1. About this policy
This policy explains how Maslow’s UK Services Ltd and its operating subsidiaries (together, “Maslow’s”, “we”, “us” or “our”) use personal data. It applies to visitors to our websites, members and their guests, prospective members, restaurant and event bookers, newsletter subscribers, suppliers, job applicants and visitors to our houses.
It is issued under the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (“PECR”). It replaces the privacy policy and the cookie statement published on maslows.com in July 2021, and supersedes any conflicting privacy wording in the Mortimer House and 1 Warwick membership terms.
2. Who we are and who controls your personal data
Maslow’s UK Services Ltd is the lead data controller for shared group functions (maslows.com, central CRM, group marketing, finance, HR and IT). Each house is controlled by its operating entity:
- • Maslow’s UK Services Ltd – group controller. Company number 10184503. Registered office: 72 Welbeck Street, London W1G 0AY. ICO registration: ZB884831.
- • 37-41 Mortimer Opco Limited (trading as Mortimer House) – data controller for Mortimer House. Company number 10184501. Registered office: 37-41 Mortimer Street, London W1T 3JH. ICO registration: ZA615841.
- • MG Warwick Street Opco Limited (trading as 1 Warwick) – data controller for 1 Warwick. Company number 12275186. Registered office: 1 Warwick Street, London W1B 5LR. ICO registration: ZB478641.
- • Kensington View Nominee 1 Limited and Kensington View Nominee 2 Limited (together, trading as Maslow’s Kensington) – joint data controllers for Maslow’s Kensington. Registered office: 6th Floor, 125 London Wall, London EC2Y 5AS. Trading address: The Kensington Building, 1 Wrights Lane, London W8 5RY.
Where two or more Maslow’s entities jointly determine the purposes and means of processing, they act as joint controllers. The central point of contact for all data protection queries is in section 18.
3. Scope
This policy covers personal data we process in connection with:
- • www.maslows.com and its subdomains;
- • Our member portals and app, operated on our behalf by Nexudus;
- • Membership applications, administration, billing and communications;
- • Restaurant, bar, meeting room, private hire and event bookings;
- • Marketing and loyalty activities;
- • Visits to Mortimer House, 1 Warwick and Maslow’s Kensington;
- • Recruitment, supplier onboarding and business correspondence.
Third-party sites linked from our platforms are governed by their own privacy policies.
4. Personal data we collect
What we hold depends on your relationship with us. We collect personal data directly from you, automatically through cookies and similar technologies (section 8), from other Maslow’s entities when you use more than one house, and from third parties including referring members, our payment and booking processors, and publicly available professional sources.
4.1 Members and their guests
- • Name, date of birth, home and work address, email, phone and emergency contact.
- • Photograph used for identification, access control and personal recognition.
- • Preferences (dietary, accessibility, interests, communications).
- • Member portal and app credentials.
- • Membership tier, agreement details, start date, referrer and member ID.
- • Payment and billing data (direct debit mandate, last four digits of card, billing address). Full card details are tokenised by our payment processor.
- • Booking history, attendance records and, where enabled, Wi-Fi session logs.
- • Records of complaints, incidents and correspondence.
4.2 Restaurant, bar and event guests
- • Reservation details (contact, date, time, party size, special requests, dietary and accessibility notes, visit history).
- • Where a deposit applies, payment information held by our booking processor.
4.3 Website visitors, enquirers and subscribers
- • Identifiers you provide (name, email, phone, company, role).
- • Technical data (IP, device identifiers, browser, operating system, referrer URL).
- • Usage data (pages viewed, clicks and, where enabled, session recordings).
- • Marketing preferences, consents and engagement (opens, clicks, unsubscribes).
4.4 Job applicants
- • CV, work history, qualifications, references and right-to-work documents.
- • Interview notes and assessment outcomes.
4.5 Suppliers and business contacts
- • Name, role, business contact details and bank details for payment.
4.6 Visitors to our houses
- • CCTV images (see section 13).
- • Reception or visitor log entries
4.7 Information from third parties
- • Referrals from existing members or partners.
- • Publicly available professional information (for example, from LinkedIn) used for business development and membership review.
- • Fraud prevention and, where required, sanctions or anti-money laundering data from screening providers.
5. Why we use your personal data and our lawful basis
We only process personal data where we have a lawful basis under Article 6 UK GDPR (and Article 9 where special category data is involved). A summary of our legitimate interests balancing assessments is available on request.
Purpose |
Categories of data |
Lawful basis |
|---|---|---|
| Assessing and onboarding membership applications | • Identifiers
• Preferences • Referrer data • Photograph |
Art. 6(1)(b) contract (or pre-contract)
Art. 6(1)(f) legitimate interests – curating our community |
| Administering membership, billing and house access | • Identifiers
• Account data • Payment data • Booking history Access logs |
Art. 6(1)(b) contract |
| Restaurant, bar, meeting room and event bookings | • Contact details
• Booking and payment data • Dietary and accessibility data |
Art. 6(1)(b) contract
Art. 9(2)(a) explicit consent for dietary or accessibility data |
| Personal recognition and in-house service | • Name
• Photograph • Preferences • Booking history |
Art. 6(1)(b) contract
Art. 6(1)(f) legitimate interests – service standards |
| Operating and securing our websites and portals | • Technical and usage data
• Account data |
Art. 6(1)(b) contract
Art. 6(1)(f) legitimate interests |
| Website analytics and measurement | • Technical and usage data via cookies | Art. 6(1)(a) consent; PECR reg. 6 |
| Marketing | • Contact details
• Preferences • Engagement data |
Art. 6(1)(a) consent and PECR reg. 22
Art. 6(1)(f) legitimate interests under the soft opt-in for existing members and B2B contacts |
| Targeted advertising via Meta, LinkedIn and Google | • Identifiers and online audiences | Art. 6(1)(a) consent; PECR reg. 6 |
| Recruitment and pre-employment checks | • Applicant data
• Right-to-work documents |
Art. 6(1)(f) selection
Art. 6(1)(c) immigration and equality obligations |
| Supplier administration and payment | • Business contact and bank details | Art. 6(1)(b) contract
Art. 6(1)(c) tax and accounting |
| Security, CCTV and incident management | • CCTV footage
• Access logs • Incident records |
Art. 6(1)(f) safety of people and property
Art. 6(1)(c) health and safety |
| Legal, regulatory, accounting and tax compliance | • All relevant categories | Art. 6(1)(c) legal obligation |
| Establishment, exercise or defence of legal claims | • All relevant categories | Art. 6(1)(f) legitimate interests
Art. 9(2)(f) where special category data is involved |
| Corporate transactions (sale, reorganisation, financing) | • Relevant categories | Art. 6(1)(f) legitimate interests |
6. Special category data
We process special category data (for example, dietary, allergy or accessibility information) only where necessary and with an Article 9 UK GDPR condition, usually your explicit consent. Where we rely on consent, you can withdraw it at any time without affecting prior lawful processing.
7. Marketing communications
We send marketing about Maslow’s houses, programming, food and drink and events. You can opt out at any time via the unsubscribe link in our emails, or by contacting us (section 18).
For existing members and customers we may rely on the soft opt-in under PECR reg. 22(3); for all other individual marketing we rely on consent. We do not sell your personal data and do not share it with third parties for their own marketing without your consent.
8. Cookies and similar technologies
Our website uses cookies and similar technologies (pixels, tags, local storage, session recordings) deployed through Google Tag Manager. Consent is managed through the HubSpot cookie consent banner. Strictly necessary cookies load automatically; all other categories load only after you consent. You can change your preferences at any time via the “Cookie preferences” link in the website footer.
Category |
Purpose |
Examples of providers |
Legal basis |
|---|---|---|---|
| Strictly necessary | Session management, site security, form spam protection and recording your cookie choices. | • Maslow’s first-party session cookies; • HubSpot consent banner (__hs_cookie_cat_pref); • Google reCAPTCHA Enterprise (form protection) |
PECR reg. 6(4) / Art. 6(1)(f) |
| Functional | Operating enquiry forms, live chat and embedded video, and remembering preferences. | • HubSpot forms and CRM (__hstc, __hssc, __hssrc, hubspotutk); Vimeo (embedded videos) | Consent |
| Analytics | Measuring how our sites are used so we can improve them. | • Google Analytics 4 (_ga, _ga_<stream>); • Google Tag Manager; Hotjar (_hjSession*); • HubSpot Analytics |
Consent |
| Marketing and advertising | Campaign measurement, audience building and third-party advertising. | • Google Ads conversion linker (_gcl_au); • Meta Pixel and Conversions API; • LinkedIn Insight Tag; • HubSpot ads pixel |
Consent |
Hotjar session recordings suppress keystrokes in form fields by default. Meta, LinkedIn, Google and HubSpot pixels may send hashed identifiers to those platforms to build audiences; any international transfer is protected by the safeguards in section 10. The HubSpot consent banner is the definitive list of cookies in use and is updated whenever new tools are added.
9. Who we share your personal data with
We share personal data with the recipients below under written contracts that oblige them to protect it and use it only for the purposes we instruct.
Recipient category. |
Named providers (as at the effective date) |
Role |
|---|---|---|
| Other Maslow’s group companies | Maslow’s UK Services Ltd, 37-41 Mortimer Opco Limited, MG Warwick Street Opco Limited, Kensington View Nominee 1 Limited and Kensington View Nominee 2 Limited | Joint or separate controllers |
| Membership, portal, app and billing platform | Nexudus (Nexudus Ltd) | Processor |
| Card acquirer and payment processing | Stripe Payments UK Ltd | Processor (sub-processor to Nexudus) |
| CRM, marketing automation and email | HubSpot (HubSpot Inc.) | Processor |
| Restaurant and hospitality CRM | SevenRooms (SevenRooms Inc.) | Processor |
| Meeting room and event CRM | Tripleseat (Tripleseat LLC) | Processor |
| Website tagging and analytics | Google Tag Manager, Google Analytics, Hotjar (Contentsquare), HubSpot Analytics, Google reCAPTCHA Enterprise | Processors |
| Advertising platforms | Meta Platforms Ireland Ltd (Facebook, Instagram); LinkedIn Ireland Unlimited Company; Google Ireland Ltd (Google Ads) | Independent or joint controllers |
| Embedded content | Vimeo.com, Inc. | Independent controller for playback analytics |
| Professional advisers | Lawyers, accountants, auditors and insurers | Independent controllers |
| Authorities and regulators | HMRC, the ICO, police and other bodies where required | Independent controllers |
| Corporate transactions | Prospective buyers, investors and their advisers in due diligence | Controllers under confidentiality |
An up-to-date list of named processors is available on request (section 18).
10. International transfers
Some recipients in section 9 are located outside the UK, including in the European Economic Area and the United States. Where we transfer personal data outside the UK we rely on one of: a UK Government adequacy decision (including the UK–US Data Bridge where applicable); the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment; or, in limited circumstances, a derogation under Article 49 UK GDPR. You may request a copy of the safeguards in place for a particular transfer (section 18).
11. How long we keep your data
We keep personal data only for as long as needed. Where a longer period is required by law or to defend a claim, we apply that longer period and record the reason.
Record |
Retention |
|---|---|
| Membership application and account records | Duration of membership plus 7 years (HMRC and limitation) |
| Member bookings and visit logs | 24 months after the booking or visit |
| Restaurant, bar and event reservations | 24 months from reservation (7 years if invoiced, disputed or deposit taken) |
| Payment and billing records | 7 years from the end of the tax year |
| Marketing consents, preferences and suppression lists | Until consent is withdrawn; suppression records kept indefinitely to honour opt-outs |
| Newsletter engagement data | Up to 24 months of inactivity, then archived or deleted |
| Website analytics and Hotjar data | Provider defaults (typically 2–14 months); full list in the cookie banner |
| CCTV footage | 31 days, unless required for investigation or legal claim |
| Access control and Wi-Fi logs | 90 days, unless required for investigation |
| Incident and conduct records | 7 years from the date of the incident |
| Unsuccessful job applications | 12 months after the decision, unless you consent to longer retention |
| Successful job applications | Throughout employment and in line with our employee privacy notice thereafter |
| Supplier and contractor records | 7 years after the end of the relationship |
| General correspondence | 36 months from last interaction |
12. How we protect your data
We apply appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit and at rest where appropriate, supplier due diligence, written data processing agreements, staff training and incident response procedures. If we become aware of a personal data breach likely to result in a risk to your rights, we will notify the ICO within 72 hours and, where the risk is high, we will notify you without undue delay.
13. CCTV and access control
Our houses have CCTV in communal and operational areas for the safety of members, guests, staff and property. We do not record in private areas such as bathrooms, changing rooms or treatment rooms. Footage is held for up to 31 days and accessed only by authorised personnel or law enforcement where required or permitted by law. Access control systems log entry and exit events; logs are kept for 90 days.
14. Automated decisions and profiling
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. We use limited profiling for marketing segmentation and online advertising audiences, under the lawful bases in sections 5 and 8. You can object at any time (section 18).
15. Children
Our services are intended for adults aged 18 and over. We do not knowingly collect personal data from children through our websites or membership. Children may visit as guests of members under house rules; in that case we may process limited data for safety, access and catering. If you believe a child’s personal data has reached us in any other context, please contact us and we will delete it.
16. Your rights
You have the following rights under UK GDPR; some apply only in certain circumstances and we will tell you if an exception applies.
- Right of access – to obtain a copy of the personal data we hold about you.
- Right to rectification – to have inaccurate or incomplete personal data corrected.
- Right to erasure – where we no longer need the data or you withdraw consent.
- Right to restriction – while a query or objection is resolved.
- Right to data portability – for data you have provided to us, in a structured, machine-readable format.
- Right to object – to processing based on legitimate interests, and to direct marketing at any time.
- Right to withdraw consent – without affecting the lawfulness of prior processing.
- Right not to be subject to solely automated decisions – with legal or similarly significant effects.
To exercise a right, contact us using the details in section 18. We respond within one month, extendable by up to two further months for complex requests. There is usually no charge, but we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive. We may ask for proof of identity before responding.
17. Complaints and the ICO
If you are unhappy with how we have handled your personal data, please contact us first. You also have the right to complain to the Information Commissioner’s Office:
- Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
- Helpline: 0303 123 1113
- Website: ico.org.uk
18. Changes to this policy and how to contact us
We review this policy regularly and may update it. Where changes are material, we will notify you by email or through our websites and member portal. The current version is at maslows.com/privacy-policy, with the effective date shown at the top.
For any privacy query, to exercise a right or to ask about our data protection practices, please contact our Data Protection Officer:
- Data Protection Officer – Maslow’s Group
- Email: privacy@maslows.com
- Post: Maslow’s UK Services Ltd, 72 Welbeck Street, London W1G 0AY, United Kingdom
___
Updated: 21 July 2026
