General information notice. This document is provided for transparency. It does not constitute legal advice. If you require formal legal interpretation of your data rights, please consult a qualified solicitor or the UK Information Commissioner’s Office (ICO).
1. Who we are
Bournemouth Music School Ltd (“we”, “our”, “us”) is a small music tuition business operating in Bournemouth, Dorset, United Kingdom. We are the data controller responsible for your personal information for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
For any data-protection enquiry you can contact us at hello@bournemouthmusicschool.com.
2. What personal data we collect
We only collect what we need to deliver lessons safely and professionally:
- Identity data: first name, last name, and (for children) the parent or guardian’s name.
- Contact data: email address, phone number, and (where applicable) home address for in-home visit lessons.
- Account data: a hashed password and authentication tokens managed by our identity provider, Clerk.
- Booking data: the lessons you book, reschedule, or cancel, plus any package credits you hold.
- Payment data: we do not store your card details. Payment processing is handled entirely by Stripe; we only retain a transaction reference, the amount paid, and the time of the transaction.
- Communications data: emails you send us and any notes we keep relating to your tuition (e.g. preferred repertoire, ABRSM grade level).
- Technical data: IP address, browser type, and device information collected by our hosting provider for security and abuse-prevention.
3. How we use your data
We use your personal data to:
- Schedule, confirm, and manage your piano lessons.
- Process payments and send you receipts.
- Send transactional email such as booking confirmations, reschedule notices, and cancellation confirmations.
- Communicate with you about your tuition, lesson materials, or ABRSM exam preparation.
- Maintain accounting records as required by HM Revenue & Customs.
- Detect and prevent fraud, abuse, or unauthorised access to our systems.
4. Lawful basis for processing
We rely on the following lawful bases under Article 6 of the UK GDPR:
- Performance of a contract — processing your bookings, payments, and account information so we can deliver the lessons you have purchased.
- Legal obligation — retaining transaction records for HMRC tax purposes, and complying with safeguarding duties when teaching minors.
- Legitimate interests — preventing fraud, maintaining the security of our website, and improving our services. We balance this against your rights and freedoms.
- Consent — for any optional marketing communications. You may withdraw consent at any time by emailing us or using the unsubscribe link in our emails.
5. Who we share your data with
We use a small number of carefully selected third-party processors to run the school. Each is contractually required to protect your data and to use it only for the purposes we instruct:
- Stripe Payments Europe Ltd — processes all card payments. Stripe is PCI-DSS Level 1 certified. See Stripe’s privacy policy.
- Clerk Inc. — handles user authentication (sign-up, sign-in, password reset). See Clerk’s privacy policy.
- Resend — sends transactional email (booking confirmations, reschedule notices, receipts). See Resend’s privacy policy.
- Railway — hosts our website and database in the EU/UK region. See Railway’s privacy policy.
We never sell your personal data, and we do not share it with advertisers, brokers, or social-media platforms for targeted advertising.
6. International transfers
Some of our processors (notably Stripe and Clerk) are headquartered in the United States. Where data is transferred outside the UK or EEA, the transfer is protected by Standard Contractual Clauses (SCCs) and/or the UK Extension to the EU–US Data Privacy Framework, in line with the requirements of the UK GDPR.
7. How long we keep your data
- Active client data: kept for as long as you are an active student, plus a reasonable grace period in case you return.
- Financial records: kept for 7 years from the end of the relevant accounting year, in line with HMRC requirements.
- Email correspondence: kept for up to 3 years unless it forms part of a financial record.
- Inactive accounts: if you have not booked a lesson for 24 months, we may delete or anonymise your booking data on request or as part of our routine data minimisation.
8. Your rights under UK GDPR
You have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”) — ask us to delete your personal data, subject to our legal obligation to retain financial records.
- Restriction — ask us to pause processing while a query is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing carried out under the legitimate-interests basis.
- Withdraw consent — for anything you have previously consented to (e.g. marketing emails).
- Complain — lodge a complaint with the UK Information Commissioner’s Office at ico.org.uk.
To exercise any of these rights, email hello@bournemouthmusicschool.com. We will respond within one calendar month.
9. Cookies
We use a small number of essential cookies to keep you signed in and to process payments securely. We do not use advertising or cross-site tracking cookies. Full details are in our Cookie Policy.
10. Children’s data
We frequently teach children. Where a student is under the age of 13, the booking and payment account must be created by a parent or legal guardian who provides explicit consent for us to process the child’s information.
We collect the minimum data needed to deliver lessons safely (typically the child’s first name and the parent’s contact details). The teacher holds an enhanced DBS certificate and follows safeguarding procedures consistent with UK best practice for peripatetic music tutors.
11. Security
We take security seriously. All data in transit is encrypted with TLS 1.2+, all data at rest is encrypted in our database, passwords are hashed by Clerk (we never see your password in plaintext), and we use industry-standard protections such as Helmet HTTP headers, rate limiting, and input validation. Full detail is in our Data Security Statement.
In the unlikely event of a personal-data breach, we will notify the ICO within 72 hours and will inform any affected individuals directly without undue delay, as required by Article 33 of the UK GDPR.
12. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of this page indicates the most recent revision. Material changes will be communicated by email where you have an active account.
13. Contact
For all data-protection enquiries, including subject access requests, please email hello@bournemouthmusicschool.com.
