Legal
Privacy Notice
Last reviewed: 10 September 2026
Who we are
The data controller for this website is Bruce De Rouche BG Holding Ltd. Bruce De Rouche BG Holding Ltd is a private limited company registered in England and Wales under company number 16893112, incorporated on 5 December 2025. Its registered office is 11 Garman Close, London, N18 1XH, United Kingdom. fEuzion is a division of that company.
For anything in this notice, write to admin@brucederouche.com or to the registered office above.
What this website actually does
This is the section most privacy notices get wrong, so it comes first.
This website has two parts. The marketing pages describe the service and carry four forms: a contact form, a booking enquiry on the home page, a newsletter sign-up and a coach application. The booking and account area (the pages under /book, /account and /admin) lets you create an account, add the athlete you are booking for, pay for an assessment and see released results. The site does not run analytics and does not advertise to you.
- No analytics. We do not use Google Analytics or any other analytics or tracking product. We do not build a profile of you, and we do not advertise to you.
- No cookies on the marketing pages. The booking and account area keeps you signed in using browser storage that is strictly necessary for it to work. Both are described in our Cookie Policy.
- The forms send what you type to us, and nothing else. Each form goes to a server we run in Google Cloud's London region and is stored there so we can reply. The next section says exactly what that includes.
- Payments are handled by Stripe. When you pay online you are taken to Stripe Checkout. We never see or store your card number.
If analytics or any other collection is ever added, this notice and the Cookie Policy are updated before it goes live, not after.
What we collect when you contact us
The contact form, the booking enquiry on the home page, the newsletter sign-up and the coach application all work the same way. When you submit one, the following is sent to a Google Cloud Function in the London region (europe-west2) and stored in Cloud Firestore in the same project:
- your name, email address and, if you give it, your telephone number;
- the answers you choose about your role, the athlete's age band, their current situation and what the enquiry is about;
- your message;
- your consent choices: that you agree to us handling the enquiry, and whether you opted in to updates;
- the time of submission, the internet address (IP address) the submission came from and the browser identification string, kept as the record of when and where consent was given and to stop abuse.
A per-connection rate limit is applied, so a small number of submissions an hour is accepted from any one address. A submission without consent is refused and not stored. Enquiries are read by our team and used to reply to you. That is all.
If you email or telephone us instead, we hold what you send in our mailbox and phone records and use it in the same way.
We do not add you to a marketing list because you made an enquiry. If you tick the box for updates, we will send them until you tell us to stop, and every one of them carries a way to do that.
What we collect when you book an assessment
Booking is a much bigger piece of processing than an enquiry. It happens in the account area of this site and in person on the day. In outline we collect:
- Your account: name, email address, telephone number, your marketing choice, and the times you confirmed you are an adult and accepted this notice.
- The athlete's profile: name, date of birth, club, position, preferred foot, height and weight if given, injury status and an emergency contact.
- Health information: medical notes, current injuries, medication and allergies, entered by you in the athlete's profile. This is special category data under UK GDPR and is handled accordingly.
- Bookings and payments: which sessions you booked, when, and the record of what you paid or hold as wallet credit. Card details stay with Stripe.
- Performance data: the measurements taken during testing, and the report built from them.
- Behavioural and psychological observations recorded by the assessor.
- Video of technical and athletic testing, which is consented to separately and can be declined without declining the assessment.
Every consent is recorded separately with the time it was given: consent to be assessed, consent to video and photography, and consent to share a report with a club, a scout or a school. You can withdraw any of them from the athlete's profile, and the withdrawal is recorded immediately.
Children's data
Most of the people we assess are children, so this is the part of the notice we take most seriously.
- High-privacy defaults. Nothing about a child is shared, published or used beyond delivering their assessment unless someone has actively agreed to it. Silence is never taken as agreement.
- The ICO's Age Appropriate Design Code is the standard we work to for anyone under 18, including its expectations on data minimisation, default settings and clear explanations.
- Under-13s do not sign themselves up. A parent or guardian creates the account and enrols them, and that adult is the person we contract with.
- Under-16s are not sent marketing without parental consent. Marketing consent from a young person is not sufficient on its own.
- Age-appropriate assent. Whatever an adult has agreed, we explain to the young person what is going to happen in terms they can follow, and we stop if they do not want to continue.
- Plain English. A child, or a parent reading with a child, should be able to understand what we hold. If any part of this notice fails that test, tell us and we will rewrite it.
Our lawful bases
- Legitimate interests, and steps taken at your request before a contract: answering an enquiry you sent us, and keeping the record of that enquiry.
- Contract: running your account and delivering an assessment or a programme you have booked.
- Consent: the marketing opt-in on our forms, video capture, and sharing a report with a third party. Each is asked for separately and each can be withdrawn.
- Explicit consent: health information, which is special category data and needs its own basis.
- Legal obligation: where the law requires us to keep or disclose something, including accounting records and a safeguarding disclosure.
Where we rely on consent, withdrawing it is as easy as giving it, and withdrawing it does not affect anything we lawfully did beforehand.
How long we keep things
When a period ends the record is deleted, or anonymised where a count is still needed for our own records. You can ask for anything to be deleted sooner; we say no only where the law requires us to keep it.
| What | Where it is | How long |
|---|---|---|
| Website analytics | Not collected. No analytics product is in use. | Nothing to keep |
| Form submissions, including the IP address and browser string | Cloud Firestore, Google Cloud, London region. | 12 months after our last contact with you about it |
| Emails and calls you send us | Our mailbox and phone records. | 12 months after our last contact with you about it |
| Account and athlete profile | Cloud Firestore, Google Cloud, London region. | For as long as the account is open. Ask us to close it and it is anonymised, subject to the rows below. |
| Bookings, payments and wallet ledger | Cloud Firestore; the payment itself with Stripe. | 6 years after the last transaction, as an accounting record |
| Assessment records, reports and health information | Cloud Firestore and Cloud Storage, Google Cloud, London region. | 6 years after the last assessment |
| Assessment video | Cloud Storage, with separate consent. | 12 months after the retest it was recorded for, or sooner if you ask |
Who we share it with
Only people who need it for their role, under the permissions you have recorded.
- Our assessors and administrative staff, to answer you, to deliver and quality-check the assessment, and to manage bookings.
- A club, scout or school, only where you have given separate, specific consent, and only the report you agreed to share.
- Google Cloud, which hosts this site and stores the data described above on our behalf, under contract, in the London region.
- Stripe, which takes card payments. Stripe is responsible for the payment data it collects on its own pages, under its own privacy policy.
- Microsoft 365, which hosts our mailbox.
- Anyone the law requires, including where a safeguarding concern must be reported.
We do not sell your data. We do not share it for advertising. We do not use it to train third-party AI models. Nothing is shared with anyone beyond the list above.
Security
The marketing pages are static files served over HTTPS and hold no personal data. Everything you submit or enter in your account is stored in Google Cloud in the London region, encrypted at rest and in transit.
Access is controlled in two places: database security rules, which let a signed-in person read only their own records, and role checks in our server-side code, which reject any attempt to read or change another account's data. Only staff with a named role can see other people's records, and every change to a booking is logged.
Sign-in to the account area uses Firebase Authentication. Card payments are handled entirely by Stripe.
Your rights
Under UK GDPR you have eight rights:
- To be informed: to know what we do with your data, which is what this notice is for.
- Of access: to get a copy of what we hold about you.
- To rectification: to have anything inaccurate corrected. Most account and athlete details can be corrected by you in the account area.
- To erasure: to have it deleted, where no legal obligation requires us to keep it. You can request this from your account page.
- To restrict processing: to have us pause what we do with it while a question is resolved.
- To data portability: to receive it in a portable format, or have it sent elsewhere. Your booking history can be downloaded from your account.
- To object: including to processing based on legitimate interests, and to direct marketing at any time.
- Not to be subject to automated decision-making, including profiling, that has a legal or similarly significant effect on you. We do not make automated decisions about athletes: every assessment outcome is a human judgement.
To exercise any of them, write to admin@brucederouche.com. We respond within one month. A parent or guardian may exercise these rights on behalf of a child, and an older child may exercise them themselves.
Exercising a right is free, and we will not treat you differently for it.
Complaints, and the ICO
If you are unhappy with how we have handled your data, tell us first at admin@brucederouche.com and give us the chance to fix it.
You also have the right to complain to the Information Commissioner's Office at any point. You do not have to come to us first.
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Who to contact about data protection
Data protection questions, rights requests and complaints go to admin@brucederouche.com and are answered in writing. We have not appointed a statutory Data Protection Officer; the address above reaches the people responsible for your data.
This notice was last reviewed on 10 September 2026.
fEuzion is a division of Bruce De Rouche BG Holding Ltd, and is delivered by Michael Bruce Speed & Performance (MBSP). For data requests or questions, contact admin@brucederouche.com.
BRUCE DE ROUCHE BG HOLDING LTD | Private limited company registered in England and Wales, company number 16893112 | Registered office: 11 Garman Close, London, N18 1XH, United Kingdom