Privacy Policy
Last updated 18 August 2026
The short version
We collect the details you put in the enquiry form, we use them to reply to you and to introduce your group to resorts that suit it, and we share them with those resorts — that introduction is the service. We do not sell your data, we do not advertise to you, and we set no cookies on the public site. Everything below is the same thing said properly.
Who we are
Sundial Socials is a free introduction service connecting UK tennis clubs and university societies with tennis resorts abroad, and is the data controller for the personal data described in this policy — meaning we decide what is collected and why, and we are the ones answerable for it. We are not a travel agent, not a package holiday organiser, and not ATOL-licensed; you book and contract directly with the resort. You can contact us about anything in this policy, including any request about your own data, at james@sundialsocials.com.
What we collect
Everything we collect from you comes from the enquiry form, which is the only form on the public site: your name, club or society name, email address, phone number (if you give one), group size, preferred dates, resort of interest (you can say you are not sure yet), and anything you write in the message box. We also keep a record of your acknowledgement that we introduce groups to resorts and are not a package operator, because that is required to submit the form. If you email us directly, we hold that correspondence too. There are no accounts or logins on this site, so there is no password or profile to hold. We do not currently send marketing email, and the site has no newsletter sign-up.
What we do not collect
We think the negatives are worth stating as clearly as the positives. We do not collect or hold payment or card details — you pay the resort, never us — nor passport, visa or travel-document data, date of birth, health, dietary, disability or accessibility information, any other special category data, precise location data, advertising or cross-site tracking identifiers, or anything bought from data brokers or list vendors. The message box is free text, so please do not put anything sensitive in it: we do not need it and would rather not hold it.
What we collect automatically
When you submit the form we read your IP address, combine it with a secret value, and turn it into an irreversible hash, which we use to limit submissions to five an hour and keep spam out. We never store your actual IP address and the hash cannot be turned back into one; those records are deleted automatically about a day after they expire. We also use a privacy-focused analytics tool that sets no cookies and builds no profile of individual visitors — it tells us how many people viewed a page and how many enquiries were started, never who you are. Our hosting provider keeps standard technical logs of requests for security and reliability.
How we use your data, and our lawful basis
We use your enquiry to respond to you, to introduce your group to resorts that may suit it, to send you a confirmation so you are not left wondering, and to alert ourselves so a real person sees it. Our lawful basis for all of that is legitimate interests — responding to an enquiry you chose to send us — and, where you ask us to arrange an introduction, taking steps at your request prior to entering into a contract. We rely on legitimate interests for spam prevention and for anonymous analytics too, and on our legal obligations where the law requires us to keep or disclose something. You contacted us asking to be put in touch with resorts, and using your details to do exactly that is what you would reasonably expect. We do not use your details for marketing, we do not profile you, and there is no automated decision-making.
Who we share your data with
This is the core of what we do, so we want it to be unambiguous: when we introduce your group to a resort, we share your enquiry details with that resort so they can quote for your trip. That normally means your name, club or society, email address, phone number if you gave one, group size, preferred dates, and anything relevant from your message. We only ever share your details with resorts relevant to your enquiry, and we will tell you which resort we are introducing you to — if you would rather we did not make a particular introduction, say so and we will not. Resorts are independent businesses acting as their own data controllers, so once introduced their own privacy policy governs how they use your details and they will usually contact you directly. Beyond that we share your data only where the law requires it, or to establish or defend a legal claim. We never sell your data to anyone, and we never share it with advertising networks or data brokers.
Service providers
We use a small number of specialist suppliers to run this service. Each acts only on our instructions and under contract, and none of them may use your details for their own purposes. They are: a database host based in the United Kingdom, where your enquiry is stored; a website hosting provider that serves this site and keeps standard request logs; an email delivery provider that sends your confirmation and our own new-enquiry alert; a business email provider that hosts the inbox you reach when you reply to us; and a privacy-focused analytics provider. We are happy to tell you exactly who these companies are — just email us and ask.
Sending data outside the UK
Your enquiry is stored in the United Kingdom. Some data still leaves it. Introducing you to a resort abroad necessarily means sending your details to that country — that is what you have asked us to do, and where the resort is in the European Economic Area no additional safeguard is needed because the UK recognises those countries as offering equivalent protection. Where a resort is outside the UK and the EEA, we rely on your specific request that we introduce you to it. For our own suppliers based outside the UK, transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, which is the safeguard UK GDPR requires. You can ask us for details of the safeguards relied on for any of these transfers.
How we keep your data safe
Enquiries are not publicly readable at all — database access rules block every anonymous and public read, so only our own server-side code and signed-in administrators can reach them, and administrator access needs a separate login. Data is encrypted in transit and at rest, IP addresses are hashed before being written anywhere, and the form carries a hidden anti-bot field and an hourly limit. One honest caveat: if saving your enquiry to the database ever fails, our system emails it to us instead so it is not silently lost, which means a copy would sit in our inbox rather than the database — it is covered by the same retention rule and the same rights. No system is completely secure and we cannot promise absolute safety, but if a breach ever put your rights at risk we would report it to the Information Commissioner's Office within 72 hours and tell you where the law requires it.
How long we keep it
We keep your enquiry and our correspondence about it for a maximum of 24 months from your last contact with us, because trips are planned a season or more ahead and groups often come back the following year. Your acknowledgement is kept with the enquiry. Anti-spam records are deleted automatically about a day after they expire, and analytics data contains nothing personal. You can ask us to delete your data sooner, and unless we have a legal reason to keep it, we will.
Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing carried out on the basis of legitimate interests — including our introducing you to resorts. If you object we will stop, unless we can show compelling grounds that override your rights. Where processing is based on consent, you may withdraw that consent at any time. Contact us at james@sundialsocials.com to exercise any of these rights — we will respond within one month, we will not charge you, and we will not treat you any differently for asking. One important limit: these rights apply to the data we hold, so once we have introduced you to a resort, that resort holds its own copy as an independent controller and you would need to contact them about it. Ask us and we will tell you who.
Cookies
The public site sets no cookies at all. No tracking cookies, no advertising cookies, no analytics cookies — which is why you see no cookie banner. Our analytics provider is cookieless by design and does not identify individual visitors or follow them across sites. The only cookies this site can set are strictly necessary session cookies in our private admin area, used solely to keep our own administrators signed in, and members of the public never reach it. We do not honour Do Not Track signals because we do not track you in the first place.
Children
This service is for adults organising group trips — tennis club members and university society committees. It is not directed at children and we do not knowingly collect data from anyone under 18. If you believe someone under 18 has sent us an enquiry, tell us and we will delete it.
Changes to this policy
We will update this policy when our practices change, and the date at the top always reflects the current version. If we make a material change — a new purpose, a new kind of recipient, or a significantly longer retention period — we will publish it at least 30 days before it takes effect, and where we hold your email address in connection with a live enquiry we will email you. Where a change needs your consent, we will ask for it rather than assume it.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first so we can put it right — most problems are quicker to fix directly, and we would rather know. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk or on 0303 123 1113. Complaining to them does not affect any other legal remedy available to you.
