Privacy Policy
Controller: Wookey Hole Limited
Company number: 04791696
Last updated: 24 July 2026
Scope: Attractions, accommodation, experiences and websites
Controller: Wookey Hole Limited
Company number: 04791696
Last updated: 24 July 2026
Scope: Attractions, accommodation, experiences and websites
Wookey Hole Limited (company number 04791696) is the controller of the personal information described in this notice. This means that we decide why and how that information is used.
We trade through attractions, accommodation and experiences including Wookey Hole, Wookey Hole Hotel, Mendip View Hot Tub Lodges, Bucklegrove Holiday Park, Wild Wookey and Wookey Hole Circus.
Our registered office is:
Wookey Hole Limited
Wookey Hole Caves, The Mill
Wookey Hole
Somerset
England
BA5 1BB
You can contact our Data Protection Officer by:
Email: [email protected], with "Data protection" in the subject line
Telephone: 01749 672243
Post: at the address above
Our designated Data Protection Officer (DPO) is the General Manager. The DPO handles questions, rights requests and complaints about personal information. Please mark postal correspondence "For the attention of the Data Protection Officer".
This notice explains how we use personal information when you:
visit our attractions, accommodation, holiday park or other premises;
book tickets, accommodation, activities, memberships, gift vouchers, events, weddings, venue hire, school visits or group visits;
use our websites, Wi-Fi, live cameras or other digital services;
contact us, enter a promotion, complete a survey or leave feedback;
receive marketing from us; or
apply to work with us.
It applies where Wookey Hole Limited is identified as the operator or controller, including on:
Some services or activities may also provide a shorter notice at the point where information is collected. That notice should be read with this one.
This notice covers job applicants, but current and former employees are outside its main scope. Their information is governed by our internal Data Protection Policy, the Data Retention Policy and any employee privacy information provided to them. If an applicant becomes an employee, those internal documents apply to the employment record.
Depending on how you interact with us, we may collect:
Identity and contact information, such as your name, title, postal address, email address and telephone number.
Booking and visitor information, such as booking references, visit or stay dates, ticket types, party members, age bands, membership details, accommodation preferences, vehicle registration, accessibility requests and information needed to confirm eligibility for a discount.
Transaction information, such as purchases, amounts paid, refunds, payment status and transaction references. Our payment providers receive your full card details; we do not normally store the full card number or security code.
Health, disability, accessibility and dietary information that you or a person booking for you chooses to provide when it is needed to make reasonable arrangements, protect health and safety or assess whether an activity such as Wild Wookey is suitable. This may be special category information under data protection law.
Communications and relationship information, including enquiries, correspondence, call notes, complaints, survey responses, competition entries, reviews and preferences.
Marketing information, including newsletter choices, campaign interactions and records of consent, objections, opt-outs and suppression.
Technical and online-use information, such as IP address, device identifiers, browser type, operating system, pages viewed, links selected, session information, approximate location derived from an IP address and cookie or similar-technology identifiers.
Images, video and audio, which may include CCTV footage, incident footage, photographs taken at events and images visible on clearly signposted live cameras.
Safety, security and incident information, such as accident reports, witness details, lost-property records, alleged misconduct, damage, fraud indicators and communications with insurers or public authorities.
Recruitment information, such as a CV, employment history, qualifications, references, right-to-work information, interview notes and information about adjustments. We may collect equality-monitoring information separately and only where legally permitted.
Please do not provide information about another person unless you are authorised to do so and have made this notice available to them. A lead booker, parent, guardian, teacher or group organiser may provide information about other members of a party.
We collect information:
directly from you, including through our websites, booking systems, forms, email, telephone and in-person contact;
from a person arranging a booking, visit, stay or activity for you;
from schools, employers, group organisers, travel agents, ticketing partners and accommodation platforms;
from payment, fraud-prevention, booking, marketing and review-service providers;
automatically through cookies, pixels, server logs and similar technology;
from CCTV, live cameras and other security or safety systems; and
from referees, recruitment agencies and publicly available professional sources when you apply to work with us.
We only use personal information when data protection law allows us to. The lawful basis depends on the purpose and circumstances.
Bookings, purchases and services
We use information to:
take and administer bookings, payments, deposits, refunds and vouchers;
provide tickets, memberships, accommodation, activities, events, venue hire and other services;
communicate important information about a booking, visit or stay; and
manage changes, cancellations, complaints, lost property and customer support.
We do this to take steps at your request before entering a contract and to perform our contract with you. We may also rely on our legitimate interests in providing effective customer service and keeping accurate operational records.
Health, accessibility and safety
We use relevant information to assess activity suitability, arrange accessibility support, respond to dietary needs, protect visitors and staff, and manage accidents or emergencies.
For ordinary personal information, we rely on our contract with you, our legal obligations and our legitimate interests in operating safely. Where information concerns health, disability or another special category, we will normally rely on your explicit consent. In an emergency, we may use it to protect someone's vital interests. We may also retain and use relevant information where necessary to establish, exercise or defend legal claims.
You may withdraw explicit consent, but this will not affect earlier use of the information. If information is necessary to provide an activity safely, withdrawing it may mean that we cannot provide that activity.
Safety, security, fraud prevention and legal claims
We use CCTV, incident records, transaction information and other relevant information to protect people and property, prevent and investigate fraud or misconduct, enforce our terms, defend legal rights, and cooperate with insurers, emergency services and public authorities.
We rely on our legitimate interests in running safe and secure premises and protecting our business and customers, as well as legal obligations and the establishment, exercise or defence of legal claims.
Business administration and legal compliance
We use information for accounting, audit, tax, insurance, governance, record-keeping, business continuity, supplier management and corporate transactions. We rely on legal obligations and our legitimate interests in managing and protecting our business.
Websites, digital services and improvement
We use technical information to operate and secure our websites, remember choices, diagnose faults, understand how services are used, improve content and measure campaigns.
Strictly necessary technology is used because it is required to provide or secure a service and in our legitimate interests. We ask for consent before using non-essential analytics, personalisation or advertising cookies where the law requires it.
Marketing
We use contact details and marketing preferences to send news, offers and information about our attractions, accommodation, activities and events.
For email and text marketing to individuals, we rely on consent or, where the Privacy and Electronic Communications Regulations allow it, the "soft opt-in" for similar products and services. We may rely on legitimate interests for some business-to-business marketing and postal marketing. We do not sell personal information or disclose it to another organisation for its own unrelated marketing unless you have given specific consent.
Photography, publicity and live cameras
We may take general photographs or video at our premises and events for security, visitor information, publicity and historical records. We rely on legitimate interests for general crowd or venue images where the impact on individuals is limited. We will seek consent where a person is the clear focus of promotional material or where consent is otherwise appropriate.
Some clearly signposted areas may be visible on live web cameras. We position and operate these cameras to avoid unnecessary identification. Live streams are not normally retained, although separate signs will explain if recording takes place.
Recruitment
We use applicant information to assess applications, arrange interviews, obtain references, make offers, carry out legally required checks and make reasonable adjustments. We rely on steps requested before entering an employment contract, legal obligations and legitimate interests in recruiting suitable staff. We use special category information only where a separate legal condition applies.
Equal-opportunities monitoring information is kept separate from selection decisions and anonymised where possible. Where we rely on consent, participation is voluntary and consent can be withdrawn.
Legal or compatible further uses
We may use information to comply with the law, respond to lawful requests, protect vital interests, or establish, exercise or defend legal claims. If we need to use information for another purpose, we will check that the purpose is compatible with the original one or identify another lawful basis. We will provide additional privacy information where required.
You can stop direct marketing at any time by selecting the unsubscribe link in an email or contacting us at [email protected].
You have an absolute right to object at any time to our use of your personal information for direct marketing, including related profiling. We will stop using it for that purpose.
We may keep a minimal suppression record so that we continue to respect your choice. Opting out of marketing will not stop service messages about an existing booking, visit, stay, membership, safety matter or transaction.
Our websites use cookies, pixels, local storage and similar technology. Some are strictly necessary for security, bookings, navigation and consent management. With your permission, others support analytics, embedded media, social sharing, personalisation and advertising.
Cookie information is not necessarily anonymous. It may identify a browser or device and may be combined by our partners with information obtained through their services.
Our cookie banner lets you accept, reject or manage non-essential technology. You can change or withdraw your choice at any time through the Cookie Declaration link in the website footer. The declaration identifies current cookies, providers, purposes and storage periods.
See our Cookie Declaration for more information.
We use CCTV in selected areas for public and staff safety, crime prevention, incident investigation and protection of property. Signs identify monitored areas. We do not use cameras in places where people reasonably expect a high level of privacy.
CCTV footage is retained only for the shortest period needed for the safety and security purpose and is then overwritten, unless it must be preserved for an incident, complaint, insurance matter, legal claim or law-enforcement request. The exact period is set in our internal retention schedule. Access is limited to authorised people who have a genuine need to know.
Some designated cameras provide live images on our websites. These streams are signposted on site and are not normally recorded. If a live camera or a particular event is recorded, we will provide additional information where appropriate.
We are a family visitor business and may process limited information about children, usually provided by a parent, guardian, teacher or group organiser. This can include a child's name, age or age band, ticket or membership details, safety information and accessibility needs.
Online purchases, accommodation bookings and newsletter subscriptions are intended to be completed by adults. We do not knowingly ask a child under 13 to subscribe to marketing directly.
When we collect information directly from a child, we will use age-appropriate language, collect only what is necessary and consider the child's best interests. Children have the same data protection rights as adults, although a parent or guardian may exercise a right for a child where appropriate.
We share only what is reasonably necessary with:
booking, ticketing and property-management providers, including Guestline, DigiTickets and CampManager or Campstead;
payment providers, including Dojo, and relevant banks or fraud-prevention providers;
website, hosting, IT, security, communications and customer-support providers;
marketing, email, analytics, advertising, social-media and consent-management providers, which may include Mailchimp, Google, ShareThis and Cookiebot;
live-camera and media technology providers, which may include IPCamLive;
review and survey providers;
schools, group organisers, travel agents, ticket partners and accommodation platforms where needed to manage a booking;
professional advisers, auditors, insurers, claims handlers and debt-recovery providers;
emergency services, courts, regulators, local authorities and law-enforcement bodies where disclosure is lawful and necessary;
other businesses in our corporate group where permitted and necessary; and
a buyer, investor or adviser in connection with a proposed sale, restructuring or transfer of all or part of our business.
Providers that process information for us are appointed under written terms. They must protect it, act only on documented instructions, apply appropriate security and limit access to people with a genuine need to know. Some recipients, such as payment providers, booking platforms or social-media services, may also act as controllers for their own purposes. Their privacy notices explain those uses.
We do not sell personal information.
Some suppliers or their support teams may process personal information outside the United Kingdom.
Where a restricted transfer is made, we use a lawful transfer mechanism. This may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another safeguard permitted by law. We assess the protection available and use additional contractual, organisational or technical measures where appropriate.
You can contact us for more information about the safeguards used for a particular transfer. We may provide a redacted copy where necessary to protect confidential information.
We keep information only for as long as it is reasonably needed for the purpose for which it was collected, including legal, tax, accounting, insurance and claims requirements. We then delete or anonymise it securely.
Our detailed internal retention schedule is maintained under the Data Retention Policy and is reviewed periodically.
Our normal retention approach is:
Bookings, purchases, accommodation and accounting records: for the statutory tax and accounting period and for as long as needed to administer the contract or deal with legal claims.
Membership records: while the membership is active and afterwards for as long as required for contract, finance and claims records.
General enquiries and routine customer-service correspondence: until the matter is resolved and for a short audit period afterwards.
Complaints, accidents, safeguarding matters, disputes and insurance or legal claims: for the applicable investigation, insurance and limitation period. Records concerning a child or an unresolved claim may need to be retained for longer.
Health and accessibility information: only for as long as needed to arrange and safely provide the relevant visit, stay or activity, unless an incident, legal obligation or claim requires longer retention.
CCTV: for the shortest period needed for the safety and security purpose, unless footage is preserved for a specific matter.
Live-camera streams: not normally retained.
Recruitment records for unsuccessful applicants: for the selection process and any relevant employment-claim period, unless the applicant agrees to a longer talent-pool period. Successful applicant information becomes part of the employment record and is then governed by our internal employee policies.
Marketing records: until consent is withdrawn, an objection is made or the information is no longer needed. We periodically review engagement and retain a minimal suppression record for as long as needed to honour an opt-out.
Cookies and similar technology: for the periods shown in the current Cookie Declaration.
Backups and securely archived copies may remain for a limited period before being overwritten.
We use proportionate technical and organisational measures designed to protect the confidentiality, integrity and availability of personal information and to prevent accidental or unlawful loss, alteration, access, disclosure or destruction. Access is authorised and limited to people with a genuine need to know. Measures include access controls, staff training, written supplier terms, secure payment processing, encryption where appropriate, backups, monitoring, audits and incident-response procedures.
We apply data protection by design and by default when developing or changing systems and processes. We carry out a data protection impact assessment where processing, including new technology, is likely to result in a high risk to people's rights and freedoms. We review and test our controls periodically.
No internet transmission or storage system can be guaranteed completely secure. Suspected personal data breaches are escalated to the DPO for assessment and action. Where a breach is likely to risk people's rights and freedoms, we notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours after becoming aware of it. Where the risk is high, we also notify affected people without undue delay, unless the law provides an exception.
Depending on the circumstances, you may have the right to:
be informed about how your information is used;
ask for access to your personal information and a copy of it;
ask us to correct inaccurate or incomplete information;
ask us to erase information;
ask us to restrict how information is used;
receive certain information in a portable format and ask for it to be transferred;
object to processing based on legitimate interests;
object at any time to direct marketing;