Effective Date: August 6th, 2025
Policy Summary
1. Who We Are
The Chislehurst Society is a local community organisation committed to preserving and promoting the heritage and wellbeing of Chislehurst. We are a data controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. What Personal Data We Collect
We may collect and process the following types of personal data:
- Name, email address, phone number, and postal address
- Membership and donation records
- Event registration details
- Website usage data (e.g., IP address, browser type)
- Communication preferences
3. Lawful Bases for Processing
We process personal data under the following lawful bases:
- Consent – when you opt in to receive communications
- Contract – to fulfil membership or event-related services
- Legal obligation – for financial and tax reporting
- Legitimate interests – to promote our charitable aims in ways that do not override your rights
4. How We Use Your Data
We use your data to:
- Manage memberships and event registrations
- Communicate with you about our activities
- Process donations and Gift Aid claims
- Improve our website and services
- Comply with legal obligations
5. Data Sharing and Third Parties
We do not sell or trade your personal data. We may share data with:
- Service providers (e.g., email platforms, payment processors)
- HMRC (for Gift Aid claims)
- Law enforcement or regulatory bodies if required by law
- We ensure that any third-party processors are GDPR-compliant
6. Data Retention
We retain personal data only as long as necessary:
- Membership and donation records: up to 5 years
- Event registration: up to 2 years
- Website analytics: up to 1 year
7. Your Rights Under UK GDPR
You have the right to:
- Access your personal data
- Request correction or deletion
- Withdraw consent at any time
- Object to processing
- Data portability (where applicable)
- Lodge a complaint with the Information Commissioner’s Office (ICO)
8. Cookies and Website Analytics
Our website may use cookies to enhance user experience. You can manage cookie preferences via your browser settings. We use anonymised analytics to understand website usage.
9. Data Security
We take appropriate technical and organisational measures to protect your data, including:
- Secure storage and access controls
- Regular data audits and updates
- Staff awareness and training
10. Accountability and Governance
We maintain a written data protection policy and assign responsibility for data protection to a designated officer. We review our policies regularly and ensure staff are aware of their responsibilities.
11. Contact Us
For any privacy-related queries, please contact:
Data Protection Officer
The Chislehurst Society
3 Queens Passage
Chislehurst
BR7 5AP
If you have any questions, feel free to contact our office:
