Privacy Policy
Last updated: 13 July 2026
This Privacy Policy explains how Philip Neil Golf collects, uses, shares and protects your personal data, and sets out your rights. We are committed to handling your personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and applicable Cyprus data protection law. It reflects broadly equivalent standards under the UK GDPR where relevant.
1. Who we are (data controller)
The data controller responsible for your personal data is Philip Neil, trading as "Philip Neil Golf" and operating as part of One Axion. You can contact us about privacy matters using the details below:
Email: philip.neil@oneaxion.com
Telephone: +357 97 481 750
Paphos, Cyprus
2. What personal data we collect
Depending on how you interact with us, we may collect and process the following categories of personal data:
- Enquiry data — your name, email address, telephone number and the content of any message you send us through our contact form or by email.
- Booking data — details relating to your lessons, such as the date, time, lesson type, venue and any scheduling notes or preferences you provide.
- Health information you choose to share — where you tell us about a relevant health condition, injury or limitation so that we can coach you safely. This may be "special category" data, which we process only where you have provided it to us for this purpose and it is necessary to protect your or another person's vital interests or to deliver the service safely.
- Payment-related data — confirmation that a payment has been made, and limited transaction details. Your full card details are collected and processed directly by Stripe through its hosted checkout and never pass through or get stored on our website.
- Technical data — limited information collected automatically when you use our website, such as basic log and device information, to the extent described in the "Cookies" section below.
3. Lawful bases for processing
We only process your personal data where we have a lawful basis to do so under the GDPR. Depending on the situation, we rely on:
- Performance of a contract — to arrange, confirm and deliver the lessons, packages or vouchers you book, and to take payment.
- Consent — for example, where you send us an enquiry, where you share health information, where you agree to marketing use of your images, or where you allow certain cookies or the loading of embedded maps. You can withdraw consent at any time.
- Legitimate interests — to respond to your enquiries, to run and improve our coaching business, to keep records, and to protect the safety and security of clients, staff and our business, provided this is not overridden by your rights and interests.
- Legal obligation — where we must retain or disclose data to comply with the law, for example accounting, tax and record-keeping requirements.
- Vital interests — in the rare event that processing is necessary to protect someone's life or health, for example in a medical emergency during a lesson.
4. How we use your personal data
We use your personal data to:
- respond to your enquiries and communicate with you;
- arrange, confirm, reschedule and deliver your lessons;
- take and confirm payment, and manage packages and gift vouchers;
- coach you safely, taking into account any health information you have shared;
- keep proper business, accounting and tax records;
- handle complaints and resolve disputes; and
- where you have agreed, use images for marketing, or send you relevant updates.
5. Third parties & processors
We use a number of trusted third-party service providers ("processors") to run our business and website. These providers process personal data on our behalf under appropriate agreements, or as independent controllers under their own privacy terms. They include:
- Cal.com — online scheduling and booking management.
- Stripe — payment processing and hosted checkout (Stripe handles your card data directly).
- Supabase — secure database hosting (in the EU) for contact-form submissions and related records.
- Resend — email delivery, used to send us and/or you email relating to your enquiry or booking.
- Netlify — website hosting and delivery.
- Google Maps — to show the location of venues, where you choose to load the map (see "Cookies" below).
We only share the personal data these providers need to perform their services, and we do not sell your personal data. We may also disclose personal data where required to do so by law, or to establish, exercise or defend legal claims.
6. International transfers
We aim to keep your personal data within the European Economic Area (EEA) where possible; for example, our contact-form database (Supabase) is hosted in the EU. However, some of our providers may process or store data outside the EEA, including in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards recognised under the GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision, so that your data continues to receive an equivalent level of protection. You can ask us for more information about these safeguards using the contact details above.
7. How long we keep your data (retention)
We keep personal data only for as long as necessary for the purposes for which it was collected, including to meet any legal, accounting or reporting requirements. As a general guide:
- Enquiries that do not lead to a booking — typically kept for a limited period (for example up to 12 months) and then deleted.
- Booking and client records — kept for the duration of our relationship and for a reasonable period afterwards.
- Financial and transaction records — kept for the period required by applicable Cyprus tax and accounting law (commonly around 6–7 years).
- Health information — kept only for as long as needed to coach you safely, and then deleted or minimised.
When we no longer need your personal data, we will securely delete or anonymise it.
8. Your rights
Under the GDPR, you have the following rights in relation to your personal data:
- Access — to request a copy of the personal data we hold about you;
- Rectification — to have inaccurate or incomplete data corrected;
- Erasure — to ask us to delete your data in certain circumstances ("right to be forgotten");
- Restriction — to ask us to limit how we use your data in certain circumstances;
- Portability — to receive certain data in a portable format, or have it transferred to another controller where technically feasible;
- Objection — to object to processing based on our legitimate interests, or to direct marketing; and
- Withdraw consent — where we rely on your consent, to withdraw it at any time (this does not affect processing carried out before withdrawal).
To exercise any of these rights, please contact us using the details above. We will respond within the timeframes required by law. There is normally no charge, although we may charge a reasonable fee or decline a request that is manifestly unfounded or excessive.
9. Complaints to the supervisory authority
If you have a concern about how we handle your personal data, we would appreciate the chance to address it first. You also have the right to lodge a complaint with the Cyprus data protection authority:
Office of the Commissioner for Personal Data Protection (Cyprus)
Website: www.dataprotection.gov.cy
If you are in another EU/EEA country or the UK, you may also complain to your local data protection authority.
10. Cookies, analytics & the map
Our website aims to use only the cookies and similar technologies necessary for it to function, together with any additional cookies you agree to. Where we use any analytics, we will do so in line with applicable law and, where required, with your consent.
To protect your privacy, embedded content such as Google Maps is loaded on a "click-to-load" basis: the map, and any related cookies or data sharing with Google, will only be activated when you actively choose to load it. Until then, no map data is requested from Google. When you load the map, Google may process data in accordance with its own privacy policy.
11. Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, misuse or alteration. This includes using reputable providers that offer encryption and secure infrastructure, limiting access to your data, and processing payments through Stripe's secure hosted checkout so that card data does not reach our website. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Children's data
We offer junior lessons, and where we collect personal data about a child we do so on the basis of consent from, and in coordination with, a parent or guardian. We collect only the data we need to provide coaching safely, and we treat children's data with particular care. If you believe we hold data about a child without appropriate consent, please contact us and we will address it.
13. Reviews, ratings & photos
If you choose to leave a review, we collect the information you give us and process it as described below. Leaving a review is entirely optional.
- What we collect — your name or first name and initial, a star rating (1–5), your written comment, and any photo you optionally upload from your lesson. We also collect limited technical data about your submission (such as basic log information and the date and time it was sent) so we can operate the feature securely.
- Lawful basis — we process this information on the basis of your consent, which you give when you tick the consent box and submit your review. You can withdraw your consent at any time (see below).
- Publishing your review — when you submit a review or photo, you are asking us to share it on our website and in marketing. We may edit, decline or remove content where we need to — for example to protect someone's privacy or safety, to comply with the law, or where a submission is not genuine.
- How we use it — we use your review, your first name or initial and any photo to display on our website and in marketing materials and testimonials that promote our coaching.
- Storage & email — your submission is stored securely in our database (Supabase, hosted in the EU) and is also emailed to Philip so that he can read it.
- Retention — we keep reviews for as long as they remain relevant to our marketing, and any submission we do not use only for a limited period. We will remove or anonymise your review promptly if you ask us to, or once it is no longer needed.
- Your rights — you can ask us to access, correct, edit or delete your review, or to withdraw your consent, at any time by contacting us using the details below; withdrawing consent does not affect any processing carried out beforehand. You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection (Cyprus).
- Photos of other people & children — please only upload photos you are entitled to share. If a photo shows anyone other than you, you must have their consent before uploading it — and the consent of a parent or guardian for any child. To protect privacy, we may blur faces, crop, or decline to publish photos that show other people or children.
- Content standards — reviews must be honest and must not contain unlawful, offensive, defamatory or otherwise inappropriate content. We may decline or remove any review that does not meet these standards.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our services, providers or legal obligations. The "Last updated" date at the top shows when it was last revised. We encourage you to review it periodically.
Contact
For any privacy question or to exercise your rights, contact:
Philip Neil Golf (part of One Axion)
Email: philip.neil@oneaxion.com
Telephone: +357 97 481 750
Paphos, Cyprus
Philip Neil Golf ·Terms ·Privacy ·Refunds ·philip.neil@oneaxion.com
Part of One Axion · Paphos, Cyprus