1. Who we are and what the service does
Chaperone Collective is a UK online platform, resource and support service for licensed child-performance chaperones and tutors, productions and organisations looking for chaperones or tutors, and agencies that represent or supply children for professional entertainment work.
Chaperone Collective is an intermediary. We are not the employer of chaperones or tutors, we do not supply workers as an employment business, we do not set pay, and we do not take commission or deduct money from chaperone or tutor earnings. Bookings, pay, working arrangements and engagement terms remain between the relevant production, organisation or agency and the chaperone or tutor.
For UK data protection purposes, Chaperone Collective is responsible for deciding how and why personal information is used for the website, portal and central platform functions described in this notice. A production, organisation or agency may become a separate controller for information it receives and uses for its own recruitment, booking, employment, safeguarding or legal purposes.
Data protection contact
hello@chaperonecollective.co.uk
Data protection enquiries are handled by the Chaperone Collective team. We may ask for proportionate information to confirm identity before disclosing, changing or deleting account information.
2. Who this notice applies to
This notice applies to:
- visitors to the Chaperone Collective website and portal;
- chaperones and tutors who register, create a profile, manage availability, respond to work or use resources;
- productions, hirers and organisations that register, publish opportunities, review applicants, make bookings or send messages;
- agencies that register or use the service in connection with professional child-performance work;
- people who contact us for support, training, resources, safeguarding signposting or practical working guidance;
- people who receive account, opportunity, booking, certification or service communications from us; and
- people who connect a Facebook or other Meta feature to Chaperone Collective where such a feature is available.
3. Children, young performers and safeguarding
The platform is not designed for child performers to create accounts. It supports adults and organisations involved in professional child-performance work.
A job post may state how many children are involved, but users must not place unnecessary identifying information about individual children in a job description, profile, message, upload or general enquiry. This includes names, dates of birth, home addresses, school details, medical information, photographs, licence documents, cast details or other recognisable characteristics unless the information is strictly necessary, lawful, authorised and shared through an appropriate secure process.
If we identify unnecessary child personal information, we may remove it, restrict access, contact the person who supplied it or take other steps to reduce the information held. Chaperone Collective is not an emergency service. Immediate safeguarding concerns should be reported through the production, agency, local authority or emergency safeguarding route appropriate to the situation.
4. Personal information we collect and use
4.1 Website visitors and contact enquiries
- IP address, browser and device information, requested pages, timestamps, server and security logs;
- cookie and session information needed to operate and protect the service;
- name, email address, enquiry type, subject and message when you use the website contact form; and
- correspondence, feedback, complaints and support records.
The public contact form sends an email to Chaperone Collective and does not save the message as a separate WordPress form submission. The email and any reply may remain in our email records for the period described below.
4.2 Account and security information
- email address and user role;
- password stored as a secure hash, not in readable form;
- email verification status, account creation and update times, and last login time;
- session, email verification and password reset token information stored in protected form with expiry controls; and
- login, security, misuse prevention and audit events.
4.3 Chaperone and tutor profiles
- full name, phone number and home postcode;
- approximate location derived from postcode, local area and travel radius;
- profile photograph, biography, professional roles and work types;
- availability calendar information and any notes the user chooses to add;
- private minimum-rate information used for matching and administration but not displayed to hirers;
- whether voluntary work may be considered; and
- notification preferences, quiet hours and selected communication channels.
4.4 Licence, vetting and certification information
Where an authorised verification process is available, we may use the declared or postcode-associated licensing authority, chaperone licence number, licence expiry date, certification type, issue and expiry dates, evidence supplied for review, verification status and limited administrative notes.
A full DBS, AccessNI or criminal-record certificate is not ordinary profile content. Users must not upload or send a full certificate unless the platform provides a specific authorised process and explains why the document is needed.
4.5 Productions, hirers, organisations and agencies
- organisation or agency name and company number where supplied;
- contact name, email address and phone number;
- verification and administration status; and
- job posting, application, booking and messaging activity.
4.6 Jobs, applications, bookings and messages
- job title, description, postcode, area, address and approximate location coordinates;
- dates, expected call and wrap times, rates, expenses and role requirements;
- the number of children involved, without child names or identifying details;
- applications, expressions of interest, availability replies and booking status;
- messages and read receipts between the relevant registered users; and
- limited administrative notes needed to operate, support, moderate or secure the service.
4.7 Training, resources and support
We may use details of resources, training or advice requested, registration and attendance information, completion or certificate records where relevant, feedback, questions, support enquiries and information needed to respond to a complaint or safeguarding-related platform concern.
4.8 Facebook and other Meta features
If you choose to use a Facebook or other Meta feature connected to Chaperone Collective, the information available to us depends on that feature and the permissions shown to you. It may include an app-scoped user identifier, name, email address, profile image, permissions granted, connection status and technical records needed to provide, support or secure the feature.
We do not use information obtained through Meta for unrelated advertising and we do not sell it. Meta also handles information under its own privacy policy and account settings. Read Meta’s Privacy Policy.
5. How we receive personal information
We may receive personal information:
- directly from you when you visit, register, complete a profile, post or respond to an opportunity, send a message or contact us;
- from another registered user where information is needed for an opportunity, application, booking, message or support request;
- from a service provider when it delivers hosting, email, storage, postcode, security or connected-platform functions;
- from Meta when you actively connect or use an available Meta feature; and
- from public or official sources where this is necessary to check business, professional, licence or safeguarding information and the use is lawful.
6. Why we use personal information and our lawful bases
| Purpose | Main information | Main lawful basis |
|---|---|---|
| Create and manage accounts | Account, role, verification and security data | Contract or steps before a contract; legitimate interests in secure service operation |
| Provide profiles, availability and opportunity matching | Profile, postcode area, travel radius, work type, availability and certification status | Contract; legitimate interests in providing relevant platform functions |
| Publish and manage work opportunities | Organisation, job, location, rate, date and requirement data | Contract; legitimate interests |
| Applications, booking coordination and messaging | Applications, status, contact details, messages and read receipts | Contract; legitimate interests in enabling users to coordinate work |
| Send service communications | Email, phone, account, job and booking data | Contract; legitimate interests; consent where required for an optional channel |
| Provide training, resources, guidance and support | Registration, participation, completion, enquiry and support data | Contract where a requested service is supplied; legitimate interests for support and free resources |
| Prevent fraud, misuse and security incidents | Logs, account, device, IP and audit data | Legitimate interests; legal obligation where applicable |
| Handle legal, regulatory, complaint and safeguarding matters | Relevant account, job, booking, message, support, verification and audit information | Legal obligation; legitimate interests; vital interests where necessary; additional legal conditions for sensitive data |
| Provide a connected Meta feature chosen by the user | Meta identifier, permitted profile information, connection and technical data | Consent where the feature asks for it; contract or legitimate interests where needed to deliver the requested feature |
Where we rely on legitimate interests, those interests may include operating a useful and secure professional platform, preventing misuse, supporting users, improving service reliability, keeping proportionate business records and protecting legal or safeguarding interests. We consider the necessity of the use and its effect on individuals.
Information you need to provide
There is generally no statutory obligation to register with or use Chaperone Collective. To create and secure an account, you must provide the account, role and contact information identified as required. To post, apply for or coordinate an opportunity, the relevant job, availability, contact and booking information is also needed. Fields identified as optional are voluntary.
If required information is not provided, we may be unable to create or protect the account, publish or submit an opportunity, perform the requested matching, send essential service communications, verify a claimed professional status or provide the requested function. Productions, organisations, agencies, chaperones and tutors remain separately responsible for any information they are required by law, licence conditions, contract or safeguarding procedure to collect or provide outside Chaperone Collective.
Your right to object
You may object where we rely on legitimate interests. Tell us what use you object to and why. We will consider your circumstances and stop the use unless we have a compelling lawful reason to continue or the information is needed for legal claims.
You have an absolute right to object to direct marketing. If we ever use your personal information for direct marketing and you object, we will stop using it for that purpose.
7. Sensitive information, licence checks and criminal offence data
Safeguarding enquiries or professional records may sometimes include health information, allegations, criminal offence information or other sensitive details. We ask users not to send this type of information through ordinary job descriptions, profiles or general messages.
Where a specific authorised verification or safeguarding process needs this information, we will identify an Article 6 lawful basis and any additional condition required by UK law before using it. Access will be limited, the amount collected will be minimised and the information will not be kept for longer than necessary. Where required, we will maintain an Appropriate Policy Document and complete a Data Protection Impact Assessment.
Our preferred approach is to retain verification status and relevant dates rather than a full DBS, AccessNI or similar certificate. A verification status is not a guarantee of suitability, and productions and organisations remain responsible for their own lawful checks and safeguarding decisions.
9. International transfers
Some technology and communications providers may process information outside the United Kingdom. Where UK transfer rules apply, we take steps intended to ensure that an appropriate mechanism and level of protection are in place. Depending on the destination and provider, this may include UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework where applicable, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses and an appropriate transfer risk assessment.
You may contact us for more information about the transfer safeguards relevant to your personal information.
11. Emails, alerts and optional notifications
We may send service communications needed to operate the platform, including email verification, password reset, opportunity matching, booking status, availability, certification expiry, security and administrative messages. These are different from general marketing.
Registered users can manage available alert and notification preferences. An unsubscribe control may stop a particular type of optional alert, but we may still send essential account, security, legal or service messages. SMS or WhatsApp notifications will only be used if the feature is enabled and the user has selected or otherwise validly requested that channel.
12. How long we keep personal information
We keep information only for as long as reasonably needed for the purpose described in this notice, including operation, safety, complaints, legal claims, insurance, accounting, safeguarding, security and regulatory requirements. Some deletion is carried out manually while retention automation develops.
| Information | Usual period or criteria |
|---|---|
| Active account and profile | While the account remains active. Following a verified closure request, information is normally deleted or de-identified within 30 days unless a limited record must be retained. |
| Unverified account | Normally reviewed and deleted after 90 days if verification is not completed and there is no security, legal or support reason to retain it. |
| Inactive account | Normally reviewed after 24 months without meaningful activity. We may contact the user before deletion or de-identification. |
| Availability calendar entries | While useful to the active account, with historic entries normally reviewed after 24 months unless linked to a booking, complaint or dispute. |
| Unsuccessful applications or expressions of interest | Normally up to 12 months after the opportunity closes, unless a shorter period is sufficient or a longer period is needed for a complaint or legal claim. |
| Job posts, bookings and related messages | Normally while needed to deliver the service and, where proportionate, up to six years after closure for contract, tax, insurance, complaint or dispute purposes. |
| Profile photograph | Until replaced, removed or the account is closed, unless a copy is required for a live complaint, safeguarding or legal matter. |
| Licence and certification evidence | Evidence is removed when it is no longer needed for verification. Minimum status, date and audit information may remain while the account is active and for a proportionate period afterwards. |
| Full DBS, AccessNI or criminal-record document | Not retained as routine profile material. If lawfully received for an authorised process, it should be deleted as soon as verification is complete and normally within 30 days unless a documented legal reason requires longer retention. |
| General contact and support enquiries | Normally up to 24 months after the matter is resolved. |
| Complaints, safeguarding, insurance or legal records | Normally up to six years after closure, or longer where the seriousness of the matter, safeguarding responsibilities, legal proceedings or another lawful requirement justifies it. |
| Security and server logs | Normally up to 90 days, with relevant records retained longer where needed to investigate misuse or a security incident. |
| Email verification and password reset tokens | Until the token expires or is used, after which it is deleted or rendered unusable. |
| Backups | Overwritten on a rolling cycle, normally within 90 days, unless an isolated backup must be retained for security, continuity or legal reasons. |
These periods are the normal operating aims, not a promise to keep every record for the maximum period. Information may be deleted sooner when it is no longer needed or kept longer where a legal, safeguarding, security or dispute reason applies. When full deletion is not appropriate, access may be restricted or information may be de-identified.
13. How we protect information
We use technical and organisational measures intended to protect personal information. These include HTTPS encryption in transit, secure password hashing, protected session and email-action tokens, access controls, restricted administrative access, controlled file storage, role-based permissions, server-side postcode lookup, logging, backups and data minimisation.
No online service can guarantee absolute security. Users should use a strong unique password, protect their email account, avoid sharing login details and contact us promptly if they believe an account or personal information has been compromised.
14. Postcodes, approximate location and opportunity matching
We may use postcodes to calculate an approximate location, display a broad area, apply a user-selected travel radius, identify a licensing authority and help match users with relevant opportunities. Job records may contain a full location address where it is needed for booking coordination, but public-facing or pre-booking information should be limited to what is necessary.
The platform may apply rules such as role, approximate area, travel radius, availability, work type and certification status to identify potentially relevant opportunities and send alerts. This is support for matching, not a solely automated decision with legal or similarly significant effect. Hirers decide whom to contact or book, and chaperones and tutors decide whether to respond or accept work.
We do not currently provide continuous live tracking. Before introducing GPS clock-in, location confirmation or similar tools, we will update this notice, explain the specific data flow and complete any required impact assessment.
15. Your data protection rights
Depending on the circumstances and lawful basis, you may have the right to:
- ask whether we use your personal information and obtain a copy;
- ask us to correct inaccurate or incomplete information;
- ask for deletion where the law provides the right to erasure;
- ask us to restrict a use while an issue is considered;
- object to processing based on legitimate interests or to direct marketing;
- receive certain information you supplied in a portable format;
- withdraw consent for a future use that relies on consent, without affecting earlier lawful use;
- ask for information about safeguards used for an international transfer; and
- make a data protection complaint to us and, if needed, to the Information Commissioner’s Office.
Send a request to hello@chaperonecollective.co.uk. Describe the right you want to exercise and identify the relevant account or interaction. We may ask for proportionate evidence of identity or authority where necessary to protect the information.
We normally respond without undue delay and within one calendar month after receiving a valid request and any information reasonably needed to verify identity. A complex request, or several requests from the same person, may take up to two additional months. If an extension applies, we will explain it within the first month.
16. Account deletion and Facebook or Meta data deletion
You can request deletion of a Chaperone Collective account and associated personal information through any self-service control made available in the portal or by emailing us. This route also covers information received through a Facebook or other Meta connection.
- Email us from the address associated with the account where possible.
- Use the subject “Account and personal data deletion request”.
- Include your name, account email, user role and, for a Meta connection, the Facebook or Meta account email or app-scoped identifier if known.
- Do not send your password, a full DBS certificate or unnecessary identity documents.
Email a deletion request Open the dedicated deletion page
We will verify the request where needed, disconnect relevant integrations and promptly delete or de-identify information that is no longer required. We will normally complete or answer the request within one calendar month, and we will explain any limited information that must be retained for security, fraud prevention, safeguarding, contract, accounting, insurance, dispute or legal reasons.
Removing Chaperone Collective from your Facebook or Meta account settings may stop future access, but it may not by itself remove information already held in Chaperone Collective systems. Use the deletion route above so we can identify and action the request.
17. How to make a data protection complaint
Email hello@chaperonecollective.co.uk with the subject “Data protection complaint”. Explain what happened, what information or account is involved, why you are dissatisfied and what outcome you are seeking. Include supporting information where useful, but do not send unnecessary sensitive documents.
We will acknowledge a data protection complaint within 30 days. We will take appropriate steps to investigate without undue delay, keep you informed where the matter takes time and explain the outcome when our review is complete.
You may also complain to the Information Commissioner’s Office. The ICO will normally expect you to have raised the issue with us first so that we have an opportunity to investigate. Read the ICO complaint guidance.
18. External links, policy changes and contact
The website and portal may link to government guidance, local authorities, training providers, Meta and other external services. Those organisations are responsible for their own websites and privacy practices. A normal external link does not send them Chaperone Collective profile or account information, although the destination may receive standard connection information when you choose to visit it.
We may update this notice when the service, law, suppliers or data uses change. We will review it before activating payments, non-essential analytics, advertising pixels, social login, routine DBS document uploads, GPS or time logging, new messaging channels, premium tools or materially different automated matching. The effective date at the top will be updated and important changes may also be brought to registered users’ attention.