GDPR POLICY

Data Protection Policy
Managing, Storing, and Deleting Personal Information (UK GDPR Compliant)

1. Introduction
This policy outlines how Estuary View Pools manages, stores, and deletes personal information in compliance with the UK General Data Protection Regulation (UK GDPR). We are committed to protecting individuals' privacy and ensuring that personal data is processed lawfully, fairly, and transparently.

2. Scope
This policy applies to all personal data collected, stored, and processed electronically by Estuary View Pools. It covers all employees, contractors, and third-party service providers who handle personal information on our behalf.

3. Lawful Basis for Processing
We process personal data under the following lawful bases:

  • Consent: The individual has given explicit consent for specific purposes.
  • Contractual Obligation: Processing is necessary for the performance of a contract.
  • Legal Obligation: Processing is required to comply with legal duties.
  • Legitimate Interests: Processing is necessary for legitimate business interests, provided it does not override individuals’ rights.

4. Data Collection and Storage

  • Personal data will be collected only for specified, explicit, and legitimate purposes.
  • Data will be stored securely using encryption, access controls, and other protective measures.
  • Access to personal data is limited to authorized personnel only.
  • Personal data shall not be retained longer than necessary for the stated purpose.

5. Data Retention and Deletion

  • Personal data will be retained in accordance with our Data Retention Schedule.
  • Once data is no longer needed, it will be securely deleted using appropriate methods, such as:
    • Secure deletion software for electronic data.
    • Permanent anonymization where applicable.
    • Secure disposal of backup data in compliance with retention policies.
  • Individuals have the right to request the deletion of their personal data, subject to legal and contractual obligations.

6. Data Security Measures

  • We employ encryption, firewalls, and secure access protocols to protect data.
  • Regular security audits and vulnerability assessments are conducted.
  • Staff receive regular training on data protection and security best practices.

7. Data Subject Rights
Individuals have the following rights regarding their personal data:

  • Right to access: Request a copy of their personal data.
  • Right to rectification: Request correction of inaccurate data.
  • Right to erasure: Request deletion of their data where applicable.
  • Right to restrict processing: Limit the use of their data.
  • Right to data portability: Request data in a structured format.
  • Right to object: Object to processing based on legitimate interests.

8. Data Breach Management

  • Any suspected or confirmed data breach must be reported immediately to the Data Protection Officer (DPO).
  • We will assess the impact and notify the Information Commissioner’s Office (ICO) within 72 hours if required.
  • Affected individuals will be informed if there is a high risk to their rights and freedoms.

9. Compliance and Review

  • This policy is reviewed annually or as required by changes in legislation.
  • Compliance with this policy is monitored through audits and assessments.
  • Non-compliance may result in disciplinary action and legal consequences.

 

 

CCTV Policy

1. Introduction
Estuary View Pool ("we", "us", "our") operates a Closed-Circuit Television (CCTV) system to monitor our swimming pool premises for security, health, and safety purposes. This policy outlines how we collect, use, store, and protect CCTV footage in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Purpose of CCTV Monitoring
The CCTV system is used for the following purposes:

  • Ensuring the safety and security of individuals using the swimming pool.
  • Preventing and detecting crime, vandalism, or unauthorised access.
  • Assisting in the investigation of incidents relating to health and safety.

3. Lawful Basis for Processing
Our use of CCTV is based on the lawful basis of legitimate interests, as outlined in Article 6(1)(f) of the UK GDPR. The operation of CCTV is necessary to maintain a safe and secure environment and prevent criminal activity.

4. Location of CCTV Cameras
CCTV cameras are positioned to monitor key areas of the swimming pool premises, including entrances, exits, and poolside areas. Cameras are not installed in private areas such as changing rooms or toilets.

5. Data Retention and Storage

  • CCTV footage is securely stored and retained for a maximum of 30 days.
  • After 30 days, footage is permanently deleted unless required for an ongoing investigation or legal proceedings.
  • Access to CCTV footage is restricted to authorised personnel only.

6. Access and Disclosure of CCTV Footage

  • CCTV footage may be accessed by designated staff responsible for security and safety.
  • Footage may be shared with law enforcement authorities or regulatory bodies if required by law.
  • Individuals captured in CCTV footage have the right to request access to their personal data under the UK GDPR, subject to applicable exemptions.

7. Signage and Transparency

  • Clear signage is displayed on the premises to inform individuals that CCTV monitoring is in operation.
  • This policy is publicly available to ensure transparency in our data processing practices.

8. Data Subject Rights
Individuals have the following rights under the UK GDPR:

  • The right to access their personal data (Subject Access Request).
  • The right to request rectification or erasure of their data.
  • The right to restrict processing in certain circumstances.
  • The right to object to processing based on legitimate interests.

Requests to exercise these rights should be directed to our Data Protection Officer.

9. Security Measures
We implement technical and organisational measures to protect CCTV footage from unauthorised access, alteration, or disclosure. This includes encryption, access controls, and secure storage.

10. Policy Review and Updates
This policy is reviewed periodically to ensure continued compliance with applicable laws and regulations. Any updates will be communicated accordingly.

11. Contact Information
For further information regarding this policy or to exercise data protection rights, please contact the Data Protection Officer:

Estuary View Pools
Portishead
estuaryviewpool@gmail.com

Effective Date: February 2025
Review Date: February 2026

 

Estuary View Pool is a trading name of Red Cameleon Limited