1. Who we are
This website (mfc-studios.co.uk) is operated by MF Creative Ltd, a company registered in England and Wales. We are the "data controller" for the personal information described in this policy.
- Company: MFC Studios
- Contact for privacy questions: mike@mfc-studios.co.uk
If you have any questions about this policy or how we handle your information, email us at the address above.
2. What information we collect
We only collect information we actually need to run the dance school. Specifically:
When you create an account
- Your name and email address
- A password (stored hashed, never in plain text)
- Your postal address and phone number (used for billing and emergencies)
When you add a student (your child or yourself) to your account
- Student's first and last name
- Date of birth (used to confirm class age-suitability and emergency contact context)
- A flag indicating whether the student is you (the account holder) or a dependant
When you purchase a membership or class bundle
- Order details (which membership/bundle, price, date)
- Billing information (passed to our payment provider — see §4)
- For Direct Debit: bank account details, captured directly by GoCardless and not stored on our servers
When you book a class
- Which student is attending, which class, the date and time
- A record of how the booking was paid for (membership, class bundle credit, or one-off payment)
Automatically, when you visit the site
- Standard server logs (IP address, browser type, pages visited) — used to keep the site secure and diagnose problems
- Cookies — see §7
We do not collect special category data (health, ethnicity, religion, etc.) through this website. If you need to tell us about a medical condition or accessibility need, please contact the studio directly so we can handle that conversation appropriately.
3. How we use your information and our lawful basis
Under UK GDPR, we have to tell you the legal basis for processing your personal data. Here's what we do with the information above and why:
| What we do | Why | Lawful basis |
|---|---|---|
| Create and manage your account | To give you access to bookings, memberships, and your dashboard | Contract |
| Process membership subscriptions and one-off payments | To deliver the services you've paid for | Contract |
| Send transactional emails (booking confirmations, reminders, cancellations) | To keep you informed about classes you've booked | Contract |
| Hold student records linked to your account | To track who's attending which class and apply membership/bundle rules | Contract |
| Send class reminders before the day | To reduce no-shows and help you remember | Legitimate interest (running a class-based business) |
| Keep accounting records of orders and payments | UK tax and accounting law requires it | Legal obligation |
| Investigate site abuse, security incidents | To protect the site and other customers | Legitimate interest |
| Send marketing emails (offers, new classes) | Only if you've opted in | Consent |
You can withdraw consent for marketing at any time by clicking "unsubscribe" in any marketing email, or by emailing us. Withdrawing consent for marketing doesn't affect transactional emails (booking confirmations, etc.) — those are part of the service you've signed up for.
4. Who we share your information with
We share the minimum necessary with carefully chosen third parties who help us run the site:
Payment processors
- Stripe — for card and Apple Pay payments. Stripe acts as an independent controller for payment data. Their privacy policy: https://stripe.com/gb/privacy
- GoCardless — for monthly Direct Debit memberships. GoCardless also acts as an independent controller for bank account / mandate data. Their privacy policy: https://gocardless.com/legal/privacy/
We do not see or store full card numbers or bank account details on our servers — those go directly to the payment provider.
Hosting and infrastructure
- SiteGround — our website host. Servers are based in the EU/UK. Their privacy policy: https://www.siteground.co.uk/privacy.htm
Professional advisers
- Accountants, lawyers, or auditors when we're legally required or genuinely need their advice
We do not sell your personal information to anyone, ever.
5. Children's data
Some students on this site are under 16. We handle their data carefully:
- A child's record can only be created and managed by their parent or legal guardian (the "account holder" on the site).
- The account holder is responsible for the accuracy of the student's information.
- We collect the minimum necessary about each student: name and date of birth.
- We do not market directly to children.
- A parent can remove a student from their account at any time via "My Students" in their account area.
If you believe a child's information has been added without proper parental consent, contact us and we'll remove it.
6. How long we keep your information
We keep your information only as long as we need it:
- Active accounts: for as long as you have an account with us.
- Order, payment, and booking history: at least 7 years after the transaction, to comply with UK tax and accounting law (HMRC).
- Email logs: typically 12 months.
- Server access logs: typically 30–90 days.
- Marketing consents: until you withdraw consent.
When the retention period ends, we delete the data or anonymise it (so it can't be linked back to you).
If you close your account, we'll delete the parts of your record that we're not legally required to keep.
7. Cookies
The site uses cookies (small files stored in your browser) for these purposes:
- Essential cookies — keeping you logged in, remembering what's in your cart, security. These can't be turned off because the site won't work without them.
- Functional cookies — remembering display preferences.
- Analytics cookies (if used) — anonymous traffic statistics so we know what's working.
We do not use advertising or tracking cookies that follow you around the web.
You can clear or block cookies in your browser settings. If you block essential cookies, parts of the site (login, checkout) will stop working.
8. Where your data is stored and processed
Your information is stored on servers based in the UK or EU by SiteGround.
Our payment providers may process some data outside the UK:
- Stripe processes payment data in the EU, UK, and US. Stripe relies on Standard Contractual Clauses (SCCs) and other UK-recognised safeguards for international transfers.
- GoCardless is UK-based; mandate and payment data stays in the UK/EU.
We don't transfer your data outside the UK other than through these processors.
9. Your rights
Under UK GDPR you have the following rights over your personal data:
- Access — ask for a copy of what we hold about you.
- Rectification — ask us to correct anything that's wrong.
- Erasure — ask us to delete your data (subject to legal retention rules — see §6).
- Restriction — ask us to stop processing your data while we resolve a query.
- Portability — ask for your data in a machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — for anything we do based on consent (e.g. marketing).
To exercise any of these rights, email us. We'll respond within one month.
If you're not happy with how we've handled your data, you can complain to the UK's data protection regulator:
Information Commissioner's Office (ICO) Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 Website: https://ico.org.uk
We'd appreciate the chance to put things right first, but you don't have to talk to us before going to the ICO.
10. Security
We take reasonable steps to protect your information:
- The site is served over HTTPS so traffic is encrypted in transit.
- Passwords are stored hashed (we can't see your actual password).
- Card and bank account details are handled by Stripe and GoCardless — they hold the relevant PCI / financial-data certifications.
- Access to the admin area is restricted to authorised staff and protected by strong passwords.
- We patch WordPress, plugins, and the server regularly to address known vulnerabilities.
No website can promise 100% security. If a breach affects your data and is likely to result in risk to you, we'll notify you and the ICO within the 72-hour deadline UK GDPR requires.
11. Changes to this policy
We may update this policy when our practices or the law change. The "Last updated" date at the top will reflect the most recent revision. If we make material changes that affect your rights, we'll notify you by email or a prominent notice on the site before they take effect.
12. Contact us
For any privacy question, request, or concern:
- Email: mike@mfc-studios.co.uk
