Privacy Policy
Last updated: June 2025
1. Who we are
BOBSTA operates this booking platform. We are the data controller for the personal information collected through this website.
Registered address:
123 High St, London, EC1A 1BB
Data controller: BOBSTA
Privacy enquiries:
privacy@bobsta.co.uk
2. What data we collect and why
We collect the following categories of personal data:
- Account information — name, email address, phone number, and billing address, collected when you register or make a booking.
- Booking and payment data — course bookings, delegate names, payment confirmations, and order history. Payment card data is processed directly by Stripe and is never stored on our servers.
- Communications — records of emails and SMS messages sent to you in connection with your bookings.
- Usage data — pages visited, session duration, and device/browser information, collected via Google Analytics to help us improve the platform.
- Marketing preferences — whether you have opted in to receive marketing communications from us.
3. Lawful basis for processing
- Contract performance — processing your booking, delivering the course, and issuing invoices and receipts.
- Legitimate interests — fraud prevention, security, improving our services, and sending transactional communications related to your bookings.
- Consent — sending marketing emails, where you have opted in via your account preferences.
- Legal obligation — retaining financial records as required by law.
4. How we use your data
We use your personal data to:
- Process and manage your course bookings and payments.
- Send booking confirmations, pre-course information, and reminders by email and/or SMS.
- Send post-course feedback surveys.
- Send marketing communications about courses and promotions via our email marketing provider (Brevo), where you have given consent through your account preferences. You can withdraw consent at any time by updating your preferences or clicking unsubscribe in any marketing email.
- Maintain your loyalty points balance and redemption history.
- Respond to enquiries and support requests.
- Comply with legal and regulatory obligations.
- Improve the platform using anonymised analytics data.
5. Third-party service providers
We share data with the following third-party processors, each of whom processes data only on our instructions and in accordance with our agreements with them:
- Stripe — payment processing. Card data is handled entirely by Stripe and subject to their Privacy Policy.
- Brevo (Sendinblue) — transactional and marketing email delivery. Recipient email addresses and personalisation tokens are passed to Brevo to deliver emails on our behalf.
- Firetext — SMS delivery for booking confirmations and reminders.
- Google Analytics — anonymised site usage analytics. Google Analytics uses cookies to collect information about how visitors use this site. We use this information to improve the site. The data collected does not identify individual visitors. See Google's Privacy Policy for details.
We do not sell your personal data to any third party.
6. Data retention
We retain your account and booking records for as long as your account is active and for a period of seven years thereafter, as required by HMRC financial record-keeping obligations. Marketing consent records are retained until you withdraw consent. You may request deletion of your account at any time (subject to legal retention obligations) — see Section 8.
7. Cookies
We use cookies to maintain your session, secure your login, and understand how the site is used. For full details of the cookies we set and how to manage them, see our Cookie Policy.
8. Your rights under UK GDPR
You have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — ask us to delete your data, subject to legal retention requirements.
- Restriction — ask us to restrict processing while a complaint is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Object — object to processing based on legitimate interests or for direct marketing.
- Withdraw consent — withdraw marketing consent at any time without affecting previous processing.
To exercise any of these rights, contact us at privacy@bobsta.co.uk. We will respond within one calendar month.
9. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection: ico.org.uk.
We would appreciate the opportunity to address your concern before you contact the ICO — please reach out to us first at privacy@bobsta.co.uk.
10. Contact us
For any privacy-related queries, please contact:
BOBSTA123 High St, London, EC1A 1BB
anton@aion.co.uk
0800 123 4567