Legal

Privacy Policy

Last updated: 4 October 2026

Version v1.0 — effective 4 October 2026. See the Version history at the end of this policy for a summary of what has changed.

Who we are

Oyster Coaching (“we”, “us”, “our”) operates the website oystercoaching.co.uk and provides coaching services to individuals and organisations.

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller for personal data you provide through this website.

We are not required to appoint a Data Protection Officer under Article 37 of the UK GDPR, but you may direct any data protection queries to the email address above.

What information we collect and how

We collect personal data only when you voluntarily submit the enquiry form on this website. The information we collect is:

Data item Source Purpose
Your name You provide it To identify you and personalise our response
Your email address You provide it To reply to your enquiry and, with your separate consent, to contact you about relevant activities in the future
Your area of interest You provide it To route your enquiry and tailor future communications to your interests
Your message (free text) You provide it To understand and respond to your enquiry
Consent record Generated at submission To evidence your consent choices
IP address Automatically collected Spam / abuse prevention
Browser identifier (user agent) Automatically collected Spam / abuse prevention
Timestamp Automatically collected Spam / abuse prevention and audit trail

We do not use analytics tools or advertising / tracking technologies anywhere on this website. The public website sets no cookies and no browser storage. The members’ area uses only strictly-necessary browser storage to keep you signed in after you log in (see “Member accounts” below); it is not used for tracking. We do not collect data from visitors who do not submit the form or create an account.

Provision of your name and email address is necessary for us to respond to your enquiry. If you do not provide them, we will be unable to reply. All other fields are optional.

Member accounts

If you create an account to access the members’ area of this website, we collect and process the following additional personal data:

Data item Source Purpose
Your email address You provide it at sign up To identify your account, verify ownership of the address, sign you in, and send account messages such as email-verification and password-reset codes
Authentication records (email-verification status, password-reset activity, sign-in and session metadata) Generated by the authentication service To operate and secure your account: confirm your email, authenticate you, manage your session, and detect suspicious activity

Your account password is set by you but is never stored by us in a form we can read: it is held only as a salted hash by our authentication provider (see “Who we share your data with”). We do not have access to your password.

Creating an account is entirely optional and separate from submitting an enquiry. You do not need an account to browse the public website or to use the enquiry form.

Anti-spam protection (Cloudflare Turnstile)

To protect the enquiry form and members’ area against automated abuse, we use Cloudflare Turnstile — a privacy-focused, invisible alternative to CAPTCHA. Turnstile runs on the public enquiry form at /contact and on the members sign-up, forgotten-password, and password-reset screens under /members, and only on those pages.

When you load one of those pages, your browser makes a background request to challenges.cloudflare.com and Turnstile processes a small set of technical signals to decide whether the request is coming from a human or a bot. Cloudflare describes these signals in its Turnstile Privacy Policy, which we incorporate by reference into this policy. The signals include your IP address, your browser’s user-agent string, basic device and browser characteristics (screen size, language, timezone, and similar), and in-browser interaction telemetry (mouse movement, keyboard activity, page timing) collected to distinguish humans from bots.

Turnstile is invisible: it does not display a puzzle, does not require you to click a box, and does not use tracking cookies, browser fingerprinting for advertising, or any cross-site identifier.

Our lawful basis for using Turnstile is legitimate interest (Article 6(1)(f) UK GDPR): protecting our website and users from spam, brute-force attacks, and automated abuse.

Why we process your data (lawful bases)

We rely on the following lawful bases under Article 6(1) of the UK GDPR:

(a) Consent — Article 6(1)(a)

(f) Legitimate interests — Article 6(1)(f)

Who we share your data with

We share your data only with the following service providers, each acting as a data processor on our behalf under a written data processing agreement (Article 28 UK GDPR):

Processor Role Location
Amazon Web Services (Amazon Web Services EMEA SARL) Website hosting, database, application logic, and account authentication / identity management (Amazon Cognito) London region (eu-west-2), UK
Brevo (Sendinblue SAS) Delivery of email notifications to us when an enquiry is submitted France (EU/EEA)
Cloudflare, Inc. Anti-spam / bot-detection signal processing via Cloudflare Turnstile (see “Anti-spam protection” above) Global edge network; corporate entity is US-based

If you pay for a coaching programme online, payment is processed by Stripe (Stripe Payments Europe, Ltd.); we do not store your full card details. We do not sell, rent, or trade your personal data, and we do not share it with any third party for their own marketing purposes.

International transfers

Personal data that we ourselves store — enquiry submissions and member account data — is held only within the United Kingdom and the European Economic Area (London region, eu-west-2). The narrow set of technical signals processed by Cloudflare’s Turnstile service may be processed outside the UK and the EEA; that transfer relies on Cloudflare’s certification under the UK-US Data Bridge and the EU-US Data Privacy Framework, with the UK IDTA and EU Standard Contractual Clauses as fallback safeguards.

How long we keep your data

Data category Retention period Basis
Enquiry data (where you did not opt in to future contact) 12 months from submission, then automatically deleted Sufficient to respond to your enquiry and handle any follow-up
Enquiry data (where you opted in to future contact) Until you withdraw consent or for a maximum of 36 months from your last interaction, whichever is sooner Necessary to fulfil the purpose you consented to
Security data (IP, user agent, timestamp) 6 months, then automatically deleted Sufficient to detect patterns of abuse
Member account data (email address and authentication records) Retained for the life of your account; removed when you delete your account Necessary to operate the account for as long as you choose to keep it

Your rights

Under UK GDPR you have the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), objection (Article 21), and to withdraw consent (Article 7(3)) at any time without affecting the lawfulness of processing before withdrawal. These are free of charge unless requests are manifestly unfounded or excessive.

To exercise any of these rights, contact us at beki.jones@oystercoaching.co.uk. We will acknowledge your request within 72 hours and respond substantively within one calendar month (extendable by two further months for complex requests, in which case we will inform you of the extension and the reasons for it).

Complaints

If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):

We would appreciate the opportunity to address your concerns before you approach the ICO, but you are not required to do so.

Automated decision-making

We do not carry out any automated decision-making or profiling (as described in Article 22 UK GDPR) based on the data you provide.

Children’s data

This website and its services are intended for individuals aged 18 or over. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has submitted data through our form, please contact us and we will delete it promptly.

Security measures

We implement appropriate technical and organisational measures to protect your data, including encryption at rest (AWS-managed keys), encryption in transit (HTTPS/TLS), access restricted to authorised personnel using multi-factor authentication, regular review of access permissions, and data processing agreements with all processors.

Changes to this policy

We may update this policy from time to time. Each version carries a version number and an effective date, both shown at the top of this page, and a summary of substantive changes is recorded in the Version history below.

Version history