Privacy Policy
Effective Date: 19 August 2026
Under The Bridge CIC (“Under The Bridge”, “we”, “us” or “our”) is committed to protecting the privacy and security of personal information entrusted to us.
This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, who we may share it with, how long we keep it, and the rights available to individuals under UK data protection law.
This policy applies to information collected through our website, online forms, activities and sessions, our online shop, communications with us, and other services we provide.
Who We Are
Under The Bridge CIC is a community organisation supporting mental health and wellbeing through blue spaces, creative arts, music, outdoor activities and community engagement.
For the purposes of UK data protection law, Under The Bridge CIC is the data controller for the personal information described in this Privacy Policy.
Website: https://underthebridgeproject.org
Privacy contact: info @ underthebridgeproject.org
Where Under The Bridge has appointed a Data Protection Officer or other designated data protection contact, their details are:
Data Protection Contact / DPO: info @ underthebridgeproject.org
What Personal Information We Collect
Depending on how you interact with us, we may collect different types of personal information, including:
Contact and identification information
- Name
- Address
- Email address
- Telephone number
- Emergency contact details
- Date of birth
- Information needed to identify or communicate with a participant, parent, guardian, volunteer, customer or other contact
Activity, participation and consent information
When people register for, participate in or provide consent for our activities, we may collect:
- Participant and emergency contact information
- Consent information
- Activity acknowledgements and waivers
- Attendance and session-register information
- Session participation information
- Information provided through participant consent forms
- Information relating to activities, sessions and events
Health and medical information
Some of our forms request information concerning health, medical needs, allergies, medication, disabilities, accessibility requirements or other information relevant to a person’s safe participation in our activities.
Health information is special category personal data under UK data protection law and is handled with additional care and safeguards. We only collect health information where it is relevant and necessary for the purpose for which it is requested.
Accident, incident and safeguarding information
We may collect information relating to accidents, incidents, near-misses, safeguarding matters, concerns or other events arising from our activities.
This may include information about participants, staff, volunteers, witnesses and other individuals involved.
Where such information contains health information or other special-category information, the additional legal requirements applicable to that information will apply.
Website and technical information
When you use our website, we may automatically receive limited technical information such as:
- IP address
- Browser type and version
- Device information
- Operating system
- Website pages visited
- Referring pages
- Basic technical and security information
The information collected depends on the technologies and services used on the website.
Online shop information
When you purchase products through our online shop, we may collect information required to process and fulfil your order, including:
- Name
- Billing address
- Delivery address
- Email address
- Telephone number
- Products purchased
- Order information
- Payment status
- Delivery and fulfilment information
- Information relating to refunds, returns or customer support
Payment card details are normally processed by the relevant payment provider rather than being stored directly by our website. The exact information shared depends on the payment provider and payment method used.
Communications
If you contact us by email, telephone, contact form or other communication channel, we may keep a record of that communication and the information contained within it.
How We Use Personal Information
We may use personal information for the following purposes:
- Responding to enquiries and requests
- Managing participant registrations
- Managing activity and event participation
- Recording attendance
- Managing consent and activity acknowledgements
- Assessing relevant medical, accessibility or safety information
- Managing accidents, incidents and near-misses
- Supporting safeguarding and participant welfare
- Communicating with participants, parents, guardians, volunteers, staff and other relevant contacts
- Administering and improving our services
- Managing our website
- Processing purchases, payments, deliveries, refunds and returns
- Providing customer support
- Maintaining appropriate organisational and financial records
- Meeting legal, regulatory, insurance and safeguarding obligations
- Protecting our organisation, participants, staff and visitors from fraud, abuse or misuse
- Improving the website, forms, activities and services
- Sending service-related communications
- Sending marketing communications where we are legally permitted to do so and where any required consent or other lawful basis has been obtained
We will not use personal information for a new purpose that is incompatible with the purpose for which it was collected without providing appropriate information and, where required, obtaining consent or identifying another lawful basis.
Our Lawful Bases for Processing
Under the UK GDPR, we must have a lawful basis for processing personal information.
Depending on the circumstances, we may rely on one or more of the following:
Consent
We may rely on consent where an individual has freely given clear permission for their personal information to be processed for a specific purpose.
Where we rely on consent, individuals may withdraw that consent at any time. Withdrawal of consent does not affect processing carried out before consent was withdrawn.
Where health or other special-category information is processed on the basis of explicit consent, that consent will be obtained in an appropriately clear and explicit manner.
Contract
We may process information where it is necessary to enter into or perform a contract, including processing and fulfilling purchases made through our online shop.
Legal obligation
We may process information where necessary for compliance with a legal obligation, including legal, accounting, tax, safeguarding, insurance or regulatory requirements.
Legitimate interests
We may process personal information where necessary for our legitimate interests, provided that those interests are not overridden by an individual’s rights and freedoms.
Examples may include maintaining organisational records, maintaining website and information security, responding to enquiries, managing our services, preventing fraud and improving our operations.
Where we rely on legitimate interests, we consider and balance the impact on individuals before processing.
Special-category information
Where we process health or other special-category information, we identify both an Article 6 lawful basis and an appropriate Article 9 condition under the UK GDPR. The precise condition used depends on the purpose and circumstances of the processing.
Participant and Activity Forms
Our website includes digital forms used to replace or supplement paper-based forms and administrative records.
These may include:
- Accident, Incident & Near-Miss Forms
- Session Review Forms
- Contact & Consent Forms with Medical Details
- Session Register Forms
- Participant Consent & Activity Acknowledgement / Waiver Forms
- Other activity, registration, consent or administrative forms
Information submitted through these forms may be stored within our website’s WordPress/Forminator system and may also be sent by email to authorised members of the Under The Bridge team for administration and record-keeping purposes.
Where a form contains health or medical information, that information is treated as special-category personal data and is subject to additional safeguards.
We aim to limit access to form submissions to people who need the information for their role.
Email Notifications and Digital Records
When a website form is submitted, the information may be:
- Stored within the website’s WordPress database as an administrative record; and
- Sent by email to designated Under The Bridge administrators for operational purposes.
This means that some form information may exist in more than one location.
We take steps to protect these records and limit access to authorised personnel. We also review retention arrangements so that information is not retained longer than necessary.
Because email is not inherently designed as a highly secure medical-record system, access to the relevant email accounts should be appropriately restricted and protected with strong passwords and multi-factor authentication where available.
Online Shop and Orders
We operate an online shop through which customers may purchase products from Under The Bridge.
Information collected during checkout may be used to:
- Process and fulfil orders
- Take or facilitate payment
- Provide invoices or order confirmations
- Deliver products
- Deal with refunds, returns and customer service enquiries
- Maintain appropriate financial and accounting records
- Prevent fraud and protect the website and customers
Depending on the payment method and other services used, relevant customer information may be shared with payment processors, delivery providers and other service providers involved in fulfilling an order.
The exact information processed and shared depends on the payment, delivery and other services enabled on the website.
Who We Share Personal Information With
We do not sell or rent personal information.
We may share personal information where necessary with trusted service providers and organisations that help us operate our services, website and shop.
Depending on the service being provided, these may include:
- Website hosting providers
- Email providers
- Form and website service providers
- Payment processors
- Delivery and fulfilment providers
- IT, security and technical support providers
- Professional advisers
- Accountants and financial service providers
- Insurers
- Legal or regulatory bodies
- Safeguarding or emergency services where appropriate
- Authorities where disclosure is required or permitted by law
Where a third party processes personal information on our behalf, we seek to ensure that appropriate contractual and security arrangements are in place. UK GDPR requires controllers to have appropriate arrangements with processors acting on their behalf.
International Transfers
Some of the service providers we use may process personal information outside the United Kingdom.
Where personal information is transferred outside the UK, we will ensure that the transfer is made in accordance with applicable UK data protection law and that an appropriate safeguard or lawful transfer mechanism is in place where required.
Where relevant, further information about international transfers and the safeguards used can be obtained by contacting us.
Data Security
We take appropriate technical and organisational measures to protect personal information from unauthorised access, loss, misuse, alteration or disclosure.
These measures may include:
- Restricted access to personal information
- Password protection and account security
- Administrative access controls
- Website security measures
- Software and plugin updates
- Appropriate backups
- Secure communications where available
- Limiting access to information based on role and need
Because some of the information we process may include health and other sensitive information, we recognise the need for appropriate additional security measures proportionate to the risks involved. No method of transmission or storage over the internet can be guaranteed to be completely secure.
Data Retention
We retain personal information only for as long as it is necessary for the purpose for which it was collected, unless a longer period is required or permitted by law.
Different categories of information may therefore be retained for different periods.
Examples include:
- Enquiries and general correspondence: retained only as long as reasonably necessary to respond to and manage the enquiry.
- Participant, consent and activity records: retained for as long as reasonably necessary for participant administration, safeguarding, insurance, legal and organisational purposes.
- Medical and health information: retained only for as long as it is necessary for the relevant safety, participation, safeguarding, legal or organisational purpose.
- Accident, incident and near-miss records: retained for an appropriate period based on safeguarding, insurance, legal and organisational requirements.
- Session registers and attendance records: retained for an appropriate period for organisational, safeguarding, funding and accountability purposes.
- Online shop orders and financial records: retained for the periods required for accounting, tax, legal and other applicable obligations.
- Website and security records: retained for an appropriate period based on security and operational requirements.
We periodically review retention periods and securely delete, anonymise or otherwise dispose of information when it is no longer required.
The specific retention periods should be documented internally in our retention schedule.
Cookies and Similar Technologies
Our website may use cookies and similar technologies.
Some cookies and technologies are strictly necessary for the website to operate, provide requested services, maintain security, remember choices or process transactions.
Other cookies or technologies may be used for analytics, functionality or other purposes, depending on the services currently enabled on the website.
Where consent is required for non-essential cookies or similar technologies, we will provide an appropriate consent mechanism.
Please note that third-party services used by the website may also set cookies or collect technical information. Cookie requirements depend on the specific technologies being used. Under PECR, non-essential cookies generally require consent before they are placed or accessed, subject to applicable exemptions.
hCaptcha
We use hCaptcha on certain forms to help protect the website from spam and automated abuse.
hCaptcha may process technical information such as IP address, browser information, device information and interactions with the service.
hCaptcha processes information in accordance with its own privacy and terms documentation.
For further information:
Marketing Communications
Where we send marketing communications by email, text message or other electronic means, we will comply with applicable UK data protection and electronic communications requirements.
Where consent is required, we will obtain appropriate consent before sending marketing communications and provide a straightforward way to withdraw that consent or opt out.
We will not use information collected through participant, medical, consent, accident or other sensitive forms for unrelated marketing purposes. Direct marketing must be transparent and have an appropriate lawful basis.
Children and Young People
Our activities occasionally involve children and young people.
Where we process information relating to children or young people, we take additional care to ensure that information is handled fairly, transparently and securely, taking into account the child’s age, understanding and circumstances.
Where appropriate, consent or information may be obtained from a parent, guardian or other person with appropriate authority.
We recognise that children’s personal information can require additional protection under UK data protection law.
Your Data Protection Rights
Subject to applicable legal conditions and exemptions, you may have the following rights:
- The right to be informed about how your personal information is used
- The right to access your personal information
- The right to correct inaccurate or incomplete information
- The right to request erasure of your personal information
- The right to request restriction of processing
- The right to object to certain processing
- The right to data portability in applicable circumstances
- The right to withdraw consent where processing is based on consent
- Rights relating to automated decision-making and profiling, where applicable
These rights are not absolute and may be subject to legal exceptions.
For example, we may need to retain certain information where this is necessary for legal, accounting, safeguarding, insurance or other legitimate obligations.
How to Exercise Your Rights
To exercise your rights or ask questions about how we process personal information, please contact:
Email: info @ underthebridgeproject.org
Post:
We may need to verify your identity before responding to a request.
We will normally respond to valid data protection requests within the applicable statutory timescale.
Complaints
We encourage anyone with a concern about how we have handled their personal information to contact us first so that we can investigate and attempt to resolve the issue.
You also have the right to complain to the UK’s data protection regulator:
Information Commissioner’s Office (ICO)
Website: https://ico.org.uk/
Telephone: 0303 123 1113
The ICO recommends that privacy information clearly tells individuals about their right to complain to the supervisory authority.
Personal Data Breaches
If we become aware of a personal data breach, we will assess the breach and take appropriate steps to contain, investigate and mitigate it.
Where required by UK data protection law, we will notify the Information Commissioner’s Office and/or affected individuals within the relevant legal timescales.
We maintain appropriate procedures for identifying, recording and responding to personal data breaches.
Third-Party Websites
Our website may contain links to external websites or services.
We are not responsible for the privacy practices, security or content of third-party websites. We recommend reviewing the privacy information of any external service before providing personal information.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, website, technology, legal requirements or data processing activities.
Where significant changes are made, we will update the effective date shown at the top of this policy and, where appropriate, provide additional notice.
Contact Us
If you have questions about this Privacy Policy or the way we handle personal information, please contact:
Under The Bridge CIC
Website: https://underthebridgeproject.org
Email: info @ underthebridgeproject.org
Address:

