Privacy & AI use Policy

This policy explains how MF Dance (West) LLP collects and uses personal information under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other applicable UK data protection law, including relevant changes made by the Data (Use and Access) Act 2025.

Our commitment

We are committed to handling personal information lawfully, fairly, transparently and securely. Because our services involve children and young people, we apply particular care to children's data, safeguarding information, photographs and recordings.

1. Who we are

MF Dance (West) LLP is the data controller for the personal information described in this policy. MF Dance is part of a franchise and data is also shared with the Main MF Organisation data controller.

Privacy contact: Sophia Dacey, MF Dance (West) LLP

Email: [email protected]

ICO registration number: ZB810566

Business postal address: 27 Old Gloucester Street, London United Kingdom WC1N 3AX

Please use this address for privacy questions, requests to exercise your rights, withdrawal of consent or complaints.

2. Information we may collect

Depending on how you interact with us, we may collect:

  • names and contact details for parents, carers, students, prospective customers, suppliers and business contacts;

  • a student's name, date of birth, class, attendance, membership and progress information;

  • payment, billing and direct debit information, usually processed through our payment and membership providers;

  • health, medical, allergy, disability, additional-needs and emergency-contact information needed to provide a safe and inclusive service;

  • photographs, video and audio recordings where the appropriate permission has been obtained;

  • enquiries, messages, feedback, complaints, survey responses and records of our communications;

  • website, form, social-media and marketing interaction information; and

  • information relating to instructors, staff, subcontractors, volunteers and applicants where relevant.

3. How we collect information

We collect information directly from you when you make an enquiry, book or attend a trial, complete a student profile or consent form, join a class, set up a payment, contact us, complete a survey, attend an event or communicate through our website, email, telephone, social media or messaging services.

We may also receive information from a parent or carer, our franchisor, instructors or authorised team members, payment and membership providers, advertising or enquiry platforms, and other organisations where there is a lawful reason for them to share it with us.

4. Why we use your information

Depending on how you interact with us, we may collect:

  • contract, to provide classes, memberships, events, products or services you have requested;

  • legal obligation, including accounting, safeguarding, health and safety and regulatory requirements;

  • legitimate interests, such as administering and improving the business, responding to enquiries, preventing misuse,

  • maintaining security and communicating appropriately with existing customers, after considering individual rights and the particular interests of children;

  • consent, including where required for particular marketing communications, photographs, recordings or optional uses; or

  • vital interests or another applicable legal condition where information is needed to protect someone in an emergency.

Where we use health or other special category information, we also identify an appropriate additional condition under data protection law. You may withdraw consent at any time, although this will not affect processing already carried out lawfully.

5. Children's information and safeguarding

We process children's information with additional care and aim to collect only what is necessary to provide safe, age-appropriate services. Safeguarding concerns, disclosures and incident information are handled through our safeguarding procedures and are shared only with authorised people or organisations where necessary and lawful.

We normally communicate about a child through their parent or carer. We do not use personal information about children for solely automated decisions that have legal or similarly significant effects.

6. Photographs, video and recordings

We use photographs, video or audio only in line with the permission obtained and for the stated purposes, which may include class administration, celebration of student achievements, publicity, social media and advertising.

Where consent covers marketing or publication, content may be hosted, formatted, edited, distributed or enhanced by approved third-party platforms. Some platforms, including social media and advertising services, may apply automated or AI-assisted features. We do not authorise the creation of a synthetic likeness, voice clone or deepfake of a student, or the use of student content to train an AI model, without separate, specific written authority and appropriate safeguards.

You can withdraw consent for future use by emailing [email protected]. We will take reasonable steps to stop new use and remove content we control, but we may not be able to remove copies already lawfully published, shared or stored by other users or platforms.

You can escalate the use of images shared to MF HQ at [email protected]

7. Our ethical use of artificial intelligence

Human-led and safeguarding-led

AI may support our work, but it does not replace professional judgement, safeguarding procedures or human responsibility.

We may use approved AI or AI-assisted tools for limited business purposes, such as drafting or improving non-confidential communications, developing general lesson or activity ideas, administrative support, research, analysis of anonymised information and marketing content. A responsible person reviews relevant output before it is used or shared.

Our approach is based on data minimisation, confidentiality, transparency, accuracy, fairness, security and human oversight. Unless a specific tool and use have been formally approved with an appropriate lawful basis and safeguards, we do not enter identifiable children's data, safeguarding information, medical information, payment details or other confidential personal information into generative AI tools.

We do not use AI to interpret safeguarding disclosures, assess a child, make recruitment or disciplinary decisions, or make solely automated decisions that have legal or similarly significant effects. We check AI-assisted material for accuracy, suitability, bias, safeguarding risk and intellectual property concerns.

Some third-party systems we use may include embedded automated or AI-assisted features. We assess suppliers and settings proportionately and seek to use only the information necessary for the relevant purpose. Please contact us if you would like more information about a particular use of personal information involving AI.

8. Third-party systems and data processors

We do not sell personal information. We use trusted suppliers to help operate our services. These organisations may process or store information on our behalf under their own security arrangements and applicable contractual terms. They may include:

  • NEST Management, for membership administration, direct debit collection and customer relationship management;

  • GoHighLevel, for customer relationship management, enquiry handling, forms, email, SMS, workflows and business automation;

  • Google services, for email, documents, analytics, online applications and cloud storage;

  • Dropbox, for cloud file storage where used;

  • website hosting, forms, messaging, email, payment, accounting and IT support providers;

  • social media and advertising platforms, such as Meta, where you interact with our pages, adverts or forms or where content is published with permission; and

  • professional advisers, insurers, regulators, safeguarding bodies, emergency services or public authorities where necessary and lawful.

The suppliers we use may change as our systems develop. We require processors to handle information only for authorised purposes and to apply appropriate confidentiality and security measures.

9. International data transfers

Some of our suppliers or their infrastructure may be located outside the UK. Where personal information is transferred internationally, we take reasonable steps to ensure an appropriate legal transfer mechanism and safeguards are in place, such as UK adequacy regulations or approved contractual protections, as applicable. You may contact us for further information about relevant safeguards.

10. How long we keep information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including providing services and meeting legal, safeguarding, accounting, insurance and dispute-resolution requirements. Different records require different retention periods.

Financial and transaction records will normally be retained for at least six years after the end of the relevant accounting period. Other records may be retained for shorter or longer periods where justified, particularly safeguarding or incident records. Marketing information is kept until you unsubscribe, withdraw consent or we decide it is no longer needed, subject to keeping a minimal suppression record so we can respect your preference.

11. Security

We use proportionate organisational and technical measures to protect information against unauthorised access, loss, misuse, alteration or disclosure. Access is limited to people who need the information for their role. Paper records containing sensitive information are kept securely, and electronic records are held within access-controlled systems. No method of storage or transmission can be guaranteed to be completely secure.

12. Your data protection rights

Depending on the circumstances and our lawful basis, you may have the right to:

  • ask for access to the personal information we hold about you;

  • ask us to correct inaccurate or incomplete information;

  • ask us to erase information in certain circumstances;

  • ask us to restrict how information is used;

  • object to processing, including direct marketing;

  • receive certain information in a portable format;

  • withdraw consent at any time where consent is our lawful basis; and

  • raise concerns about solely automated decisions, where applicable.

These rights are not absolute and may be limited by law. We may need to verify your identity before responding. We will normally respond within one month, although the law allows additional time for complex or numerous requests.

Your right to object

You can object to direct marketing at any time by using the unsubscribe link in a marketing message or emailing [email protected].

13. Complaints

Please contact us first at [email protected] so we have the opportunity to address your concern. You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator, at ico.org.uk or by telephone on 0303 123 1113.

14. Sale or transfer of the business

If all or part of the business is sold, reorganised or transferred, relevant personal information may be disclosed to professional advisers, prospective purchasers ( no personal data is shared until transfer is complete and the new owner where necessary and subject to appropriate confidentiality and data protection safeguards.

15. Changes to this policy

We may update this policy when our services, suppliers, use of technology or legal obligations change. The current version will be made available through our usual channels. Where a change materially affects how we use personal information, we will take reasonable steps to bring it to the attention of affected people before the new use begins.

This document, including its original wording, structure, design and branding, is the intellectual property of MF Dance (West) LLP. It is provided for information relating to MF Dance (West) LLP only.

No part of this document may be copied, reproduced, adapted, republished, distributed, presented as another organisation’s policy or used for commercial purposes without prior written permission from MF Dance (West) LLP, except where permitted by law.

The MF Dance name, logo and associated branding must not be copied or used without the permission of the relevant rights holder.

For permission enquiries, contact [email protected].

Privacy & AI use Policy

This policy explains how MF Dance (West) LLP collects and uses personal information under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other applicable UK data protection law, including relevant changes made by the Data (Use and Access) Act 2025.

Our commitment

We are committed to handling personal information lawfully, fairly, transparently and securely. Because our services involve children and young people, we apply particular care to children's data, safeguarding information, photographs and recordings.

1. Who we are

MF Dance (West) LLP is the data controller for the personal information described in this policy. MF Dance is part of a franchise and data is also shared with the Main MF Organisation data controller.

Privacy contact: Sophia Dacey, MF Dance (West) LLP

Email: [email protected]

ICO registration number: ZB810566

Business postal address: 27 Old Gloucester Street, London United Kingdom WC1N 3AX

Please use this address for privacy questions, requests to exercise your rights, withdrawal of consent or complaints.

2. Information we may collect

Depending on how you interact with us, we may collect:

  • names and contact details for parents, carers, students, prospective customers, suppliers and business contacts;

  • a student's name, date of birth, class, attendance, membership and progress information;

  • payment, billing and direct debit information, usually processed through our payment and membership providers;

  • health, medical, allergy, disability, additional-needs and emergency-contact information needed to provide a safe and inclusive service;

  • photographs, video and audio recordings where the appropriate permission has been obtained;

  • enquiries, messages, feedback, complaints, survey responses and records of our communications;

  • website, form, social-media and marketing interaction information; and

  • information relating to instructors, staff, subcontractors, volunteers and applicants where relevant.

3. How we collect information

We collect information directly from you when you make an enquiry, book or attend a trial, complete a student profile or consent form, join a class, set up a payment, contact us, complete a survey, attend an event or communicate through our website, email, telephone, social media or messaging services.

We may also receive information from a parent or carer, our franchisor, instructors or authorised team members, payment and membership providers, advertising or enquiry platforms, and other organisations where there is a lawful reason for them to share it with us.

4. Why we use your information

Depending on how you interact with us, we may collect:

  • contract, to provide classes, memberships, events, products or services you have requested;

  • legal obligation, including accounting, safeguarding, health and safety and regulatory requirements;

  • legitimate interests, such as administering and improving the business, responding to enquiries, preventing misuse,

  • maintaining security and communicating appropriately with existing customers, after considering individual rights and the particular interests of children;

  • consent, including where required for particular marketing communications, photographs, recordings or optional uses; or

  • vital interests or another applicable legal condition where information is needed to protect someone in an emergency.

Where we use health or other special category information, we also identify an appropriate additional condition under data protection law. You may withdraw consent at any time, although this will not affect processing already carried out lawfully.

5. Children's information and safeguarding

We process children's information with additional care and aim to collect only what is necessary to provide safe, age-appropriate services. Safeguarding concerns, disclosures and incident information are handled through our safeguarding procedures and are shared only with authorised people or organisations where necessary and lawful.

We normally communicate about a child through their parent or carer. We do not use personal information about children for solely automated decisions that have legal or similarly significant effects.

6. Photographs, video and recordings

We use photographs, video or audio only in line with the permission obtained and for the stated purposes, which may include class administration, celebration of student achievements, publicity, social media and advertising.

Where consent covers marketing or publication, content may be hosted, formatted, edited, distributed or enhanced by approved third-party platforms. Some platforms, including social media and advertising services, may apply automated or AI-assisted features. We do not authorise the creation of a synthetic likeness, voice clone or deepfake of a student, or the use of student content to train an AI model, without separate, specific written authority and appropriate safeguards.

You can withdraw consent for future use by emailing [email protected]. We will take reasonable steps to stop new use and remove content we control, but we may not be able to remove copies already lawfully published, shared or stored by other users or platforms.

You can escalate the use of images shared to MF HQ at [email protected]

7. Our ethical use of artificial intelligence

Human-led and safeguarding-led

AI may support our work, but it does not replace professional judgement, safeguarding procedures or human responsibility.

We may use approved AI or AI-assisted tools for limited business purposes, such as drafting or improving non-confidential communications, developing general lesson or activity ideas, administrative support, research, analysis of anonymised information and marketing content. A responsible person reviews relevant output before it is used or shared.

Our approach is based on data minimisation, confidentiality, transparency, accuracy, fairness, security and human oversight. Unless a specific tool and use have been formally approved with an appropriate lawful basis and safeguards, we do not enter identifiable children's data, safeguarding information, medical information, payment details or other confidential personal information into generative AI tools.

We do not use AI to interpret safeguarding disclosures, assess a child, make recruitment or disciplinary decisions, or make solely automated decisions that have legal or similarly significant effects. We check AI-assisted material for accuracy, suitability, bias, safeguarding risk and intellectual property concerns.

Some third-party systems we use may include embedded automated or AI-assisted features. We assess suppliers and settings proportionately and seek to use only the information necessary for the relevant purpose. Please contact us if you would like more information about a particular use of personal information involving AI.

8. Third-party systems and data processors

We do not sell personal information. We use trusted suppliers to help operate our services. These organisations may process or store information on our behalf under their own security arrangements and applicable contractual terms. They may include:

  • NEST Management, for membership administration, direct debit collection and customer relationship management;

  • GoHighLevel, for customer relationship management, enquiry handling, forms, email, SMS, workflows and business automation;

  • Google services, for email, documents, analytics, online applications and cloud storage;

  • Dropbox, for cloud file storage where used;

  • website hosting, forms, messaging, email, payment, accounting and IT support providers;

  • social media and advertising platforms, such as Meta, where you interact with our pages, adverts or forms or where content is published with permission; and

  • professional advisers, insurers, regulators, safeguarding bodies, emergency services or public authorities where necessary and lawful.

The suppliers we use may change as our systems develop. We require processors to handle information only for authorised purposes and to apply appropriate confidentiality and security measures.

9. International data transfers

Some of our suppliers or their infrastructure may be located outside the UK. Where personal information is transferred internationally, we take reasonable steps to ensure an appropriate legal transfer mechanism and safeguards are in place, such as UK adequacy regulations or approved contractual protections, as applicable. You may contact us for further information about relevant safeguards.

10. How long we keep information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including providing services and meeting legal, safeguarding, accounting, insurance and dispute-resolution requirements. Different records require different retention periods.

Financial and transaction records will normally be retained for at least six years after the end of the relevant accounting period. Other records may be retained for shorter or longer periods where justified, particularly safeguarding or incident records. Marketing information is kept until you unsubscribe, withdraw consent or we decide it is no longer needed, subject to keeping a minimal suppression record so we can respect your preference.

11. Security

We use proportionate organisational and technical measures to protect information against unauthorised access, loss, misuse, alteration or disclosure. Access is limited to people who need the information for their role. Paper records containing sensitive information are kept securely, and electronic records are held within access-controlled systems. No method of storage or transmission can be guaranteed to be completely secure.

12. Your data protection rights

Depending on the circumstances and our lawful basis, you may have the right to:

  • ask for access to the personal information we hold about you;

  • ask us to correct inaccurate or incomplete information;

  • ask us to erase information in certain circumstances;

  • ask us to restrict how information is used;

  • object to processing, including direct marketing;

  • receive certain information in a portable format;

  • withdraw consent at any time where consent is our lawful basis; and

  • raise concerns about solely automated decisions, where applicable.

These rights are not absolute and may be limited by law. We may need to verify your identity before responding. We will normally respond within one month, although the law allows additional time for complex or numerous requests.

Your right to object

You can object to direct marketing at any time by using the unsubscribe link in a marketing message or emailing [email protected].

13. Complaints

Please contact us first at [email protected] so we have the opportunity to address your concern. You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator, at ico.org.uk or by telephone on 0303 123 1113.

14. Sale or transfer of the business

If all or part of the business is sold, reorganised or transferred, relevant personal information may be disclosed to professional advisers, prospective purchasers ( no personal data is shared until transfer is complete and the new owner where necessary and subject to appropriate confidentiality and data protection safeguards.

15. Changes to this policy

We may update this policy when our services, suppliers, use of technology or legal obligations change. The current version will be made available through our usual channels. Where a change materially affects how we use personal information, we will take reasonable steps to bring it to the attention of affected people before the new use begins.

This document, including its original wording, structure, design and branding, is the intellectual property of MF Dance (West) LLP. It is provided for information relating to MF Dance (West) LLP only.

No part of this document may be copied, reproduced, adapted, republished, distributed, presented as another organisation’s policy or used for commercial purposes without prior written permission from MF Dance (West) LLP, except where permitted by law.

The MF Dance name, logo and associated branding must not be copied or used without the permission of the relevant rights holder.

For permission enquiries, contact [email protected].

LOOKING FOR A DIFFERENT AREA?

SOCIAL MEDIA

BOOK YOUR FREE CLASSES

Check out our timetable below!

© 2026 MF Dance (West) LLP. All rights reserved.