PRIVACY NOTICE AND DATA PROTECTION POLICY
Organisation: Boxology Limited
Trading names: Boxology® Academy and Boxology® Online
Company number: 10523458
Registered in: England and Wales
Registered office: Brook Cottage, High Street, Paulerspury, Towcester, England, NN12 7NR
Responsible person: Cathy Brown – Director and Data Protection Lead, Boxology Limited
Email: info@boxology.academy
Version: 3.0
Effective date: 3 August 2026
Review date: 3 August 2027, or sooner where legal, organisational, CIMSPA, technological or delivery arrangements change
1. Purpose
Boxology Limited is committed to handling personal information lawfully, fairly, transparently and securely.
This Privacy Notice and Data Protection Policy explains:
what personal information Boxology Limited collects;
where the information comes from;
why it is used;
the lawful bases relied upon;
how sensitive information is protected;
when information may be shared;
how long information is retained;
the rights available to individuals; and
how to raise a data-protection concern.
Boxology Limited processes personal information in accordance with applicable UK data-protection law, including the UK General Data Protection Regulation, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations.
2. Who is responsible for your information?
Boxology Limited is the data controller for personal information it collects and determines how to use in connection with its own:
commercial courses;
online learning;
memberships;
assessments;
certificates;
products and purchases;
websites;
enquiries;
events;
marketing;
employment and contractor relationships; and
programme-delivery responsibilities.
A data controller decides why and how personal information is processed.
Questions about Boxology Limited’s use of personal information should be sent to:
Email: info@boxology.academy
Post:
Boxology Limited
Brook Cottage
High Street
Paulerspury
Towcester
England
NN12 7NR
Boxology Limited has not appointed a formal Data Protection Officer. Cathy Brown is the responsible internal contact for data-protection matters.
3. Organisational separation
Boxology® Academy and Boxology® Online are commercial boxing-education brands operated by Boxology Limited. They are not separate legal organisations.
Boxology Limited is legally, financially and operationally separate from:
HEADGUARD C.I.C., company number 16212678, which is a community interest company and is not a registered charity; and
any separate HEADGUARD Charitable Incorporated Organisation that may be registered in the future.
Boxology Academy Limited, company number 10803282, was dissolved on 25 June 2019 and has no current activity, assets, control or role. Current use of the name “Boxology Academy” refers to a trading brand operated by Boxology Limited.
Personal information does not automatically transfer between:
Boxology Limited;
HEADGUARD C.I.C.; and
any future registered HEADGUARD CIO.
Each organisation is responsible for the personal information it collects and controls.
Where organisations work together, their respective responsibilities will be identified through an appropriate written agreement. Depending on the activity, they may act as:
separate independent data controllers;
joint controllers for a defined shared purpose; or
controller and processor.
Any future HEADGUARD CIO will have its own trustee-approved privacy arrangements following registration. This policy will not automatically become the CIO’s policy.
4. Who this policy applies to
This policy may apply to personal information about:
prospective learners;
current and former learners;
members and customers;
course and assessment participants;
children and young people;
parents, guardians and carers;
tutors, assessors and coaches;
employees, contractors and volunteers;
programme participants;
partner representatives;
website visitors;
event attendees;
people making enquiries or complaints;
people appearing in photographs, films or testimonials; and
members of the public who interact with Boxology Limited.
5. Information we may collect
Depending on the relationship and activity, Boxology Limited may collect:
Identity and contact information
name;
title;
date of birth or age;
postal address;
email address;
telephone number;
emergency-contact details;
photograph; and
account or learner identification number.
Booking, customer and account information
courses or services booked;
membership details;
products purchased;
transaction and invoice information;
payment status;
delivery information;
account login and access records;
communications; and
customer-service history.
Boxology Limited does not ordinarily retain full payment-card details. Payments are normally processed by an authorised payment provider.
Learning and assessment information
enrolment information;
prerequisite evidence;
attendance;
course progress;
assessment submissions;
practical-assessment recordings where required;
assessor feedback;
results;
resits;
certificates;
CPD information;
reasonable adjustments;
complaints and appeals; and
malpractice or quality-assurance records.
Health, safety and accessibility information
Physical Activity Readiness Questionnaire information;
injuries;
disabilities;
medical conditions relevant to participation;
pregnancy or postnatal information where relevant;
medication information where necessary for emergency safety;
accessibility requirements;
communication needs;
reasonable-adjustment information; and
emergency medical information.
Boxology Limited will not request a full medical history where more limited information is sufficient.
Safeguarding information
Where necessary, Boxology Limited may process information concerning:
a safeguarding concern;
suspected or disclosed abuse, neglect or exploitation;
risk to a child or adult at risk;
professional boundaries;
incidents;
referrals;
actions taken;
witnesses;
communications with partner organisations; and
reports to statutory agencies.
Equality and monitoring information
Where appropriate and proportionate, Boxology Limited may collect information concerning:
age;
disability;
race or ethnicity;
religion or belief;
sex;
gender reassignment;
sexual orientation;
pregnancy or maternity;
language;
socio-economic circumstances; or
other information relevant to evaluating access and inclusion.
Equality-monitoring information will normally be optional unless it is genuinely required for programme eligibility, safeguarding, safety, reasonable adjustments or lawful reporting.
Employment, contractor and volunteer information
This may include:
employment and contact details;
qualifications and professional experience;
references;
right-to-work information;
bank and tax information;
insurance;
training records;
performance and conduct information;
safeguarding checks; and
relevant criminal-offence or DBS information.
Boxology Limited will not normally retain a complete DBS certificate where recording the check date, level, outcome and reference is sufficient.
Website and technical information
This may include:
IP address;
browser and device information;
website activity;
login records;
security information;
cookie choices;
page interaction; and
technical-error information.
Further information is provided in the separate Cookie Notice.
Photography, filming and stories
This may include:
photographs;
video;
audio;
interviews;
testimonials;
case studies;
course demonstrations; and
personal stories.
Promotional use requires an appropriate separate permission or lawful basis and is not assumed merely because a person attends a course or programme.
6. How we obtain personal information
Boxology Limited may receive information:
directly from the individual;
from a parent or person with parental responsibility;
from an employer or organisation purchasing training;
from a tutor, assessor or contractor;
from a school or education provider;
from HEADGUARD C.I.C.;
from a charity, care service, refuge, safe house or community partner;
from a referral or commissioning organisation;
through an online-learning or membership platform;
through a website, payment or booking provider;
from CIMSPA where appropriate;
from publicly available professional information;
from a witness, complainant or safeguarding reporter; or
from an emergency, statutory or regulatory authority.
Where Boxology Limited receives information from another source, it will provide appropriate privacy information to the individual unless a lawful exception applies.
7. Why we use personal information
Boxology Limited may use personal information to:
respond to enquiries;
assess eligibility for a course or programme;
create and manage bookings;
enter into and perform contracts;
provide online or face-to-face education;
administer memberships;
process payments and refunds;
deliver products;
provide learner accounts;
record attendance and progress;
conduct assessments;
issue and verify certificates;
record CIMSPA CPD information;
provide reasonable adjustments;
support safe physical participation;
communicate course or service information;
manage safeguarding concerns;
administer complaints and appeals;
investigate malpractice or misconduct;
maintain quality assurance;
protect websites, systems and accounts;
prevent fraud and misuse;
comply with accounting, tax, consumer and legal requirements;
maintain insurance and legal records;
improve courses and services;
manage tutors, workers, contractors and volunteers;
administer partner programmes; and
send lawful marketing communications.
Boxology Limited will not use personal information for a materially incompatible new purpose without first considering the lawful basis and providing updated privacy information where required.
8. Lawful bases
Boxology Limited must have a lawful basis for every use of personal information.
Depending on the purpose, Boxology Limited may rely upon:
Contract
Processing may be necessary to:
take steps before entering into a contract;
manage an enrolment or purchase;
provide a course or membership;
process payment;
supply a product;
provide account access;
assess a learner; or
issue a certificate.
Legal obligation
Processing may be necessary to comply with legal duties relating to:
accounting and taxation;
health and safety;
consumer rights;
data protection;
safeguarding;
employment;
insurance;
court orders; or
lawful regulatory requirements.
Legitimate interests
Boxology Limited may process information where this is necessary for legitimate interests and those interests are not overridden by the individual’s rights.
Legitimate interests may include:
administering and improving services;
maintaining course and certificate records;
preventing fraud and account misuse;
protecting systems and intellectual property;
maintaining security;
quality assurance;
handling complaints;
managing business relationships;
defending legal claims; and
communicating with existing customers about relevant services where lawful.
Where legitimate interests are relied upon, Boxology Limited will consider necessity, proportionality and the impact on the individual.
Particular care will be taken where children are involved.
Consent
Consent may be used where an individual has a genuine choice, including for:
some marketing;
promotional photographs and films;
testimonials and personal stories;
optional information;
some forms of health information; and
other voluntary participation.
Consent must be specific, informed and freely given.
Consent may be withdrawn at any time. Withdrawal will not make earlier lawful processing unlawful.
Vital interests
Information may be used where necessary to protect someone’s life or respond to a serious medical emergency and the person cannot give consent.
9. Special-category information
Information about health, disability, race, ethnicity, religion, sexual orientation and certain other sensitive matters is special-category personal data.
Boxology Limited will only process special-category information where it has:
a lawful basis under Article 6 of the UK GDPR; and
an additional condition under Article 9.
Depending on the circumstances, the additional condition may include:
explicit consent;
vital interests;
establishment, exercise or defence of legal claims;
employment or social-protection obligations;
reasons of substantial public interest, including safeguarding children and individuals at risk; or
another lawful condition that applies to the specific purpose.
Where required, Boxology Limited will maintain an Appropriate Policy Document explaining its safeguards and retention arrangements.
Health information collected for physical participation will be limited to what is reasonably necessary for:
risk assessment;
emergency planning;
reasonable adjustments;
safe course delivery; and
protecting the participant and others.
10. Children and young people
Boxology Limited may process children’s personal information through specifically approved HEADGUARD, school, charity, care, safe-house or community programmes.
Children’s information will be handled with particular care.
Boxology Limited will:
place the child’s best interests at the centre of decisions;
collect only information that is reasonably necessary;
use clear and age-appropriate privacy information;
involve a parent, guardian or responsible organisation where appropriate;
consider the child’s own understanding and wishes;
apply a high level of privacy by default;
restrict access to authorised people;
avoid unnecessary profiling or monitoring;
avoid direct commercial marketing to children;
not sell children’s information; and
not use personal stories, photographs or films merely because a child participated.
Consent from a parent or partner organisation does not remove the child’s own rights over their information.
Children have data-protection rights in their own name. Whether the child or an adult exercises those rights will depend on the child’s age, understanding and circumstances.
11. Safeguarding information
Safeguarding information will be processed only where necessary and proportionate.
Boxology Limited may share safeguarding information without consent where there is a lawful and compelling reason, including where this is necessary to:
protect a child or adult at risk;
prevent serious harm;
obtain specialist safeguarding advice;
make a statutory referral;
cooperate with police or local authorities; or
comply with a legal obligation.
Where possible and safe, the individual will be told that information is being shared.
Consent will not be sought where doing so could:
place someone at greater risk;
compromise an investigation;
alert an alleged perpetrator;
delay necessary protective action; or
be otherwise inappropriate.
Safeguarding information will not be disclosed more widely than reasonably necessary.
12. CIMSPA-endorsed training and CPD information
Boxology Limited is a CIMSPA Training Provider Partner and delivers specific courses that are CIMSPA-endorsed and quality assured.
Where relevant to an endorsed course, Boxology Limited may process:
learner identity;
course enrolment;
attendance;
assessment outcome;
completion date;
certificate information;
CPD points;
complaints or appeals;
reasonable adjustments;
malpractice records; and
evidence required for quality assurance.
Information may be shared with CIMSPA where reasonably necessary for:
recording or verifying CPD;
confirming completion of endorsed training;
quality-assurance review;
endorsement monitoring;
audit;
investigation of a complaint, appeal or malpractice concern; or
compliance with the terms of Boxology’s CIMSPA partnership.
Only information relevant to the purpose should be supplied.
CIMSPA is a separate organisation and data controller for the personal information it receives. CIMSPA’s own privacy notice applies to its subsequent use of that information.
CIMSPA endorsement does not allow unrestricted access to Boxology learner records.
13. HEADGUARD and partner programmes
Where Boxology Limited provides education or delivery for HEADGUARD C.I.C. or another organisation, a written agreement should identify:
the organisations involved;
the purpose of the programme;
which organisation collects each category of information;
the lawful basis relied upon;
whether the organisations are separate or joint controllers;
safeguarding responsibilities;
who may access the information;
how information may be shared;
retention periods;
security arrangements; and
how individual rights and complaints will be handled.
Boxology Limited will not automatically use HEADGUARD participant, supporter, donor or mailing-list information for Boxology marketing.
HEADGUARD C.I.C. will not automatically receive Boxology learner, customer or membership information.
Any future HEADGUARD CIO will not receive Boxology data merely because the organisations share founders, personnel, expertise or branding.
14. Photography, filming and personal stories
Attendance at a course, event or programme does not automatically amount to consent for promotional photography, filming or storytelling.
Where content will be used publicly, Boxology Limited will explain:
what will be recorded;
why it is being recorded;
where it may appear;
which organisation will use it;
how long it may be used;
whether it may be shared internationally; and
how permission may be withdrawn for future use.
Promotional consent will be separate from ordinary course or programme participation.
A person will not be refused access merely because they decline promotional use.
For children and young people, Boxology Limited will obtain appropriate permission from a parent, guardian or responsible organisation where required and will also take account of the child’s own wishes.
Particular caution will be used with stories involving:
abuse;
trafficking;
violence;
mental health;
displacement;
care experience;
sexual violence;
safeguarding; or
another sensitive personal experience.
Assessment or safeguarding recordings are not automatically available for promotional use.
15. Marketing communications
Boxology Limited may send information about:
courses;
memberships;
events;
educational products; and
related Boxology services.
Marketing will only be sent where there is an appropriate lawful basis and the applicable electronic-marketing rules are met.
This may include:
consent; or
the lawful existing-customer exemption for similar Boxology products and services, where contact details were obtained directly and an opt-out was provided.
Every electronic marketing message will provide a clear way to unsubscribe.
Service messages concerning an existing booking, account, payment, safety matter or course change are not marketing.
Boxology Limited will not:
buy marketing lists without proper legal checks;
add HEADGUARD supporters automatically to Boxology marketing;
share Boxology marketing lists with HEADGUARD automatically; or
send commercial marketing directly to children as ordinary practice.
A minimal suppression record may be retained after an opt-out so that the person is not contacted again accidentally.
16. Who we may share information with
Where necessary and lawful, Boxology Limited may share information with:
tutors, assessors, employees and authorised contractors;
website, ecommerce and online-learning providers;
cloud-storage and IT providers;
email and communication providers;
payment processors;
accountants, auditors and professional advisers;
delivery and courier services;
insurers;
venues;
employers or organisations purchasing training;
schools, charities and community partners;
HEADGUARD C.I.C., where it has an identified lawful role;
CIMSPA;
emergency services;
local-authority safeguarding services;
police;
courts;
regulators; and
another organisation where disclosure is legally required.
Current service providers may include systems supplied by organisations such as:
Squarespace;
Thinkific;
Google Workspace;
Stripe;
PayPal; and
email or mailing-list providers.
Providers and systems may change. Boxology Limited will use appropriate contractual and security arrangements and will update this notice where a change materially affects how information is used.
Boxology Limited does not sell personal information.
17. International transfers
Some technology, cloud, email, payment or platform providers may process information outside the United Kingdom.
Where personal information is transferred internationally, Boxology Limited will ensure that an appropriate legal mechanism applies, such as:
UK adequacy regulations;
an International Data Transfer Agreement;
the UK Addendum to approved contractual clauses;
another approved safeguard; or
a lawful exception applying to the particular transfer.
Where required, Boxology Limited will assess the risks of the transfer and introduce additional safeguards.
Information will not be transferred merely for convenience without considering the applicable legal requirements.
18. Data security
Boxology Limited will use proportionate technical and organisational measures to protect personal information against:
unauthorised access;
accidental loss;
unlawful use;
disclosure;
alteration;
destruction; and
cyberattack.
Measures may include:
password protection;
multifactor authentication where available;
access controls;
encryption;
secure cloud systems;
software updates;
secure backups;
restricted sharing;
confidentiality requirements;
staff guidance;
processor contracts;
secure disposal;
incident reporting; and
periodic review of access permissions.
Access will be limited to people who reasonably require the information for their role.
No method of electronic storage or transmission can be guaranteed to be completely secure, but Boxology Limited will take reasonable and proportionate precautions.
19. Data retention
Personal information will be retained only for as long as reasonably necessary for the purpose for which it was collected, including legal, contractual, safeguarding, insurance and quality-assurance requirements.
The following periods will normally apply:
Enquiries
General enquiries that do not lead to a contract will normally be retained for up to 12 months after the final communication.
Customer, booking and purchase records
Contracts, orders, invoices, refunds and associated customer records will normally be retained for six years after completion of the transaction or relationship.
Course, assessment and certification records
Learner, assessment, certificate and quality-assurance records will normally be retained for six years after course completion.
A limited certificate-verification record may be retained for longer where necessary to verify that a certificate was issued.
Records relating to CIMSPA-endorsed courses will also be retained for the period reasonably required by the applicable endorsement, CPD and quality-assurance arrangements.
Health and participation records
Adult health, PAR-Q, informed-participation and incident records will normally be retained for up to three years after the final relevant activity, unless a longer period is justified by an incident, legal claim, insurance requirement or safeguarding concern.
Where the record concerns someone under 18, relevant health, safety and incident information may be retained until at least their 21st birthday, where proportionate and necessary.
Safeguarding records
Safeguarding records will be retained in accordance with the nature and seriousness of the concern.
Where a safeguarding record concerns a child, it may be retained until at least the person’s 25th birthday, and longer where necessary because of continuing risk, legal proceedings, insurance, regulatory requirements or the interests of another child or adult at risk.
Complaints, appeals and malpractice records
Ordinary complaint, appeal and malpractice records will normally be retained for six years after closure.
Safeguarding-related records may be retained longer.
Marketing
Marketing contact details will be retained while the relationship or lawful marketing basis remains active.
A minimal suppression record may be retained after an opt-out to ensure the preference continues to be respected.
Photography, filming and testimonials
Promotional content will be retained only while it remains appropriate, accurate and covered by a valid lawful basis or permission.
Content involving children or sensitive personal stories will be reviewed more frequently.
Recruitment and workforce records
Information about unsuccessful applicants will normally be retained for up to six months after the recruitment process.
Employment, contractor and volunteer records will normally be retained for up to six years after the relationship ends, subject to specific legal or safeguarding requirements.
Website and cookie information
Retention periods for cookies and similar technologies are explained in the Cookie Notice.
Records may be deleted earlier where they are no longer required or retained longer where a legal hold, safeguarding concern, insurance matter or active dispute applies.
20. Automated decision-making
Boxology Limited does not currently use solely automated decision-making that produces legal or similarly significant effects for learners, customers or participants.
Technology may be used to:
process payments;
mark simple objective online questions;
detect unusual account activity;
manage bookings; or
support administration.
Significant decisions about assessment, safeguarding, exclusion or eligibility will involve appropriate human review.
If this position changes, Boxology Limited will update this notice and provide the information required by law.
21. Individual rights
Depending on the circumstances, individuals may have the right to:
be informed about how their information is used;
access their personal information;
correct inaccurate or incomplete information;
request deletion where the right applies;
restrict processing;
object to processing;
receive certain information in a portable format;
withdraw consent;
object to direct marketing; and
challenge qualifying automated decisions.
These rights are not absolute and may be subject to lawful exemptions or competing obligations.
Requests should be sent to:
info@boxology.academy
Boxology Limited may ask for proportionate information to confirm identity or authority to act on behalf of another person.
There is normally no charge.
Boxology Limited will normally respond without undue delay and within one month after receiving a valid request and any information reasonably required to confirm identity. The period may be extended where permitted by law because the request is complex or numerous.
Children have data-protection rights in their own name.
22. Data-protection complaints
A person who is concerned about Boxology Limited’s use of their personal information should contact:
Email: info@boxology.academy
The complaint should include, where possible:
the complainant’s name;
contact details;
the information or processing concerned;
what they believe went wrong;
relevant dates;
any supporting information; and
the outcome sought.
Boxology Limited will:
provide a clear route for submitting the complaint;
acknowledge the complaint as soon as reasonably possible and no later than 30 days after receipt;
investigate without undue delay;
keep the complainant informed where appropriate; and
communicate the outcome.
Boxology Limited aims to acknowledge complaints within five working days, notwithstanding the statutory maximum period.
A complaint involving HEADGUARD or another partner will be directed to the organisation responsible for the relevant processing. Information will only be shared for that purpose where lawful.
23. Complaints to the Information Commissioner
A person may complain to the Information Commissioner’s Office if they remain dissatisfied with the way Boxology Limited has handled their personal information or data-protection complaint.
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Boxology Limited would normally welcome the opportunity to consider and resolve the matter before it is referred externally.
24. Personal-data breaches
A personal-data breach may involve accidental or unlawful:
loss;
destruction;
alteration;
disclosure;
unauthorised access; or
loss of availability.
Suspected breaches must be reported immediately to:
info@boxology.academy
Boxology Limited will:
contain the incident where possible;
preserve relevant evidence;
assess the information affected;
consider the likely risk to individuals;
record the incident;
take corrective action;
notify relevant partner organisations where appropriate;
report a notifiable breach to the Information Commissioner’s Office without undue delay and within 72 hours of becoming aware of it; and
inform affected individuals without undue delay where the breach is likely to create a high risk to their rights and freedoms.
25. Cookies
Boxology websites use cookies and similar technologies for purposes that may include:
essential website operation;
account login;
shopping-cart functions;
security;
payment processing;
analytics;
embedded content; and
user preferences.
Strictly necessary cookies may be used without consent where permitted by law.
Non-essential cookies will only be used after an appropriate choice has been made through the website’s cookie controls.
Visitors should be able to:
accept non-essential cookies;
reject non-essential cookies; and
manage their preferences.
Full information about cookie providers, purposes and durations is provided in the separate Cookie Notice.
26. Accuracy of information
Individuals should inform Boxology Limited where their personal information changes or is inaccurate.
Boxology Limited will take reasonable steps to correct inaccurate information and will not retain information known to be materially misleading where correction is possible.
27. Changes to this policy
This policy will be reviewed at least annually and sooner where:
data-protection law changes;
ICO guidance changes;
CIMSPA requirements change;
Boxology services or systems change;
HEADGUARD or partner arrangements change;
new categories of information are collected;
information is used for a new purpose;
a serious incident identifies a gap; or
new technology materially affects the processing.
Material changes will be brought to the attention of affected individuals where required.
28. Contact
Boxology Limited
Trading as Boxology® Academy and Boxology® Online
Company number 10523458
Registered office: Brook Cottage, High Street, Paulerspury, Towcester, England, NN12 7NR
Data Protection Lead: Cathy Brown
Email: info@boxology.academy
