Legal
Privacy Policy
Last updated: 6 August 2026
1. Who this policy applies to
This Privacy Policy explains how personal information is collected and used when you visit vortexcentre.com, contact us, join our community, register for or attend an event, buy a service, make a voluntary contribution, participate in a programme, or appear in event media.
2. The data controller
The data controller is Jim McFadyen, a sole trader trading as The Vortex Centre for Wellbeing.
Contact details:
151A Hyndford RoadLanark
ML11 9BG
Email: info@team.vortexcentre.com
Telephone: +44 7700 144573
3. Information we may collect
Depending on how you interact with us, we may collect:
- identity and contact details, such as name, date of birth or age confirmation, address, email address and telephone number;
- booking and attendance details, including the event selected, timestamps, acceptance records, check-in status and communications;
- payment and transaction details, although complete payment-card details are normally held by the payment provider rather than us;
- health and accessibility information that is relevant to safe participation, reasonable adjustments or an emergency;
- emergency-contact details that you provide, after you have told that person that their details will be shared with us;
- correspondence, enquiries, complaints, feedback, reviews and survey responses;
- marketing choices and a record of when and how consent was obtained or withdrawn;
- photographs, video and audio from events where appropriate notice and a lawful basis apply;
- website and device information, such as IP address, browser, pages viewed, referral source and cookie identifiers, subject to cookie choices; and
- information supplied by a parent, guardian, booking partner, payment provider, venue, facilitator or emergency service where it is lawful and necessary to receive it.
Please do not send detailed medical records or information that we have not asked for.
4. Why we use information and our lawful bases
We use personal information only where a lawful basis applies.
Enquiries and bookings
We use contact, booking and payment information to answer enquiries, take steps requested before a contract, confirm bookings, provide services, process payments and handle cancellations. The lawful basis is contract or steps taken at your request before a contract.
Event administration and safety
We use attendance information, emergency contacts and non-medical safety information to plan capacity, check people in, communicate essential changes, manage the event and respond to incidents. The lawful basis is contract and our legitimate interests in operating safe, effective events.
Health information
Health information is special-category data. Where we ask for it for screening, adjustments or participation decisions, we normally rely on your consent under Article 6(1)(a) and your explicit consent under Article 9(2)(a) of the UK GDPR.
You may withdraw consent, but we may be unable to approve participation in an activity if we cannot obtain information reasonably needed for safety. Withdrawal does not make earlier lawful use unlawful.
In a genuine emergency where a person cannot give consent, we may use or share necessary information to protect life under the vital-interests bases in Articles 6(1)(d) and 9(2)(c). Where necessary for an actual or properly anticipated legal claim, we may rely on legitimate interests and Article 9(2)(f).
Essential communications
We may send booking confirmations, safety instructions, reminders, access details and material event changes without marketing consent because these messages are necessary to administer the booking. We will not add unrelated promotions to a message and call it essential.
Marketing
We send promotional email, text message or WhatsApp messages to individuals only where we have the consent required by data-protection and electronic-marketing law, or where a lawful exception clearly applies. Consent for email and for text or WhatsApp is requested separately.
You can unsubscribe at any time using the link in an email, replying STOP where supported, or contacting us. We keep a minimal suppression record so that we do not contact you again against your wishes.
We do not use health information to target marketing.
Photography, video and audio
We normally use separate consent for identifiable close-ups, interviews, testimonials and promotional features. Consent is optional and can be withdrawn for future use.
We may use non-intrusive wide images of an event on the basis of our legitimate interests in documenting and promoting our work, where this is fair, proportionate and clearly notified. You can object and use the event no-photo process. We will not knowingly make an opted-out person the subject of promotional content.
Website operation, security and improvement
We use necessary technical information to operate and secure the website. With consent where required, we use analytics or advertising technologies to understand use and measure campaigns. The lawful bases are legitimate interests for necessary security and consent for non-essential storage, access and associated processing.
Legal, accounting and complaints
We use relevant records to keep accounts, meet tax and regulatory duties, prevent fraud, respond to complaints, notify insurers and establish or defend legal claims. The lawful bases are legal obligation and legitimate interests.
5. Data minimisation and access to health information
We aim to collect only health information reasonably needed for safety. Access is restricted to people who need it for screening, adjustments, first aid, emergency response, insurance or legal handling.
Do not place health details in general marketing notes, broad team chats or audience lists. We do not sell health information and do not use it to profile people for advertising.
6. Who we may share information with
Where necessary and lawful, information may be shared with:
- authorised staff, facilitators and volunteers on a need-to-know basis;
- venues, event contractors, first-aid providers, competent water-safety or rescue providers and emergency services;
- website hosting, customer-relationship management, form, booking, email, messaging, cloud-storage and IT-support providers acting under contract;
- payment processors, banks and accountants;
- professional advisers, insurers and claims handlers;
- analytics, advertising and social-media providers where the required consent or other lawful basis exists; and
- police, regulators, courts, local authorities or other bodies where disclosure is required by law or is necessary to protect life or legal rights.
Service providers may use information only for the contracted purpose unless they are an independent controller and provide their own privacy information.
We do not sell personal information.
7. International transfers
Some service providers may process information outside the United Kingdom. Where that happens, we use a lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another safeguard permitted by law. Details of relevant safeguards are available on request.
8. How long we keep information
We keep information only for as long as needed for its purpose. Our usual periods are:
- unanswered or unconverted enquiries: up to 12 months after the last meaningful contact;
- ordinary free-event contact and attendance details: up to 12 months after the event, unless needed for a complaint, consent record or legal purpose;
- the record showing which terms were accepted, by whom, when and from which form version: up to five years after the event or end of the service;
- health-screening information where there was no incident: normally deleted or anonymised within 90 days after the event;
- incident, complaint, safeguarding, insurance and related health records: normally up to five years after the matter is closed, or longer where an insurer, court or law reasonably requires it;
- payment, invoice and tax records: for the period required by HMRC, which for a sole trader is generally at least five years after the relevant 31 January tax-return deadline;
- marketing records: while consent remains valid and for a reasonable period afterwards to demonstrate compliance, with suppression records retained as needed to honour an opt-out;
- raw event media not selected for use: normally reviewed and deleted within 12 months; and
- selected published media: for as long as it remains relevant and lawful, subject to objections, consent withdrawal and periodic review.
We may keep a record longer where there is an ongoing dispute, legal hold, safeguarding issue or clear statutory requirement. We may delete information earlier where it is no longer needed.
9. Security
We use proportionate organisational and technical measures to protect personal information. These include role-based access, strong authentication, secure service providers, staff confidentiality, restricted access to health records, backups and procedures for reporting a suspected breach.
No internet service can promise absolute security. Please contact us immediately if you believe information has been lost, misdirected or accessed without authority.
10. Your rights
Depending on the circumstances and lawful basis, you may have the right to:
- be informed about how information is used;
- obtain a copy of your personal information;
- correct inaccurate or incomplete information;
- ask for erasure;
- restrict processing;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- receive certain information in a portable format; and
- withdraw consent without affecting earlier lawful processing.
These rights are not absolute. For example, we may need to retain information required by tax law or needed for a legal claim.
To exercise a right, email info@team.vortexcentre.com. We may request reasonable proof of identity. We normally respond within one month.
11. Automated decisions
We do not make solely automated decisions about event participation that produce legal or similarly significant effects. A human reviews any safety concern that may lead to refusal or an adjustment.
12. Children and young people
Participant services are generally for people aged 16 and over. For a 16 or 17-year-old, we may collect both the young person’s details and a parent or guardian acknowledgement as an additional safeguard. The young person’s own views and privacy remain important.
We do not knowingly collect participant information from a child under 16 through general booking forms. Contact us if you believe this has occurred.
13. Emergency contacts
If you give us another person’s details as an emergency contact, tell them that you have done so and direct them to this policy. We use their details only for safety, incident response and related administration unless another lawful reason applies.
14. Cookies
Our Cookie Policy explains the technologies used on the website and how to change preferences. Non-essential analytics and advertising technologies must not be activated before the required consent is obtained.
15. Complaints
Please contact us first so we can try to resolve a concern:
Email: info@team.vortexcentre.com
Post: Jim McFadyen trading as The Vortex Centre for Wellbeing, 151A Hyndford Road, Lanark, ML11 9BG
You also have the right to complain to the Information Commissioner’s Office. Information is available at https://ico.org.uk/make-a-complaint/
16. Changes to this policy
We may update this policy when our activities, service providers or the law change. The latest version will be published with its date. If a change materially affects an existing consent or how sensitive information is used, we will provide a more direct notice and obtain fresh consent where required.
Last updated: 6 August 2026