How Lions Campus Ltd collects, uses, shares and protects personal information

Purpose of this notice

This notice explains our handling of personal information across our website, enquiries, referrals, admissions, residential and day programmes, behavioural coaching, case management, family liaison, education coordination and related business activities.

Controller Lions Campus Ltd
Company number 13111830
Effective date 5 August 2026
Privacy contact office@lions-campus.co.uk | +44 (0) 20 7190 9670
Registered office Blythe Hall, 100 Blythe Road, London, England, W14 0HB

This policy should be read with our Cookie Policy and any programme-specific, consent or fair-processing information provided to you.

Contents

  1. About this notice
  2. Who we are and how to contact us
  3. Who this notice covers
  4. The information we collect
  5. Where information comes from
  6. How and why we use information
  7. Special category and criminal offence information
  8. Young people, parents and confidentiality
  9. Referrals, admissions and programme records
  10. Who we share information with
  11. International data transfers
  12. Our website, cookies and third-party services
  13. Communications, marketing, images and testimonials
  14. Retention
  15. Security and data breaches
  16. Your data protection rights
  17. Questions and complaints
  18. Changes to this notice

At a glance

Our commitment

Lions Campus handles personal information lawfully, fairly and transparently. We collect only what we reasonably need, use it for defined purposes, restrict access, retain it only for as long as necessary and respect the rights of young people and adults whose information we hold.

  • We do not sell personal information.
  • We do not use information about a young person’s mental health, eating, substance use, disability or safeguarding circumstances for targeted advertising.
  • A parent or payer does not automatically receive every detail shared by a young person. We consider the young person’s age, understanding, wishes, safety and the law.
  • Lions Campus is not registered with the Care Quality Commission and does not provide regulated clinical activities, personal care, nursing care or medical treatment. Independent registered providers are responsible for their own clinical services and records.
  • Our contact channels are not emergency services and are not continuously monitored. In an immediate risk to life or safety, call 999 or use the appropriate emergency service.

1. About this notice

This privacy policy is also our privacy notice under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and those laws as amended, including by the Data (Use and Access) Act 2025. It explains what personal information we process, why we process it, the legal grounds we rely on, who may receive it, how long we retain it and the rights available to you.

It applies to our own activities. If another organisation provides a service independently—for example a psychiatrist, psychologist, therapist, medical provider, school, tutor or treatment centre—that organisation will usually be a separate controller for its own records and decisions. Its privacy notice will also apply.

A separate workforce privacy notice may apply to employees, workers and long-term contractors. Additional notices or consent forms may be provided for a particular programme, activity, event, photograph, research project or safeguarding situation. Where an additional notice conflicts with this general notice about a specific activity, the more specific notice applies for that activity.

2. Who we are and how to contact us

Lions Campus Ltd is the controller of personal information described in this notice when we decide why and how it will be used.

Detail Information
Legal name Lions Campus Ltd
Company number 13111830
Registered office Blythe Hall, 100 Blythe Road, London, England, W14 0HB
Email office@lions-campus.co.uk (please use ‘Privacy’ or ‘Data protection complaint’ in the subject line)
Telephone +44 (0) 20 7190 9670
Website https://www.lions-campus.co.uk/

We have not appointed a statutory Data Protection Officer. Privacy enquiries and rights requests are handled through the contact details above. We may ask for information reasonably required to confirm identity, authority and the scope of a request.

3. Who this notice covers

This notice may apply to:

  • young people and young adults who enquire about, apply for, receive or previously received a Lions Campus service;
  • parents, guardians, family members, carers, emergency contacts and people funding or supporting a programme;
  • professional referrers, clinicians, counsellors, coaches, schools, universities, local authorities and other organisations involved in a young person’s support;
  • website visitors, newsletter subscribers, event attendees and people who contact us by telephone, email, enquiry form, referral form, WhatsApp or social media;
  • suppliers, professional advisers, partners, visitors and other business contacts; and
  • job applicants and prospective contractors, where no more specific recruitment notice has been provided.

If you provide us with another person’s information, please make sure you are authorised to do so and, where safe and appropriate, that they know about this notice. Do not tell someone about a disclosure if doing so could create a safeguarding risk, prejudice an investigation or otherwise be unlawful; contact us for guidance instead.

4. The information we collect

The information we need depends on the relationship and service. We may collect the following categories.

4.1 Identity, contact and relationship information

  • name, preferred name, title, date of birth, age, pronouns, photograph and identity-verification information;
  • postal address, email address, telephone number, country of residence and communication preferences;
  • parental responsibility, guardianship, family relationships, emergency contacts and authorised representatives;
  • professional role, employer, organisation, referral relationship and business contact details.

4.2 Enquiry, admission and programme information

  • the reason support is sought, goals, strengths, interests, routines, family circumstances and relevant history;
  • referral information, assessments of suitability, admissions decisions, risk and support information, programme plans and attendance;
  • case-management notes, mentoring or coaching records, progress reviews, goals, incident records, participation in groups and activities, and transition or discharge planning;
  • accommodation, dietary, accessibility, travel, visitor and emergency-arrangement information relevant to safe participation;
  • education, qualifications, school or university history, learning needs, attendance, careers interests, employment and future planning;
  • correspondence, call notes, meeting notes, feedback, complaints and records of decisions.

4.3 Financial, contractual and administrative information

  • fee, funding, invoicing, payment and transaction records;
  • contracts, authorisations, consents, signatures and records of terms accepted;
  • information needed for insurance, due diligence, fraud prevention, audit, accounting and legal compliance.

Payment card details may be handled directly by a payment provider. Where this happens, we generally receive confirmation and limited transaction information rather than full card details.

4.4 Website, device and communications information

  • IP address, device identifiers, browser type, operating system, approximate location, pages visited, referral source and interaction events;
  • cookie and consent choices, analytics identifiers, security logs and anti-spam signals;
  • emails, form submissions, telephone or video-call details, WhatsApp messages and social-media interactions;
  • newsletter subscriptions, marketing preferences and unsubscribe or suppression records.

4.5 Images, recordings and public-facing material

  • photographs, audio or video recordings, testimonials, case studies, event material and related consent records;
  • biographical details chosen for publication, which may include a pseudonym, broad location or a description of experiences.

4.6 Special category and other particularly sensitive information

Where relevant and lawful, we may handle information concerning:

  • physical or mental health, emotional wellbeing, disability, neurodiversity, medication relevant to safety, allergies and accessibility needs;
  • eating behaviours and eating disorders, substance use, behavioural dependencies, self-harm, trauma, risk, safeguarding and crisis history;
  • racial or ethnic origin, religion or philosophical beliefs, sex life or sexual orientation, where volunteered or necessary to provide respectful and appropriate support;
  • criminal allegations, cautions, convictions, court restrictions, police involvement or unlawful conduct, where genuinely relevant to safety, safeguarding, legal claims or programme arrangements.

We do not ask for sensitive information merely because it may be interesting. We seek to collect only what is reasonably necessary for an identified purpose and restrict access to people who need it.

5. Where information comes from

We may receive personal information:

  • directly from you, including through conversations, forms, messages, programme activities and feedback;
  • from a parent, guardian, family member, carer, emergency contact or person paying for a service;
  • from a professional referrer, clinician, counsellor, coach, treatment provider, school, university, tutor, local authority or other organisation involved in support;
  • from Lionheart Education or another partner where information sharing is authorised and necessary;
  • from emergency services, safeguarding bodies, courts, police, regulators, insurers or legal advisers where lawful;
  • automatically from our website, communications and security systems; and
  • from public sources, such as Companies House or a professional website, where relevant to business due diligence or professional contact.

We may combine information from different sources to understand needs, coordinate arrangements, keep people safe and maintain an accurate record. If information is obtained indirectly, we provide privacy information within the period required by law unless an exemption applies—for example where doing so would be impossible, involve disproportionate effort, prejudice safeguarding or investigations, or is otherwise restricted by law.

6. How and why we use information

UK data protection law requires a lawful basis under Article 6 UK GDPR for every use of personal information. Sensitive information also needs a separate condition under Article 9 or Article 10, explained in section 7. The bases below are those we most commonly expect to use; the appropriate basis depends on the circumstances.

Purpose Typical Article 6 lawful basis
Respond to enquiries; arrange calls or tours; understand initial needs; assess suitability; manage applications and admissions. Contract or steps requested before a contract where the person is a party; legitimate interests in responding, assessing fit and operating our services; consent where a person has a genuine choice.
Design, administer and review residential, day, behavioural coaching and case-management programmes; communicate with participants and authorised contacts. Contract where applicable; legitimate interests in delivering and improving a safe, effective programme; legal obligation where a specific law requires processing.
Coordinate education, tutoring, careers planning, external professional support and transition arrangements. Contract where applicable; legitimate interests in coordinated support; consent where information sharing is optional.
Support welfare, safeguarding, risk management, incident response and emergency action. Legal obligation; vital interests in an emergency; legitimate interests in protecting participants, staff and others; substantial public interest where applicable.
Manage family liaison, authorised representatives, professional referrals and funding arrangements. Contract where applicable; legitimate interests in coordinated communication and administration; legal obligation.
Invoice, collect fees, keep accounting records, prevent fraud, manage insurance and enforce or defend contractual rights. Contract; legal obligation; legitimate interests in financial administration, fraud prevention and legal claims.
Handle complaints, concerns, rights requests, audits, disputes, legal claims and regulatory enquiries. Legal obligation; legitimate interests in accountability, resolving concerns and establishing, exercising or defending legal rights.
Protect our people, premises, systems, website and communications; detect abuse, malicious activity and spam. Legitimate interests in security and service integrity; legal obligation where applicable.
Measure service quality, analyse trends, train staff, plan resources and improve programmes. Legitimate interests in quality, learning and service development. We use anonymised or aggregated information where reasonably possible.
Send newsletters, updates, invitations or information about relevant services. Consent for individual electronic marketing unless PECR permits another route; legitimate interests for limited business-to-business contact where lawful.
Operate non-essential analytics, advertising or embedded-media technologies. Consent under PECR and, where personal data is processed, consent under the UK GDPR.
Publish a photograph, recording, testimonial or case study. Consent, normally supported by a specific release; explicit consent where publication would reveal special category information.
Recruit and assess staff or contractors and maintain a recruitment record. Steps before a contract; legal obligation; legitimate interests in recruitment and workforce planning.

6.1 Legitimate interests

Where we rely on legitimate interests, we identify a legitimate business or third-party purpose, consider whether the processing is necessary, and balance that purpose against the person’s interests, rights and reasonable expectations. Our interests include responding to families, coordinating safe support, maintaining records and continuity, protecting people and systems, improving services, managing relationships and defending legal rights. We apply additional caution where a young person or sensitive information is involved. You may ask for more information about a relevant balancing assessment.

Where consent is our basis, it must be freely given, specific, informed and unambiguous; explicit consent is recorded where required. You may withdraw consent at any time using the contact details in section 2. Withdrawal does not make earlier processing unlawful. It may, however, mean we cannot continue an optional activity that depends on the information.

6.3 If information is not provided

Some information is needed to respond to a request, assess suitability, enter into or perform a contract, keep someone safe, meet legal obligations or coordinate an agreed programme. If required information is not provided, we may be unable to progress an enquiry, offer or continue a service, arrange an activity, process payment or safely involve a person. We will explain the practical consequence where possible.

7. Special category and criminal offence information

7.1 Special category information

In addition to an Article 6 basis, we use one or more Article 9 UK GDPR conditions when processing special category information. Depending on the situation, these may include:

  • explicit consent—for optional sharing, public testimonials or another clearly described activity;
  • vital interests—where processing is necessary to protect life and the person is physically or legally incapable of consenting;
  • legal claims—where necessary to establish, exercise or defend legal rights or when courts act in their judicial capacity;
  • substantial public interest under the Data Protection Act 2018—for example safeguarding children or individuals at risk, preventing or detecting unlawful acts, or meeting other applicable statutory conditions, with an appropriate policy document where required; and
  • information manifestly made public by the person, used cautiously and only where the legal test is met.

Lions Campus provides coaching, education, personal development, structured programmes and a supportive environment. We are not a CQC-registered provider and do not rely on the health or social care condition in order to claim that we provide regulated clinical treatment. An independent registered clinician or healthcare provider may rely on its own legal bases and conditions for its separate clinical work.

7.2 Criminal offence information

We process criminal offence information only where necessary and lawful under Article 10 UK GDPR and the Data Protection Act 2018—for example for safeguarding, prevention or detection of unlawful acts, legal claims, insurance or compliance with a legal requirement. Access is tightly limited, relevance is reviewed, and an appropriate policy document is maintained where the law requires one.

7.3 Confidentiality and safeguarding limits

We treat programme and wellbeing information as confidential, but confidentiality is not absolute. We may share information without consent where reasonably necessary to protect a person from serious harm, safeguard a child or adult at risk, respond to an emergency, comply with law or a court order, prevent or detect serious unlawful conduct, or establish or defend legal rights. We share only what is necessary and record significant decisions where appropriate.

8. Young people, parents and confidentiality

Our services concern young people and young adults, including individuals under 18. We apply the best interests of the young person as a primary consideration when their information is involved and aim to explain privacy in language appropriate to their age and understanding.

  • Data protection rights belong to the young person, although a parent, guardian or authorised representative may exercise them where the law and the young person’s capacity permit.
  • We consider age, maturity, understanding, competence, parental responsibility, risk, the nature of the information and the purpose of the request.
  • A parent who arranges or funds a programme does not automatically have an unrestricted right to all information shared by a competent young person.
  • We encourage constructive family involvement where appropriate, and we agree communication expectations at the outset where possible.
  • We may withhold information from a parent or another person where disclosure would breach confidence, conflict with the young person’s rights or best interests, create a safeguarding risk, reveal another person’s information or be otherwise unlawful.
  • We may disclose information despite a young person’s objection where necessary and lawful to protect them or another person from serious harm or to meet a safeguarding or legal duty.

Our website and marketing are not designed for children under 13 to provide consent independently for an online service. If we identify that parental authorisation or another legal safeguard is needed, we will seek it or stop the relevant processing.

9. Referrals, admissions and programme records

9.1 Referrals and suitability

A referral may contain information supplied before we have spoken directly with the young person. We use it to understand the request, identify immediate risk, determine whether our non-clinical services may be suitable and decide what further information or external input is needed. Receiving a referral does not guarantee admission. We may decline, pause or redirect an enquiry if the person’s needs fall outside our service model or require regulated clinical or emergency care.

9.2 Programme records

We keep an appropriate record of plans, goals, attendance, reviews, communications, significant incidents, safeguarding decisions, consent and transitions. Records support continuity, accountability and safe coordination. Case-management records may describe information received from multiple people; we distinguish fact, opinion and source where reasonably practicable.

9.3 External clinical and educational providers

Clinical or healthcare services are delivered by independent registered providers. Education may be coordinated with Lionheart Education or another provider. These organisations may be separate controllers and may create their own clinical, educational or professional records. We share information with them only where there is a lawful basis and it is necessary, proportionate and consistent with confidentiality and safeguarding requirements. We aim to explain the roles of the organisations involved when arrangements are made.

10. Who we share information with

We do not sell personal information. We may share information, on a need-to-know basis, with:

  • Lions Campus directors, employees, live-in support staff, case managers, programme staff, educators, mentors and authorised contractors;
  • parents, guardians, family members, carers, funders and authorised representatives, subject to the confidentiality principles in section 8;
  • professional referrers, schools, universities, local authorities, tutors and organisations coordinating education or support;
  • Lionheart Education and appropriate partner organisations involved in an agreed arrangement;
  • independent registered clinicians, therapists, treatment providers, hospitals, pharmacies or other healthcare professionals where a lawful and necessary coordination or safeguarding reason exists;
  • emergency services, safeguarding leads, children’s or adult social care, local authorities, police, courts, regulators or other public authorities where required or justified by law;
  • insurers, auditors, accountants, lawyers and other professional advisers;
  • website, hosting, customer-relationship management, communications, form, analytics, consent-management, security, cloud, document, payment and IT support providers acting under appropriate terms;
  • a prospective buyer, investor or successor in connection with a genuine reorganisation, financing, sale or transfer of all or part of the business, subject to confidentiality and data-protection safeguards.

Where a supplier acts as our processor, we require it to process information only on documented instructions, protect it appropriately, assist with rights and incidents, and delete or return it as agreed. Where a recipient is an independent controller, it is responsible for its own compliance and privacy information.

10.1 Current website and communications services

Our website and communications environment may include the following services. The exact configuration can change as systems are improved; our Cookie Policy and consent tool provide more detail about active website technologies.

Service category Typical role
WordPress / WP Engine Website content and hosting; security and operational logs.
HubSpot Enquiry forms, contact and relationship management, communications and related analytics where enabled.
Gravity Forms / WP Armour Website forms and spam or abuse prevention.
CookieYes / cookie consent tools Recording and applying website consent choices.
Google Tag Manager, Google Analytics and Google services Tag management, measurement and analytics, subject to consent where required.
YouTube Embedded video content, which may connect to YouTube when permitted or activated.
WhatsApp / Meta Messaging initiated through WhatsApp and related service delivery.
Email, cloud, document, security and IT providers Business communications, record storage, access management, backups and support.

Provider names do not mean every service receives every category of information. We configure access and data flows according to purpose. Copies of relevant processor details or further information about recipients can be requested, subject to security and confidentiality restrictions.

11. International data transfers

Some suppliers, partners, users or support professionals may be located outside the United Kingdom, and cloud services may process or access information internationally. An overseas transfer can also occur when someone outside the UK is given remote access.

Where UK data-protection law restricts a transfer, we use an approved safeguard, such as:

  • a UK adequacy regulation covering the destination or recipient;
  • the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, together with a transfer risk assessment and supplementary safeguards where required;
  • another lawful transfer mechanism, including a limited statutory exception where its strict conditions are met.

Supplementary safeguards may include encryption, access controls, minimisation, contractual commitments and limits on onward transfer. You may contact us for more information about the mechanism relevant to your information; we may redact commercially sensitive or security-related material.

12. Our website, cookies and third-party services

12.1 Cookies and similar technologies

Our website uses cookies and similar storage or access technologies. Strictly necessary technologies may operate without consent where permitted because they are needed for security, core functionality, consent choices or a service you request. Analytics, advertising and other non-essential technologies are used only after the required consent.

You can accept, reject or customise non-essential technologies through our cookie banner and revisit the choice using the consent control on the website. Withdrawing website consent does not remove information lawfully collected before the change and may not delete cookies already stored; browser controls can also be used. Please read our Cookie Policy for active cookies, providers, purposes and durations.

Where configured, Google Consent Mode may send limited consent-status, device or cookieless measurement signals when analytics or advertising consent is refused. We assess and configure such signals under applicable UK requirements and do not treat the use of a ‘cookieless’ label as removing the need for privacy assessment. Optional storage and personalised advertising remain subject to consent where required.

Embedded videos, maps, social-media tools and other third-party content may collect device or interaction information when loaded or activated. We use consent controls where required, but the third party’s privacy notice applies to its independent processing. External websites are not controlled by Lions Campus, and we are not responsible for their privacy practices.

12.4 Spam, fraud and security prevention

Forms may use honeypots, IP checks, rate limiting or other automated security signals to identify spam and malicious submissions. A submission may be blocked or quarantined, but we do not use this process to make a decision producing legal or similarly significant effects about programme eligibility.

13. Communications, marketing, images and testimonials

13.1 Email, telephone and WhatsApp

We keep appropriate records of communications concerning enquiries, referrals, programmes, safeguarding, complaints and administration. WhatsApp and ordinary email may not be appropriate for highly sensitive or urgent information. Use the secure method we specify where one is offered, and do not use these channels for emergencies. Messages may be processed by the communications provider under its own terms as well as by us.

We do not record telephone or video calls routinely. If a call will be recorded, we will normally tell participants in advance, explain the purpose and identify the lawful basis unless a legal exception applies.

13.2 Newsletters and direct marketing

We may send newsletters, event invitations or service information where you have consented, where the PECR ‘soft opt-in’ lawfully applies to a similar service, or in limited business-to-business circumstances where legitimate interests and PECR permit. We do not buy lists of young people for electronic marketing.

Every marketing email provides an unsubscribe route. You can also contact us at any time. We retain a minimal suppression record after an opt-out so that we can respect the instruction. Service messages—such as programme, safety, payment or appointment communications—are not marketing and may continue where necessary.

13.3 Photographs, video, testimonials and case studies

We use a separate, specific process before using identifiable images, recordings, testimonials or case studies for publicity. We explain the intended channels, audience, duration and whether a real name, pseudonym or other details will appear. For a young person, we consider their own wishes and understanding and obtain parental or guardian authorisation where legally or ethically appropriate.

Consent may be withdrawn for future use, but withdrawal cannot always remove material already printed, lawfully published, shared, indexed, cached or reposted by others. We will take reasonable steps within our control and explain practical limitations. Participation in publicity is voluntary and is not a condition of receiving a service unless the content is intrinsic to a separately agreed activity.

14. Retention

We keep identifiable information only for as long as reasonably necessary for the relevant purpose, including continuity, safeguarding, contractual, tax, insurance, complaint and legal-claim requirements. We consider the amount, sensitivity and risk of the information, the person’s age, applicable limitation periods and whether the purpose can be achieved with anonymised information.

Our standard retention framework is set out below. A different period may apply where law, a contract, an insurer, an active safeguarding matter, an investigation or a legal claim requires longer retention, or where information can safely be deleted sooner.

Record category Standard period
General enquiries that do not proceed 24 months after last meaningful contact.
Unsuccessful or withdrawn admission / suitability records 2 years after the decision or withdrawal, unless a safeguarding, complaint or legal reason requires longer.
Programme, coaching and case-management records 7 years after the service ends. If the participant is under 18 when it ends, until their 25th birthday or 7 years after the service ends, whichever is later.
Safeguarding and serious incident records At least 7 years after closure, or until the young person’s 25th birthday if later; longer where required by an investigation, statutory guidance, insurer or legal claim.
Contracts, invoices, payments and core accounting records 7 years after the end of the contract or relevant financial year.
Complaints, disputes and legal-claim files 7 years after closure, or longer while a claim, hold, investigation or enforcement issue remains possible or active.
Professional referrer, supplier and partner records 7 years after the relationship or last relevant transaction; routine contact details are reviewed sooner.
Newsletter and marketing records While subscribed and relevant; inactive subscriptions reviewed after 24 months. Minimal suppression records are kept for as long as needed to honour an opt-out.
Images, recordings, testimonials and case studies For the period described in the release or until valid withdrawal for future use; active public material is reviewed at least every 3 years.
Cookie, consent and analytics information As set out in the Cookie Policy and provider settings; analytics data is generally configured for no more than 14 months unless a justified shorter or longer period applies.
Website and security logs Usually up to 12 months; longer where needed to investigate an incident, abuse or legal issue.
Unsuccessful recruitment records 6 months after the process ends; up to 12 months for a talent pool with consent.

When a retention period ends, information is securely deleted, anonymised or placed beyond routine use pending deletion through controlled backup rotation. Truly anonymised information that no longer identifies anyone may be kept indefinitely for statistics, planning and service improvement.

15. Security and data breaches

15.1 Security measures

We use organisational and technical measures proportionate to the nature and risk of the information. Measures may include:

  • role-based access, least-privilege permissions and regular access review;
  • password controls and multi-factor authentication where available;
  • encryption in transit and, where supported and appropriate, at rest;
  • confidentiality commitments, staff training and clear handling procedures;
  • supplier due diligence, data-processing terms and controlled data sharing;
  • secure disposal, backups, patching, monitoring and incident-response procedures;
  • physical access controls and secure storage for paper or on-site records.

No system or transmission method is completely secure. We continually review proportionate safeguards and expect users to protect account details, verify recipients and tell us promptly about suspicious messages, unauthorised access or information sent in error.

15.2 Personal data breaches

A personal data breach includes accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal information. We assess suspected incidents promptly, contain and investigate them, preserve relevant evidence, reduce harm and record decisions. Where a breach is likely to risk people’s rights and freedoms, we notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of awareness. Where it is likely to create a high risk, we also notify affected people without undue delay unless an exception applies.

15.3 Accuracy

We take reasonable steps to keep information accurate and up to date, particularly where it influences safety, programme arrangements or decisions. Please tell us if contact, family, risk, consent, education or other relevant information changes. We may retain a record of a correction where needed to understand past decisions or meet accountability requirements.

16. Your data protection rights

Depending on the circumstances and subject to legal exemptions, you may have the right to:

  • be informed about how your information is used;
  • request access to your personal information and receive a copy;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase information in certain circumstances;
  • ask us to restrict processing in certain circumstances;
  • object to processing based on legitimate interests or a task in the public interest;
  • object at any time to use of your information for direct marketing;
  • receive information you provided in a structured, commonly used and machine-readable format, and have it transmitted to another controller, where portability applies;
  • withdraw consent at any time where consent is the basis;
  • not be subject to a decision based solely on automated processing, including profiling, that has legal or similarly significant effects, except where the law permits it with safeguards; and
  • complain to us and to the Information Commissioner’s Office.

Your right to object

You have an absolute right to object at any time to direct marketing. You may also object to processing based on our legitimate interests. If you object to legitimate-interest processing, we will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.

16.1 Making a request

Send a request to office@lions-campus.co.uk or our registered office. Describe the information or processing concerned and provide contact details. We may ask for proportionate proof of identity or authority, especially where sensitive information or a young person’s record is involved. This protects confidentiality.

We normally respond without undue delay and within one calendar month after receiving a valid request and any information reasonably needed to identify the person and locate the information. We may extend by up to two further months for a complex request or multiple requests, but will explain this within the first month. Requests are usually free; the law permits a reasonable fee or refusal where a request is manifestly unfounded or excessive.

16.2 Limits and third-party information

Rights are not absolute. We may withhold or redact information where an exemption applies—for example to protect another person’s rights and confidentiality, safeguard someone, preserve legal professional privilege, avoid prejudicing prevention or detection of crime, comply with another legal duty, or protect management information or negotiations where the statutory test is met. We explain the main reason unless the law prevents us from doing so.

16.3 Automated decision-making

Lions Campus does not currently make programme admission, continuation or safeguarding decisions solely by automated means where the decision produces legal or similarly significant effects. Staff may use digital systems to organise information or flag security issues, but material decisions involve appropriate human review. If this changes, we will provide specific information about the logic, significance, consequences and available safeguards.

17. Questions and complaints

17.1 Contacting Lions Campus

We welcome questions and want the opportunity to resolve concerns. For a formal data-protection complaint, email office@lions-campus.co.uk with ‘Data protection complaint’ in the subject line, or write to Lions Campus Ltd at Blythe Hall, 100 Blythe Road, London, England, W14 0HB.

Please describe what happened, whose information is involved, the outcome you seek and any relevant dates or correspondence. We will acknowledge the complaint within 30 days, take appropriate steps to investigate it, and communicate the outcome without undue delay. We may ask for further information and will keep you informed where the matter is complex.

17.2 Information Commissioner’s Office

You may complain to the UK Information Commissioner’s Office (ICO) at any time. We would appreciate the chance to address the issue first, but you are not required to contact us before the ICO.

ICO contact Details
Address Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone 0303 123 1113
Website https://ico.org.uk/make-a-complaint/

18. Changes to this notice

We review this notice when our services, systems, partners or legal obligations change. The current version is published on our website with its effective date. If a change materially affects how existing information is used, we will take reasonable steps to bring it to the attention of affected people and seek consent where a new use legally requires it.

Privacy contact: office@lions-campus.co.uk | +44 (0) 20 7190 9670