top of page

PRIVACY

The Living Life Project Ltd, trading as ‘The Living Project’, is committed to protecting your privacy and security. This statement explains how we collect and process personal data about you — whether you’re a school, a parent or guardian, a student, or an Adventure Leader working with us — and information collected as you interact with our website and services. Wherever you provide personal information to us, we treat it in line with this statement and current data protection law.

​

Who are we — who holds your data?

​

We are The Living Life Project Ltd, trading as ‘The Living Project’. Company number: 12938598, whose registered office is The Old Stables, Sutton Manor Farm, Bishops Sutton, Alresford, SO24 0AA. Our Data Controller is our Company Director, Joshua Bulpin. This statement applies to us and our activities in the UK and abroad.

​

1. What data do we collect, and from whom?

​

We collect the following categories of data:

  • School staff: name, date of birth, dietary and medical information, emergency contact details, and email address (for logging in and receiving updates about your school’s adventure).

  • Parents/guardians: name, email address, a typed signature, and contact details, submitted with the consent form for your child.

  • Students: name, date of birth, address, contact number, sex, team/group assignment, dietary requirements, medical conditions and treatment, emergency contact details, and consent and payment status. Separately, and only with your specific opt-in consent, we record whether we may use a photograph of your child.

  • Adventure Leaders (self-employed contractors who deliver our Programmes): name, email address, a bio and profile photo, T-shirt/gear size, certification records (type, expiry date, and an uploaded certificate file), DBS/safeguarding check status (we hold the DBS certificate number itself, to check and verify it, but it is never shown or stored within the app, the app itself only ever holds an evidenced/checked date and its expiry), emergency contact details, home address and bank details for payment, and records submitted in the course of a Programme (kit sign-out/return, incident report forms, a post-Programme report, and expense/invoice submissions).

  • Accidents or incidents: if an accident or incident occurs on one of our Programmes, or involving a member of our staff, we keep a record of this, which may include health information about those involved.

​

2. How do we use your personal data?

​

We process personal data for specific purposes permitted by data protection law, which enable us to carry out our services. We use your data to:

  • Plan and deliver your school’s adventure Programme safely

  • Confirm Adventure Leaders hold the certifications and safeguarding checks required to work with children

  • Maintain contact with you about your booking

  • Process payments due, including paying Adventure Leaders for their work

  • Improve the services we provide

  • Meet our administrative and legal/regulatory obligations

We will always comply with the law.

​

3. Who has access to your data?

​

We disclose personal information to our own employees, contractors, agents and subcontractors, only so far as reasonably necessary for the purposes set out in this statement. This includes:

  • Supabase, our database and hosting provider, who stores your data on our behalf (project region confirmed UK/EU) under a signed data processing agreement.

  • Google, for Workspace email delivery and, for our own Ops team’s administration only, a small set of Drive/Sheets documents, never your full record.

  • The Adventure Leader(s) assigned to deliver your school’s Programme.

​

We may also disclose your personal information:

  • to the extent that we are required to do so by law;

  • in connection with any ongoing or prospective legal proceedings;

  • in order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk);

  • to the purchaser (or prospective purchaser) of any business or asset that we are (or are contemplating) selling; and

  • to any person who we reasonably believe may apply to a court or other competent authority for disclosure of that personal information, where in our reasonable opinion such court or authority would be reasonably likely to order disclosure.

​

Except as set out in this statement, we will not provide your information to third parties.

​

Some of our partners and service providers are established outside the UK/EU. Where this constitutes an international transfer of personal data, we put appropriate safeguards in place; the level of data protection in some countries outside the UK/EU does not always match that within it.

​

4. How do we secure your data, and how long do we keep it?

​

We take reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal information.

Personal data is held in our database, access to which is restricted so that, for example, a school can only ever see its own data, and an Adventure Leader can only ever see their own profile and the Programmes they are assigned to. A set of Programme information is also kept in sync with a small number of internal Sheets used by our Ops team, and is never shared outside Ops.

​

All data sent to and from our systems is protected by encryption (HTTPS/TLS). You acknowledge that the transmission of information over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet.

​

We do not keep personal data for longer than necessary to meet the purposes described in this statement. Student, parent/guardian and school staff data is generally kept for no longer than 2 years after the relevant Programme ends, after which it is deleted or anonymised so it can no longer be linked to you. Adventure Leader data is kept for as long as they are engaged to deliver Programmes for us, and reviewed periodically thereafter.

 

Incident records are kept for a minimum of 3 years, or until the Participant turns 21, whichever is longer.

​

5. Your preferences

​

By providing personal data you consent to its processing as described in this statement. If you do not wish to receive information from us by mail, telephone, email or SMS, or wish to express other preferences, contact hello@thelivingproject.life.

​

6. Website

​

Use of cookies

​

A cookie is a piece of data about a website that is stored in your web browser. Cookies are often used to store choices about how you use a site, to improve your user experience. Our website uses cookies in this way, and to help us understand visitor numbers, anonymously; we don’t know what you personally are looking at, only that someone has looked at what you’ve looked at.

​

Some parts of our site rely on cookies, but we will tell you where and when. Most browsers let you control how cookies are handled, whether they’re accepted, and how long they’re stored for. If you’re concerned about privacy and security, check the ‘help’ documentation for your particular browser.

​

External links

​

Our website provides hyperlinks to other websites. This information is supplied in good faith; we exercise no control over linked sites and are not responsible for the privacy practices of other organisations and their websites. Each linked site maintains its own independent privacy and data collection policies. If you visit a site linked from ours, consult that site’s privacy policy before providing personal information. This statement applies solely to information gathered by The Living Project.

​

7. How can I exercise my rights?

​

You may contact us at hello@thelivingproject.life at any time to exercise the rights you are granted under applicable data protection law, including the right to: (1) access your data, (2) rectify it, (3) erase it, (4) restrict its processing, (5) data portability, and (6) object to processing. We may ask you to provide additional information to verify your identity.

​

You can also contact us with any questions, remarks or complaints about this statement. If you have unresolved concerns, you also have the right to lodge a complaint with your Data Protection Authority (in the UK, the Information Commissioner’s Office).

​

If you have any problems or queries about your data, please contact: The Company Director — hello@thelivingproject.life

​

8. Data breach

​

If a breach of personal data security occurs, leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to your data, we will assess the risk to people’s rights and freedoms and take appropriate action. Where a breach is likely to result in a high risk to individuals’ rights and freedoms, we will inform those individuals without delay, and notify the Information Commissioner’s Office within 72 hours. We document all breaches and near-breaches of personal data security.

​

9. Statement amendments

​

The Living Project reserves the right to amend this Privacy Statement at any time. Any change will be posted on our website and will take effect on publication. Your continued use of our website after changes are posted constitutes your acceptance of this statement.

bottom of page