Privacy
Last updated: 7 October 2026
1. Who We Are
Bayswater Dungeon Suite (bayswaterdungeonsuite.com) (“we”, “us”, “our”) is the data controller of the personal data described in this policy.
Privacy contact: [email protected]
2. Our Commitment: UK GDPR
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR). We are governed by the laws of England and Wales.
We understand that booking our suite is a private matter. All client information is treated with strict confidentiality and discretion, and is only accessible to the people who need it to manage your booking.
3. Personal Data We Collect
- Booking data (through our online booking system): your name, email address, phone number, the date, time and type of booking, add-ons, number of guests, your acceptance of our Terms and Conditions, any notes you add, your booking history, and gift card or package codes.
- Payment data: amount, date and status of payments and refunds, and limited card details (such as card type and last four digits) provided to us by our payment provider. We never see or store your full card number.
- Age checks: we may ask to see photo ID at check-in to confirm that every guest is aged 18 or over.
- Professional verification: if you book a Pro-Domme rate or professional package, the proof of professional status you send us.
- Visiting Domme promotion: if you are a professional and you agree to it, your professional name, photos and availability for our Visiting Domme page and social media.
- Enquiries: your name, email address, phone number (optional) and message when you use our contact form or email us.
- Newsletter: your email address, if you subscribe.
- Technical data: IP address, browser and device information, and server logs, collected automatically to deliver and protect the website.
We do not ask for information about your sexual preferences or practices. If you choose to share such information with us (for example in a booking note or an email), we treat it as special category data: we use it only to handle your booking or enquiry, on the basis of your explicit consent, and keep it strictly confidential.
4. Why We Use Your Data and Our Lawful Bases
- To take, manage and reschedule your booking and communicate with you about it: performance of a contract.
- To take payments, process refunds and keep accounting records: performance of a contract and legal obligation.
- To check that guests are 18+, keep the suite safe and secure, prevent fraud and chargebacks, and enforce our Terms and Conditions: our legitimate interests.
- To verify professional status for discounted rates: performance of a contract.
- To feature professionals on our Visiting Domme page and social media: consent, which you can withdraw at any time.
- To answer your enquiries: our legitimate interests, or steps taken at your request before entering into a contract.
- To send our newsletter: consent. Every email includes an unsubscribe link.
- To run and secure the website, including spam protection on our contact form: our legitimate interests.
- To comply with the law, respond to lawful requests from public authorities, and establish or defend legal claims: legal obligation and our legitimate interests.
5. Who We Share Your Data With
We never sell or rent your personal data. We share it only with service providers who act on our behalf and under our instructions:
- Acuity Scheduling (Squarespace): online booking system, gift cards and client records.
- Stripe: secure card payment processing. Stripe also acts as an independent controller for its own legal, fraud-prevention and regulatory obligations.
- Mailchimp (Intuit): newsletter.
- Google: email (Gmail) and reCAPTCHA spam protection on our contact form.
- Cloudflare and our web hosting provider: website hosting, security and performance.
We may also share data with our professional advisers (such as our accountant or solicitor), and with the police or other authorities where we are legally required to.
If our business is sold or transferred, your data may be transferred to the new owner. It will remain protected under this policy, and we will inform you before the transfer.
6. International Transfers
Some of our providers (including Acuity/Squarespace, Stripe, Mailchimp, Google and Cloudflare) store or process data in the United States or other countries outside the UK.
Where this happens, the transfer is protected by the UK Extension to the EU-US Data Privacy Framework (the “UK-US data bridge”) where the provider is certified, or by the International Data Transfer Agreement or Addendum approved by the ICO.
7. How Long We Keep Your Data
We keep personal data only for as long as necessary for the purposes described above:
- Booking and payment records: for as long as required by UK tax and accounting rules.
- Client profile in our booking system: while you remain a client, then only as long as needed for accounting purposes or to deal with any claim.
- Enquiries and correspondence: only as long as needed to deal with your enquiry.
- Professional verification: while you continue to book professional rates.
- Visiting Domme promotion: until you withdraw your consent.
- Newsletter: until you unsubscribe.
- Server and security logs: for a limited period, for security purposes only.
8. Your Rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to how we use your data, including an absolute right to object to direct marketing;
- receive your data in a portable format;
- withdraw your consent at any time, where we rely on consent.
To exercise any of these rights, email [email protected]. It is free of charge.
We will reply within one month. This can be extended by two further months for complex requests, in which case we will tell you why. We may need to confirm your identity before acting on your request.
9. Cookies
We keep cookies to a minimum. We do not use advertising cookies, tracking pixels or analytics.
- Strictly necessary cookies: used by WordPress, Cloudflare and our caching system so that the website works securely and quickly.
- Booking calendar: our booking calendar is provided by Acuity Scheduling and may set cookies needed for the booking process to work.
- Spam protection: our contact form uses Google reCAPTCHA, which may set cookies to protect the form against spam and abuse.
You can block or delete cookies in your browser settings. If you do, some features (such as booking or the contact form) may not work.
10. Security
The website is served over an encrypted connection (HTTPS). Access to client information is restricted.
Card payments are handled entirely by Stripe, a PCI DSS compliant payment provider.
11. Age Restriction
Our website and services are strictly for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18.
12. Complaints
If you have a concern about how we handle your data, please contact us first at [email protected] and we will do our best to resolve it.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data protection regulator:
- Address: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
- Helpline: 0303 123 1113
- Online: ico.org.uk/make-a-complaint
13. Changes to This Policy
We may update this policy from time to time. The latest version will always be published on this page with its date. If we make significant changes, we will let you know.
14. Governing Law
This Privacy Policy is governed by the laws of England and Wales. The courts of England and Wales have jurisdiction over any dispute arising from it. This does not affect your right to complain to the ICO.

