Legal
Privacy Policy
Version v1.0 — effective 4 October 2026. See the Version history at the end of this policy for a summary of what has changed.
Who we are
Oyster Coaching (“we”, “us”, “our”) operates the website oystercoaching.co.uk and provides coaching services to individuals and organisations.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller for personal data you provide through this website.
- Controller: Oyster Coaching
- Postal address: [Postal address to be confirmed]
- Data protection enquiries: beki.jones@oystercoaching.co.uk
- ICO registration number: Registration pending
We are not required to appoint a Data Protection Officer under Article 37 of the UK GDPR, but you may direct any data protection queries to the email address above.
What information we collect and how
We collect personal data only when you voluntarily submit the enquiry form on this website. The information we collect is:
| Data item | Source | Purpose |
|---|---|---|
| Your name | You provide it | To identify you and personalise our response |
| Your email address | You provide it | To reply to your enquiry and, with your separate consent, to contact you about relevant activities in the future |
| Your area of interest | You provide it | To route your enquiry and tailor future communications to your interests |
| Your message (free text) | You provide it | To understand and respond to your enquiry |
| Consent record | Generated at submission | To evidence your consent choices |
| IP address | Automatically collected | Spam / abuse prevention |
| Browser identifier (user agent) | Automatically collected | Spam / abuse prevention |
| Timestamp | Automatically collected | Spam / abuse prevention and audit trail |
We do not use analytics tools or advertising / tracking technologies anywhere on this website. The public website sets no cookies and no browser storage. The members’ area uses only strictly-necessary browser storage to keep you signed in after you log in (see “Member accounts” below); it is not used for tracking. We do not collect data from visitors who do not submit the form or create an account.
Provision of your name and email address is necessary for us to respond to your enquiry. If you do not provide them, we will be unable to reply. All other fields are optional.
Member accounts
If you create an account to access the members’ area of this website, we collect and process the following additional personal data:
| Data item | Source | Purpose |
|---|---|---|
| Your email address | You provide it at sign up | To identify your account, verify ownership of the address, sign you in, and send account messages such as email-verification and password-reset codes |
| Authentication records (email-verification status, password-reset activity, sign-in and session metadata) | Generated by the authentication service | To operate and secure your account: confirm your email, authenticate you, manage your session, and detect suspicious activity |
Your account password is set by you but is never stored by us in a form we can read: it is held only as a salted hash by our authentication provider (see “Who we share your data with”). We do not have access to your password.
Creating an account is entirely optional and separate from submitting an enquiry. You do not need an account to browse the public website or to use the enquiry form.
Anti-spam protection (Cloudflare Turnstile)
To protect the enquiry form and members’ area against automated abuse, we
use Cloudflare Turnstile — a privacy-focused, invisible alternative to
CAPTCHA. Turnstile runs on the public enquiry form at /contact and on
the members sign-up, forgotten-password, and password-reset
screens under /members, and only on those pages.
When you load one of those pages, your browser makes a background request
to challenges.cloudflare.com and Turnstile processes a small set of
technical signals to decide whether the request is coming from a human or
a bot. Cloudflare describes these signals in its Turnstile Privacy
Policy, which we
incorporate by reference into this policy. The signals include your IP
address, your browser’s user-agent string, basic device and browser
characteristics (screen size, language, timezone, and similar), and
in-browser interaction telemetry (mouse movement, keyboard activity, page
timing) collected to distinguish humans from bots.
Turnstile is invisible: it does not display a puzzle, does not require you to click a box, and does not use tracking cookies, browser fingerprinting for advertising, or any cross-site identifier.
Our lawful basis for using Turnstile is legitimate interest (Article 6(1)(f) UK GDPR): protecting our website and users from spam, brute-force attacks, and automated abuse.
Why we process your data (lawful bases)
We rely on the following lawful bases under Article 6(1) of the UK GDPR:
(a) Consent — Article 6(1)(a)
- Responding to your enquiry: By submitting the form and ticking the required consent checkbox, you consent to us storing and processing your data to respond to your enquiry.
- Future contact: If you tick the optional “keep me informed” checkbox, you consent to us retaining your name, email address, and area of interest so we may contact you in the future about activities or services from Oyster Coaching that are relevant to the interest you indicated. This is a separate, optional consent.
- Member accounts: By creating an account you consent to us storing and processing your email address and the associated authentication records so we can operate your account. You may withdraw this consent at any time by deleting your account (see “Your rights”).
(f) Legitimate interests — Article 6(1)(f)
- Security data (IP address, user agent, timestamp): Our legitimate interest is protecting the website and its users from spam, automated abuse, and malicious activity.
- Account security: We also have a legitimate interest in keeping member accounts secure — for example, detecting and blocking suspicious sign-in attempts and applying rate limiting to authentication requests.
Who we share your data with
We share your data only with the following service providers, each acting as a data processor on our behalf under a written data processing agreement (Article 28 UK GDPR):
| Processor | Role | Location |
|---|---|---|
| Amazon Web Services (Amazon Web Services EMEA SARL) | Website hosting, database, application logic, and account authentication / identity management (Amazon Cognito) | London region (eu-west-2), UK |
| Brevo (Sendinblue SAS) | Delivery of email notifications to us when an enquiry is submitted | France (EU/EEA) |
| Cloudflare, Inc. | Anti-spam / bot-detection signal processing via Cloudflare Turnstile (see “Anti-spam protection” above) | Global edge network; corporate entity is US-based |
If you pay for a coaching programme online, payment is processed by Stripe (Stripe Payments Europe, Ltd.); we do not store your full card details. We do not sell, rent, or trade your personal data, and we do not share it with any third party for their own marketing purposes.
International transfers
Personal data that we ourselves store — enquiry submissions and member
account data — is held only within the United Kingdom and the
European Economic Area (London region, eu-west-2). The narrow set of
technical signals processed by Cloudflare’s Turnstile service may be
processed outside the UK and the EEA; that transfer relies on Cloudflare’s
certification under the UK-US Data Bridge and the EU-US Data Privacy
Framework, with the UK IDTA and EU Standard Contractual Clauses as
fallback safeguards.
How long we keep your data
| Data category | Retention period | Basis |
|---|---|---|
| Enquiry data (where you did not opt in to future contact) | 12 months from submission, then automatically deleted | Sufficient to respond to your enquiry and handle any follow-up |
| Enquiry data (where you opted in to future contact) | Until you withdraw consent or for a maximum of 36 months from your last interaction, whichever is sooner | Necessary to fulfil the purpose you consented to |
| Security data (IP, user agent, timestamp) | 6 months, then automatically deleted | Sufficient to detect patterns of abuse |
| Member account data (email address and authentication records) | Retained for the life of your account; removed when you delete your account | Necessary to operate the account for as long as you choose to keep it |
Your rights
Under UK GDPR you have the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), objection (Article 21), and to withdraw consent (Article 7(3)) at any time without affecting the lawfulness of processing before withdrawal. These are free of charge unless requests are manifestly unfounded or excessive.
To exercise any of these rights, contact us at beki.jones@oystercoaching.co.uk. We will acknowledge your request within 72 hours and respond substantively within one calendar month (extendable by two further months for complex requests, in which case we will inform you of the extension and the reasons for it).
Complaints
If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Live chat: ico.org.uk/make-a-complaint
We would appreciate the opportunity to address your concerns before you approach the ICO, but you are not required to do so.
Automated decision-making
We do not carry out any automated decision-making or profiling (as described in Article 22 UK GDPR) based on the data you provide.
Children’s data
This website and its services are intended for individuals aged 18 or over. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has submitted data through our form, please contact us and we will delete it promptly.
Security measures
We implement appropriate technical and organisational measures to protect your data, including encryption at rest (AWS-managed keys), encryption in transit (HTTPS/TLS), access restricted to authorised personnel using multi-factor authentication, regular review of access permissions, and data processing agreements with all processors.
Changes to this policy
We may update this policy from time to time. Each version carries a version number and an effective date, both shown at the top of this page, and a summary of substantive changes is recorded in the Version history below.
Version history
- v1.0 — 4 October 2026. Initial privacy policy for the Oyster Coaching website: data collected via the enquiry form and member accounts, consent and legitimate-interest lawful bases, processors (Amazon Web Services, Brevo, Cloudflare, and Stripe for payments), retention periods, international-transfer safeguards, and your rights under UK GDPR.