Reskoo
How it works Pricing Log in Start a club

Privacy Policy

How Reskoo handles personal data, and which of us (we or your club) is legally responsible for what under UK data-protection law.

Version
1.0
Effective
23 July 2026
Operator
BN3 Consulting Limited (trading as Reskoo)
Company no.
12848799 (registered in England & Wales, based in Horsham)
ICO reference
ZC178630
Contact
hello@reskoo.app

1Who we are

Reskoo is a membership-management service built for UK lifesaving clubs. It is operated by BN3 Consulting Limited, a company registered in England and Wales (company number 12848799) and based in Horsham, England. In this policy, "Reskoo", "we", "us" and "our" mean BN3 Consulting Limited trading as Reskoo.

We are registered with the Information Commissioner's Office (ICO) under reference ZC178630. For any privacy question (or to exercise your rights over data we hold as controller), contact us at hello@reskoo.app.

2The roles: who is responsible for what

UK data-protection law splits responsibility between a "controller" (who decides how and why data is used) and a "processor" (who acts on the controller's instructions). For Reskoo:

  • Your club is the controller for the personal data of its members, and for the children, parents, and emergency contacts in those members' households. The club decides who to enrol, what to record, and how to use it.
  • Reskoo is the processor for that member data. We process it only on the club's instructions, under the data-processing terms in our Terms of Service.
  • Reskoo is the controller for data about the club itself: its account, billing details, and the people authorised to run Reskoo on the club's behalf (Owners, Managers, Staff).

3What we collect, and why

  • Account & billing data (we are controller): names, contact details, and payment-method references for the people who run a club's account with us. Card details are tokenised by Stripe, so we never see or store card numbers.
  • Member data, on behalf of clubs (we are processor): whatever a club records about its members and households. This may include children's data, health and allergy information, and safeguarding records. The club decides what to record and why; inside the product, safeguarding records are gated by a separate grant, independent of a person's role.
  • Operational data (we are controller): server logs and error reports we use to keep the service running and secure.

4Our lawful bases

For member data, the club (as controller) chooses the lawful basis. That is usually the performance of the membership arrangement (contract) or the club's legitimate interests in running its activities, plus consent where it's needed (for example marketing, or the use of photos and media).

Health and safeguarding information is special-category data under Article 9 of the UK GDPR. The club relies on an appropriate Article 9 condition (such as the provision of its activity, or reasons of substantial public interest for safeguarding), and Reskoo processes it only on the club's instructions.

For the data we hold as controller (billing, account administration, security), we rely on contract and legitimate interest.

Because clubs record data about children, Reskoo is built around data-minimisation and safeguarding controls, consistent with the ICO's Age Appropriate Design Code.

5Cookies and analytics

We use Fathom Analytics for website usage statistics. Fathom is privacy-first and cookieless: it sets no cookies, does not track people across sites, and collects only anonymous, aggregated page-view data and the referring page. No cookie banner is required because we use no cookies that need consent.

We use a small number of strictly-necessary cookies to keep you signed in. These don't require consent under UK PECR rules.

6Who we share data with

We use a small number of trusted providers ("sub-processors") to run the service. Each is bound by data-protection terms and handles data only as needed to deliver it:

  • Amazon Web ServicesHosting, database, sign-in, and email delivery. Primary region: London (UK).
  • StripeCard and Direct Debit payment processing.
  • Fathom AnalyticsPrivacy-first, cookieless website analytics.
  • SentryError and performance monitoring, to keep the service reliable.

We do not sell personal data, and we don't share it with anyone else except where the law requires it.

7Where your data is processed

Your core member data is stored and processed in AWS's London (UK) region. Some providers (notably Stripe and Sentry) may process limited data, such as payment details or diagnostic information, outside the UK. Where that happens, the transfer is protected by appropriate safeguards recognised under UK data-protection law, such as the UK International Data Transfer Agreement or an adequacy decision.

8How long we keep data

  • While a club's account is active, its data is retained.
  • After a club closes its account, personal data is kept for a 90-day wind-down (so the club can export and reconcile), then deleted.
  • Financial and transaction records are kept for 6 years to meet HMRC and accounting obligations, de-identified where we can.
  • Safeguarding records follow the club's own safeguarding-retention obligations, which are often longer; the club, as controller, decides these.
  • An individual's records can be deleted earlier on request through the club's data-request route, subject to the financial and safeguarding retention above.

9Your rights

Under the UK GDPR you have the right to access your data, correct it, have it erased, restrict or object to how it's used, and receive it in a portable form.

For member data, exercise these rights through your club, which is the controller. Reskoo gives the club the in-app tools (export and permanent erasure) to respond. For data we hold as controller (the account and billing details of people who run a club with us), contact us at hello@reskoo.app.

If you're unhappy with how your data has been handled, you can complain to the Information Commissioner's Office at ico.org.uk.

10Security

Every club's data is isolated from every other club's at the database layer. Sign-in uses AWS Cognito with mandatory multi-factor authentication for staff. Data is encrypted in transit and at rest, and backups are encrypted.

11Changes to this policy

We may update this policy from time to time. Substantive changes update the version above, and we email club owners about them; typo-level corrections don't.

How it worksPricingFAQLost & foundSecurityPrivacyTermsDPAContact

Reskoo - built for lifesaving clubs.

Version DF06A7F