Safeguarding and media consent policy

Last updated 17 September 2026 · Written for parents, guardians and safeguarding leads

1. Who this is for

If you are a parent or guardian deciding whether to let a child's information go into PerfHQ, or a safeguarding lead deciding whether your organisation should use it, this is the document to read.

It is written to be checkable. Where the software does something, it says so and says where. Where the software does not do something you might reasonably assume it does, it says that too — in the same typeface, in the same place. Every limit in section 4 is a real limit in the current release.

PerfHQ holds health information about children, some under 13, alongside video and on-device skeletal analysis of those children moving. That is the defining constraint on the product rather than a feature of it.

2. Where our responsibility ends and yours begins

The organisation is responsible for

Deciding who to enrol and what to collect. Obtaining consent from parents and guardians before entering a child's information, and before filming. Deciding which coaches may see sensitive records. Its own safeguarding policy, its DBS checks, its coaches' conduct, and what they write. Moderating what its members upload.

PerfHQ is responsible for

Keeping the service secure. Providing the permissions, the consent record, the consent gate, the reporting route and the moderation queue, and making them work as described. Telling the organisation about a breach. Acting on reports the organisation does not act on. Saying accurately what the software does and does not do — which is what this document is.

3. Who can see a child's information

Information The child A linked guardian Coaching staff
Profile, sessions, attendance Yes Yes Yes
Medical notes, allergies, conditions, medications Yes Yes Only with the medical permission
Emergency contacts Yes Yes Only with the medical permission
Coaching feedback addressed to them Yes Yes Yes
General coach notes Yes Yes Yes
Internal coach notes No No Only with the internal-notes permission
Photographs and video of them Yes Yes Yes
Another athlete's anything No No Yes, within the organisation

Two things follow from that table that are worth stating outright.

An athlete never sees another athlete's content. There is no public feed, no comments, no direct messaging and no athlete-to-athlete visibility anywhere in PerfHQ. The only content an athlete sees is coaching content addressed to them, by staff of their own organisation.

Internal notes are hidden, not confidential. They are excluded from the athlete's and the guardian's view before any permission check runs, so the exclusion is structural rather than a setting someone can get wrong. They are still visible to coaches who hold the permission, and they are still disclosable under a subject access request. A coach who writes something in an internal note should expect the family to read it eventually.

4. The limits of the software

These four are the ones a safeguarding lead should ask about, so we are answering them without being asked. None of them is a bug in the sense of something behaving unexpectedly; each is a thing that has not been built yet.

Media consent is opt-out, not opt-in

PerfHQ records two consent decisions against each athlete — media (photography and video) and social media (use outside PerfHQ) — with who recorded it and when, and either can be recorded at the organisation level or globally.

The trackside Capture camera checks that record. Pick an athlete whose media consent has been withdrawn and the viewfinder is covered: "[name] has no photo or video consent on file." Capture is refused in the camera and refused again on the way to the server.

What it does not do:

  • An absent record is treated as permission, not as refusal. Only an explicit withdrawal blocks anything. An athlete nobody has ever recorded a decision for can be filmed.
  • The check is applied in Capture, and not at every other route by which a photograph or video can reach PerfHQ — uploading an existing clip from the photo library, for instance.

So the consent gate is a genuine control when a withdrawal has been recorded in Capture, and it is not a guarantee anywhere else. An organisation must manage photography consent as a policy matter and must not rely on the software to enforce it.

Guardian access cannot be ended early through the product

A guardian link is scoped to one organisation and ends automatically on the child's eighteenth birthday — that part is reliable and needs nobody to remember it.

The software also honours a recorded revocation immediately, on every read path. But there is currently no screen and no endpoint that records one. If a guardian's access must end before the child turns 18 — a change in parental responsibility, a court order, a safeguarding concern — email privacy@perfhq.com, or safety@perfhq.com if it is a safeguarding matter, and we will do it by hand. Say which child, which guardian and which organisation.

Coach notes follow the athlete, not the organisation

If a child trains at two organisations that both use PerfHQ, coaching staff at either can see notes written at the other. Medical notes and emergency contacts are shared across organisations deliberately, so that an emergency is not answered from a half-record. Coach notes are shared as a consequence of how the data is structured, which is not the same thing and was not a decision anyone took on purpose.

Erasure does not remove every trace

What deleting an account removes, and what it leaves behind, is set out in section 10 of the Privacy notice. The short version: identity, medical notes, emergency contacts, date of birth and sign-in history go; some coaching records keep an internal reference with the identity detached from it; and the change-audit trail keeps the fact that a change was made, by whom and when, for seven years, though the previous values it held are cleared at the point of erasure.

5. Photography and video

The rules coaches agree to are in the Acceptable Use Policy. In summary: film for coaching and nothing else; have consent, and for a child that means the consent of someone with parental responsibility; frame it for the purpose; do not film people who are not part of the session; and remember that exporting a clip takes it outside PerfHQ's permission system entirely.

Consent to be coached is not consent to be filmed, and consent to be filmed is not consent to be posted. Social media consent is recorded separately and means only what it says.

Video and photographs are stored in private object storage and are served only through short-lived links tied to a specific file and a specific viewer. They are not public, not indexed and not shareable by URL.

Media has no automatic expiry unless the organisation sets one, and by default none is set. A club that wants footage of children deleted after a season must configure that; it will not happen on its own. Items placed in the trash are purged after 30 days.

6. Movement analysis

Some captures extract skeletal joint positions and depth — where the shoulders, hips and knees are through a movement. This is the part of the product that sounds most alarming in a safeguarding conversation, so it is worth being exact.

That processing is computed on the coach's device, using Apple's own Vision and ARKit frameworks. The app contains no third-party code at all, so nothing is shared with an analytics or machine learning provider.

The results are stored with the video they came from: the skeleton and golf-swing analysis, and for recordings made with the depth (LiDAR) recorder the depth, joint and audio files. They are readable only by people already allowed to watch that video, and they are trashed, purged and erased with it. Nothing about them is visible to anyone the video itself is not shared with.

None of it is used to train machine learning models, and we have not reserved a right to start. If that ever changed it would require a new privacy notice, an explicit opt-in that is off by default, and active agreement — not a quiet clause.

7. Raising a concern

If a child is at immediate risk, contact the police. Do that first. Then tell us so we can act on our side.

Situation Route
A child is at immediate risk Police, then safety@perfhq.com
Content in PerfHQ that concerns a child's safety The Report action on that content, and safety@perfhq.com
A coach's conduct Your organisation's safeguarding lead, and safety@perfhq.com if PerfHQ needs to act
Guardian access that must end now safety@perfhq.com
A data protection question or request privacy@perfhq.com

Every piece of content in PerfHQ carries a Report action that needs no permission — an athlete's account can use it. Reporting hides the content from you immediately. Reports are acted on within 24 hours, administrators at the organisation are emailed the moment one is filed, and PerfHQ staff see every organisation's outstanding reports and step in where an organisation does not.

Where the law requires it, we will report a matter to the police or to the relevant safeguarding authority, and we will suspend an account immediately where a child's safety is involved.

8. Questions a safeguarding lead usually asks next

Can a coach take footage out of PerfHQ? Yes, by exporting it to their device. Nothing in the software prevents that, and nothing in the software protects it afterwards. It is a matter for your code of conduct.

Can an athlete message another athlete? No. There is no messaging in PerfHQ at all.

Can a parent see everything about their child? Everything except internal coach notes, and only for the organisation their guardian link is scoped to.

What happens at 18? Guardian access ends automatically. The young person keeps their own account and their own data.

Who at PerfHQ can see our data? Access to production systems is restricted to the operator and limited to what is needed to run and support the service. PerfHQ staff can see every organisation's outstanding content reports, which is how the 24-hour backstop works.

Do you have a DPIA? Not yet. Article 35 makes one mandatory for this processing and it is outstanding; it is named as an open obligation in our own decision record rather than left unmentioned. Ask us where it has got to before you rely on it.

Who do we complain to if we are not happy with your answer? The Information Commissioner's Office, at ico.org.uk. We would ask you to raise it with us first, at privacy@perfhq.com, so we have a chance to put it right — but that is a request and not a condition, and you can go straight to the ICO if you prefer.

9. Contact