4. Cookies
Our websites use cookies and similar technologies to enhance functionality and marketing. None of these cookies store personally identifiable information unless you provide it through forms or interactions.
Cookie types used:
- 
Essential Cookies: Record consent, session functionality, security, and survey completion.
- 
Performance Cookies: Analyse site usage and provide customised content (e.g., Google Analytics 4: _ga, _gid, _gat).
- 
Usage / Analytics Cookies: Track visits and interactions for reporting (e.g., DoubleClick, Google Ads, rfihub.com).
- 
Targeting / Advertising Cookies: Used by third parties, including Meta (Facebook Pixel, Instagram Ads), Google DoubleClick, and adservice.google.com, to deliver personalised adverts, build custom audiences, and measure campaign performance.
You can manage or block cookies via our cookie consent tool or your browser settings. Blocking cookies may affect functionality of our site.
5. Data Received from Third Parties
We may receive personal data from third parties, such as when taking over management of a service or via third-party sales agents. This includes names, contact details, membership information, and health data. All such data is processed under the same lawful bases as data collected directly from you. For special category data, we will notify you within one month of receipt.
6. Who We May Share Your Data With
We may share your data with:
- Professional advisers, consultants, auditors, and legal teams
- Suppliers or service providers for operational purposes
- Debt collection or tracing agencies
- Business partners or contractors
- Credit reference and financial organisations
- Health and social welfare organisations where relevant
- Local authorities or venue operators (often joint controllers)
- Incoming service providers when contracts change
- Software, storage, and IT providers
- Agencies providing secure destruction of records
- Customer support systems (e.g., Zendesk, BT for calls)
- Course, training, and library software providers (e.g., OpenPlay, CAP2 Solutions, Swimphony, Education Software Solutions, Collate Systems)
- Marketing contractors (e.g., Dotdigital, Patron Point)
- Incident reporting and medical professionals (where necessary)
- Sports foundations, clubs, and awarding bodies
Meta / Social Media Sharing:
 We may share limited customer data (e.g., hashed email addresses or device identifiers) with Meta Platforms, Inc. (Facebook and Instagram) to create custom or lookalike audiences for advertising and measure campaign effectiveness. Your data is encrypted or hashed prior to transfer. Meta acts as a separate data controller. You can opt out via your marketing preferences or by contacting privacy@gll.org.
7. Transfer of Data Outside the EU / UK
GLL generally does not share or transfer any customer visitor or supplier personal data outside of the EEA. However some software providers are located, or store customer data, in the U.S. In such instances, the EU-US Privacy Shield is engaged. The European Commission has decided this provision ensures adequate protection to allow personal data to be transferred to the United States.
GLL will not share, disclose or transfer your personal data outside the EEA or the US without ensuring the relevant contract includes the standard data protection clauses adopted by the European Commission; in this way, GLL is providing adequate safeguards for the transfer of this data outside of the EEA.
Our software provider Zendesk Inc uses data storage centres some of which are located in the Asia Pacific region.
8. How We Store Your Data
- 
Paper / Hard Copy: Stored securely in controlled-access facilities
- 
Electronic Data: Stored on secure servers or cloud storage in the UK or with approved third-party providers, with controlled access
Access to personal data is restricted to authorised personnel only.
9. Data Retention
Personal data is retained only for as long as necessary, considering:
- Legal or contractual obligations
- Expiry of limitation periods for potential claims
- Time needed to handle complaints, disputes, or audits
Internal retention schedules define precise periods per data category.
10. Rights of the Data Subject
Under UK GDPR, you have the right to:
- 
Access: Obtain confirmation and a copy of your personal data
- 
Rectification: Correct inaccurate or incomplete data
- 
Erasure (“Right to be Forgotten”): Delete personal data where lawful
- 
Restrict Processing: Limit how your data is used
- 
Data Portability: Receive your data in a structured, machine-readable format
- 
Object: Object to direct marketing, including profiling and social media advertising
- 
Automated Decision-Making / Profiling: Not be subject to solely automated decisions that produce legal or similarly significant effects
Requests should be sent to privacy@gll.org. We will respond within one month.
11. Withdrawing Consent
Where processing is based on consent (e.g., marketing, social media advertising), you may withdraw it at any time via your online account or by emailing privacy@gll.org. Withdrawal does not affect lawful processing before consent was withdrawn.
12. Making a Complaint
If you believe your personal data has been mishandled, contact the Data Protection Officer at privacy@gll.org.
If unresolved, you may report to the Information Commissioner’s Office (ICO): https://ico.org.uk
13. Contacting the Data Protection Officer
Data Protection Officer: Mr Philip Donnay
Email: privacy@gll.org
Address: Middlegate House, The Royal Arsenal, London, SE18 6SX
14. Updates to This Privacy Notice
This Privacy Notice may be updated periodically. Significant changes will be communicated via email or prominent notice on our website.
End of Privacy Notice