Summary of how R360 use your data
- R360 uses your personal data to manage and administer your involvement with its courses and events, and to keep in contact with you for these purposes
- Data will not be shared with parties other than those involved in the R360 courses.
- Where we rely on your consent, such as any consent we seek for email marketing, you can withdraw this consent at any time.
- Amongst the data we collect from you may be medical (including injury) information. We will hold this where you (or your parent) have given consent, so that we can ensure we are aware of your condition and can that you are supported appropriately.
What does this policy cover?
This policy describes how R360 (also referred to as “the Club”, “we” or “us”) will make use of the data we handle in relation to our attendees.
It also describes your data protection rights, including a right to object to some of the processing which we carry out. More information about your rights, and how to exercise them, is set out in the “What rights do I have?” section.
What information do we collect?
Wecollect and process personal data from you or your parent when you join and when we carry out annual renewals of your membership. This includes:
- your name
- your gender,
- your date of birth,
- your home address, email address and phone number;
- your clothing sizes
- your payment and/or bank account details, where you provide these to pay for attending courses;
- your marketing preferences, including any consents you have given us;
- your medical conditions or disability, where you provide this to us with your consent (or your parent’s consent) to ensure we are aware of any support we may need to provide to you.
Some information will be generated as part of your involvement with us, in particular data about your performance, involvement in particular matches in match reports and details of any disciplinary issues or incidents you may be involved in on and off the pitch, such as within health and safety records.
What information do we receive from third parties?
Sometimes, we receive information about you from third parties. For example, if you are a child, we may be given information about you by your parents.
We may receive information from the Disclosure and Barring Service and RFU on the status of any DBS check you have been required to take.
How do we use this information, and what is the legal basis for this use?
We process this personal data for the following purposes:
- To fulfil a contract, or take steps linked to a contract: this is relevant where you make a payment for your attendance or any merchandise. This includes:
- taking payments;
- communicating with you;
- providing and arranging the delivery or other provision of products, prizes or services;
- As required by the Club to conduct our business and pursue our legitimate interests, in particular:
- we will use your information to manageand administer your membership and your involvement with its teams and club, and to keep in contact with you for these purposes;
- we use CCTV cameras to maintain the security of our premises, and may use this video to investigate incidents at our venues;
- we may choose to send you promotional materials and offers by post or by phone, or by email where we want to send you offers relating to similar products and services that you have already .
- we use data of some individuals to invite them to take part in market research;
- Where you give us consent:
- we will send you direct marketing or promotional material by email;
- we may handle medical or disability information you or your parent provides to us, to ensure we support you appropriately;
- on other occasions where we ask you for consent, we will use the data for the purpose which we explain at that time.
- For purposes which are required by law:
- we maintain records such as health and safety records and accounting records in order to meet specific legal requirements;
- we ensure, where you will work with children, that you have undergone an appropriate DBS check – this is also carried out with your consent.
- where you hold a role at the Club requiring us to check your right to work, we may process information to meet our statutory duties;
- we may respond to requests by government or law enforcement authorities conducting an investigation.
Withdrawing consent or otherwise objecting to direct marketing
Wherever we rely on your consent, you will always be able to withdraw that consent, although we may have other legal grounds for processing your data for other purposes, such as those set out above. In some cases, we are able to send you direct marketing without your consent, where we rely on our legitimate interests. You have an absolute right to opt-out of direct marketing, or profiling we carry out for direct marketing, at any time. You can do this by following the instructions in the communication where this is an electronic message, or by contacting us using the details set out below in the “How do I get in touch with you?” section.
Who will we share this data with, where and when?
We will not share your data with any third party.
Some limited information may be shared with other stakeholders in rugby, such as other clubs, Constituent Bodies, referee societies, league organisers, so that they can maintain appropriate records and assist us in organising matches and administering the game.
Personal data may be shared with government authorities and/or law enforcement officials if required for the purposes above, if mandated by law or if required for the legal protection of our or the RFU’s legitimate interests in compliance with applicable laws.
Personal data will also be shared with third party service providers, who will process it on our behalf for the purposes identified above. Such third parties include the providers of MailChimp, who we use to provide our email marketing.
Where information is transferred outside the EEA, and where this is to a stakeholder or vendor in a country that is not subject to an adequacy decision by the EU Commission, data is adequately protected by EU Commission approved standard contractual clauses, an appropriate Privacy Shield certification or a vendor’s Processor Binding Corporate Rules. A copy of the relevant mechanism can be provided for your review on request.
What rights do I have?
You have the right to ask us for a copy of your personal data; to correct, deleteor restrict(stop any active) processing of your personal data; and toobtain the personal data you provide to us for a contract or with your consent in a structured, machine readable format.
In addition, you can object to the processingof your personal data in some circumstances (in particular, where we don’t have to process the data to meet a contractual or other legal requirement, or where we are using the data for direct marketing).
These rights may be limited, for example if fulfilling your request would reveal personal data about another person, or if you ask us to delete information which we are required by law to keep or have compelling legitimate interests in keeping.
Much of the information listed above must be provided on a mandatory basis so that we can make the appropriate legal checks and register you as required by RFU Rules and Regulations. We will inform you which information is mandatory when it is collected. Some information is optional, particularly information such as your medical information. If this is not provided, we may not be able to provide you with appropriate assistance, services or support.
How do I get in touch with you?
We hope that we can satisfy queries you may have about the way we process your data. If you have any concerns about how we process your data, or would like to opt out of direct marketing, you can get in touch at firstname.lastname@example.org.
How long will you retain my data?
We process the majority of your data for as long as you are an active member and for 2 years after this.
Where we process personal data for marketing purposes or with your consent, we process the data for 2 years unless you ask us to stop, when we will only process the data for a short period after this (to allow us to implement your requests). We also keep a record of the fact that you have asked us not to send you direct marketing or to process your data indefinitely so that we can respect your request in future.
Where we process personal data in connection with performing a contract or for a competition, we keep the data for 2 years from your last interaction with us.
We will retain information held to maintain statutory records in line with appropriate statutory requirements or guidance.