Privacy Policy

Last Updated: [Insert Date]

At GoMtbkids we are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you visit our website, book an activity with us, or fill out our forms, in accordance with the General Data Protection Regulation (GDPR).

1. Data Controller Contact Details

For the purposes of the GDPR, we are the Data Controller. If you have any questions about this privacy policy or how we handle your data, please contact us:

  • Business Name: Gomtbkids 

  • Contact Person: Kevin Turner, Founder

  • Email Address: gomtbkids@gmail.com

  • Postal address: 1 Hatherden Avenue , Poole, BH140PJ

2. The Data We Collect and Why We Collect It

We only collect personal data that you voluntarily provide to us. We use third-party tools to process this data safely.

A. When You Browse Our Website (Squarespace)

  • What we collect: IP addresses, cookie identifiers, and website usage data (via browser cookies).

  • Purpose: To ensure our website functions correctly, analyze traffic, and improve your user experience.

  • Legal Basis: Consent (via our cookie banner) and Legitimate Interests.

B. When You Book an Activity (Acuity Scheduling)

  • What we collect: Your name, email address, phone number, and appointment date/time.

  • Purpose: To manage, schedule, and confirm your activity bookings, and to send you automated booking reminders.

  • Legal Basis: Performance of a Contract (we need this data to provide the service you booked).

C. When You Complete a Pre-Activity Form (Jotform)

  • What we collect: Rider information, emergency contact details, health/fitness declarations, waiver agreements.

  • Purpose: To safely prepare for and conduct the activities you have booked, and to comply with health and safety regulations.

  • Legal Basis: Performance of a Contract.

3. Third-Party Data Processors

To run our business, we share your data with trusted third-party service providers who act as Data Processors. These providers are bound by strict Data Processing Agreements (DPAs) to keep your data safe:

  • Squarespace: Hosts our website and handles basic web analytics. (Data may be transferred to the US under secure EU-US Data Privacy Framework agreements).

  • Acuity Scheduling (a Squarespace company): Manages our booking system and appointment details.

  • Jotform: Processes our intake and registration forms. Your form data is securely stored on encrypted servers located within the European Union (Frankfurt, Germany).

4. How Long We Keep Your Data

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or insurance reporting requirements.

  • Booking & Intake Records: Retained for up to 7 years after your last activity with us for insurance and tax purposes.

  • General Inquiries: Retained for up to 7 years after our last communication.

5. Your Rights Under GDPR

Under the GDPR, you have the following rights regarding your personal data:

  • The Right to Access: You can request a copy of the personal data we hold about you.

  • The Right to Rectification: You can ask us to correct inaccurate or incomplete data.

  • The Right to Erasure ("Right to be Forgotten"): You can ask us to delete your personal data (provided we do not have a legal obligation or insurance requirement to keep it).

  • The Right to Restrict/Object to Processing: You can object to us processing your data under certain circumstances.

  • The Right to Data Portability: You can request that we transfer your data to another organization.

To exercise any of these rights, please contact us at gomtbkids@gmail.com. We will respond to your request within one month.

If you believe we have not processed your data legally, you have the right to lodge a complaint with your local Data Protection Authority (e.g., the ICO in the UK or your national EU authority).

6. How We Protect Your Data

We take data security very seriously. Access to your data is strictly limited to authorized personnel who need it to run the activities. All data captured via Jotform and Acuity is encrypted during transit and at rest where possible, and our backend systems are protected by secure passwords and two-factor authentication (2FA).