Privacy Policy

About this policy 

This Privacy Policy is Connection Crew CIC's external privacy notice. It explains how we collect, use, share, store and protect personal information, the legal grounds we rely on, and the rights available to individuals under UK data protection law. 

It applies when Connection Crew CIC is the data controller, including through the services and teams it operates, such as Connection Crew and Stitch. It covers website visitors, people who contact us, clients and prospective clients, suppliers and partners, job and crew applicants, employees and workers, freelance crew, Academy participants, referral contacts, and other people whose information we use in our work. 

We may give you a shorter or more specific notice when we collect information from you, for example through our recruitment site, a workforce form, an Academy referral process, a photography consent form, or a cookie banner. Those notices should be read alongside this one. Where a specific notice describes a particular activity in more detail, that specific information applies to that activity. 

Sometimes we process personal information only on a client's documented instructions, for example where a client supplies an accreditation or attendee list for a project. In that situation the client is normally the controller and its privacy notice explains the use of the information. We will still protect the information and assist the client with its obligations. 

Who we are and how to contact us 

Data controller: Connection Crew CIC, company number 07008450. 

Registered office: Unit 1 & 2, St James Mews, 276 St James's Road, London, England, SE1 5JX. 

Data Protection Lead: Warren Rogers. 

Email: info@connectioncrew.co.uk. (Please use the subject line 'Privacy request' or 'Data protection complaint' so that it reaches the right person promptly.) 

Telephone: 020 7231 8117. 

Laws that apply 

We handle personal information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and those laws as amended by the Data (Use and Access) Act 2025. Other laws may also require or permit particular uses or retention periods, including employment, tax, health and safety, immigration, safeguarding, and limitation laws. 

Personal information we collect 

Identity and contact information 

Names, pronouns, dates of birth where relevant, addresses, email addresses, telephone numbers, emergency contacts, signatures, and identity or right-to-work evidence. 

Business and relationship information 

Job titles, organisations, professional contact details, enquiries, proposals, bookings, contracts, project details, venue and accreditation information, correspondence, feedback, and relationship history. 

Financial and transaction information 

Bank and payment details, invoices, purchase orders, expenses, payroll, pension, and tax information. Where a payment provider processes card information, we generally receive transaction details rather than full card data. 

Website and technical information 

IP address, device and browser information, cookie identifiers, security logs, pages viewed, referring links and interactions with our sites, forms, and communications. 

Recruitment, workforce and professional information 

Applications, CVs, work history, references, interview and assessment notes, qualifications, licences, training, skills, availability, assignments, attendance, time records, location or check-in information where needed for a job, performance, conduct, pay, and benefits. 

Academy, referral, and support information 

Referral details, eligibility, education and employment history, training attendance, support needs, barriers to work, programme outcomes and information needed by a funder, commissioner, or referral partner. 

Safety, access and incident information 

Next-of-kin details, access requirements, risk assessments, accident and near-miss reports, safeguarding information, complaints, and investigations. 

Images and communications 

Photographs, video or audio recordings, testimonials, case studies, survey responses, emails, call notes, messages, and social-media interactions. 

Equality, diversity and impact information 

Voluntarily supplied monitoring data, information about lived experience or disadvantage, and the information we need to measure and report our social mission. Wherever practical, reporting is aggregated or anonymised. 

More sensitive information 

Some information receives additional legal protection. Special-category information can include racial or ethnic origin, religious or philosophical beliefs, trade-union membership, genetic or biometric identification data, health information, and information about sex life or sexual orientation. Criminal-offence information is protected under a separate legal regime. 

We collect more sensitive information only where it is relevant and necessary, limit access to authorised people, and apply additional safeguards. Depending on the activity, we rely on an appropriate UK GDPR Article 6 lawful basis together with an Article 9 condition and, where required, a Data Protection Act 2018 Schedule 1 condition. These may include employment and social-protection law; equality of opportunity or treatment; safeguarding; occupational health; vital interests; legal claims; substantial public interest; or explicit consent for a genuinely optional use. 

We do not conduct criminal-record checks as a routine requirement for every role. Where information about an unspent conviction is disclosed, or a role-specific assessment is necessary, authorised staff use only the information needed to assess relevance to the role, legal and contractual requirements, safety and proportionate risk controls. We rely on the applicable Article 6 basis and a condition authorised by Article 10 and Schedule 1 of the Data Protection Act 2018, and maintain an Appropriate Policy Document where the law requires one. Decisions are not made by automated means. 

Where we obtain information 

We obtain personal information from the following sources: 

Directly from you 

For example through a website form, email, telephone call, booking, contract, application, onboarding process, survey, programme, meeting or event. 

From organisations connected with you 

Such as your employer, client, venue, event organiser, colleague, referee, emergency contact, recruitment agency, training provider, referral partner, funder, commissioner, or professional adviser. 

From public or professional sources 

Such as company websites, Companies House, professional directories, social-media or professional-network profiles, and publicly available event, or business information. 

From technology and service providers 

For example website, analytics, CRM, recruitment, scheduling, payment, security, and communication systems. 

From our own activities 

Such as project records, attendance, training, performance, safety reports, correspondence, feedback, and investigations. 

If we obtain your information from another source, we will provide or make this notice available within the period required by law, unless you already have the information or a legal exception applies. 

How and why we use personal information 

The lawful basis depends on the purpose and our relationship with you. We may rely on contract, legal obligation, legitimate interests, consent or vital interests. Where a new recognised legitimate-interest basis under UK law is relevant, we use it only for the purposes and subject to the safeguards set by law. We do not treat consent as the default basis where another basis is more appropriate. 

Websites, forms and digital services 

What we use 

Contact and form information, device and browser data, IP addresses, cookies, usage information, and security logs. 

Why we use it 

To operate and secure our websites, respond to requests, remember choices, diagnose faults, understand site performance, and improve content and services. 

Lawful bases 

Legitimate interests in operating, protecting and improving our digital services; contract or steps requested before a contract where a form relates to a service; legal obligation where applicable; and consent for non-essential cookies or tracking where PECR requires consent. 

Enquiries, quotations, and prospective clients 

What we use 

Contact details, organisation and role, enquiry or event information, correspondence, quote requirements, and relevant access or operational needs. 

Why we use it 

To respond, prepare and follow up quotations, understand requirements, arrange site visits or meetings, maintain a record of discussions, and develop our services. 

Lawful bases 

Steps requested before entering a contract; legitimate interests in responding to business enquiries, maintaining business relationships and developing our services; consent where a genuinely optional use requires. 

Clients, projects, venues, and service delivery 

What we use 

Business contacts, bookings, contracts, project and venue information, instructions, access and accreditation details, communications, service records, health and safety information, invoices, and feedback. 

Why we use it 

To plan, staff, and deliver projects; manage venues and access; communicate during delivery; protect health and safety; provide reports; invoice; resolve issues; and establish or defend legal rights. 

Lawful bases 

Contract where you contract with us personally; legitimate interests in delivering and administering contracts with organisations and providing safe, reliable services; legal obligations, including health and safety, tax and accounting; vital interests in an emergency; and legal claims where necessary. 

Suppliers, subcontractors, and business partners 

What we use 

Contact and business information, qualifications, due-diligence information, contracts, insurance, bank and tax information, performance records, and correspondence. 

Why we use it 

To select and manage suppliers, purchase services, make payments, maintain security and quality, administer partnerships, meet client or legal requirements, and manage disputes. 

Lawful bases 

Contract; legitimate interests in operating our business and supply chain; and legal obligations relating to tax, accounting, safety, sanctions, or other applicable requirements. 

Recruitment and selection 

What we use 

Contact details, application and CV information, work history, references, interview and assessment information, eligibility and right-to-work evidence, access needs and, where lawful and necessary, limited criminal-offence information. 

Why we use it 

To advertise opportunities, assess suitability, make and administer offers, provide reasonable adjustments, check eligibility, maintain recruitment records, and defend legal claims. 

Lawful bases 

Steps requested before a contract; legal obligations, including right-to-work and equality requirements; legitimate interests in fair and effective recruitment; and the additional conditions described under 'More sensitive information'. 

Our recruitment website provides additional recruitment-specific privacy information, and tools to request or remove recruitment data. 

Employees, workers, freelance crew, and contractors 

What we use 

Identity and contact details, emergency contacts, contracts, right-to-work and tax information, bank details, availability, assignments, skills and training, attendance and time records, performance and conduct, pay and benefits, safety and incident information, access needs, equality monitoring, and other workforce records. 

Why we use it 

To enter into and manage working relationships; schedule and deploy crew; pay people; provide training; monitor standards; communicate operational information; meet employment, tax, immigration, equality, safeguarding and safety obligations; manage complaints or investigations; and provide evidence to clients where proportionate. 

Lawful bases 

Contract; legal obligation; legitimate interests in workforce planning, project delivery, quality, safety, security and client assurance; vital interests in an emergency; and the additional special-category or criminal-offence conditions described above. 

Where we share a crew member's name, role, relevant qualification or contact information with a client, venue or event organiser, we limit the information to what is reasonably required for deployment, accreditation, safety, communication, or verification. 

Connection Crew Academy, referrals, and employment support 

What we use 

Identity and contact information, referral and eligibility information, work and education history, programme attendance and outcomes, support and access needs, barriers to work, safety and safeguarding information, and information required by referral or funding arrangements. 

Why we use it 

To assess eligibility and suitability; deliver training, mentoring and support; make referrals or introductions; arrange paid work or progression; provide reasonable adjustments; protect participants; meet funder or commissioner requirements; and evaluate programme outcomes. 

Lawful bases 

Contract or steps requested before a contract; legitimate interests in operating the Academy and furthering Connection Crew's social mission; legal obligations; vital interests; and applicable special-category conditions, including social protection, equality, safeguarding, substantial public interest or explicit consent for optional activities. 

Referral partners should provide individuals with relevant privacy information before sending us their details. We will use referral information only for the stated referral, support, work and reporting purposes, unless another use is lawful and transparent. 

Social impact, equality monitoring, and reporting 

What we use 

Information about participation, work outcomes, equality and diversity, lived experience and barriers to work, together with testimonials or images where separately agreed. 

Why we use it 

To measure our social mission, improve inclusion and support, meet CIC, B Corp, funder, client or partnership reporting requirements, demonstrate social value, and communicate impact. 

Lawful bases 

Legitimate interests in measuring and demonstrating our social purpose and improving our services; legal or contractual requirements where applicable; substantial public interest conditions for equality monitoring; and explicit consent for named stories, sensitive quotations, or promotional images where consent is appropriate. 

We use aggregated or anonymised information wherever that can meet the reporting purpose. We do not publish identifiable information about a person's experience of homelessness, health, criminal history, or other sensitive circumstances without a valid lawful basis and appropriate transparency, and their explicit agreement for a named public story. 

Marketing, newsletters, and relationship communications 

What we use 

Names, roles, organisations, professional contact details, interests, enquiry or client history, subscription choices, and engagement with communications. 

Why we use it 

To send requested updates, relevant service or impact news, event invitations and business-development communications; manage preferences; and measure communication effectiveness where permitted. 

Lawful bases 

Consent where PECR requires it; the applicable soft opt-in where all legal conditions are met; and legitimate interests for proportionate business-to-business relationship marketing where PECR permits this. Every electronic marketing message provides a simple way to opt out. 

We do not buy purported 'soft opt-in' lists. We screen and manage marketing preferences as required and keep a minimal suppression record after an opt-out. 

Photography, film, case studies, and social media 

What we use 

Images, recordings, names, roles, quotations, testimonials, project information, and social-media interactions. 

Why we use it 

To document projects, communicate our services and impact, provide client reporting, share news, and promote opportunities. 

Lawful bases 

Legitimate interests for proportionate business and project communications; contract where content is part of an agreed service; and consent or explicit consent where the use is optional, particularly personal impact stories or sensitive information. 

Safety, safeguarding, complaints, and legal matters 

What we use 

Incident, accident, near-miss, safeguarding, complaint, conduct, insurance, correspondence and legal-claim information, which may include health or criminal-offence information. 

Why we use it 

To protect people, investigate and respond, meet reporting duties, maintain insurance, prevent or detect unlawful acts, and establish, exercise, or defend legal claims. 

Lawful bases 

Legal obligation; legitimate or recognised legitimate interests where applicable; vital interests; legal claims; and relevant Data Protection Act 2018 conditions for sensitive or criminal-offence information. 

IT security, fraud prevention and business administration 

What we use 

Account, access, device, audit, security and communications information, together with information necessary for insurance, audits, certification, governance, and corporate transactions. 

Why we use it 

To protect systems and people, manage permissions, detect security incidents or fraud, maintain business continuity, comply with audits and certifications, and administer or restructure the organisation. 

Lawful bases 

Legitimate interests in security, governance and business administration; legal obligation; recognised legitimate interests where specifically available; and legal claims. 

If you do not provide information 

Some information is required by law or is necessary to enter into or perform a contract, deliver a safe service, pay you, verify a right to work, arrange site access or assess eligibility for a particular programme. We will identify mandatory fields or explain the requirement when we collect the information. If you do not provide necessary information, we may be unable to provide a service, enter into or continue a working relationship, process an application, make a payment or provide access to a project or programme. Optional information will be clearly distinguished wherever practical. 

Who we share information with 

We share only what is reasonably necessary for the relevant purpose. Depending on your relationship with us, recipients may include: 

Technology and administration providers 

Website and hosting providers; cloud storage and email; CRM, scheduling and workforce systems; recruitment platforms; analytics and cookie providers; IT support, cyber-security, document-signing and communications services. These include, where used, Microsoft 365, HubSpot, OnSinch, and Teamtailor. 

Finance and employment providers 

Banks, payment providers, payroll and pension providers, accountants, auditors, insurers, benefits providers, and professional advisers. 

Clients and project organisations 

Clients, venues, event organisers, production partners, accreditation or access providers and other project suppliers where information is needed to plan, deploy, access, communicate, protect safety, or verify delivery. 

Recruitment, training and support organisations 

Referees, recruitment agencies, training and certification providers, occupational-health or wellbeing providers, referral partners, funders, commissioners, and public employment or support services. 

Public and regulatory bodies 

HM Revenue & Customs, immigration and employment authorities, emergency services, police, courts, regulators, local authorities, and other bodies where disclosure is required or permitted by law. 

Corporate and professional recipients 

Legal advisers, consultants, certification bodies, prospective purchasers, investors or restructuring advisers, subject to confidentiality and appropriate safeguards. 

Some recipients act as our processors and may use information only on our instructions. Others, such as HMRC, a client, venue, funder, or professional adviser, may act as an independent controller for their own legal purposes. We require appropriate contracts and safeguards where data protection law requires them. We do not sell personal information. 

International transfers 

Some technology or service providers may store or access personal information outside the UK. Before making a restricted international transfer, we use a lawful transfer mechanism and consider the protection available in the destination. Depending on the circumstances, this may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another mechanism permitted by UK law. We may also apply contractual, technical, and organisational safeguards such as access controls and encryption. 

You may contact us for more information about the safeguard used for a particular transfer and, where available, to request a copy. We may redact confidential or third-party information from that copy. 

How long we keep information 

We retain personal information only for as long as it is needed for the stated purpose, legal and regulatory requirements, funding or contractual obligations, safety, dispute resolution and the establishment or defence of claims. The table gives our usual periods or the criteria we apply; a longer or shorter period may apply where a specific law, contract, claim, safeguarding concern or active investigation requires it. 

Usual retention period or criteria 

Website cookies and similar technologies 

For the period stated in the relevant Cookie Policy or cookie-preference tool. Security and operational logs are retained for the period needed to operate, diagnose and protect the service, and longer only where an incident is under investigation. 

Enquiries that do not become a client relationship 

Normally up to two years after the last meaningful contact, unless the person asks us to delete the information sooner or a legal issue requires retention. 

Client, project, contract and supplier records 

Normally six years after the end of the relevant contract, project or business relationship. Core financial and contractual evidence may be retained longer where law or an active claim requires it. 

Accounting, tax, payment and payroll records 

Normally six years plus the current tax or accounting year, or for any longer period required by tax, pension or company law. 

Right-to-work evidence 

For the working relationship and two years after it ends, unless the applicable law changes. 

Unsuccessful recruitment applications 

Normally six months after the recruitment process. Where a person joins a talent pool or agrees to consideration for future opportunities, normally up to 24 months, subject to the recruitment notice and periodic review. 

Employees, workers, freelance crew and contractors 

Core records are normally retained for six years after the relationship or last engagement ends. Some pension, tax, health and safety or legal records may require a different period. 

Academy and funded-programme records 

Normally six years after participation ends or for the period specified by the relevant funder or commissioner. Safeguarding or legal records may be retained longer where necessary. 

Criminal-offence information 

Only for the minimum period necessary for the relevant assessment or legal purpose, in line with our Appropriate Policy Document where applicable. Detailed information is deleted or restricted when no longer required; a limited decision or risk-management record may be retained where necessary. 

Accident, incident and health and safety records 

Normally at least three years from the relevant report or event, with longer periods where the individual was under 18, an investigation or claim remains possible, or another legal rule applies. 

CCTV, where used 

Normally 30 to 90 days, unless footage is needed for an incident, investigation, insurance matter or legal claim. Signage or a local notice will provide more information. 

Marketing records 

Until consent is withdrawn, an objection is made or the information is no longer useful. Active marketing records are reviewed periodically, normally at least every 24 months. A minimal suppression record may be kept for as long as needed to honour an opt-out. 

Privacy requests, complaints and legal matters 

Normally six years after closure, or longer while a claim, investigation or regulatory matter remains active. 

Anonymised or aggregated information 

May be retained indefinitely because it no longer identifies an individual. 

When a retention period ends, we securely delete, destroy, or anonymise the information. Data may remain in protected backups until the relevant backup cycle expires, during which it is not used for ordinary business purposes. 

Cookies and similar technologies 

Our websites may use cookies and similar storage or access technologies. Strictly necessary technologies are used to provide and secure the site. We ask for consent before using non-essential cookies where PECR requires consent. UK law permits limited exceptions for certain low-intrusion functions; where we rely on an exception, we still provide clear information and an available way to object where the law requires one. 

The cookie banner or preference tool on the relevant website identifies the current cookies, their providers, purposes and duration. You can change or withdraw non-essential cookie choices through that tool. Blocking some technologies may affect site functionality. Cookie information for our recruitment site is available separately. 

View the recruitment-site Cookie Policy

Automated decision-making and profiling 

We do not currently make decisions about people solely by automated means where the decision produces legal or similarly significant effects. Systems may assist with administration, matching, scheduling, analytics, or prioritisation, but significant recruitment, work-allocation, risk and conduct decisions involve authorised people. If this changes, we will provide the information required by law, including meaningful information about the logic, likely consequences, and available safeguards. 

Information about children and young people 

Our main business website and services are not directed at children. If a recruitment, work-experience, training, Academy or event activity involves someone under 18, we take their age and needs into account, provide age-appropriate information, limit the data collected, and obtain parent or guardian involvement where the law or circumstances require it. Safeguarding obligations may require us to use or share information without consent where this is lawful and necessary to protect a child or another person. 

How we protect information 

We use proportionate technical and organisational measures designed to protect confidentiality, integrity and availability. These include access controls based on job need, multi-factor authentication where available, password standards, device and endpoint protection, encryption where appropriate, backups, supplier due diligence, contractual controls, staff training, incident procedures and secure disposal. No internet or storage system can be guaranteed completely secure, but we review safeguards against the nature of the information and the risks involved. 

If a personal data breach presents a risk to people's rights and freedoms, we will report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. If it is likely to create a high risk for affected people, we will also tell them without undue delay unless a legal exception applies. 

Your data protection rights 

Your rights depend partly on the lawful basis and circumstances. They are not absolute, and a legal exemption may sometimes apply. You may ask us to explain a refusal or restriction. 

Access 

You may ask whether we use your personal information and request a copy, together with supporting information about the processing. 

Correction 

You may ask us to correct inaccurate information or complete information that is incomplete. 

Erasure 

You may ask us to delete information in circumstances set by law, for example where it is no longer needed and no overriding legal reason requires retention. 

Restriction 

You may ask us to restrict how information is used while a dispute about accuracy, lawfulness or our grounds for processing is considered. 

Objection 

You may object to processing based on legitimate interests or certain public-interest grounds. We will stop unless we demonstrate compelling overriding grounds or need the information for legal claims. 

[You have an absolute right to object to the use of your personal information for direct marketing. We will honour the objection and may retain only enough information to prevent further marketing.] 

Data portability 

Where processing is automated and based on consent or contract, you may ask for information you provided to us in a structured, commonly used and machine-readable format, or for it to be sent to another controller where technically feasible. 

Withdraw consent 

Where we rely on consent, you may withdraw it at any time as easily as you gave it. Withdrawal does not affect processing that was lawful before withdrawal or processing supported by another lawful basis. 

Automated decisions 

Where the law gives you rights concerning a solely automated significant decision, you may request human involvement, express your view, and challenge the decision. 

How to exercise your rights 

Email info@connectioncrew.co.uk or write to our registered office, marking the message for the Data Protection Lead. Describe what you are requesting and provide enough information for us to locate the relevant records. You do not normally have to pay a fee. We may ask for proportionate proof of identity only where we have reasonable doubts about identity or authority. 

We normally respond without undue delay and within one month. The law may allow an extension for a complex request or multiple requests; if so, we will explain this and give the expected date. We carry out reasonable and proportionate searches when responding to access requests. 

How to make a data protection complaint 

If you are unhappy with how we have used your information, handled a rights request or protected your data, please email info@connectioncrew.co.uk with the subject line 'Data protection complaint', or write to the Data Protection Lead at our registered office. Tell us what happened, what information is involved and what outcome you are seeking. If another person acts for you, we may ask for evidence of their authority. 

We will acknowledge receipt within 30 days. Without undue delay, we will make appropriate enquiries, keep you informed where the matter is ongoing and tell you the outcome. We will record the complaint and any action taken in line with our retention schedule. 

You also have the right to complain to the Information Commissioner's Office (ICO). We would appreciate the opportunity to address the issue first, but you do not lose your right to approach the ICO. 

Make a complaint to the ICO  |  ICO Helpline: 0303 123 1113  |  Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. 

Changes to this notice 

We review this notice regularly and update it when our activities, systems, suppliers or legal obligations change. The effective date at the beginning shows when it was last updated. If a change materially affects how we use information already collected, we will bring the change to the attention of affected people before the new use begins where the law requires this. 

Contact summary 

Privacy requests and complaints: info@connectioncrew.co.uk. 

Data Protection Lead: Warren Rogers. 

Post: Connection Crew CIC, Unit 1 & 2, St James Mews, 276 St James's Road, London, England, SE1 5JX. 

Telephone: 020 7231 8117.