Last reviewed: March — Policies are reviewed annually or sooner where operational or legislative changes require.
1 Data Controller

The data controller for this website is:

THE TRAINING AND CONFERENCE CENTRE FOR THE MEMBERS OF THE BOYS' BRIGADE IN THE NORTH WEST OF ENGLAND AND THE ISLE OF MAN TRUST
Registered Charity Number: 1097985
Registered Address: Carr Lane, Treales, PR4 3SS
Telephone: 01772 685000
Email: [email protected]

For data protection enquiries, please contact us using the details above or via the website contact page.

2 Information We Collect
  • Name and contact details (email address and telephone number)
  • Information submitted through contact or booking enquiry forms
  • Email correspondence relating to enquiries or bookings
  • Administrative records necessary for operational and legal purposes

We only collect information necessary to respond to enquiries and manage bookings.

If you create or use a booking, customer, administrator or visitor account, we also process account details, role/access records, authentication and security events, audit logs, booking documents, messages, feedback, payment administration records and system-support records needed to run the service.

Where a Centre incident, safeguarding concern, accident report or health and safety record contains personal data, it is handled as an operational record and access is limited to people with a genuine need to know.

3 How We Use Your Information
  • To respond to enquiries
  • To manage bookings and related administration
  • To maintain appropriate operational and financial records
  • To comply with legal obligations
  • To protect accounts, detect abuse, investigate security incidents and keep audit records
  • To maintain recoverable backups and business-continuity records
  • To support safe use of electronic booking, document, reporting and communications systems
4 Legal Basis for Processing
  • Contractual necessity – to manage bookings and deliver services
  • Legitimate interests – to respond to enquiries and administer Centre operations
  • Legal obligation – where record keeping is required
  • Vital interests – where information is needed in an emergency to protect someone's safety
  • Consent – where optional analytics or optional communications need consent
5 Special Category Data (Dietary & Health Information)

Where necessary for residential stays, we may collect limited dietary or allergy-related information (for example food allergies or specific dietary requirements).

This information is processed solely to ensure participant safety and to comply with food hygiene and environmental health requirements.

The legal basis for processing this information is:

  • Article 6(1)(c) – Legal obligation (compliance with food safety and environmental health requirements), and
  • Article 9(2)(i) – Reasons of public interest in the area of public health.

Dietary and allergy information is handled confidentially and retained only as long as required to meet legal and environmental health obligations.

6 Sharing Information

We do not sell personal data.

Information may be shared with trusted service providers who support booking administration or website hosting, payment administration, email delivery, security controls, backup/recovery and approved support. Information may also be shared where required by law, with emergency services, insurers, regulators or professional advisers where this is necessary and proportionate.

7 Retention

Enquiry information is retained only as long as necessary to manage correspondence.

Booking and financial records may be retained for up to 6 years where required for legal or accounting purposes.

Dietary and allergy information may be retained where required for environmental health, food safety compliance or audit purposes, and is securely deleted once no longer required.

Security logs, audit events, generated documents and electronic records are kept for the period needed to administer the Centre, investigate incidents, meet legal obligations and prove the integrity of the record.

Backups may contain copies of records that have since changed or been deleted in the live system. Backup retention is limited, encrypted and controlled, and restored data is handled under the same access, deletion and legal-hold rules as the live record.

8 Your Rights

Under UK GDPR, you have the right to request access to, correction of, or deletion of personal data, and the right to restrict or object to processing where applicable.

To make a request, please contact us using the details above or via the contact page.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk.

9 International Transfers

We do not transfer personal data outside the United Kingdom unless appropriate safeguards are in place.

10 Cookies & Third-Party Services

What are cookies?

Cookies are small text files stored on your device when you visit a website. Some cookies are essential to make a site work properly, while others help website owners understand how visitors use their site or provide optional features.

How we use cookies

We only use cookies that are necessary for the website to function, or that you have chosen to allow. Optional cookies are controlled through our cookie banner. You can accept or decline analytics cookies when you first visit the site, and you can update your preference at any time using the "Cookie settings" link in the footer.

Essential cookies

We use essential cookies required for basic site functionality, such as remembering your accessibility or theme preferences. These cookies do not require consent.

If you sign in to the booking or My Stay Portal services, the following essential authentication and security cookies may also be set by the BB Centre booking API:

  • __Host-bb_access in production, or bb_access in local development — keeps you signed in for authenticated API requests using an opaque server-side session. All sessions expire after 15 minutes of inactivity. Customer sessions have a 24-hour absolute limit; administrator, staff and finance sessions have an 8-hour absolute limit. It never stores the server-side session hash in the browser. It is HttpOnly and has SameSite=Lax. In production it uses the browser-enforced __Host- cookie rules: Secure, Path=/, and no Domain attribute. In local development it uses the compatible bb_access name, is scoped to /api, and is not marked Secure so ordinary localhost HTTP can work.
  • __Host-bb_refresh in production, or bb_refresh in local development — allows the service to renew your short sign-in session without storing authentication tokens in browser storage. It expires after 7 days. It is HttpOnly and has SameSite=Lax. In production it uses Secure, Path=/, and no Domain attribute. In local development it uses the compatible bb_refresh name, is scoped to /api/auth, and is not marked Secure.
  • __Host-bb_csrf in production, or bb_csrf in local development — protects cookie-authenticated actions against cross-site request forgery by allowing the site to send a matching x-csrf-token header. It expires after 7 days. It is readable by site JavaScript for this security check and has SameSite=Lax. In production it uses Secure, Path=/, and no Domain attribute. In local development it uses the compatible bb_csrf name, Path=/, and is not marked Secure.

These authentication and security cookies are essential. They continue to work whether you accept or decline analytics cookies.

Google Analytics (analytics cookies — optional)

With your consent, we use Google Analytics to understand how visitors use this site — for example, which pages are visited most and how people navigate the site. This helps us improve content and usability. Google Analytics sets the following cookies:

  • _ga — distinguishes users (expires after 2 years)
  • _gid — distinguishes users (expires after 24 hours)
  • _ga_* — maintains session state (expires after 2 years)

Analytics cookies are only set if you click "Accept analytics" on the cookie banner. If you decline, no analytics cookies are set and Google Analytics does not load. IP addresses are anonymised before being sent to Google.

Data collected by Google Analytics may be processed on servers outside the United Kingdom. Google acts as a data processor under our instruction. For more information see Google's Privacy Policy.

Google Translate (functional — optional)

This website offers an optional Google Translate feature. It is not loaded automatically — it only activates if you choose to use the translation button in the accessibility panel. When activated, Google may set third-party cookies in accordance with Google's Privacy Policy. By clicking the translation button you are indicating your consent to Google Translate loading.

Email and SMS delivery (essential — service providers)

We use third-party services to send booking, account, security and reminder messages by email and text message. These providers act as data processors under our instruction and only send the messages we ask them to send — they do not use your contact details for their own marketing.

  • Resend — sends transactional emails (booking confirmations, password resets, account notifications).
  • Twilio — sends text messages (booking confirmations, arrival and payment reminders) and phone number verification / SMS password-reset codes, where you have provided a phone number and chosen to be contacted this way. You can turn text message notifications on or off at any time in your account preferences.

No advertising cookies

We do not use advertising or cross-site tracking cookies. If this changes in future, this policy will be updated and appropriate consent mechanisms will be implemented before any such cookies are set.

11 Security, Access Control & Electronic Records

The booking and administration systems use role-based access, server-side sessions, CSRF and origin checks, abuse protection and audit logging. Production authentication and security cookies use the browser-enforced __Host- prefix where the service is deployed over HTTPS.

Access is limited to authorised users and is reviewed when roles change. Sensitive administrative actions, electronic approvals, generated documents and audit records are retained as system records so the Centre can demonstrate what was created, approved, sent, changed or withdrawn.

The Centre does not ask users to store authentication tokens in browser storage. If a session expires or looks abnormal, the system may require sign-in again or revoke related sessions.

12 Security Incidents & Personal Data Breaches

Suspected security incidents are logged, contained and reviewed. Where an incident may involve personal data, the Centre records the facts, assesses the risk to individuals and decides whether notification is required.

Reportable personal data breaches are reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. If a breach is likely to result in high risk to individuals, the affected people are informed without undue delay.

13 Backups, Recovery & Business Continuity

The Centre keeps encrypted backups and recovery records so bookings, financial records, operational documents and audit history can be restored after accidental loss, system failure or security incident.

At least one protected backup copy must be offline or immutable during its retention period, and restore checks are recorded. Readable backup exports are created only for an approved purpose, protected while in use and securely removed when no longer needed.

If the online system is unavailable, the Centre may use controlled manual records, phone, email and paper forms to keep essential booking, safety and communication processes running. Manual records are reconciled into the system when service resumes.

14 Communications

We use contact details to send booking, account, safety, payment, service and operational messages. Optional marketing or analytics-related communications are only sent where an appropriate lawful basis and consent or preference record applies.

Email and system messages may be logged so the Centre can prove what was sent, investigate delivery problems and respond to disputes or safety concerns.

15 AI-Assisted Features

AI-assisted features may help staff or users draft, summarise or find approved Centre information, but AI does not make safeguarding, health and safety, pricing, refund, access-control or trustee-approval decisions.

Staff must review AI-assisted output before relying on it for Centre operations. Personal data is shared with AI services only where there is an approved purpose, appropriate protection and a record of the processing route.

16 Policy Review

This policy is reviewed annually and sooner where law, ICO guidance, system behaviour, providers or Centre operations materially change.

Your data

Questions about how your information is used

Contact us if you need clarification about your data or how it is handled when making enquiries or bookings.

Link copied!