---
title: Privacy Policy
date: 2025-11-27T16:02:00+00:00
author: James
canonical_url: "https://www.itsinnottingham.com/policies/privacy-policy"
section: Policies
---
[Back Home](/) 

 

# Privacy Policy

 

 

## **Our Privacy Policy**

How Nottingham BID Company Ltd, trading as It's in Nottingham, uses personal information

Last updated: 1 September 2026

**At a glance**

This notice covers our website, business and member relationships, communications and marketing, events, suppliers, recruitment and employment, photography and videography, and the It's in Nottingham Business Crime Reduction Partnership (BCRP) use of Alert.

Our separate Cookie Policy explains the cookies and similar technologies used on our website.

**1. Who we are**

Nottingham BID Company Limited, trading as It's in Nottingham, is the controller responsible for the personal information described in this notice unless we explain otherwise.

- Company number: 07205523
- ICO registration: Z3386656
- Address: Cawley House, 149–155 Canal Street, Nottingham, NG1 7HR
- Data-protection email: [data@itsinnottingham.com ](data@itsinnottingham.com%C2%A0)

Richard Lane is our data protection lead and the contact within the organisation for data-protection matters. Nottingham BID Company Limited is the Data Controller.

**2. Scope of this notice**

This notice applies when we collect or use personal information in connection with:

- our website, online forms and enquiries;
- BID members, prospective members, partners and stakeholders;
- newsletters, operational updates and other communications;
- events, training and projects;
- customers, suppliers, contractors and professional advisers;
- recruitment, employment, workers and volunteers;
- photography and videography; and
- the BCRP and Alert information-sharing platform

Some activities may also have a shorter, more specific notice at the point information is collected. That notice should be read with this one.

**3. The information we collect and where it comes from**

**Website use and enquiries**

We may collect your name, organisation, role, contact details, the content of your enquiry, correspondence, preferences and any information you choose to provide through a form, email, telephone call or face-to-face contact. Our systems may also record IP address, browser or device information, timestamps and security logs.

Information may come directly from you, from your employer or organisation, from a person making an introduction, or from public professional and business sources. Optional analytics and advertising technologies are addressed in our separate Cookie Policy.

**BID members, partners and stakeholders**

We may use business contact information, role and organisation details, records of meetings and engagement, service interests, attendance, feedback, BID-related records and relevant correspondence. This information may come from you, your organisation, Nottingham City Council in connection with BID arrangements, event or project partners, or public business sources.

**Events, projects and training**

We may collect registration and attendance details, contact information, organisation and role, participation records, feedback, dietary or accessibility requirements, qualifications or assessment results, and payment information where applicable. Please provide only the health, dietary or accessibility information needed for us to support you safely.

**Suppliers, contractors and financial administration**

We may collect business contact details, contracts, quotations, purchase orders, invoices, payment and bank details, due-diligence information, insurance information, performance records and correspondence.

**Recruitment, employment, workers and volunteers**

Depending on your relationship with us, we may process application and employment history, references, qualifications, identity and right-to-work information, contact and emergency-contact details, payroll, tax, pension and bank information, attendance, leave, performance, training, disciplinary and grievance records, health information and criminal-record information where a lawful and proportionate check is required. Employees, workers and volunteers may also receive more detailed privacy information relevant to their role.

**Photography, videography and Alert**

The information used for photography, videography and Alert is described in the dedicated sections below because the purposes, risks and lawful bases are different.

**4. Why we use personal information and our lawful bases**

We use personal information only where we have an appropriate lawful basis. Depending on the activity, this may be:

- contract - where processing is necessary to enter into or perform a contract with you;
- legal obligation - where we must comply with tax, employment, health and safety, company, regulatory or other legal requirements;
- legitimate interests - where the processing is necessary for our or another person’s legitimate interests and those interests are not overridden by your rights;
- consent - where we have asked you to make a genuine choice, including certain marketing and planned photography uses;
- recognised legitimate interests -for qualifying public-interest purposes specified in Annex 1 to the UK GDPR, including relevant BCRP crime-prevention processing; or
- vital interests - in rare emergencies where processing is necessary to protect someone’s life.

Where we use special-category or criminal-offence information, we also identify an additional condition under Articles 9 or 10 of the UK GDPR and the Data Protection Act 2018, as explained below.

**5. General business, member and website purposes**

We may use personal information to:

- respond to enquiries and provide requested information or services;
- manage BID membership, member relationships, projects and partnerships;
- organise events, training, meetings, grants and initiatives;
- operate, secure, maintain and improve our website, systems and services;
- manage contracts, suppliers, contractors, payments, accounting and audits;
- maintain accurate business records and demonstrate compliance;
- recruit and manage employees, workers and volunteers;
- protect our organisation, systems, staff, visitors and legal rights; and
- establish, exercise or defend legal claims and cooperate with lawful regulatory or law-enforcement requests.

The relevant lawful bases are normally contract, legal obligation and legitimate interests. Where optional health, dietary or accessibility information reveals special-category information, we will normally use explicit consent, employment and social-protection law, health and safety obligations, vital interests or legal claims, depending on the circumstances.

**6. Communications and direct marketing**

We communicate with BID members, partners and business contacts about our services, projects, city-centre matters, events, operational information and opportunities relevant to their role. Some messages are service or operational communications rather than direct marketing.

Where communication is direct marketing, we use consent where the Privacy and Electronic Communications Regulations require it. In appropriate business-to-business circumstances, we may rely on legitimate interests after considering necessity, expectations, and individual rights. Every electronic marketing message will provide a clear way to unsubscribe or object. We retain a minimal suppression record where necessary to ensure that a person who has opted out is not contacted again inadvertently.

We use HubSpot to manage contacts and send communications.

**Before publication**

We will store HubSpot CRM marketing content data for a period of up to five years, including: email addresses, email delivery, open rate, and click through data. HubSpot accounts in the UK are hosted in the European Union (Germany) and customer data is processed and stored in that location.

You can withdraw marketing consent or object to direct marketing at any time by using the unsubscribe link in an email or contacting data@itsinnottingham.com. This will not stop essential operational or contractual communications where we still have a valid reason to contact you.

**7. Photography and videography**

**What we collect**

We may take still photographs, video and audio recordings at events, activities and locations connected with our work. This may include your image, voice, appearance and the event or location. Where a consent form is used, we also retain the name, signature, date and other information needed to record that consent. We will not publish a person’s name, job title or quotation alongside an image or recording unless this is separately agreed with them.

**How we use images and recordings**

We use photography and recordings to promote Nottingham, It's in Nottingham, our projects, events, members and partners. Uses may include:

- social-media posts and paid social-media advertising;
- our website and other digital content;
- email communications;
- printed and digital publications;
- posters, banners and promotional displays;
- advertising, press and media activity; and
- promotional films and videos.

**Our lawful bases for photography**

For planned photography or recordings in which a person is the principal or prominent subject, we will normally ask for consent. Consent is voluntary and refusing it will not result in any disadvantage.

For general event, street-scene or crowd photography where obtaining individual consent from everyone is not practical, we may rely on our legitimate interests in documenting and promoting Nottingham and our activities. We will use appropriate notices or signage, provide a reasonable way to avoid being photographed where practicable, and consider objections. We will take additional care where an individual is prominent, the setting is sensitive or the proposed use could have a significant effect on them. Prominent individual imagery used in paid advertising will normally require consent.

**Children**

For a planned or prominent image or recording of a child under 16, we will obtain consent from a person who has parental responsibility. Where appropriate, we will also explain the photography to the child in suitable language, seek their agreement and respect their wishes. We will take particular care before publishing any image that could identify a child or reveal sensitive information about them.

**Sharing and worldwide access**

We may share imagery with photographers, videographers, creative agencies, printers, advertising providers, media organisations, project partners working on our behalf and social-media platforms. Material published online or on social media may be accessible worldwide and may be downloaded, copied or republished by others outside our control.

**Retention and withdrawal**

We retain original photographs, recordings and the associated consent record for five years from capture, unless an earlier deletion is appropriate or a longer period is required for a legal claim. Published material may remain in circulation or online during that period.

You may withdraw consent or object to legitimate-interest photography by contacting [data@itsinnottingham.com](data@itsinnottingham.com%C2%A0). We will stop new uses and, where reasonably practicable, remove the relevant material from channels under our control. Withdrawal does not affect uses that took place lawfully before withdrawal. We may be unable to recall printed material already distributed or copies independently shared, downloaded or republished by other people.

**8. BCRP and Alert information**

**Who operates the BCRP**

Nottingham BID Company Limited operates the It's in Nottingham Business Crime Reduction Partnership and is the controller for the BCRP records described in this section. Alert is supplied by Shop Safe Limited, which acts as our processor for the hosting and technical operation of the platform. Alert is hosted in the United Kingdom.

Authorised member businesses and partner organisations are independent controllers for their own decisions and actions using information made available to them. Nottinghamshire Police, Nottingham City Council and other law-enforcement or public bodies are independent controllers for their own processing.

**What the BCRP does**

The BCRP enables trained and authorised organisations to share relevant information to prevent, detect, report and respond to crime, anti-social behaviour and current safety risks affecting businesses, staff, customers, visitors and property. It also supports accurate reporting, police or court action, safeguarding, lawful civil proceedings and the correction or withdrawal of inaccurate information.

The BCRP does not operate a partnership-wide banning scheme. Individual businesses make their own lawful decisions about entry to their premises. We do not use Alert for facial recognition, biometric matching, automated social-media searching or solely automated decisions producing legal or similarly significant effects.

**Information recorded on Alert**

Depending on what is necessary and proportionate, Alert may contain:

- name, aliases, date of birth or estimated age;
- facial images, CCTV images or police images lawfully supplied;
- physical description and perceived ethnicity where necessary for identification;
- incident details, allegations, intelligence and relevant professional opinions;
- police incident or crime references and police person-of-interest or wanted status;
- relevant court orders, civil orders, conditions and expiry dates;
- limited health or safety warnings directly relevant to a current identifiable risk;
- relevant associations, vehicle information and location information; and
- source, review, correction, restriction and withdrawal information.

Information about alleged or suspected offending is criminal-offence data. Perceived ethnicity and health information are special-category data and are used only where necessary and supported by an additional legal condition.

**Where Alert information comes from**

- BCRP member businesses and their authorised staff;
- Nottinghamshire Police and other law-enforcement bodies;
- Nottingham City Council and other relevant partner agencies;
- CCTV and other evidential material lawfully supplied;
- other BCRPs where there is a relevant operational connection; and
- the person concerned, including information supplied through a rights request, complaint or correction.

We do not search public social-media accounts to build Alert profiles.

**Alert lawful bases and conditions**

Our main Article 6 lawful basis is recognised legitimate interests under Article 6(1)(ea) of the UK GDPR, for processing necessary for the recognised public-interest purpose of preventing, detecting, investigating or apprehending crime. We may also rely on legal obligation, legitimate interests, consent or legal claims where appropriate to a specific activity.

For criminal-offence data, we rely on Article 10 of the UK GDPR together with the relevant conditions in Schedule 1 to the Data Protection Act 2018, principally preventing or detecting unlawful acts. Legal-claims conditions may also apply where processing is necessary for legal proceedings or legal rights.

Where limited special-category information is necessary, we rely on an applicable Article 9 condition and the relevant Schedule 1 condition, including substantial public interest in preventing or detecting unlawful acts, safeguarding, vital interests or legal claims, depending on the circumstances. Our BCRP Data Protection Framework and Appropriate Policy Document records the safeguards applied.

**Who may receive Alert information**

- trained and authorised BCRP member users where they have a genuine need to know;
- Nottinghamshire Police and other law-enforcement or public authorities;
- Nottingham City Council and approved safety partners;
- Shop Safe Limited and approved subprocessors only as necessary to provide and support Alert;
- another BCRP where there is a clear operational connection and a documented case-by-case decision; and
- courts, legal advisers, insurers or other recipients where disclosure is necessary and lawful.

BCRP information must not be copied to WhatsApp, personal email, social media or another unapproved system. Cross-BCRP and other disclosures are limited to what is necessary and are recorded.

**How long Alert information is retained**

- Adult incident records: 12 months from the incident date.
- Adult profiles: deleted after 12 months without a further relevant incident; a further incident resets the review period.
- Unidentified adult images or profiles: 12 months from the associated incident or confirmation date.
- Children aged 14–17: six months from the relevant incident, with no automatic extension beyond what is necessary.
- Children under 14: processed only exceptionally following a documented necessity and proportionality assessment, reviewed after three months and retained for no more than six months.
- Alert instant messages: 12 months for adults and six months where the message relates solely to a child.
- Police person-of-interest, wanted notices, court orders and civil orders: until withdrawal, expiry or the applicable shorter review period.
- Complaints, rights requests, breaches, agreements, training, audit and compliance records: normally six years.

Information may be preserved for longer within a restricted complaint, investigation or legal case where necessary. It will not be kept indefinitely merely because it exists in a backup.

**Alert transparency**

We publish this notice prominently and will provide or signpost it directly where reasonably possible. When information is obtained from another source, we will normally provide privacy information within a reasonable period and no later than one month, or earlier if we first communicate with the person or disclose the information.

Notification may be delayed, restricted or omitted only where a specific legal exception or exemption applies, including where providing the information would be likely to prejudice crime prevention or detection. Any restriction is considered and documented case by case and is not applied automatically.

**9. Sharing personal information**

Outside the specific Alert and photography arrangements described above, we may share information with:

- IT, website, CRM, email, cloud-storage and security providers;
- event, training, project, printing and professional-service suppliers;
- banks, payment providers, accountants, auditors, insurers and legal advisers;
- BID members, delivery partners and public bodies where necessary for a stated purpose;
- police, regulators, courts and other authorities where required or permitted by law; and
- a successor organisation in connection with a genuine restructuring, merger or transfer, subject to appropriate safeguards.

We require processors acting on our behalf to handle personal information only on documented instructions, keep it secure and assist us in meeting our legal responsibilities. We do not sell personal information.

**10. International transfers**

Alert is hosted in the United Kingdom. Some other suppliers and online platforms, particularly social-media, communications and cloud-service providers, may process information outside the UK.

Where we make a restricted transfer, we will use an appropriate legal safeguard, such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved contractual clauses, together with an appropriate transfer assessment and additional safeguards where required. Information published openly online may be accessed or copied worldwide in ways we cannot fully control.

**11. How long we retain other information**

We keep information only for as long as necessary for the purpose for which it was collected, including legal, accounting, safeguarding and dispute-resolution requirements. Our usual periods or criteria are:

- general enquiries and routine correspondence: normally up to two years after the matter is resolved;
- BID member, partner and stakeholder records: while the relationship remains active and normally up to five years afterwards where required for accountability or legal claims;
- marketing contacts: while there is a relevant relationship or valid consent, subject to periodic review; suppression records are retained as necessary to respect an opt-out;
- event and training attendance records: normally up to five years, unless qualification, safeguarding, funding or contractual requirements justify longer retention;
- financial, tax and accounting records: normally six years after the relevant financial period;
- supplier and contractual records: normally six years after the relationship or contract ends, subject to any longer contractual limitation period;
- unsuccessful recruitment applications: normally six months after the recruitment process ends, unless the applicant agrees to a longer talent-pool period;
- employment and worker records: according to the applicable HR retention schedule, generally for the relationship and up to six years afterwards, with shorter or longer periods for particular records where law or necessity requires;
- website security logs: only for the period reasonably needed to protect and investigate the service; and
- photography, videography and Alert: as set out in sections 7 and 8.

We may retain information for longer where a legal hold, complaint, investigation or legal claim requires it. When information is no longer needed, it will be securely deleted or irreversibly anonymised.

**12. Security**

We use proportionate organisational and technical measures to protect personal information against unauthorised access, alteration, disclosure, loss or destruction. Measures include role-based access, individual accounts, staff and user training, secure systems, access reviews, contractual controls, audit records, incident reporting and restrictions on downloading and onward sharing. No system can be guaranteed completely secure, but we regularly review our controls and respond to identified risks.

**13. Your information rights**

Depending on the circumstances and the lawful basis, you may have the right to:

- ask for access to your personal information;
- ask us to correct inaccurate or incomplete information;
- ask for deletion of information;
- ask us to restrict how information is used;
- object to processing based on legitimate interests or recognised legitimate interests;
- receive certain information in a portable format;
- withdraw consent at any time where consent is the lawful basis; and
- ask for human intervention where a solely automated decision has a legal or similarly significant effect.

**Direct marketing**

You have an absolute right to object to the use of your personal information for direct marketing. We will stop direct marketing when you object.

Rights are not absolute. In particular, Alert information may be restricted where disclosure, deletion or another action would prejudice crime prevention, detection, legal proceedings, the rights of another person or another protected purpose. Any exemption will be considered and documented individually.

We may ask for proportionate identification before acting on a request. We normally respond within one month. If a request is complex or involves another controller, we will explain any permitted extension or consultation.

**14. How to contact us or complain**

To exercise a right, withdraw consent, object to processing, unsubscribe from marketing or raise a data-protection complaint, contact:

- Email: [data@itsinnottingham.com ](data@itsinnottingham.com%C2%A0)
- Post: Data Protection Lead, It’s in Nottingham, Cawley House, 149–155 Canal Street, Nottingham, NG1 7HR

We will acknowledge a data-protection complaint within 30 days, investigate it appropriately and respond without undue delay. Where appropriate, a complaint may be reviewed by somebody not involved in the original decision.

You also have the right to complain to the Information Commissioner's Office:

- Website: ico.org.uk
- Telephone: 0303 123 1113

**15. Changes to this notice**

We review this notice at least annually and sooner where our activities, systems, suppliers or legal obligations materially change. The current version will be published on our website. Where a change is significant, we will take reasonable steps to bring it to the attention of affected people.

The GDPR in the UK is governed by the ICO – [WWW.ICO.ORG.UK](http://www.ico.org.uk/)

 

 

 

 

 

         ![Nottingham Contemporary Art Gallery](/uploads/generic/_360x540_crop_center-center_none/footer-flick2-01.jpg)  

         ![Nottingham Market Square](/uploads/generic/_360x540_crop_center-center_none/footer-flick2-03.jpg)  

         ![Red Leaves](/uploads/generic/_360x540_crop_center-center_none/footer-flick2-02.jpg)  

 

 

 

 Follow us *on* SOCIALS

 

 Amazing food and drinks, all the shops you'll ever need, and inspirational events and activities.

 

 [ 

 ](https://www.instagram.com/itsinnottingham/?hl=en) [  

 

 ](https://www.facebook.com/itsinnottingham/?locale=en_GB) [  

 

 ](https://twitter.com/itsinnottingham) [  

 

 ](https://www.linkedin.com/company/its-in-nottingham/)
