Privacy
Your information, handled with care.
This notice explains what Cynefin Quest collects, why it is needed and the choices you have.
Last updated: 29 July 2026
Who is responsible for your information?
Cynefin Quest, operated by Joe Fishwick in North Wales, is the controller of personal information collected through this website and during enquiries and bookings. For any privacy question or request, email hello@cynefinquest.co.uk or call 07942 981572.
Information we collect
Depending on how you contact or book with us, we may collect:
- your name, email address and telephone number;
- preferred dates, group size, children’s age ranges, transport and accommodation area;
- the activities you are interested in and relevant experience or confidence;
- accessibility or practical information needed to suggest and deliver a suitable activity;
- booking, payment and correspondence records;
- technical security information recorded by our website host, such as IP address, date, time and requested page; and
- where genuinely necessary for safety, limited health or emergency information provided separately before an activity.
Please do not send detailed medical information through the initial website enquiry form. We will ask for any safety-critical details at the appropriate stage and through a proportionate process.
Why we use it and our lawful bases
We use personal information to answer enquiries, recommend suitable activities, prepare quotations, manage bookings, deliver activities, communicate changes, maintain safety and keep required business records.
- Steps before a contract and performance of a contract: responding to your request, preparing a quotation and managing a booking.
- Legitimate interests: operating and improving the business, preventing spam or misuse, maintaining appropriate records and handling complaints. We balance these interests against your rights.
- Legal obligation: records required for tax, accounting, insurance, health and safety or safeguarding purposes.
- Consent: where we specifically ask for it. You may withdraw consent at any time, although this does not affect earlier lawful processing.
Health information is special category data. Where it is necessary, we identify both a lawful basis and an additional condition under UK GDPR, normally explicit consent or, in a genuine emergency, protection of vital interests. We collect only what is relevant to safe participation.
What you must provide
A name, valid contact method and short enquiry are needed so we can respond. Other fields are optional at the enquiry stage. We may be unable to confirm or safely deliver an activity if information reasonably required for suitability, safety or the booking contract is not provided.
Who receives your information?
Information is accessed only where needed. It may be processed by our website and email hosting providers, payment or accounting providers, insurers and professional advisers. It may also be shared with a suitably qualified activity provider involved in your booking, but only when necessary and with appropriate care. We may disclose information where the law requires it or where this is necessary to protect someone’s vital interests.
We do not sell personal information.
International transfers
Some technology suppliers may process information outside the UK. Where this happens, Cynefin Quest will use a lawful transfer mechanism, such as UK adequacy regulations or appropriate contractual safeguards, and will take reasonable steps to protect the information.
How long we keep information
- General enquiries that do not become bookings are normally deleted within 12 months of the last meaningful contact.
- Booking, payment and core business records are normally retained for up to six years where needed for accounting, insurance, contract or legal purposes.
- Safety, health or safeguarding information is reviewed after the activity and deleted when no longer needed. It may be retained longer where an incident, complaint, insurance or legal requirement makes that necessary.
- Host security logs are kept for the limited period set by the hosting provider.
We may anonymise information so it can no longer identify anyone.
Children’s information
A parent, guardian or responsible adult should make an enquiry for a child. At the initial stage we ask for age ranges rather than children’s names. Additional information is requested only where it is needed to plan and deliver an appropriate activity.
Security
We use proportionate technical and organisational measures to protect personal information. No internet or email service is completely risk-free, so please avoid including unnecessary sensitive detail in an initial message.
Cookies and automated decisions
This version of the website does not use advertising, analytics or other non-essential tracking cookies. The hosting service may use essential technical functions and security logs. We do not make solely automated decisions that have legal or similarly significant effects on you.
Your rights
Depending on the circumstances, you may have the right to ask for access to your information, correction, deletion, restriction, portability or to object to processing. Where processing relies on consent, you may withdraw it. To exercise a right, contact hello@cynefinquest.co.uk. We may need to confirm your identity before responding.
Complaints
Please contact us first so we can try to resolve the concern. You also have the right to complain to the Information Commissioner’s Office. Visit ico.org.uk/make-a-complaint or call 0303 123 1113.
Changes to this notice
We review this notice when our services, suppliers or legal obligations change. The latest version will always appear on this page.