PRIVACY POLICY
How Tactical Global Events Ltd, trading as BZ Academy, collects, uses, protects and shares personal data.
We use personal data to answer enquiries, manage bookings, deliver firearms and tactical training, arrange accommodation and transport, process payments, verify identity and eligibility, manage safety, communicate with customers and—where consent is given—send marketing and publish photographs or video.
We do not receive or store full payment-card details. Card payments are processed directly by Stripe or PayPal.
Full passport or identity-card copies, criminal-record certificates and medical forms are normally deleted from active systems within 90 days after the relevant training ends. We may retain limited verification and course records for up to six years where necessary for administration, legal obligations or the establishment, exercise or defence of legal claims.
1. Who we are
This Privacy Policy explains how Tactical Global Events Ltd, trading as BZ Academy ("BZ Academy", "we", "us" or "our"), processes personal data.
Data controller: Tactical Global Events Ltd, trading as BZ Academy
Registered office: 13 High Street, Kenilworth, England, CV8 1LY
Company number: 09473728
Email: info@bz-academy.com
Training activities: delivered in Poland and, where arranged, internationally
EU contact or representative: [INSERT DETAILS BEFORE THE PRODUCTION WEBSITE IS LAUNCHED]
We process personal data under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where applicable, the EU General Data Protection Regulation (EU GDPR) and relevant Polish law.
2. Scope of this policy
This policy applies when you:
- visit our website or use contact, registration or booking forms;
- book or attend a BZ Academy course;
- pay through Stripe or PayPal;
- communicate with us by email, telephone, WhatsApp or social media;
- use accommodation or transport arranged as part of a course package;
- submit identity, eligibility, criminal-record or medical information;
- subscribe to marketing communications;
- take part in photography or video recording.
3. Personal data we collect
3.1 Identity and contact data
This may include your name, date of birth, nationality, postal address, email address, telephone number and other details you provide to identify or contact you.
3.2 Booking, course and travel data
This may include your chosen course, dates, booking reference, attendance, training history, relevant experience, licences or certificates, language preferences, accommodation requirements, flight or travel details, pickup arrangements and related communications.
3.3 Identity documents
Where required for identity, eligibility, security or booking verification, we may request a copy of your passport or national identity card. Access is restricted to authorised persons. The full copy is normally deleted from active systems within 90 days after the relevant training ends, unless continued retention is required by law or is necessary because of an accident, complaint, dispute, investigation, insurance matter or legal claim. After deleting the full copy, we may retain a limited identity-verification record for up to six years, such as your name, date of birth, document type, the last four characters of the document number, verification date, verifier and booking or course reference.
3.4 Criminal-record certificates
For some courses we may request an official criminal-record or good-conduct certificate to assess eligibility and safety requirements. Information relating to criminal convictions and offences is subject to additional legal restrictions. We process it only where the processing is authorised by applicable law, an Article 6 lawful basis and any additional legal condition are satisfied, and appropriate safeguards are in place. We do not maintain a comprehensive criminal-record database.
The full certificate is normally deleted from active systems within 90 days after the relevant training ends, or sooner where verification has been completed and the full copy is no longer necessary. Where lawful and necessary, we may keep a limited verification record for up to six years, such as the issuing country or authority, issue date, verification date, eligibility outcome, verifier and deletion date of the original copy. Because even a verification outcome may constitute criminal-offence data, we retain such a record only where we can justify the legal basis and necessity.
3.5 Medical and health information
Before training, we may ask you to complete a medical or safety form limited to information relevant to safe participation, such as medical conditions, injuries, medication, allergies, mobility restrictions or other circumstances that may affect training or emergency response.
Health information is special-category personal data. For routine medical-form information, we request your explicit consent and collect only information relevant to safe participation, reasonable adjustments or emergency response. Access is limited to authorised staff and instructors who need the information for safety. The full medical or safety form is normally deleted from active systems within 90 days after the relevant training ends. We may retain a limited administrative record for up to six years confirming that the declaration was completed, that relevant limitations were reviewed, whether adjustments were required and the date of consent, without retaining unnecessary medical detail. If an incident, legal obligation, insurance matter or claim arises, relevant information may be retained for longer under a legal hold.
3.6 Payment and transaction data
We may receive payment status, transaction reference, amount, billing name, billing address and limited payment-related information from Stripe or PayPal. We do not receive or store your full card number, card security code or online-banking credentials.
3.7 Communications
We may retain messages sent through website forms, email, telephone, WhatsApp or social-media channels, including the content of your enquiry and our response.
3.8 Photographs and video
We may take photographs or video recordings during training. During registration you may indicate whether you agree to publication, and we also seek confirmation before a photographer records a course. Publication is voluntary and based on consent.
3.9 Website and device data
Depending on your cookie choices, this may include your IP address, device and browser information, operating system, referral source, pages visited, approximate location, interactions, advertising identifiers and cookie-consent records.
3.10 Safety, incident and claim data
If an accident, safety event, complaint or legal issue occurs, we may record information necessary to respond, investigate, manage insurance, comply with law, or establish, exercise or defend legal claims.
4. How we collect personal data
We collect personal data:
- directly from you when you enquire, register, book, pay or attend training;
- through Event Booking and website forms;
- from Stripe or PayPal in relation to payment status and transactions;
- from hotels, drivers or other providers where necessary to update arrangements;
- from cookies and similar technologies, subject to your choices;
- from official or public sources where reasonably necessary to verify information or protect legal rights.
5. Why we use personal data and our lawful bases
| Purpose | Typical lawful basis |
|---|---|
| Responding to enquiries and pre-booking requests | Steps taken at your request before a contract; legitimate interests in responding to prospective customers |
| Managing bookings, attendance and course delivery | Performance of a contract |
| Verifying identity, licences, qualifications and eligibility | Performance of a contract; legitimate interests in safety, security, fraud prevention and appropriate course placement; legal obligation where applicable |
| Processing criminal-record certificates | An Article 6 lawful basis together with authorisation under applicable UK, EU or Member State law and appropriate safeguards |
| Processing routine medical-form information | Performance of a contract or legitimate interests for course safety, together with explicit consent for health data; other conditions may apply in emergencies or legal claims |
| Arranging accommodation and transport | Performance of a contract |
| Processing payments, refunds and financial records | Performance of a contract; compliance with legal and tax obligations |
| Website, booking and account security | Legitimate interests in cybersecurity, service integrity and fraud prevention; legal obligation where applicable |
| Accidents, complaints, disputes, insurance and legal claims | Legitimate interests; legal obligation; vital interests in an emergency; establishment, exercise or defence of legal claims |
| Publishing identifiable photographs and videos | Consent |
| Newsletter and promotional messages | Consent, or a limited customer soft opt-in where legally available |
| Analytics, advertising measurement and remarketing | Consent to non-essential cookies or similar technologies |
Where we rely on legitimate interests, we consider necessity, proportionality, reasonable expectations and the effect on your rights. Where we rely on consent, you may withdraw it at any time, although withdrawal does not affect processing that was lawful before withdrawal.
6. Bookings, Event Booking and payments
Course registrations are managed through the Event Booking system used on our Joomla website. Information submitted through the booking form is used to administer your booking, verify requirements, communicate with you and deliver the course and related services.
Payments are processed by Stripe or PayPal. Payment-card data are entered into and processed by the chosen payment provider, not by the BZ Academy server. Stripe and PayPal may act as separate controllers for fraud prevention, regulatory compliance and payment-network obligations.
8. International data transfers
Tactical Global Events Ltd is established in the United Kingdom and provides services in Poland and internationally. Personal data may therefore be processed in the United Kingdom, the European Economic Area and countries in which service providers operate.
Where a transfer is made outside the country or region in which the data were collected, we use an available lawful mechanism, such as an adequacy regulation or decision, approved standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, and additional safeguards where required.
9. How long we keep personal data
We apply a documented retention schedule based on the purpose of the processing, legal obligations, data minimisation and the time reasonably required to establish, exercise or defend legal claims. The periods below are our standard periods and may be shortened where information is no longer necessary.
| Data category | Standard retention period | What may be retained afterwards |
|---|---|---|
| Passport and identity-card copies | Up to 90 days after the relevant training ends. | A limited identity-verification record may be retained for up to six years, such as name, date of birth, document type, last four characters of the document number, verification date, verifier and booking or course reference. |
| Criminal-record or good-conduct certificates | Up to 90 days after the relevant training ends, or deleted sooner once verification is complete and the full copy is no longer necessary. | Where lawful and necessary, a limited verification record may be retained for up to six years. This may include issuing country or authority, issue date, verification date, eligibility outcome, verifier and deletion date. We retain no comprehensive criminal-record database. |
| Medical and health forms | Up to 90 days after the relevant training ends. | A limited safety-administration record may be retained for up to six years, confirming that the form was completed, relevant limitations were reviewed, whether adjustments were required and the date of explicit consent, without keeping unnecessary medical detail. |
| Bookings, contracts, accepted terms, attendance, training records, safety briefings, declarations and course correspondence | Normally six years after the relevant course ends. | Longer only where law, an insurer, an investigation or an active or reasonably anticipated claim requires it. |
| Invoices, payment, refund and transaction records | Normally six years from the end of the relevant company financial year, or longer where tax, accounting or company law requires. | Only the financial and audit information required by law; BZ Academy does not retain full card details. |
| General enquiries that do not lead to a booking | Normally up to 24 months after the last meaningful contact. | A shorter suppression or dispute record may be kept where required to respect a request or defend a claim. |
| Accident, incident, complaint, safeguarding, insurance and claim records | Normally six years after the incident or closure of the matter. | Longer where an investigation, insurance requirement, court proceeding, legal hold or applicable limitation period remains open. |
| Photography and video consent records | While the material is used and normally for six years after the last use, withdrawal or removal request. | A minimal record of consent, withdrawal and action taken may be retained to demonstrate compliance and prevent renewed use. |
| Newsletter and direct-marketing records | Until unsubscribe or withdrawal of consent. | A minimal suppression record may be retained for as long as necessary to ensure that the address is not added back to marketing lists. |
| Security logs, cookie-consent records and analytics data | According to the configured security need, consent-management setting or provider retention period. | Aggregated or anonymised information may be retained where it no longer identifies an individual. |
Legal hold and extended retention
If an accident, complaint, dispute, insurance notification, regulatory inquiry, threatened claim or legal proceeding occurs, we may suspend scheduled deletion for the records relevant to that specific matter. This is known as a legal hold. Access is restricted and the data are retained only until the matter is resolved and any applicable legal or insurance retention period has expired.
A legal hold does not mean that we keep every participant's full documents indefinitely. It applies only to information that is relevant and proportionate to the specific incident, investigation or claim.
Deletion and backups
When a retention period expires, data are deleted, securely destroyed or anonymised. Residual copies may remain temporarily in protected backup systems until they are overwritten under the normal backup cycle. Backup copies are not used for ordinary business purposes and are restored only where necessary for disaster recovery or security.
10. Photographs and video recordings
Publication of identifiable photographs or video is based on consent. You may decline without affecting your ability to attend training. You may withdraw consent by emailing info@bz-academy.com.
We will take reasonable steps to stop future use and remove material from channels we control. We cannot guarantee removal of copies already shared, downloaded, archived, indexed or republished by third parties.
11. Newsletter and direct marketing
When launched, the newsletter will be managed through AcyMailing. We intend to use double opt-in: after submitting the subscription form, you receive a confirmation email and the subscription becomes active only after you click the confirmation link.
Every marketing email will identify BZ Academy and include an unsubscribe method. Service messages about a booking, payment, transport, safety or course administration are not marketing and may still be sent where necessary to perform the contract.
13. Security
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. These may include encrypted connections, access controls, restricted staff access, server protection, backups, logging and service-provider safeguards.
Full identity documents, criminal-record certificates and medical forms are treated as higher-risk records. We restrict access, separate them from general marketing data where practical, and apply scheduled deletion and legal-hold procedures.
No internet or storage system is completely secure. Where a personal-data breach creates a notification obligation, we will notify the relevant authority and affected individuals as required by law.
14. Your data-protection rights
Depending on the law that applies, you may have the right to:
- be informed about how your data are used;
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion in certain circumstances;
- request restriction of processing;
- receive certain data in a portable format;
- object to legitimate-interest processing and to direct marketing;
- withdraw consent at any time where processing is based on consent;
- complain to a supervisory authority;
- receive safeguards relating to solely automated decisions with legal or similarly significant effects.
The right to deletion is not absolute. We may retain information where this is required by law or necessary for the establishment, exercise or defence of legal claims, but only for as long as that reason continues to apply.
To exercise a right, email info@bz-academy.com. We may need to verify your identity. Rights are subject to legal conditions and exemptions.
15. Complaints and automated decisions
We do not make solely automated decisions about course admission or service provision that produce legal or similarly significant effects. Advertising platforms may perform audience profiling after consent, but BZ Academy does not use that profiling for eligibility or safety decisions.
Please contact us first so that we can try to resolve a concern. You may also complain to the UK Information Commissioner's Office. Where the EU GDPR applies, you may complain to the supervisory authority in the EU or EEA country where you live, work or believe an infringement occurred, including the Polish supervisory authority where appropriate.
16. Contact and policy updates
For privacy questions, requests or complaints:
Tactical Global Events Ltd, trading as BZ Academy
13 High Street, Kenilworth, England, CV8 1LY
Company number: 09473728
Email: info@bz-academy.com
EU contact or representative: [INSERT DETAILS BEFORE THE PRODUCTION WEBSITE IS LAUNCHED]
We may update this policy when services, systems, providers or legal obligations change. The current version will be published on the website with the revised date.