Privacy Policy — yhge.co.uk
Last updated: 28 May 2026
1. Who we are
This website (yhge.co.uk) is operated by YHGE Ltd, a company registered in Scotland with its registered office at 16 Ravelston House Park, Edinburgh, EH4 3LU (“YHGE”, “we”, “us”, “our”).
For the purposes of UK GDPR and the Data Protection Act 2018, YHGE Ltd is the data controller for personal data collected through this website.
Data protection contact: Data Protection Lead — privacy@yhge.co.uk ICO registration: YHGE Ltd is registered with the UK Information Commissioner’s Office as a data controller.
2. What this policy covers
This policy explains how we handle personal data collected through yhge.co.uk only. Personal data processed through our parent portal application (used by enrolled families) is covered by a separate Parent Portal Privacy Policy, available within the app.
3. What data we collect and why
3.1 Class sign-up form
When you sign up for a free taster class through the website, we collect:
- Name
- Email address
Purpose: to contact you about the class you signed up for and to follow up about enrolment. Lawful basis: Article 6(1)(b) UK GDPR — taking steps at your request prior to entering a contract. Retention: We keep this information for 24 months from your last interaction with us. If you enrol, your data moves into the parent portal system and is governed by that policy. If you do not enrol, we delete the record after 24 months.
3.2 Contact form
When you send us a message through the contact form, we collect:
- Name
- Email address
- Any other information you choose to include in your message
Purpose: to respond to your enquiry. Lawful basis: Article 6(1)(f) UK GDPR — legitimate interests (responding to people who contact us). Retention: We keep contact form submissions for 24 months, unless they relate to an ongoing matter or become part of a customer record.
3.3 Website analytics (Google Analytics 4)
We use Google Analytics 4 to understand how visitors use our website. It collects:
- Pages visited and time spent on each page
- Approximate location (city/region, not precise)
- Device type, browser, and operating system
- How you arrived at our site (referrer)
Purpose: to improve the website. Lawful basis: Article 6(1)(a) UK GDPR — your consent, given through our cookie banner. You can withdraw consent at any time using the cookie preferences link on our site or by clearing your browser cookies. Retention in Google Analytics: 2 months (the shortest retention period available).
If you do not consent to analytics cookies, none of the above is collected.
3.4 Form spam protection (Google reCAPTCHA v3)
Our forms are protected by Google reCAPTCHA v3, which helps us prevent automated spam submissions. When you load a page containing a form, reCAPTCHA collects:
- Your IP address
- Browser and device information
- Mouse and touch interaction patterns on the page
This data is sent to Google and is used by Google in accordance with Google’s privacy policy (policies.google.com/privacy).
Lawful basis: Article 6(1)(f) UK GDPR — legitimate interests (preventing spam and abuse of our forms).
3.5 Security and login protection
We use security plugins (Sucuri Security, Really Simple Security, Limit Login Attempts Reloaded) on our WordPress installation. These tools may process visitor IP addresses to detect and block malicious activity.
Lawful basis: Article 6(1)(f) UK GDPR — legitimate interests (protecting our website and its users from attack).
4. Cookies
We use the following categories of cookies:
- Strictly necessary cookies: required for the site to function, including session and security cookies. No consent needed.
- Analytics cookies (Google Analytics): set only if you consent via our cookie banner.
We do not use advertising or tracking cookies. We do not sell or share data with advertisers.
You can change your cookie preferences at any time using the cookie settings link on the site.
5. Who we share data with
We share personal data with the following third parties:
| Recipient | Purpose | Role | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting our WordPress server | Processor | UK / EU |
| Google (Analytics 4) | Website analytics | Independent controller | EU / USA |
| Google (reCAPTCHA v3) | Form spam protection | Independent controller | EU / USA |
| SendGrid (Twilio Inc.) | Sending emails from the website (replies, confirmations) | Processor | USA |
| Sucuri Inc. | Website security monitoring | Processor | USA |
| CookieYes | Recording your cookie consent choices | Processor | EU |
International transfers: Where personal data is transferred outside the UK (in particular to the USA), the transfer is protected by the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an applicable adequacy decision, as relevant to each provider.
We do not sell your data. We do not share it with advertisers.
6. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Rectification of inaccurate data
- Erasure in certain circumstances
- Restriction of processing in certain circumstances
- Object to processing based on legitimate interests
- Data portability for data you provided to us
- Withdraw consent at any time where we rely on consent
To exercise any of these rights, email privacy@yhge.co.uk. We will respond within one calendar month.
If you are not satisfied with our response, you have the right to complain to the Information Commissioner’s Office:
- ico.org.uk
- 0303 123 1113
- Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
7. Security
We use technical and organisational measures appropriate to the risk, including:
- Encryption in transit (HTTPS / TLS)
- Two-factor authentication on administrator accounts
- Automatic updates for WordPress, plugins, and the underlying server
- Login protection and security monitoring
- Access controls limiting who can see personal data
No system is perfectly secure, and we cannot guarantee absolute security.
8. Children
This website is intended for parents and adults interested in our classes. We do not knowingly collect personal data about children through this website. Children’s data is only collected through the separate parent portal, where it is provided by a parent or guardian.
9. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top will reflect the most recent change. Material changes will be communicated on the website.
10. Contact
YHGE Ltd Registered office: 16 Ravelston House Park, Edinburgh, EH4 3LU Trading address: 471 Gorgie Road, Edinburgh, EH11 3AD Data protection contact: privacy@yhge.co.uk
