1. Who we are and how to contact us

Sunday Red Media (“we”, “us”, “our”) is a marketing agency working with golf clubs, resorts and golf brands across the United Kingdom and Ireland. We provide digital marketing, videography and photography, branded merchandise, consulting and team training, and website design.

For the personal data described in this policy, Sunday Red Media is the data controller — the organisation that decides why and how your data is processed. In some engagements we also act as a processor on behalf of a client club; section 12 explains that distinction and what it means for you.

Trading nameSunday Red Media
Postal addressSunday Red Media, Warwickshire, United Kingdom
Email[email protected]
Telephone07764 188061
Data protection contactThe founder acts as our data protection point of contact. We are not required to appoint a statutory Data Protection Officer, but every request reaches a named person.
Supervisory authorityInformation Commissioner's Office (ICO), United Kingdom

By using this website and any other Sunday Red Media service, you agree to be bound by this privacy policy. If you do not agree with it, please do not submit personal data through the site — you are still very welcome to read anything published here.

2. A few definitions

Four terms are used throughout and are worth pinning down.

  • Personal data — any information relating to an identified or identifiable living person. A name and an email address, obviously. Also an IP address, or a club name plus a job title where that points at one individual.
  • Processing — doing anything at all with personal data: collecting it, storing it, reading it, emailing it, backing it up, deleting it.
  • Controller — whoever decides the purposes and means of the processing.
  • Processor — whoever processes data on a controller's instructions, such as our email provider or our hosting company.

“UK GDPR” means the retained EU General Data Protection Regulation as it forms part of UK law, read alongside the Data Protection Act 2018. “PECR” means the Privacy and Electronic Communications Regulations 2003, which govern cookies and electronic marketing.

3. What personal data we collect

We collect only what we need. The table below lists every category, where it comes from, and whether providing it is optional.

CategoryExamplesSourceRequired?
Identity dataFirst and last name, job title, club or organisation You, via a form, email or a callYes, to reply
Contact dataEmail address, telephone number, postal address for merchandise deliveries YouYes, to reply
Enquiry contentWhat you write in a message field, notes we take on a call, the service you selectedYouOptional
Client business dataRounds played, membership numbers, green fee rates, marketing spend, campaign resultsYou, during an engagementOnly if we work together
Marketing preferencesWhether you subscribed, which emails you opened, when you unsubscribed You and our email providerOptional
Usage dataIP address, approximate location, browser type and version, operating system, referral source, pages viewed, time on page, navigation path Our analytics, if you consent to itOptional
Technical and security dataServer logs, request timestamps, failed submissions, spam-filter resultsAutomaticNecessary for security
Consent recordsThe cookie choice you made and when, the consent tick on a form and when AutomaticNecessary to prove compliance
ImageryPhotographs and video footage taken at a client club, which may include recognisable individualsShoot daysSee section 11

What we do not collect

  • Special category data — health, race, religion, political opinions, sexual orientation, trade union membership, biometric or genetic data. We have no business need for any of it. Please do not send it to us.
  • Criminal offence data.
  • Payment card details. Invoices are settled by bank transfer or through a regulated payment provider; card numbers never touch our systems.
  • Data about children. Our services are aimed at businesses. We do not knowingly collect data from anyone under 16 — see section 10 for junior golf imagery, which is handled differently.

4. Why we process it, and our lawful basis

Under the UK GDPR we must have a lawful basis for every processing activity. Here is ours, purpose by purpose.

PurposeData usedLawful basis
Replying to an enquiry and arranging a strategy callIdentity, contact, enquiry content Article 6(1)(b) — steps prior to entering a contract; and 6(1)(f) legitimate interests in responding to people who contact us
Delivering services under an agreementIdentity, contact, client business data Article 6(1)(b) — performance of a contract
Invoicing, accounting and tax recordsIdentity, contact, transaction records Article 6(1)(c) — legal obligation (Companies Act and HMRC record-keeping)
Sending the newsletter and marketing emailsIdentity, contact, marketing preferences Article 6(1)(a) — consent (and PECR regulation 22)
Marketing to existing business clients about similar servicesIdentity, contact Article 6(1)(f) — legitimate interests, using the PECR “soft opt-in”, with an unsubscribe link in every message
Website analytics and measuring which pages help clubsUsage data Article 6(1)(a) — consent, given through the cookie banner
Advertising measurement and remarketingUsage data, online identifiers Article 6(1)(a) — consent
Keeping the site secure and preventing spam and fraudTechnical and security data Article 6(1)(f) — legitimate interests in protecting our systems and our clients
Producing photography and video at a client clubImagery Article 6(1)(f) — legitimate interests, supported by on-site notices and an opt-out; consent where a recognisable individual is the subject of the shot
Establishing, exercising or defending legal claimsWhatever is relevant Article 6(1)(f) — legitimate interests

Our legitimate interests assessment, in short

Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms. In every case above the processing is what a reasonable person contacting a marketing agency would expect, it uses the minimum data needed, it carries a low risk of harm, and you can object at any time under section 9. Where the balance was not comfortably in our favour, we asked for consent instead — which is why analytics and remarketing sit behind the cookie banner rather than being switched on by default.

Withdrawing consent

Where we rely on consent, you can withdraw it at any time — click unsubscribe in any email, or clear this site's data to bring the cookie banner back. Withdrawal does not make anything we did beforehand unlawful, and it will never affect our willingness to work with you.

5. Marketing communications

We send one regular email, the Hole In One Marketing Advice newsletter, plus occasional messages about our services.

  • You are only added if you ask to be. Either you fill in a newsletter form, or you are an existing client and we are telling you about a service similar to one you have already bought.
  • We do not buy lists. Ever. We have never sent a cold email to a purchased list of club secretaries and we are not about to start.
  • Every message has a one-click unsubscribe in the footer, which takes effect immediately. You can also reply to any email with the word “stop” and a human will action it.
  • Unsubscribing from marketing does not stop service emails. If we are running your campaigns we will still send you reports and project messages, because those are part of the contract.
  • Suppression list. When you unsubscribe we keep a minimal record — your email address and the fact that you opted out — precisely so we do not accidentally email you again. That record is kept indefinitely and is itself a compliance measure.

We do not use your data for automated profiling that produces legal effects, and we do not make automated decisions about you without human involvement. See section 13.

6. Cookies and similar technologies

This site uses a small number of cookies and, where you consent, browser storage for analytics and advertising measurement. Essential cookies are set without consent because the site cannot work without them; everything else waits for your choice on the banner.

Rather than summarise it badly here, the detail — every cookie, what it does, who sets it, how long it lasts and how to remove it — lives on its own page.

Read the full cookie policy →

Two things worth stating on this page as well. First, the current build of this website ships with no third-party trackers at all — no analytics scripts, no advertising pixels, no fonts loaded from someone else's server. Every asset is served from this domain. Second, if analytics is switched on in future, this policy and the cookie policy will be updated before it goes live, and the banner will ask again.

7. Who we share your data with

We do not sell personal data, and we never have. We do not share it with third parties for their own marketing purposes. We share it only with the processors that make our business function, and only as far as each of them needs.

Recipient typeWhat they receiveWhy
Website hosting providerServer logs, form submissions in transitServing the site
Email and CRM providerIdentity, contact, marketing preferences, message history Replying to you and sending the newsletter
Cloud storage and file transferProject files, imagery, campaign assets Delivering work to clients
Advertising platformsAggregate or hashed identifiers, only with consent Running and measuring campaigns for clients
Accountants and bookkeeping softwareInvoice and contact details Statutory accounts and tax
Professional advisersOnly what is strictly relevant Legal or insurance advice, if ever needed
Merchandise suppliersDelivery name and addressShipping a physical order
Regulators and law enforcementWhatever we are legally compelled to provide Legal obligation
A buyer, in a business saleClient and contact records Legitimate interests in a corporate transaction — you would be told before it happened

Every processor is engaged under a written contract that meets Article 28 of the UK GDPR: they may act only on our documented instructions, must keep the data confidential, must apply appropriate security, must help us answer your rights requests, and must delete or return the data when the contract ends. We review that list at least once a year and drop anything we no longer genuinely need.

If you would like the current named list of processors, email us and we will send it. We keep the names off this page so that it stays accurate rather than quietly going stale.

8. International transfers

We are a UK business and we prefer UK or EEA hosting. Some of our providers, however, are established outside the UK — most commonly in the United States.

Where personal data leaves the UK, we make sure one of the following applies before it goes:

  • the destination country is covered by UK adequacy regulations (which includes the EEA); or
  • the transfer is covered by the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum; or
  • the recipient is certified under the UK Extension to the EU–US Data Privacy Framework.

In each case we also carry out a transfer risk assessment, and we apply supplementary measures — encryption in transit and at rest, and minimising what is sent in the first place — where the assessment calls for them. You can ask us for a copy of the safeguards relied upon for any particular transfer.

9. How long we keep it

We keep personal data only as long as we have a reason to. Once the reason expires, the data is deleted or irreversibly anonymised. This is our retention schedule.

RecordRetention periodWhy that long
Enquiry that did not become a client24 months from last contact Clubs commonly come back a season or two later; after that the data is stale
Client contract, project files and correspondence6 years from the end of the engagement The limitation period for contract claims in England and Wales
Invoices and accounting records6 full financial years plus the current year HMRC record-keeping requirements
Newsletter subscriber recordUntil you unsubscribe, then deleted within 30 days Consent-based, so it ends when consent does
Unsubscribe suppression recordIndefinitely So we can prove we honoured your opt-out and never email you again
Consent and cookie-choice records24 monthsEvidence of compliance under PECR
Website analytics26 months maximumLong enough for year-on-year comparison
Server and security logs12 monthsInvestigating incidents and abuse
Photography and video footageFor the life of the licence granted to the club, plus 12 months Clients need re-cuts and re-edits; see section 11
Rights requests and our responses3 yearsDemonstrating we handled them properly

Backups are on a rolling cycle and are overwritten within 90 days. If you ask us to erase data, we remove it from live systems immediately and it drops out of backups within that window; in the meantime it is not used for anything.

10. Your rights, and how to use them

Under the UK GDPR you have the following rights. All of them are free to exercise, and none of them will affect how we treat you.

The right to be informed

To know how your data is used — which is what this page is for. If anything here is unclear, ask and we will explain it properly.

The right of access

To get a copy of the personal data we hold about you, plus an explanation of what we do with it. This is often called a subject access request. We will supply it in a commonly used electronic format.

The right to rectification

To have inaccurate data corrected and incomplete data completed. If you tell us your details have changed we will also pass the correction to any processor that received them.

The right to erasure

Often called “the right to be forgotten”. It applies where we no longer need the data, where you withdraw consent and there is no other basis, or where you successfully object. It is not absolute — we may keep records we are legally required to keep, such as invoices, and we will tell you exactly what we kept and why.

The right to restrict processing

To have us pause processing — for example while we investigate a claim that data is inaccurate. We keep the data but stop using it.

The right to object

To object to processing based on legitimate interests. Where you object to direct marketing, this right is absolute: we stop immediately, with no balancing test and no questions.

The right to data portability

To receive the data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible.

Rights relating to automated decision-making

Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. See section 13 — we do not do this.

The right to withdraw consent

At any time, as easily as you gave it, without affecting the lawfulness of what came before.

How to make a request

Email [email protected] with “Data request” in the subject line, or write to us at the postal address in section 1. Tell us which right you are exercising and what you are asking for.

  • We may ask for proof of identity, but only where we genuinely cannot be sure who you are.
  • We respond within one calendar month. If a request is unusually complex we may extend by up to two further months, and we will tell you within the first month if that happens.
  • There is no fee, unless a request is manifestly unfounded or excessive — in which case we will explain our reasoning rather than simply refuse.

Complaining

Please tell us first if something has gone wrong; most issues are a misunderstanding we can fix the same day. You also have the right to complain directly to the Information Commissioner's Office at any time:

Websiteico.org.uk
Helpline0303 123 1113
PostInformation Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

11. Photography, video and people on camera

Our videography service means we spend days on golf courses with cameras, and golf courses have people on them. That deserves its own section.

  • The club is told first. Shoot dates are agreed with the club, and we ask them to notify members in advance through their usual channels.
  • Notices on the day. We ask for signage at the first tee and the clubhouse entrance saying filming is taking place, who is doing it and how to opt out.
  • Opting out is easy. Tell anyone on the crew and we will not film you. If you appear in the background of something already shot, tell the club or email us and we will cut or blur it.
  • Featured individuals give consent. Where someone is the clear subject of a shot — an interview, a portrait, a hero clip — we get a signed release before we use it.
  • Juniors. We do not film identifiable under-18s without written consent from a parent or guardian, obtained by the club in advance. If that consent has not been collected, we shoot around them.
  • Withdrawal. You can withdraw consent to appear at any time. We will remove the footage from anything we control and ask the club to do the same. Material already printed or already distributed cannot always be recalled, and we will be honest with you about that.

12. When we act for a club rather than for ourselves

Most of the time we are the controller of your data — for example when you enquire about our services.

But when we run a campaign for a client club, and a golfer fills in that club's enquiry form, the club is the controller and we are the processor. In that situation:

  • we process that golfer's data only on the club's documented instructions;
  • the club's own privacy notice governs what happens to it, not this one;
  • rights requests should go to the club, and we will help the club answer them promptly;
  • we do not add those contacts to our own marketing lists — not once, not ever;
  • at the end of the engagement we return or delete the data at the club's choosing.

Ad accounts, pixels, audiences and lead data created during an engagement belong to the client. If we part ways, all of it stays with the club.

13. Automated decision-making and profiling

We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you. There is no algorithm here deciding whether you get a proposal.

We do use ordinary, low-impact automation that is worth being open about:

  • Spam filtering on form submissions, including a hidden honeypot field. A false positive means an enquiry is not delivered — if you never hear back within a working day, please ring us.
  • Email segmentation, so a club that asked about video does not receive six emails about merchandise. A human writes every campaign.
  • Advertising platform optimisation when running campaigns for clients. Those platforms decide who sees an advert; that is the platform acting as controller of its own users' data, under its own policies.

14. How we keep it safe

We apply technical and organisational measures appropriate to the risk, including:

  • encrypted connections (HTTPS/TLS) across the website and all administrative tools;
  • encryption at rest on our devices and in cloud storage;
  • multi-factor authentication on every account that holds client or contact data;
  • access on a need-to-know basis, reviewed when anyone joins or leaves;
  • a password manager rather than a shared spreadsheet;
  • reputable providers with their own recognised security certifications;
  • routine backups, held encrypted and tested;
  • an annual review of what data we hold and whether we still need it.

No transmission over the internet is ever completely secure, so we cannot guarantee absolute security. What we can promise is honesty when something goes wrong.

If there is a breach

We will assess it immediately and contain it. Where a breach is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware. Where it is likely to result in a high risk to you, we will tell you directly and without undue delay, in plain language, including what happened and what you should do.

This site links out to third-party websites — social media profiles, the ICO, industry resources. Those links are provided for convenience and do not imply endorsement.

We have no control over the content or privacy practices of any external site, and this policy does not apply once you leave sundayredmedia.com. Please read the privacy notice of any site you visit before giving it personal data.

16. Changes to this policy

We review this policy at least annually and whenever our services or the law change materially.

  • The version in force is always the one published on this page.
  • The date it was last updated is shown at the top of the page and in the sidebar.
  • Material changes — a new purpose, a new category of recipient, a change of lawful basis — will be flagged prominently here for at least 30 days, and subscribers will be told by email.
  • Minor corrections, such as fixing a typo or a broken link, are made without notice.

Where a change requires fresh consent, we will ask for it before relying on it. We will never apply a new purpose retrospectively to data already collected.