Data Protection & Privacy Policy

Document control

 

Policy reference 

AU-POL-05

Version 

1.0

Approved by 

Board of Directors, Apex Up CIC

Date adopted 

4 June 2026

Last reviewed 

4 June 2026

Next review due 

4 June 2027 (or sooner if legislation or guidance changes)

Policy owner 

Director (Data Protection point of contact)

Applies to 

All directors, staff, sessional coaches, volunteers, students  and anyone acting on behalf of Apex Up CIC



Apex Up CIC Data Protection & Privacy Policy 

1 Policy statement 

Apex Up CIC collects personal information about the children, young people, families, staff  and volunteers we work with. We are committed to handling this information lawfully, fairly and  securely, in line with the UK General Data Protection Regulation (UK GDPR) and the Data  Protection Act 2018. We treat people’s privacy with respect and only use their information for  the reasons we have explained to them. 

2 Purpose and scope 

This policy explains what information we collect, why, how we keep it safe, and the rights  people have. It applies to everyone who handles personal information on our behalf. 

3 The principles we follow 

We make sure personal information is: 

  • used lawfully, fairly and transparently; 
  • collected only for clear, specified purposes; 
  • limited to what we actually need; 
  • accurate and kept up to date; 
  • kept no longer than necessary; and 
  • kept secure, protected against loss, damage or unauthorised access. 4 What we collect and why 

We collect information such as names and contact details, dates of birth, emergency contacts,  medical and dietary information, and consent forms, so that we can run our sessions safely,  keep children safe, contact families, and meet the requirements of funders such as the HAF  programme. We collect this on the basis of consent, our legitimate interests in running safe  activities, and our legal obligations, including safeguarding. 

5 Children’s and special category data 

Because we work mainly with children, we take particular care with their information. We  obtain consent from a parent or carer where appropriate, keep medical and safeguarding  information secure and separate, and share it only with those who need it to keep a child safe  or well. 

6 Keeping information secure 

We store information securely, whether on paper or electronically, using locked storage,  password protection and access limited to those who need it. We do not leave registers or  personal information unattended, and we make sure devices used for our work are protected.  We keep information only as long as we need it, following a retention schedule, and dispose  of it securely. 

7 Sharing information 

We do not sell personal information or share it unnecessarily. We share information with  funders, partners or authorities only where there is a clear and lawful reason. Where a child 

AU-POL-05 | Version 1.0 Page 2 of 4 

Apex Up CIC Data Protection & Privacy Policy 

or adult at risk may be at risk of harm, the duty to keep them safe overrides confidentiality,  and we will share relevant information promptly with safeguarding agencies. 

8 People’s rights 

People have the right to ask what information we hold about them, to have inaccurate  information corrected, to ask us to delete information where appropriate, and to object to  certain uses. Anyone wishing to exercise these rights can contact the Director. We will respond  within one month. 

9 Data breaches 

If personal information is lost, stolen or shared in error, staff and volunteers must tell the  Director immediately. We will act quickly to contain the breach, assess the risk, and — where  the breach is likely to harm the people involved — report it to the Information Commissioner’s  Office (ICO) within 72 hours and inform those affected. 

10 Responsibilities and review 

The Director acts as our point of contact for data protection. All staff and volunteers are  responsible for following this policy. We review it at least annually and after any breach or  change in the law. 

11 Key contact

Contact 

Details

Data protection point of  

contact

Muhammed Zahir — mz@apexup.org — 07706  803260

Information Commissioner’s  Office (ICO) 

0303 123 1113 — ico.org.uk



AU-POL-05 | Version 1.0 Page 3 of 4 

Apex Up CIC Data Protection & Privacy Policy 

Approval and adoption 

This Data Protection & Privacy Policy has been approved and adopted by the Board of  Directors of Apex Up CIC. It will be reviewed at least every twelve months, and sooner if there  is a change in legislation, national or local guidance, or following any relevant incident or  learning. 

Policy reference 

AU-POL-05

Version 

1.0

Date adopted 

4 June 2026

Next review due 

4 June 2027



Signed on behalf of the Board of Directors of Apex Up CIC: 

Muhammed Zahir 

Director, Apex Up CIC 

Date: 4 June 2026