The Wimbledon Club
Data Controller
Document Version 1.1
Data Audit: 24 January 2024
ICO REGISTRATION NO: Z 6355980
C O R P O R A T E R E S P O N S I B I L I T Y:-
MIKE FULLER
Data Manager
ONLINE PRIVACY NOTICE
THE WIMBLEDON CLUB
Registered Member of the GDPR Check & Verify Register

1.1. The Wimbledon Club Church Road Wimbledon London SW19 5AG hereinafter referred to as ‘the Club’, We, Us and Our.
1.2. Our email address is: reception@twcsport.co.uk
1.3. Our contact telephone number is: 020 8971 8090
1.4. We are a Data Controller under the provisions of the UK GDPR and the Data Protection Act 2018 and have registered with the UK Information Commissioners office:
ICO Registration Number: Z 6355980
2.1. We have designated Mr Mike Fuller as Data Protection Manager for the business.
2.2. We are not required to formally designate a Data Protection Officer (DPO) Because we are not engaged in any of the following activities:
2.2.1. We are not a public authority.
2.2.2. We are not an organisation that carries out the regular and systematic monitoring of individuals on a large scale.
2.2.3. We are not an organisation that carries out the large scale processing of special categories of data, such as health records, or information about criminal convictions.
2.3. We do not believe it is necessary to appoint a DPO voluntarily but if this policy changes, or such a change is made or planned to be made, we will complete a Data Protection Impact Assessment and update this policy statement accordingly.
3.1. The Club is committed to the highest standards of information security and treats confidentiality and data security extremely seriously.
3.2. We have robust information security management systems in place to protect your personal data and have implemented appropriate technical and organisational security measures to protect it against any unauthorised or unlawful processing and against any accidental loss, destruction, or damage.
3.3. Pursuant to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA) the Club must:
3.3.1. use technical or organisational measures to ensure personal data is kept secure, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage;
3.3.2. implement appropriate technical and organisational measures to demonstrate that it has considered and integrated data compliance measures into the Club’s data processing activities; and be able to demonstrate that it has used or implemented such measures and complied with the data protection principles.
3.3.3. The Club maintains records of its own actions and our interactions with other Data Controllers and our Data Processors to ensure we can suitably demonstrate adherence to the data protection principles. Specifically, we ensure data is processed:
3.4. This Online Privacy Notice is a precis of our written policies held at our business premises
4.1. This Privacy Notice applies to Personal Data we process when you visit or use our website. Further Privacy Policy statements and documents may apply offline and these are available, if relevant, on request.
4.2. We are committed to protecting your personal data privacy and, in accordance with relevant data protection laws, we uphold strict security procedures for the collection, storage, use and disclosure of your personal information.
4.3. We have described below the personal information we may gather about you, the purposes we will hold it for and the limited categories of people to whom we may disclose it.
5.1. During your visit to our site, we will only collect personal information that you choose to provide. If, for example, you contact us with an enquiry or request us to provide you with further information.
5.2. If you share other people’s data with us, for example if you refer business to us on behalf of another, you will need to check you have lawful authority to do so. E.G. The other party has consented to you providing us with their information. In such a case you are responsible for ensuring the transmission to us of the information is lawful and we may ask you for documentary evidence of this.
6.1. In general if you fail or refuse to provide us with your Personal Data we will not be able to deal with your enquiry or do business with you. The following explains the consequences for each Lawful Basis of processing.
7.1. We may use the information you provide us with in the following ways
8.1. Data we receive and process is held by us in secure electronic devices and separate back up devices and servers.
8.2. Personal Data may also be held in encrypted 3rd party ‘Cloud’ Servers.
8.3. Further encrypted back ups of data may be held securely in offsite locations which are also subject to physical security at their location.
8.4. We will not sell, rent or otherwise disclose the personal information you provide to us through the site to third parties (other than as listed below) unless we are required to do so by law.
8.5. The Main Establishment for all of our Data Processing is the UK. We do not generally operate or transfer Personal Data outside of the United Kingdom.
8.6. Due to the operation of the Internet and other computer based applications Personal Data under our control may transit countries outside of the UK.
8.7. We will only transfer data outside the UK if adequate safeguards are in place in the destination country.
8.8. Where Personal Data is transferred to a third country or an international organisation we will ensure that an adequacy decision or similar authority exists between the UK and the relevant country or area.
8.9. Where no adequacy decision exists and we rely on the provisions of Standard Contractual Clauses or Binding Corporate Rules evidence of the safeguards provided thereby will be available upon request.
9.1. Identity data: name, username, title, date of birth. Contact data: billing and delivery address, email address, phone number.
9.2. Financial data: payment card details (processed by a third-party payment services provider and not stored by us).
9.3. Transaction data: details of products purchased, amounts, dates etc.
9.4. Technical data: IP address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform based on your Cookie preference choices.
9.5. Profile data: username and password, purchases or orders made by users.
9.6. Usage data: information about how users use our website, products and services.
9.7. Marketing and communications data: record of Website users preferences in receiving marketing from us about the products we sell.
10.1. The following is a chart of the personal data under our control.
Personal Data |
Lawful Base(s) |
Types of Data |
Retention Period |
Data Sharing |
Prospective and existing Clients providing their personal information either Online or Offline including Social Media, telephone and by written means to ourselves or third parties to request information regarding our available products and services |
Consent |
Identity Data Marketing Data Communications Data |
Maximum of 12 months. Or Until Consent is withdrawn whichever comes first. |
Data is only shared with our authorised Data Processors. |
Prospective and existing Clients providing their information for the purposes of contracting with us for goods and services. We process this Personal Data to provide relevant advice, to manage and administer our business relationships and communicate with clients, their employees and representatives, to manage billing and payments and to keep records. |
Contract |
Identity Data Financial Data Transaction Data Marketing Data Communications Data |
Duration of Contract Plus Seven Years |
Data is shared with our Data Processors and our professional advisors including IT, Accounts and Legal where necessary. |
Personal data provided because the Data Subject may be interested in working with us or learning more about working with us. |
Consent |
Identity Data |
Duration of time to consider request. Maximum of 12 months; or Until Consent is withdrawn. |
Data is only shared with our authorised Data Processors. |
Online or Offline face to face meetings with people who provide their personal data to us for the purposes of later contact regarding products and services provided by us. |
Consent |
Identity data |
Maximum of 12 months. Or Until Consent is withdrawn whichever comes first. |
Data is only shared with our authorised Data Processors. |
Online or Offline face to face meetings with people who provide their personal data to us for the purposes of later contact regarding products and services provided by us. |
Consent |
Identity data |
Maximum of 12 months. Or Until Consent is withdrawn whichever comes first. |
Data is only shared with our authorised Data Processors. |
Suppliers of products and services to us who provide information of themselves or individuals who assist them to provide us with products and services on their behalf. |
Contract |
Identity data Transaction Data |
Duration of Contract Plus Seven Years |
Data is shared with our Data Processors and our professional advisors including IT, Accounts and Legal where necessary. |
Personal Data of prospective customers provided by third parties both commercially and informally for future contact by us regarding our products and services. |
Consent |
Identity data |
Maximum of 12 months. Or Until Consent is withdrawn whichever comes first. |
Data is only shared with our authorised Data Processors. |
Suppliers of software who manage data via End User Service Agreements (EUSAs). |
Contract |
Identity Data Transaction Data Technical Data |
Duration of Contract Plus Seven Years |
Data is only shared with our authorised Data Processors. |
Employees who provide their personal information for the purposes of working with us. |
Contract Legal Obligation |
Special Category Data Identity Data Technical Data |
Duration of Contract Plus Seven Years Any Other Legal Requirements |
Data is shared with our Data Processors and our professional advisors including HMRC, IT, Accounts and Legal where necessary. |
Personal Data of prospective customers provided to us by Companies who generate leads on our behalf. |
Consent |
Identity Data Marketing Data Communications Data |
Maximum of 12 months. Or Until Consent is withdrawn whichever comes first. |
Data is only shared with our authorised Data Processors. |
People identified via proprietary Video Conference software |
Legitimate Interests |
Identity Data |
Until Legitimate Interest no longer exists or 3 months if recorded |
Data is only shared with our authorised Data Processors |
People identified through our CCTV systems. |
Legitimate Interests |
Identity Data |
Until Legitimate Interest no longer exists or 3 months Max. |
Data is only shared with our authorised Data Processors |
Personal data collected at the time of purchasing or negotiating a contract with us using the ‘Soft Opt in’ exemption under the PECR Regs. |
Legitimate Interests |
Identity Data Marketing Data Communications Data |
Until Legitimate Interest no longer exists or Data Subject Unsubscribes |
Data is only shared with our authorised Data Processors |
11.1. Below is a chart showing the organisations and individuals with whom we may share data.
Processor |
Processor |
Google AWS |
|
Microsoft Teams |
|
Zoom |
|
Social Media: Linkedin/WhatsApp FB/Tik Tok/Twitter/Snapchat/Instagram |
|
Mailchimp |
|
AI – Otter/ChatGPT |
12.1. We hold and process your data by lawfully allowed means, these include:
14.1. Under the UK General Data Protection Regulation (UK GDPR) and The Data Protection Act 2018 (DPA) you have a number of rights with regard to your personal data. To exercise any of your rights contact our Data Manager using the details given above.
14.2. We protect the individual’s rights provided by the UK GDPR and Data Protection Act 2018 as being the following:
14.3. You have the right to request from us access to and rectification or erasure of your personal data; the right to restrict processing; the right to object to processing as well as in certain circumstances the right to data portability as below.
14.4. In the event that you provide your data directly to us for the purpose of a contract, or in circumstances where you have provided your data by consent, you have the right to be provided with your data in a structured, machine-readable format. This is known as Data Portability.
14.5. Following a request relating to Data Portability we will transmit the relevant personal data to the data subject or their nominated data controller where it is possible and technically feasible for us to do so.
14.6. Where you have provided your data voluntarily by Consent you have the right to withdraw your Consent at any time. However, withdrawal of Consent does not affect the lawfulness of any processing of your data based on your Consent prior to its withdrawal.
14.7. Where we need to process data for the purposes of entering into a Contract with you, if you fail to provide such data it may mean that we cannot establish legal relations between us and the contract may not be able to go ahead. We will inform you if this happens.
14.8. Automated decision making and profiling means making decisions without human intervention, usually with the use of a computer program or software. We may use automated decision making about you if it is necessary for entering into or performing a Contract with you or where you Consent to the actions.
14.9. Please note we will retain and use your personal information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. If we need to use your data for a reason it was not collected and you are not aware of this, we will inform you and in appropriate cases obtain your further consent to such use.
14.10. If we process data about you but we have not obtained the data personally from you, we must provide you with the information described in this Privacy Notice and some additional information.
14.11. The additional information will be provided to you at least by the time we contact you and in any event within the space of one month after we obtain it.
14.12. If the processing is based on Legitimate Interests, you are entitled to know what and whose Legitimate Interests they are.
14.13. You are entitled to know the purpose of the processing, whether we or someone else is processing it and the categories of Personal Data involved.
14.14. You are entitled to know the source of the information and whether the source is publicly accessible.
14.15. There are some exceptions to this additional information rule. If we obtain your Personal Data from a source other than yourself, the additional information rules will apply unless:-
14.16. We do not use the lawful basis of Legitimate Interests for processing data.
OR We use the lawful basis of Legitimate Interests for processing data in the following circumstances:
14.17. Our Specific Legitimate Interests are:
14.17.1. Video Conferencing
14.17.2. CCTV
14.17.3. Video Conferencing
14.17.4. Dashcams
14.17.5. Soft Opt in
14.18. You have the right to complain to the Data Regulator at the Information Commissioners Office on 0303 123 1113 or through their website www.ico.org.uk.
15.1. Our site is not directed at children and should not be accessed by them.
15.2. We will not knowingly collect information from persons under 13 years of age without their parent's or guardian's consent.
15.3. If a Parent or Guardian of a person under 13 years of age discovers their child has engaged with our Website without their consent, please inform us immediately using the contact email provided above.
15.4. We have considered the elements of the AADC (Children’s code) in relation to our Online activity and concluded that we are not a relevant Information Society Service which is likely to be accessed by children.
15.5. There is nothing on our Website which could be damaging to children who view the pages or the pictures.
15.6. The products on our Website are only available and relevant to adults over the age of 18 years.
15.7. We protect the rights of the child in accordance with the UNCRC and the AADC by [trading only with adults] OR [using self-certifying Age Gate Technology on pages where payments can be made.]
16.1. From time to time our site may contain links to and from the websites of our suppliers or other third party sites.
16.2. If you visit any of these sites you should confirm they have their own privacy policies and you should check these before submitting any personal data on their site. We cannot accept any responsibility or liability for the policies on any other Websites.
17.1. You have rights of access to the data we hold about you. Should you wish to exercise these rights please contact our Data Manager whose details are given above.
17.2. There is usually no charge for the Data Access service. As soon as we are satisfied as to your identity, we will send you, without delay and in any case within one Month, the Personal Data we hold relating to you, which we are legally obliged to provide.
17.3. We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that your Personal Data is not disclosed to anyone who has no right to receive it.
17.4. In the event we need more time to gather the requested information we will let you know without delay and in any event within one month.
17.5. A fee may be payable for Data Access services if the request(s) are manifestly unfounded or excessive or repetitive in nature. Alternatively, we may choose to ignore this type of request. In these cases we will inform you of our decision and if applicable any fee that may be required.
17.6. Please contact us if you believe that any personal data or information which we hold about you is incorrect or incomplete. Any information or data which is found to be incorrect will be corrected as soon as practicable.
17.7. Please contact us if you wish to have your personal data removed entirely from our systems. As soon as we are satisfied as to your identity and the data is not required to be kept for any other lawful reason or purpose it will be removed from our systems forthwith.
17.8. If you so wish, your Data will be provided to you electronically in a commonly used format such as email.
17.9. If you are unhappy with any of the responses given to you by us you may complain about us to the regulator at the Information Commissioners Office on 0303 123 1113 or through their website www.ico.org.uk.
18.1. In the event our business, or part of it, is taken over, bought or merged with another business we may need to disclose any personal data we are holding about you to the other Company so they can continue to provide services to you in accordance with this Privacy Policy.
18.2. It may be necessary to transfer your data to a Company that is negotiating with us for the purchase of our business but only where it is necessary to evaluate the business purchase transaction.
18.3. In the case of a pre-sale transfer of personal data, the data would be kept safe during the negotiations and destroyed by the third party if the sale or merger did not go ahead.
19.1. There may be developments in how we use your data according to changes in the Law.
19.2. We reserve the right to make changes to this Data Protection and Privacy Policy at any time without notice and it is your responsibility to revisit this page from time to time to re-read this policy including any and each time you visit our website.
19.3. Any revised terms shall take effect as at the date of posting.
19.4. If you don’t find your concern addressed here, feel free to contact us by e-mailing our Data Manager at the contact details given above.
All emails sent by the system contain a tracking pixel. This is used to track whether each email has been opened by the recipient, and when. This information can be viewed by those users of the system with permission to view email delivery reports. We do not display any information regarding the location of the recipient. Note that the tracking pixel is only activated if the recipient chooses to download images into their email client.
We, The Wimbledon Club, make use of the myClubhouse software supplied by Simmetrics Ltd to process personal data we include on our myClubhouse website in accordance with our privacy policy set out above. Simmetrics Ltd processes your personal data on our behalf and they can only do so in accordance with our written instructions. You can find the details of our data processor’s privacy policy here: http://www.myclubhouse.co.uk/Home/PrivacyPolicy.