UKSA are committed to protecting and respecting your privacy.
At a glance (summary)
- We collect only what we need to run our programmes safely, fairly and well.
- We ask for medical information for all participants so we can keep people safe. A “no medical needs” answer is still medical data under data protection law.
- We may use CCTV and body worn video for safety and safeguarding, with strict rules.
- We sometimes ask optional questions (e.g., funding eligibility, inclusion, religion/belief for food and prayer needs). You can skip these.
- We follow UK GDPR, PECR, safeguarding law and sector codes. We also take account of the Data Use and Access Act 2025 where relevant.
- You can change marketing preferences or ask for your data at [email protected].
or write to :
Data Protection Lead
UKSA
Arctic Road
Cowes
Isle of Wight
PO31 7PQ
This privacy policy covers:
- Who we are
- The information we collect and how we use it
- Who will have access to your information
- Your choices
- Your Data Protection Rights
- Security precautions in place to protect the loss, misuse, or alteration of your information
- Use of cookies
- Links to other websites and transfer of data outside of UK
- How to complain
Review of this Policy: We keep this Policy under regular review. This Policy was last updated on 23rd February 2026.
UKSA is a registered charity providing maritime training, youth development, residentials and career pathways, based in Cowes, Isle of Wight (Charity 299248; Company 02251024). Address: Arctic Road, Cowes, Isle of Wight, PO31 7PQ.
We comply with: UK GDPR and the Data Protection Act 2018; the Privacy and Electronic Communications Regulations (PECR); the Charity Commission’s guidance; the Fundraising Regulator’s Code; safeguarding law; and, where relevant, the Data Use and Access Act 2025 (DUAA) and any related codes or regulations (we keep this under review). Contact us: [email protected].
We collect information we genuinely need to deliver our services, safeguard participants, meet legal duties, secure funding and show our charitable impact.
2.1 Basic details
Name, date of birth, contact details; emergency contacts.
2.2 Booking & programme information
Booking forms; attendance, assessment and certification records; school or group details.
2.3 Medical & special category information (everyone who books)
We collect medical information for all participants as part of our duty of care. This includes allergies, medical conditions, disability or additional support needs, dietary requirements, and the content of medical forms (including a declaration of no medical issues, which is still medical data). We use this to keep people safe, make reasonable adjustments and respond in emergencies.
2.4 Religious or philosophical belief (optional)
To make appropriate arrangements (for example, food requirements and access to prayer facilities), we may ask for limited information about your religion or belief. These questions are optional and you can say “prefer not to say”. We use this only to accommodate needs and foster inclusion.
2.5 Financial information
Payment details (processed securely by providers), donations and Gift Aid information.
2.6 Website & digital
Cookies/analytics, device identifiers and IP addresses.
2.7 Photos & videos
Images taken during activities (only used externally with consent); testimonials/case studies (with consent). See also safeguarding guidance.
2.8 CCTV
CCTV operates in entrances/exits, public indoor areas, operational zones and external grounds to keep people safe and protect property (never in bedrooms, bathrooms, toilets, showers or changing rooms).
2.9 Body-worn cameras (BWC)
For safeguarding, welfare and incident response, trained staff may use body-worn video in specific contexts. We follow our Body Worn Camera Procedure based on the Surveillance Camera Code’s 12 principles (announcements, limited use, secure storage, short retention). BWCs are not used in private spaces.
2.10 Demographic, funding & impact information
We collect limited information to assess eligibility, monitor inclusion and demonstrate impact:
· Funding applications (children & young people): nonidentifying, group level data (e.g., socioeconomic indicators, school demographic profiles) to check eligibility and allocate support fairly. We don’t collect names at this stage.
· Optional demographic questions (medical forms): Free School Meals/Pupil Premium/Universal Credit, EAL, care/caring, armed forces affiliation, ethnicity. These are optional with a clear optout.
· Anonymised programme level data: e.g., SEND, mental health indicators, neurodiversity, water confidence. We analyse only in groups large enough to protect identity.
· Adult careers funding: employment status, income/outgoings (and, rarely, parental income) to assess eligibility per funder rules.
This supports fair access, evaluation and funding reports.
2.11 Internet filtering and monitoring
To help keep our systems secure, protect children and vulnerable people, and ensure appropriate use of our IT systems, we use an internet filtering and monitoring system. When you use our network or organisation‑managed devices, this system may record:
· websites and URLs accessed or attempted
· search terms entered into search engines; and
· attempts to access blocked or restricted content.
This information is linked to a user account or device.
We rely on different lawful bases depending on the activity:
Contract – to process bookings, deliver programmes safely and provide essential updates.
Legal obligation – to meet duties to regulators/authorities/accrediting bodies (e.g., Ofsted, ESFA, RYA, MCA, HMRC).
Vital interests – for emergencies and safeguarding life.
Legitimate interests – to run UKSA effectively: safety/security; improving services; alumni contact; postal marketing; email/SMS under PECR soft opt-in; CCTV; body-worn cameras for safeguarding and incident response; maintaining IT security, preventing access to illegal or harmful online content, and supporting safeguarding through proportionate internet filtering and monitoring; anonymised impact reporting. We balance our interests with your rights.
Consent – for email/SMS marketing (where soft opt-in doesn’t apply), fundraising messages, identifiable photos/video, optional religion/belief questions, optional demographic questions, surveys/case studies. You can withdraw consent any time.
Public interest / safeguarding – where required to protect children or vulnerable adults (see UKSA safeguarding policy and procedures [link]).
Special category data conditions (Article 9 UK GDPR)
- Health data: explicit consent and/or vital interests; safeguarding/health & care conditions in DPA 2018 Schedule 1 (where applicable).
- Religion/belief: explicit consent; and, where appropriate, substantial public interest (equality of opportunity or treatment) under DPA 2018 Schedule 1 with an Appropriate Policy Document.
- Equality/inclusion monitoring: substantial public interest (equality of opportunity) with safeguards and an Appropriate Policy Document.
Criminal offence data
If recordings (e.g., BWC/CCTV) or capture potential criminal offence data, we rely on DPA 2018 Schedule 1 substantial public interest conditions such as preventing or detecting unlawful acts, with safeguards, DPIA and access controls in place.
We send marketing only when: (a) you’ve opted in (email/SMS); or (b) we rely on legitimate interests (post); or (c) the soft opt-in applies (you gave details during a booking/enquiry/purchase; we market similar services; you had a clear opt-out then; and every message has an unsubscribe). You can change preferences or opt out any time.
We may use trusted third-party processors (e.g., email platforms/CRMs) to manage marketing lists and send messages on our behalf. They must follow UK GDPR, act only on our instructions and never use your data for their own marketing.
Where used: entrances/exits, external grounds, reception areas, corridors, equipment stores, and during specific operational activities (BWC).
Not used: bedrooms, changing rooms, toilets, showers or other private areas.
Retention: normally up to 30 days (BWC under short retention per procedure); longer if required for investigations.
Access: restricted to trained staff (and, where appropriate, safeguarding/security leads) and police/insurers where legally justified.
This information is linked to a user account or device and is used to:
- enforce website blocking and content controls;
- identify potential safeguarding concerns;
- maintain network security; and
- investigate suspected misuse of our IT systems.
Date is retained for one month unless relates to a potential safeguarding concern or an investigation into suspected misuse of our IT system, where is will be retained in accordance with our data retention and records framework.
We do not use routine internet monitoring for performance management.
In some circumstances, monitoring data may incidentally reveal special category data (for example through search terms or attempted website access). Where this occurs, processing is limited to what is necessary, and appropriate safeguards are in place.
- Deliver programmes, accommodation, meals and pastoral support safely and inclusively.
- Provide adjustments (medical, disability, religion/belief – food and prayer facilities).
- Support grant applications, evaluate outcomes and report impact (anonymised).
- Manage donations and Gift Aid.
- Maintain safety and security (including CCTV and body-worn cameras).
We do not sell your information.
We may share information with: emergency services; the LADO; schools/group organisers; accreditation/regulatory bodies (MCA, RYA, Ofsted, ESFA, HMRC); IT/CRM/secure payment providers (including internet filtering and monitoring providers acting under our instructions); third-party marketing processors acting under contract; police/insurers for incident investigation. All suppliers must follow UK GDPR and our contracts.
If we transfer data outside the UK, we use UK adequacy regulations or UK International Data Transfer Agreements (IDTAs) and appropriate safeguards.
- Medical forms: programme end + up to 12 months (longer if linked to an incident).
- Safeguarding records: statutory periods.
- Accident/incident records: general 3 years from data of incident, up to age 25 (children).
- Course records/certification: 7–10 years.
- Donations & Gift Aid: 6 years (HMRC).
- Marketing preferences: 5 years after last contact for audit.
- CCTV/BWC: usually up to 30 days; longer if part of an investigation.
We apply detailed retention rules in our Retention & Records procedure.
You can:
- Access your data; ask us to correct or complete it.
- Ask us to delete it (where allowed) or restrict/stop certain uses.
- Object to marketing and profiling.
- Change marketing preferences or withdraw consent at any time. Email [email protected]. We normally respond within one month.
Our website uses cookies for functionality and analytics. You can control cookies in your browser settings.
This notice does not cover external websites we link to.
If you have concerns, contact [email protected]. You can also complain to the UK Information Commissioner’s Office (ICO).
We review this notice at least annually, or sooner if laws or our practices change.