractual clauses, or another lawful transfer mechanism.
10. Retention
The Company retains personal information only for as long as reasonably necessary for the purpose collected, legal obligations, safety, insurance and the establishment or defence of claims.
- Membership contracts, policy acceptance and core transaction records: normally six years after the Membership ends, subject to tax, accounting and legal requirements.
- Stripe payment data: retained by Stripe under its own policies. The Company retains only the limited transaction records it needs.
- Booking and access records: normally for the active Membership and up to 24 months afterwards, unless an incident or legal reason requires longer retention.
- CCTV footage: normally no longer than 90 days, often overwritten sooner. Relevant extracts may be preserved for an incident or claim.
- Accident, complaint, damage and insurance records: for the applicable legal, insurance and limitation period. Records involving a child may need to be retained longer.
- General enquiries: normally up to 24 months after the enquiry closes, unless it forms part of another record.
- Marketing preferences: until consent is withdrawn or an objection is made. Minimal suppression details may be retained to prevent further marketing.
- Health information: for the shortest period necessary for safety, consent, incident management or legal claims.
These periods are reviewed and may be shortened or extended where the purpose, law, system settings, an incident or a legal hold requires it.
11. Security
The Company uses proportionate technical and organisational measures, including restricted access, strong account controls, provider security features, access logging and secure deletion processes.
No system is completely secure. You must protect your access credentials and notify the Company promptly if you suspect a compromise.
12. Marketing and service communications
Service communications about payments, bookings, access, safety, incidents and policy changes are necessary to administer Membership and are not marketing.
Marketing is sent only where permitted by law. You may opt out at any time. The Company may retain a minimal suppression record to ensure the opt-out is respected.
13. Cookies and similar technology
The website and third-party services may use strictly necessary cookies or local storage for security, checkout, authentication and preferences. Non-essential analytics or marketing technologies should be used only with the consent required by law.
Further details should be provided in the website Cookie Notice and consent interface.
14. Your rights
Depending on the circumstances, you may have the right to:
- Request access to your personal information.
- Request correction of inaccurate or incomplete information.
- Request deletion where there is no lawful reason to retain the information.
- Request restriction of processing.
- Object to processing based on legitimate interests or to direct marketing.
- Request transfer of information you provided where the right to data portability applies.
- Withdraw consent where processing relies on consent.
- Complain to the Information Commissioner's Office.
Rights are not absolute. The Company may need to verify identity and may withhold or redact information where the law requires or permits, including to protect another person's rights.
15. CCTV access requests
You may request CCTV footage containing your personal information. Provide the date, approximate time, location and identifying information needed to locate the footage.
The Company may need to obscure other people, withhold material covered by an exemption, or refuse a manifestly unfounded or excessive request. Make requests promptly because footage may be overwritten within the retention period.
16. Children
A person under 18 may use the Studio only under supervision. The Company may process identity, consent, booking, access, CCTV and incident information concerning that person where necessary for safety and access administration.
A parent or legal guardian should contact the Company before providing detailed information about a child.
17. Automated decision-making
The Company does not make decisions with legal or similarly significant effects solely by automated means. Automated payment retries, security alerts and access events may support decisions that are reviewed by a person where appropriate.
18. Data breaches
The Company will assess suspected personal data breaches and will notify the Information Commissioner's Office and affected individuals where required by law.
19. Changes to this policy
This policy may be updated to reflect legal, operational, security or service changes. Material changes will be communicated where appropriate. The current version will be made available through the website or membership process.
20. Contact and complaints
Data controller: HOUND PERFORMANCE LTD, company number 17328701, trading as Hound Performance Studio.
Email: info@houndperformance.com
You may also complain to the Information Commissioner's Office. The Company encourages you to contact it first so the concern can be investigated.
