Privacy Policy:

Rickmansworth Aikido Club

1. Introduction

This Privacy Policy explains how Rickmansworth Aikido Club ("the Club," "we," "us") collects, uses, stores, and protects your personal data (including Special Category Data such as health information).

We are committed to respecting your privacy and protecting your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Who We Are (The Data Controller)

The Club acts as the Data Controller for the personal data processed under this policy. This means we determine the purposes and means of processing your data.

Club Name: Rickmansworth Aikido Club

Address: 27 Arnett Way, Rickmansworth, Herts, WD3 4DA

Contact for Privacy Matters: Mike Abel - mike.abel.ma@googlemail.com 

3. The Data We Collect
3.1. Standard Personal Data

We collect and process the following types of personal data:
Contact Information: Name, address, phone number, and email address.
Membership Details: Date of joining, membership status, grade/belt level, and attendance records.
Financial Data: Records of membership and training fee payments (we do not store full bank details or credit card information).

3.2. Special Category Data (Health Data)

Medical Information: Details of injuries, pre-existing medical conditions, allergies, or anything that could affect your ability to train safely.

Purpose: This data is essential for fulfilling our duty of care and ensuring your safety and the safety of other members during physical training. 

3.3. Junior Member Data (Under 18s)

We collect the standard data of the junior member, along with the contact information and legal declaration of the parent or legal guardian. 

4. How We Use Your Data and the Legal Basis

We will only use your personal data when the law allows us to (the lawful basis).
Purpose of Processing
Type of Data Used
Lawful Basis for Processing (UK GDPR)
Membership Administration
Contact, Membership Details, Financial
Contract (To fulfil the agreement to provide club services)
Ensuring Safety and Welfare
Medical Information 
Legal Obligation (Duty of care) and Substantial Public Interest (Preventative/Occupational Medicine)
Communication
Contact Information
Legitimate Interests (Communicating training changes, fee updates, and club activities)
Insurance and Affiliation
Name, Membership Details
Legal Obligation (To register you with the governing body for mandatory insurance)
Marketing 
Email Address
Consent (For non-essential news, which you can withdraw at any time)

5. How and Where We Store Your Data
5.1. Security

We take reasonable steps to ensure your data is secure and protected against accidental loss, unauthorised access, or unlawful processing.

Digital records are stored on password-protected devices or secure cloud services.

Hard copy records (like waiver forms) are stored securely in a locked location accessible only by the Club's committee members. 

5.2. Data Sharing

We may need to share your personal data with the following third parties:

Governing Body/National Association: Your name and grading information may be shared with the official UK Aikido governing body (e.g., the British Aikido Federation) for affiliation, grading records, and mandatory insurance purposes.

Instructors: Relevant medical and safety information is shared with instructors on a "need-to-know" basis to manage risks during training.

Emergency Services: In the event of an emergency, we may share necessary contact and medical information with paramedics or emergency contacts.

We will never sell your personal data to any third party for marketing or commercial purposes.

5.3. Data Retention

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for satisfying any legal, accounting, or reporting requirements.

Membership Data: We retain basic membership records (name, dates) for seven years after you cease to be a member to comply with tax and audit requirements.

Accident/Medical Data: Records related to accidents or injuries are kept for three years after the event, or, for junior members, three years after they turn 18, as required by insurance liability and health and safety legislation.

6. Your Rights Under UK GDPR

Under the UK GDPR, you have the following rights regarding your personal data:

Right to be Informed: You have the right to be informed about how we use your data (this policy).

Right of Access: You have the right to request a copy of the personal data we hold about you (Subject Access Request).

Right to Rectification: You have the right to have any incomplete or inaccurate data we hold about you corrected.

Right to Erasure ('Right to be Forgotten'): You have the right to ask us to delete your personal data where there is no good reason for us to continue processing it.

Right to Restrict Processing: You have the right to request the suspension of the processing of your personal data.

Right to Data Portability: You can request that we transfer your personal data to another party in a structured, commonly used, machine-readable format.

Right to Object: You can object to the processing of your personal data based on legitimate interests or direct marketing.

To exercise any of these rights, please contact the Club's Privacy Contact using the details provided in Section 2.

7. Cookie Policy

This section explains how we use cookies and similar tracking technologies on our website. For a complete and detailed breakdown of the cookies we use, their purpose, and how to manage them, please refer to our dedicated Cookie Policy linked below. What are Cookies? Cookies are small data files that are placed on your computer or mobile device when you visit a website. They allow the website owner to recognize your device and store certain information about your preferences or past actions. How We Use Cookies We use cookies for several reasons, including: Strictly Necessary: To enable core website functionality (e.g., security, network management, and accessibility). Performance and Analytics: To collect information on how visitors use our site, allowing us to measure and improve performance. Functionality: To remember your settings and choices (e.g., language preference) for a more personalized experience. Targeting and Advertising: To track your browsing habits and deliver relevant advertisements. Third-Party Cookies In addition to our own cookies (first-party), we also use third-party cookies from services like Google Analytics and embedded content providers (e.g., YouTube videos) for advertising and analytical purposes. Your Choices You have the right to decide whether to accept or reject cookies. You can exercise your preferences through our Cookie Consent Banner upon visiting the site, or by adjusting the settings in your web browser. Please note that if you choose to reject strictly necessary cookies, the website may not function correctly.

8. Changes to this Policy

We reserve the right to update this privacy policy at any time. The most current version will always be available on the Club’s website. We will notify members directly of any significant changes.

9. Complaints

If you have any concerns about our use of your personal data, you can make a complaint to the Club’s Data Contact in the first instance.

You also have the right to lodge a complaint directly with the supervisory authority for data protection in the UK:

Information Commissioner's Office (ICO):

Website: https://ico.org.uk/concerns/

Helpline: 0303 123 1113