Privacy Policy

St Albans Adventure Group Privacy Policy

This privacy policy explains how the St Albans Adventure Group (STAG) collects, uses and protects the personal information of our members and of visitors to our website.

INTRODUCTION

STAG is committed to protecting and respecting your personal data.

Data Protection

The Group does not have to register under the General Data Protection Regulation (GDPR), as we are an organisation that does not make a profit to enrich others. Nevertheless, we conform to the requirements of the Act.

Lawful basis for processing data

The lawful basis for processing data is ‘legitimate interest’. All the personal data is provided by members. Processing of data is for maintaining membership such as subscriptions and disseminating Group news/information. STAG does not participate in any marketing activities involving member’s data. Data processing is limited to that necessary for the day-to-day management of the group.

PERSONAL DATA

Contact Data and General Administrative Records

Membership data consists of the contact details (name, address, telephone number and email address) and communications for current members. This is held on a variety of group and personal systems (PCs, the emailing list, social media or on paper) so that members can be contacted about group activities. The committee may also retain the completed membership application forms received when a person applies for membership.

Records of group committee meetings, general meetings and past activities are retained indefinitely.

Retention of Membership Data

Contact data for prospective members who never join are retained for a maximum of two years.

Membership forms from lapsed members are retained for a maximum of two years after membership lapses. However, some minimal contact details (names and email addresses) for lapsed members may be retained for a longer period to facilitate the organisation of celebrations and reunions.

At any time, a prospective, current or lapsed member may request deletion of the data that is held on them by the committee. Note that this does not include information that may have been posted via email or social media, which is beyond the control of the committee. Requests should be made by contacting a committee member.

Disclosure

We may disclose your information to the extent that we are required to by law, legal proceedings or for the purpose of fraud prevention. We do not participate in sharing membership data involving marketing activities.

Internal and External Publications

Photographs taken during group activities may appear in internal communications and may appear in group publicity including the website or posters. Any individuals who are sensitive about their image being used are advised to stand aside when photos or videos are being taken and make clear that they do not wish to be included. If you feature in a photograph on the website and would like it removed, please contact the webmaster or any committee member.

COMMUNICATIONS AND SOCIAL MEDIA

Various internal communications mechanisms are used for group announcements, chat and to enrich the life of our members. The messages are processed by third party systems and are not stored by the group itself.

Members are responsible for the posts that they make and are advised not to reveal any sensitive personal data about themselves or others; and not to share content likely to cause harm or distress.

Members shall not make public, use or make available for external use any personal data revealed through group communications and social media accounts without consent of the individual(s).

The group does not use email or social media to promote commercial products or services, but may on occasion share information about external activities likely to be of interest to members, such as charity events.

WhatsApp Community

The group has a WhatsApp Community to which members are normally added. They can then choose to join one or more subgroups with particular functions. The following personal data is visible to other members of the Community or subgroup:

  • The member’s WhatsApp display name
  • The member’s mobile phone number

Messages are processed by the WhatsApp service but are ultimately stored only on members own devices.

If any member feels that inappropriate content has been posted, they should notify the administrator of the chat group as soon as possible. Administrators can remove inappropriate posts made within a time limit (currently 60 hours) but deletion is impossible once that limit has passed. Even if the administrator is able to delete the offending post(s) from the chat group, there is no technical means for them to delete content that has been copied by members prior to its deletion. Similarly, members cannot remove their own posts except during the 60 hour time limit.

Emailing List

Google Groups is used to provide an email distribution list that members can join. Messages posted to this Google Group by an individual group member will be received by all members.

When you receive an email from the list, the email addresses of the recipients are not disclosed. However, if you post or reply to the list then your email address will be visible in the Reply-To header field.

Note that email messages can be stored in many places including email servers, user’s own machines and backup devices. If you join the email list via your Google Account, then messages will also be stored in that account (subject to available storage space). Thus it is not possible for messages to be deleted once they have been sent, either by you or by the committee.

STAG Website

STAG has a website to attract new members, provide information on forthcoming activities, and news about the group. Personal data published on the site comprises:

  • First names of event leaders
  • Photographs illustrating group activities
  • Reports about recent activities

Members requiring deletion or correction of personal data on the website should contact the Web Master or another committee member.

The contact details of event organisers (if supplied) are visible only to members that are currently logged in.

GENERAL PROVISIONS

Exercise of Member Rights

Group members enjoy rights of access, rectification and erasure of their personal data, where the data is held by the group itself. This does not apply to messages sent to the WhatsApp Community or to the emailing list, which are outside the committee’s control.

Members have the right to complain to the Committee about the way their personal data has been used. The Committee will investigate and respond to the complainant. 

Restrictions on use of Personal Data

Members are not permitted to make public, use or make available for external use any personal data revealed through group communications and social media accounts without the consent of the individual(s).

Website, Tracking and Cookie Policy

Generally, the website for STAG is open to all. A small Members’ Only section holds information visible only to logged-in members.

The website does not use cookies apart from the strictly necessary cookies used for the authentication of logged-in users.

Website usage is tracked and some statistics are stored on our web server. This information includes, but is not limited to: IP addresses, browser details, timestamps and referring pages. None of this information can personally identify specific visitors to our site. The information is recorded for routine administration and maintenance purposes, and lets us know what pages and information are most visited and therefore useful and helpful to visitors. None of this information is passed to other organisations or companies.

Third Party Websites

Our website includes links to third party websites and we have no control over their privacy policies.