Privacy Notice & Data Protection

How we protect your data

What Data We Collect

To provide security, maintenance, and incident management services, we collect:

  • Guest names, accommodation details, and stay dates
  • Security incident reports and witness statements
  • First aid and health-related incident information
  • Work order and maintenance requests
  • Lost property and missing person reports
How We Protect Your Data
Encryption: All sensitive guest and personal data is encrypted at rest using AES-256-GCM, military-grade encryption. Data in transit is encrypted using HTTPS (TLS 1.2+).
Access Control: Only authorized staff with proper roles can access sensitive data. All access is logged and auditable.
Security: We use secure, automated backups and follow UK GDPR technical standards for data protection.
Data Retention & Deletion
Retention Period: Guest and incident data is automatically deleted 90 days after collection. This balances operational needs with privacy.
Manual Deletion: Site managers can request manual deletion of specific records at any time via the Data Management page.
Right to Erasure: Guests and individuals have the right to request deletion of their personal data. Contact your site manager or admin.
Your GDPR Rights

Under UK GDPR, you have the right to:

  • Access: Request a copy of your personal data we hold
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data (right to be forgotten)
  • Restrict Processing: Limit how we use your data
  • Portability: Receive your data in a portable format
  • Object: Object to certain uses of your data

To exercise these rights, contact your site manager or the site's authorized contact.

Data Controller

Each holiday park/resort site is the data controller for personal data collected at that location. The site's authorized contact is responsible for data protection compliance and GDPR requests.

Contact your site management for any privacy or data protection questions.

Last updated: May 2026