Skip to main content

General Privacy Notice

(How we use personal information)

Preamble

Renfrewshire Leisure Ltd, trading as OneRen, and referred to in this privacy notice as "OneRen", "we", "us" or "our", controls and processes a range of personal information about individuals who interact with us, use our website, use our services, visit our premises, work with us, supply goods or services to us, apply for opportunities with us, or otherwise communicate with us.

In this privacy notice, "your personal information" means your personal data, namely information about you from which you can be identified, directly or indirectly. Your personal information does not include data where your identity has been removed so that you can no longer be identified from it, either on its own or when combined with other information available to us.

It is important that the personal information we hold about you is accurate and up to date. Please keep us informed if your personal information changes during your relationship with us, including where you change your contact details, membership details, account details, service requirements, accessibility needs, emergency contact details, or other information relevant to the services or relationship we have with you.

This notice explains what personal information we collect, when we collect it, where it comes from, why we use it, the lawful bases we rely on, who it may be shared with, how long we keep it, and the rights you have under UK data protection law.

During the course of our activities, we will process personal data about you. This information may be held electronically, on paper, in membership, booking, ticketing, library, museum, leisure, finance, customer relationship, recruitment, procurement, communications, security, audio-visual or operational systems, within email and collaboration platforms, or otherwise. We recognise the need to treat your personal information in an appropriate, fair, transparent and lawful manner.

Introduction

The purpose of this General Privacy Notice is to explain the reasons why OneRen may collect, hold, use, disclose and otherwise process your personal information, and to explain your rights under current data protection laws.

OneRen is a local charitable trust providing culture, leisure, sport, libraries, museums, heritage, learning, health and wellbeing, venue, community and related public services in Renfrewshire. This notice applies to personal information processed in connection with those services and with OneRen's website, apps, online services, communications and general administration.

This notice applies to website users, customers, members, other service users, visitors, event attendees, ticket holders, library and leisure users, sports participants, supporters, volunteers (where not covered by a separate notice), subscribers to mailing lists, competition entrants, people who contact us, complainants, correspondents, parents, guardians, carers, children and young people where relevant, applicants for jobs or other opportunities, contractors, consultants, suppliers, business contacts, professional advisers, and other individuals whose personal information we process.

This notice should be read alongside any more specific privacy information we provide to you at the point we collect your personal information. Where you are an employee, worker, agency worker, consultant, contractor, volunteer, apprentice or intern working for or with OneRen in an HR context, our Employee Privacy Notice will provide you with the necessary privacy information.

This notice does not form part of any contract, membership agreement, booking terms, employment contract, supplier agreement or other agreement with us. We may amend this notice from time to time. Where we make material changes, we will notify you as appropriate.

Your personal information will be processed by:

OneRen,
Renfrewshire House,
Cotton Street,
Paisley,
PA1 1JD

Renfrewshire Leisure Ltd is registered as a data controller with the Information Commissioner's Office ("ICO") under registration number Z7486491.

Our Data Protection Officer is provided by RGDP LLP and can be contacted using the details set out in the "Queries and Complaints" section of this notice.

Where does your personal information come from?

OneRen may collect your personal information from a range of sources, including:

  • personal data which you provide directly to us;
  • forms, accounts, applications, memberships, booking records, ticketing records, library records, leisure management systems, online accounts, mobile apps, website forms, enquiry forms, feedback forms, complaints forms, venue hire forms, donation forms, survey responses, competition entries, consent forms, event registration forms and service-specific forms;
  • information provided when you visit, book, buy, subscribe, donate, register, attend, participate in, hire, cancel, change, renew or otherwise use OneRen services;
  • information provided by parents, guardians, carers, family members, schools, clubs, community groups, teams, coaches, teachers, youth workers, support workers, referrers or representatives where they act on your behalf or provide information relevant to a service;
  • information from partner organisations, funders, referral bodies, community organisations, public bodies, local authorities, health bodies, sports bodies, arts and cultural bodies, educational bodies, charitable partners, venues, ticketing partners or event partners where relevant and lawful;
  • payment processors, banks, direct debit providers, debt management partners, Renfrewshire Council, courts, professional advisers or other organisations involved in payments, refunds, arrears, debt recovery or financial administration;
  • identity documents, proof of age, eligibility information, residency information, concession entitlement information, membership eligibility information or other verification documentation provided by you or on your behalf;
  • health, disability, accessibility, wellbeing, fitness-to-participate, emergency, safeguarding, incident, accident or risk information provided by you or by someone acting lawfully on your behalf;
  • CCTV, access control, security systems, visitor sign-in records, body-worn or fixed audio-visual systems, incident reporting systems and venue management systems where you are captured or identifiable;
  • website, app, Wi-Fi, online booking, streaming, ticketing, email, SMS, telephony, social media, analytics, cookies, device, network, security and technical logs;
  • social media platforms and other online platforms where you interact with OneRen, tag OneRen, message us, comment on our content, take part in campaigns or otherwise make information available to us;
  • recruitment platforms, application forms, CVs, covering letters, interview notes, assessment materials, referees, previous employers, background-check providers, Disclosure Scotland, the PVG scheme, occupational health providers and other recruitment sources;
  • contractors, suppliers, service providers, consultants, agencies, professional advisers and other business contacts;
  • procurement portals, tender submissions, contract documents, due diligence materials, supplier questionnaires, insurance documents, health and safety documents, accreditation records and financial systems;
  • government agencies, regulators, law enforcement bodies, courts, tribunals, auditors, insurers, solicitors, professional advisers, safeguarding bodies, OSCR, Companies House, HM Revenue & Customs, and other public authorities;
  • information generated through your relationship with OneRen, including service records, attendance records, participation records, account history, correspondence, case records, complaint records, consent records, preference records, audit records, operational records and notes made by authorised staff.

 

What Information do we collect and why?

The personal information we collect and process may include the following categories of information.

Identification and contact details

  • your name, address, email address, telephone number and other contact details;
  • date of birth, age, title, preferred name and gender where relevant;
  • customer, member, library, booking, ticketing, account, application, supplier, invoice or other reference numbers;
  • proof of identity, proof of age, proof of address, concession, eligibility, residency or entitlement information where required;
  • parent, guardian, carer, emergency contact, representative or authorised contact details where relevant.

We use this information to identify you, communicate with you, maintain accurate records, create and manage accounts, administer memberships, bookings, tickets, library records, event participation, venue hire, payments, donations, recruitment, supplier relationships and service records, verify eligibility, confirm entitlement to services or concessions, meet legal, contractual, safeguarding and operational requirements, and deliver OneRen services.

Account membership, booking, ticketing and service information

  • account registration details, usernames, membership details, access credentials and service preferences;
  • membership start and end dates, membership type, payment status, attendance, booking history, cancellation history and service usage records;
  • fitness class bookings, swimming bookings, gym access records, venue hire records, theatre, performance, event and ticketing records;
  • library membership, borrowing, reservation, overdue, replacement, fines or service-use information where relevant;
  • programme, course, workshop, activity, camp, sports, arts, culture, museum, heritage, health and wellbeing, school or community participation records;
  • information relating to access to premises, facilities, online services, apps, digital content, RenTV or other OneRen channels.

We use this information to provide, administer, manage and improve our services, process bookings, manage attendance and capacity, provide access to facilities and content, administer memberships and cancellations, manage ticketing and events, support customer service, plan service delivery, maintain service records, comply with health and safety and safeguarding requirements, manage payments and arrears, and support public-interest cultural, leisure, sporting, library, museum, heritage, wellbeing and community services.

Payment, transaction and financial information

  • payment details, direct debit details, card payment references, payment status and transaction records;
  • membership fees, booking fees, ticket purchases, refunds, donations, Gift Aid information where relevant, venue hire charges, invoices, purchase orders, supplier payments and other financial records;
  • arrears, debt recovery, failed payments, refunds, cancellations, chargebacks and related correspondence;
  • bank account details, tax information, VAT information, payroll or payment information for suppliers, contractors or other business contacts where relevant.

We use this information to process payments, refunds, donations, bookings, memberships, venue hire, supplier payments, invoices and purchase orders; administer direct debits; maintain financial and accounting records; manage arrears and debt recovery; prevent and detect fraud; comply with tax, accounting, charity, audit and legal obligations; and establish, exercise or defend legal claims.

Enquiries, correspondence, complaints, feedback and surveys

  • enquiries, comments, requests, complaints, compliments, feedback, survey responses and service-improvement suggestions;
  • records of telephone calls, emails, letters, online forms, social media messages, webchat or other communications;
  • complaint details, investigation notes, outcomes, correspondence and related case management records;
  • preferences about how and when you wish to be contacted.

We use this information to respond to you, provide customer support, resolve issues, investigate complaints, improve services, monitor service quality, evidence our handling of matters, respond to rights requests, maintain records of decisions, train staff where appropriate, comply with legal and regulatory obligations, and support accountability and public service improvement.

Marketing, communications, newsletters, campaigns and fundraising information

  • marketing preferences, mailing list subscriptions, opt-in and opt-out records, consent records and preference centre records;
  • information about events, activities, performances, services, offers, campaigns, fundraising, donations, volunteering, community initiatives or charitable support that you have asked to receive or may reasonably expect to receive where lawful;
  • records of emails, SMS messages, postal communications, telephone communications or other marketing and service communications sent to you;
  • campaign, competition, prize draw, promotion, fundraising, donor and supporter information.

We use this information to send service communications, membership updates, booking information, event information, newsletters, marketing communications, fundraising communications, campaign information, competition communications and other information about OneRen services where lawful. We also use this information to manage mailing lists, record preferences, administer donations and supporter relationships, measure engagement, avoid sending marketing where you have opted out, and comply with direct marketing and privacy laws.

Website, app, cookies, analytics and online identifiers

  • IP address, device identifiers, browser type, operating system, referral source, pages viewed, dates and times of visits, website navigation, clickstream data and related analytics information;
  • cookie identifiers, consent records, preference records and similar technologies used on our website, apps, online booking systems, digital services, streaming services or email communications;
  • online account activity, login records, security logs, error logs, app usage records, Wi-Fi usage records and technical records;
  • information generated through social media engagement, embedded content, video platforms, ticketing platforms, payment platforms, booking systems or third-party online services where relevant.

We use this information to operate, secure, maintain and improve our website, apps and online services; remember preferences where lawful; manage cookie choices; deliver online bookings, memberships, ticketing, streaming and digital content; understand how services are used; monitor performance; troubleshoot issues; prevent fraud, misuse and cyber security incidents; comply with legal obligations; and provide relevant communications where permitted.

Please note, we have a separate cookie notice, available here.

Images, video, audio and associated recordings

  • photographs, video footage, voice recordings and associated audio-visual material;
  • CCTV footage, security footage, body-worn or fixed camera footage, incident footage and access-control images where relevant;
  • recordings or photographs from events, performances, activities, workshops, learning sessions, sports sessions, museum, heritage, cultural or community programmes;
  • recorded telephone calls, online meetings, webinars, training, presentations, public information videos, educational videos, interpretive content and digital content where you are captured or identifiable.

We use this information for purposes including service delivery, security, health and safety, safeguarding, incident investigation, crime prevention and detection, accessibility, training, quality assurance, educational and cultural learning resources, museum interpretation, heritage engagement, public information, customer service, event management, community engagement, public accountability and approved communications.

Children, young people, parents, guardians, carers, schools and community participants

  • child or young person's name, age, date of birth, school, class, group, club, team, activity, programme, session, booking or participation details;
  • parent, guardian, carer, emergency contact, consent and collection information;
  • medical, allergy, accessibility, disability, wellbeing, behavioural, support, safeguarding, incident or risk information where relevant and proportionate;
  • photographic, video or audio consent records and participation permissions;
  • information provided by schools, clubs, coaches, teachers, youth workers, parents, guardians, carers, referrers or partner organisations.

We use this information to administer activities for children and young people, manage consent and parental involvement, provide safe access to services, deliver school, library, sport, arts, culture, heritage, museum, community, holiday, learning and wellbeing programmes, make reasonable adjustments, manage health and safety, protect children and vulnerable groups, respond to incidents, meet safeguarding obligations, and deliver OneRen's public-interest services.

Health, accessibility, disability, wellbeing, safeguarding, accident and incident information

  • health conditions, disability, accessibility needs, allergies, medication information, fitness-to-participate information, wellbeing information and reasonable adjustment requirements;
  • accident, incident, near-miss, injury, emergency, first aid, risk assessment, safeguarding, child protection, adult protection, welfare, referral and case management records;
  • information about support needs, vulnerabilities, behavioural risks or restrictions where relevant to safe service delivery;
  • information from medical professionals, emergency services, safeguarding bodies, health providers, schools, carers, parents, guardians, local authorities, or other relevant organisations where lawful.

We use this information to protect your health, safety and wellbeing; make reasonable adjustments; provide accessible and inclusive services; assess suitability and risk for activities; administer first aid and emergency responses; manage safeguarding, child protection and adult protection matters; investigate incidents; comply with health and safety, equality, safeguarding, public health and legal obligations; and support service continuity and safe participation.

Equality, diversity, inclusion and monitoring information

  • equalities monitoring information, where you choose to provide it or where we are required to collect it;
  • information about protected characteristics, including age, disability, sex, gender reassignment, race or ethnicity, religion or belief, sexual orientation, marriage or civil partnership, pregnancy or maternity, where relevant and lawful;
  • information about care experience, socio-economic circumstances, access needs or other inclusion-related information where relevant to a programme, application, grant, funding, reporting or service objective.

We use this information to monitor and promote equality, diversity, inclusion and accessibility, assess the reach and impact of OneRen services, support fair access, administer guaranteed interview or inclusion schemes where relevant, comply with equality and reporting obligations, support public-interest service planning, produce anonymised or aggregated reporting, and help ensure that services are fair, accessible and inclusive.

Recruitment and applicant information

  • application forms, CVs, covering letters, supporting information and candidate profile information;
  • qualifications, skills, experience, employment history, licences, certifications, memberships and other suitability information;
  • interview notes, assessment results, recruitment decision records and correspondence;
  • references, pre-employment screening information, right-to-work information, identity documents, criminal conviction information where relevant and lawful, Disclosure Scotland or PVG information where required;
  • reasonable adjustment information, equality monitoring information and care-experienced status where relevant to recruitment schemes or monitoring;

We use this information to manage recruitment and selection, assess suitability for roles, communicate with applicants, provide vacancy alerts where requested, make recruitment decisions, carry out pre-employment checks, verify identity and right to work, make reasonable adjustments, support equality monitoring, administer guaranteed interview or inclusion schemes, meet safeguarding and regulatory requirements, enter into employment or other working arrangements with successful candidates, and comply with legal obligations.

Once you have successfully entered into a contract of employment with us, the Employee Privacy Notice will govern the data processing activities involving your personal data.

Contractor, supplier, consultant and business contact information

  • names, roles, job titles, business contact details, organisation details and correspondence records;
  • tender, procurement, due diligence, insurance, health and safety, qualification, certification, accreditation, conflict of interest, financial standing and contract information;
  • purchase orders, invoices, payment details, bank details, tax information, VAT information, credit control records and supplier account records;
  • records relating to access to premises, systems, facilities, keys, ID badges, induction, training, incident reporting, safeguarding, health and safety and service delivery;
  • contract management records, performance records, complaints, audit findings, investigation records and legal correspondence.

We use this information to procure goods and services, assess suppliers, manage tenders and contracts, administer payments and invoices, maintain procurement and financial records, manage access to premises and systems, comply with health and safety, safeguarding, charity, audit, procurement, tax and legal obligations, manage disputes, establish, exercise or defend legal claims, and support the effective delivery of OneRen services.

Premises, security and access information

  • visitor, customer, contractor, supplier, staff, volunteer or guest sign-in records;
  • CCTV, access control, door entry, alarm, incident and security records;
  • vehicle registration details, parking, delivery, restricted area access, key, pass, badge or permit records where relevant;
  • records relating to banned, restricted or excluded individuals where lawful and proportionate.

We use this information to manage access to OneRen premises and restricted areas, protect staff, service users, visitors, contractors, suppliers, buildings and assets, maintain safety and security, prevent and detect crime, investigate incidents, comply with health and safety and safeguarding obligations, manage emergencies, support business continuity, and enforce lawful restrictions where necessary.

Governance, compliance, legal, audit and organisational administration information

  • information required for governance, charity administration, statutory reporting, public accountability, audit, insurance, finance, legal claims, regulatory correspondence, risk management or complaints handling;
  • information relating to subject access requests, data protection rights requests, freedom of information requests, environmental information requests, complaints, investigations or regulatory matters;
  • information required for safeguarding, public-interest service delivery, funding, grants, partnership reporting, community benefit reporting, research, evaluation and statistical purposes where lawful;
  • any other information which is reasonably necessary for OneRen's services, legal obligations, public-interest functions, legitimate interests, contractual relationships, safeguarding responsibilities or organisational administration.

We use this information to meet legal, regulatory, contractual, charitable, governance, accounting, audit, insurance, safeguarding, reporting and public accountability obligations, respond to requests and complaints, manage risk, improve services, demonstrate community benefit, administer funding and grants, establish, exercise or defend legal claims, and ensure effective organisational administration.

Where do we store your personal data?

Your personal information may be held in membership systems, booking systems, ticketing systems, library systems, leisure management systems, customer relationship systems, finance systems, payment systems, recruitment systems, procurement systems, case management systems, email systems, website systems, app systems, security systems, audio-visual systems, shared drives, archives and other secure locations. Access to such information is restricted to those who require it for authorised purposes.

Your information will generally be processed within the United Kingdom. Where personal data is transferred outside the UK, we will ensure that the transfer is lawful and protected by appropriate safeguards. This may include adequacy regulations, standard contractual clauses, the International Data Transfer Agreement, the UK Addendum, or another lawful transfer mechanism.

Where we use online services, cloud providers, support providers, ticketing systems, booking systems, payment providers, email systems, analytics services, recruitment systems, social media platforms or other technology services, personal data may be accessed from or processed in countries outside the UK. We will assess such transfers and apply appropriate safeguards where required.

What are the legal bases for us processing your personal data?

We will only process your personal data where we have a lawful basis to do so. Depending on the purpose of processing, we may rely on one or more of the following lawful bases:

  • Contract: where processing is necessary for the performance of a contract with you, such as a membership agreement, booking, ticket purchase, venue hire arrangement, supplier contract, consultancy agreement or other agreement, or to take steps at your request before entering into such a contract or arrangement.
  • Legal obligation: where processing is necessary for us to comply with a legal obligation, including obligations relating to health and safety, safeguarding, equality, charity administration, tax, accounting, employment, immigration, procurement, audit, statutory reporting, information rights, public records, crime prevention or regulatory requirements.
  • Public task: where processing is necessary for the performance of a task carried out in the public interest, including OneRen's public-interest functions connected with culture, leisure, sport, libraries, museums, heritage, learning, health and wellbeing, community access, public participation, service planning, public accountability and related public services.
  • Legitimate interests: where processing is necessary for our legitimate interests or those of a third party, except where your interests, rights and freedoms override those interests. Where we rely on legitimate interests, we will consider whether the processing is necessary and whether your interests, rights and freedoms override the interests relied upon. Current examples of processing activities relying on legitimate interests may include aspects of customer administration, service improvement, fraud prevention, debt recovery, CCTV surveillance, information systems security, supplier management, handling general enquiries, maintaining records, managing complaints, protecting OneRen's assets, member analysis, reporting & service improvement, and maintaining business continuity.
  • Recognised legitimate interests: as added via the Data (Use and Access) Act 2025, where a pre-approved recognised legitimate interest applies under UK GDPR and the processing is necessary for that recognised purpose. This lawful basis is limited and will only be used where the relevant statutory condition applies, such as specified public-interest disclosure, emergency, crime prevention or safeguarding circumstances.
  • Vital interests: where processing is necessary to protect your life or the life of another person, such as in a medical emergency or serious incident.
  • Consent: where you have given clear consent for a specific purpose, such as receiving certain marketing communications, participating in certain optional activities, allowing non-essential cookies, or using images or audio-visual material for specified promotional purposes. Where we rely on consent, you may withdraw your consent at any time.

The lawful basis relied upon will depend on the purpose and context of the processing. We may rely on different lawful bases for different purposes involving the same category of personal data.

Our Processing of Special Category Personal Data

Special category personal data means personal data revealing or concerning:

  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade union membership;
  • genetic data;
  • biometric data where used for the purpose of uniquely identifying a person;
  • health;
  • sex life; or
  • sexual orientation.

Special category personal data requires a higher level of protection. Where we process special category personal data, we must identify both an Article 6 lawful basis and an Article 9 condition under UK GDPR. Where required, we will also identify an appropriate condition under Schedule 1 of the Data Protection Act 2018 and maintain an appropriate policy document.

Our Article 9 condition for processing your special category personal data may include one or more of the following:

  • you have given explicit consent;
  • processing is necessary to protect vital interests where you are physically or legally incapable of giving consent;
  • the information has been manifestly made public by you;
  • processing is necessary for legal claims or judicial acts;
  • processing is necessary for reasons of substantial public interest, with a basis in law;
  • processing is necessary for occupational medicine, assessment of working capacity, medical diagnosis, health or social care, with a basis in law;
  • processing is necessary for public health, with a basis in law;
  • processing is necessary for archiving, research or statistical purposes, with a basis in law.

We will process your special category personal data for the below purposes.

  • We may use health, disability, accessibility, allergy, medication, fitness-to-participate, wellbeing or support information to provide safe, inclusive and accessible services, make reasonable adjustments, assess risk, administer first aid, respond to emergencies, manage incidents, support participation and comply with health and safety, equality, safeguarding, public health or legal obligations.
  • We may use information about disability or accessibility needs to make reasonable adjustments, support access to services, meet equality obligations and improve inclusive service delivery.
  • We may use information about racial or ethnic origin, sex, sexual orientation, religion or belief, disability, age, care experience or other protected or inclusion characteristics for equality, diversity, inclusion, monitoring, funding, reporting, public accountability and service improvement purposes, where lawful and proportionate.
  • We may process special category information where it is relevant to safeguarding, child protection, adult protection, complaints, investigations, legal claims, regulatory matters, funding requirements, risk management or public-interest service delivery.
  • We may process special category information that appears in images, video, audio, correspondence, complaints, incident reports, safeguarding records or social media material where it is unavoidable, relevant and proportionate for the specified purpose, or where the material reveals such information by context.

Criminal Offence Data

Criminal offence data is treated separately from special category personal data. It includes information about criminal convictions, criminal offences, allegations, proceedings, cautions, warnings, related security measures, PVG scheme information, Disclosure Scotland information, barred list information and related safeguarding or vetting information.

We will only process criminal offence data where the law permits us to do so. This may include where processing is necessary for:

  • safer recruitment, safeguarding children or vulnerable adults, or assessing suitability for roles or activities;
  • carrying out PVG, Disclosure Scotland, criminal record, barred list or other role-specific checks where relevant and lawful;
  • managing safeguarding concerns, allegations, incidents, exclusions, restrictions, complaints or investigations;
  • protecting OneRen's staff, service users, visitors, contractors, suppliers, premises, assets and services;
  • preventing and detecting crime, fraud, theft, abuse, misuse, security incidents or unlawful conduct;
  • complying with legal or regulatory obligations;
  • legal claims, insurance, audit, regulatory requirements or substantial public interest conditions.

Access to criminal offence data will be restricted and such information will be retained only for as long as necessary and in accordance with applicable retention requirements.

Direct marketing and service communications

We may send you service communications where they are necessary for a service you have requested or a relationship you have with us. These may include booking confirmations, membership updates, cancellation notices, changes to opening times, safety notices, service changes, event information, venue hire information, payment reminders, account administration messages or other operational communications. You may not be able to opt out of service communications that are necessary for us to provide a service, administer a contract, meet legal obligations or protect safety.

We will only send direct marketing communications where we have a lawful basis and comply with applicable direct marketing rules. This may include where you have consented to receive newsletters, updates, fundraising communications, campaign communications, offers, events, activities or other marketing communications. Each electronic marketing message will include an unsubscribe or preference management option where required.

You have an absolute right to object to direct marketing at any time. If you object or withdraw consent, we will stop sending direct marketing communications to you, although we may retain a suppression record to ensure we do not contact you again for that purpose.

Who might my data be shared with, or seen by?

We may disclose your personal data to any of our employees, officers, trustees, contractors, volunteers, insurers, professional advisers, agents, suppliers, subcontractors, processors, partners, government agencies, regulators, healthcare providers, safeguarding bodies and law enforcement bodies so far as reasonably necessary, and in accordance with data protection legislation.

We may also disclose your personal data:

  • with your consent;
  • where we are required or permitted to do so by law;
  • to provide services you have requested or are entitled to receive;
  • to administer memberships, bookings, tickets, events, library services, leisure services, venue hire, donations, recruitment, procurement, supplier relationships and other OneRen services;
  • to comply with regulatory, safeguarding, audit, statutory, charity, tax, accounting, procurement, health and safety, equality or reporting requirements;
  • to protect the rights, property and safety of OneRen, employees, workers, volunteers, service users, children, vulnerable groups, visitors, website users, contractors, suppliers and others;
  • in connection with ongoing or prospective legal proceedings, complaints, investigations, insurance matters or claims;
  • to obtain legal advice or establish, exercise or defend legal claims;
  • for the provision of services by trusted partners, suppliers and processors, including IT, website, hosting, cloud, security, payment, booking, ticketing, membership, library, leisure, CRM, email, marketing, survey, recruitment, payroll, finance, procurement, audio-visual, archiving, professional advisory and support providers;
  • with Renfrewshire Council, NHS Greater Glasgow & Clyde, sport, culture, arts, library, education, museum, heritage, health, wellbeing, charitable and community partners where necessary and lawful for service delivery, partnership working, safeguarding, referrals, funding, public-interest reporting or service improvement;
  • with Disclosure Scotland, PVG scheme administrators, occupational health providers, referees, former employers, background check providers and recruitment platforms where relevant to recruitment or safer recruitment;
  • with payment providers, direct debit providers, banks, debt management partners, courts, auditors, insurers and professional advisers where relevant to payments, arrears, refunds, debt recovery, audit, accounting or legal claims; or
  • where necessary for the delivery of OneRen's public-interest functions.

Where we use external processors to process personal data on our behalf, we will put appropriate contractual arrangements in place requiring them to process personal data only on our instructions, keep it secure, protect confidentiality and comply with applicable data protection requirements.

Images, video, audio and associated recordings

OneRen may process images, video footage, voice recordings and associated audio-visual material relating to customers, members, service users, visitors, event attendees, participants, children, young people, parents, guardians, carers, contractors, suppliers, volunteers and other individuals. This may include photographs, filmed interviews, narrated content, recorded presentations, training material, meeting recordings, CCTV footage, educational videos, museum interpretation videos, cultural learning content, public information videos and other audio-visual material.

Such processing may be undertaken for purposes including:

  • community education, cultural learning or museum interpretation;
  • interactive museum videos and exhibition materials;
  • learning resources for schools, community groups, visitors and the wider public;
  • service delivery, operational guidance and accessibility information;
  • training, induction, health and safety and service quality purposes;
  • public information about OneRen services and facilities;
  • annual reporting, accountability, community benefit and service impact reporting;
  • event, activity, programme and venue administration;
  • internal communications, where reasonably necessary;
  • CCTV surveillance and premises security;
  • detection and prevention of crime;
  • safeguarding, health and safety and incident investigation;
  • business continuity, audit, legal claims and regulatory purposes.

Where OneRen intends to use identifiable images, video or audio for marketing, fundraising, advertising or promotional purposes that are not otherwise covered by a lawful basis, we will provide appropriate information and seek consent where required. Where consent is relied upon, you may withdraw consent at any time, although this will not affect processing carried out before withdrawal or material already lawfully published where removal is not reasonably practicable.

Children and young people

OneRen provides services which may be used by children and young people, including library, leisure, sport, arts, culture, museum, heritage, school, learning, holiday, health and wellbeing, community and events services. We may process children's personal information where it is necessary to provide those services, protect health and safety, meet safeguarding obligations, administer participation, manage consent, communicate with parents, guardians or carers, and deliver public-interest functions.

Where we need consent for a child or young person's participation or for a particular use of their information, we may need the consent of a person with parental responsibility, depending on the age of the child, the nature of the service and the purpose of processing. We will explain this where relevant.

We will handle children's personal information with particular care and will only collect and use information that is relevant and proportionate to the service or purpose involved.

Suppliers, contractors, consultants and business contacts

Where we work with suppliers, contractors, consultants, agencies, professional advisers or other business contacts, we may process business contact details and related personal information to manage procurement, tenders, contract negotiation, contract performance, due diligence, payments, insurance, service delivery, access to premises or systems, health and safety, safeguarding, information security, audit, complaints, disputes, legal claims and compliance obligations.

Where a supplier, contractor or consultant provides personal information about its employees, workers, representatives or subcontractors to us, the supplier, contractor or consultant should ensure that those individuals are given appropriate privacy information explaining how their personal information may be shared with and processed by OneRen.

Applicants and recruitment

Where you apply for a job, volunteering opportunity, traineeship, placement or other role with OneRen, we may process recruitment information to manage the recruitment process, communicate with you, assess your suitability, make decisions, carry out checks, provide reasonable adjustments, meet safeguarding requirements, monitor equality and enter into an employment or other working relationship where appropriate.

Recruitment information may be processed through recruitment platforms used by OneRen. Such providers process applicant information on behalf of OneRen and in accordance with our instructions. More detailed recruitment-specific information may be provided in our Recruitment Privacy Notice and during the recruitment process.

If your application is unsuccessful, we will retain recruitment records for a period of 6 months in line with our retention schedule, unless a longer period is required for legal, safeguarding, Home Office, regulatory, audit or claims-related reasons. If your application is successful, relevant recruitment records may be transferred to your employee or worker record and retained in accordance with our Employee Privacy Notice and retention requirements.

How do we keep your data safe?

When you give us information, we take steps to ensure that your personal information is kept secure and protected against unauthorised or unlawful processing, accidental loss, destruction or damage.

All data is held in accordance with OneRen's data protection policies, information security policies and related procedures. Depending on the nature of the data and system, security measures may include:

  • role-based access controls;
  • password protection and authentication controls;
  • multi-factor authentication where appropriate;
  • secure customer, membership, booking, ticketing, library, leisure, finance, recruitment, procurement and operational systems;
  • encryption or secure transmission where appropriate;
  • restricted access to confidential records;
  • audit logs and access monitoring;
  • staff training and confidentiality obligations;
  • supplier due diligence and processor contracts;
  • incident reporting and breach management procedures;
  • backup, business continuity and disaster recovery arrangements;
  • retention and secure deletion processes.

How long do we keep your data?

We will only retain your personal information for as long as is necessary for the purpose for which it was collected or processed, including for the purposes of satisfying legal, accounting, reporting, safeguarding, audit, insurance, public-interest, contractual, tax, charity, regulatory or legal claims requirements. Retention periods are set out within OneRen's Data Retention Policy and Schedule.

Where personal information is no longer required, we will securely delete, destroy, anonymise or archive it in accordance with OneRen's retention requirements. Where information is anonymised, it will no longer identify you and may be used for statistical, reporting, planning, public accountability, service-improvement or research purposes.

If you do not wish to provide your personal data

In many cases, you decide what information you provide to us. However, we may need certain personal information to provide services, administer bookings, memberships, tickets, library accounts, venue hire, events, donations, recruitment, supplier relationships, payments, refunds, complaints, safeguarding, health and safety, legal compliance or other OneRen functions.

Information we may require includes your name, contact details, account or membership details, booking details, payment information, eligibility information, health or accessibility information where required for safe participation, emergency contact details, recruitment information, supplier information and other information necessary for the relevant purpose.

If you do not provide information that we require, this may mean that we cannot provide a service, process a booking or payment, administer a membership, issue a ticket, provide a refund, allow participation in an activity, manage a complaint, consider an application, enter into a contract, pay an invoice, comply with legal obligations or permit access to particular services, premises, systems or activities.

Where information is optional, we will make this clear where appropriate. Where we request optional information, we will explain why we are asking for it and how it will be used.

Automated decision-making and profiling

We do not currently make decisions about you based solely on automated processing which produce legal effects concerning you or similarly significantly affect you.

We may use automated or partly automated tools to support website security, fraud prevention, spam filtering, payment processing, account administration, analytics, marketing preference management, recruitment administration or service delivery. Where any decision would have a legal or similarly significant effect on you, we will ensure appropriate human involvement unless the law permits otherwise and we have provided the required information.

OneRen may analyse member data for the purposes of demographic and member participation analysis, benchmarking, reporting and service improvement.

If this changes, we will update this notice and provide you with information about the logic involved, the significance and envisaged consequences of such processing, and your rights in relation to automated decision-making.

Your Rights

Subject to certain conditions and exemptions, you have the following rights under UK data protection law.

Right to be informed

You have the right to be informed about how we collect and use your personal information. This privacy notice is intended to provide you with that information.

Right of access

You have the right to request access to the personal information we hold about you and to receive information about how we process it. This is commonly known as a subject access request (SAR).

Right to rectification

You have the right to ask us to correct personal information we hold about you where it is inaccurate or incomplete.

Right to erasure

You have the right to ask us to delete your personal information in certain circumstances. This right does not apply where we need to retain the information for legal compliance, public task purposes, contractual obligations, safeguarding, legal claims, regulatory requirements or other lawful reasons.

Right to restrict processing

You have the right to ask us to restrict the processing of your personal information in certain circumstances, for example where you contest the accuracy of the information or object to processing and we are considering your objection.

Right to data portability

You have the right to receive certain personal information in a structured, commonly used and machine-readable format where the processing is based on consent or contract and is carried out by automated means.

Right to object

You have the right to object to processing where we rely on public task, official authority, legitimate interests or recognised legitimate interests. If you object, we will consider your objection and determine whether we have compelling legitimate grounds to continue the processing, whether the processing is necessary for legal claims, or whether another lawful reason permits or requires continued processing. You also have an absolute right to object to direct marketing.

Rights relating to automated decision-making and profiling

You have rights in relation to decisions based solely on automated processing, including profiling, where such decisions have legal effects concerning you or similarly significantly affect you.

Right to withdraw consent

Where we rely on your consent, you have the right to withdraw that consent at any time. Withdrawing consent will not affect the lawfulness of processing carried out before consent was withdrawn, and it will not affect processing that we carry out on another lawful basis.

Queries and Complaints

Any questions relating to this notice and our privacy practices should be directed, in the first instance, to OneRen by emailing OneRen_dataprotection@renfrewshire.gov.uk.

Our Data Protection Officer is provided by RGDP LLP and can be contacted either via info@rgdp.co.uk.

You also have the right to complain to the Information Commissioner's Office in relation to our use of your information. The Information Commissioner's contact details are noted below:

Telephone: 0303 123 1113

Online: https://ico.org.uk/make-a-complaint/

This Privacy Notice was last updated in July 2026.

Please Support Us

As a charity, our services help people live healthy, happy and fulfilled lives. A donation to Renfrewshire Leisure will help us continue to provide charitable services across our communities.

Back to top