Contents

1. Background
2. Policy Summary
3. What is covered by this Policy?
4. Identity of the Data Controllers
5. How do we collect personal information?
6. Information you submit: When do we collect personal information?
7. What information might we collect?
8. Information about children
9. Debit and Credit Card Information
10. How we use the information you submit?
11. Information we collect: Cookies on the WARGM website
12. Information shared with Website Provider
13. Who do we share your information with?
14. Your right to know what we know about you, make changes or ask us to stop using your data
15. Security
16. Changes to this policy
17. Ownership and communication

  1. Background

Waltham Abbey Royal Gunpowder Mills (WARGM) takes your privacy seriously. This privacy policy sets out how we use and protect any information about you which we have obtained from you.

In line with General Data Protection Regulations (2018) we are moving to an ‘opt-in only’ communication policy. This means that we will only send communications to you when you have explicitly stated that you are happy for us to do so via your preferred channel(s) (email, SMS, phone or post).

This policy is effective from 25th May 2018 and replaces the policy of 30th April 2014.

If you have any queries about the content of this policy, please contact us on  01992707340 or [email protected].

  1. Policy Summary

We respect your privacy and take great care with the information we obtain. We only ask for personal data when it is necessary to provide you with the service you have requested, such as registering you as a volunteer, fulfilling an order, enquiry or subscription from you or providing you with a Newsletter.

We may also make your personal information anonymous to undertake statistical analysis for internal use.

If we want to use your data for any purpose outside of the terms of this policy, we will ask you first and will not proceed without your explicit permission.

  1. What is covered by this Policy?

This policy covers all web pages on WARGM site (www.royalgunpowdermills.com) and associated sites used specifically for WARGM transactions, enquiries and subscriptions. This policy also covers information that you provide to us directly when you contact us by post, e-mail, SMS or phone.

This policy does not cover external sites such as Facebook or Twitter, who may

have links on WARGM pages. WARGM is not responsible for the content of these sites. You should check the terms and conditions and privacy policies of the sites that you visit.

  1. Identity of the Data Controllers

The Data Controllers for WARGM are the Chief Officer and his/her deputies.

  1. How do we collect personal information?

We respect your privacy and take great care with the information we obtain.

WARGM may collect the following about you via our website:

  • Examples such as information you provide to us when buying something, signing up to our e-News service, making an enquiry or contacting us for any other reason. We collect this via forms available on this website or in hard copy from the site offices
  • Information we gather via cookies: transactional data and information about how you arrived at the WARGM website and what you did when you got here.

The terms of how we collect and use this data are outlined below.

  1. Information you submit: When do we collect personal information?

We obtain information when you:

  • Send a query or enquiry
  • register to receive our Newsletter
  • book advance tickets or make any other purchase
  • provide us with personal information when you join us as a member of staff, register as a Volunteer or you undertake work for us on a contractual basis

We only ask you to give us information about yourself when we need it to provide the service you have requested.

  1. What information might we collect?

We may ask you to provide the following minimum information in order for us to complete the service or order you have requested. Depending on the service we may collect the following:

  • Your name
  • Year of birth
  • Email address
  • Postal address
  • Telephone number (mobile and/or landline)
  • Photographs (please see our Photo Consent Form)

If you are employed by us as a member of staff or sign up to be a Volunteer, we will ask for additional information such as:

  • Health questions
  • Driving licence-and driving details
  • Skills and interests (includes previous volunteering)
  • Availability
  • DBS check/declaration
  • Referees
  • Emergency contacts

Debit and credit card information is not stored by WARGM (see section on Debit and Credit Cards below).

Any personal information you provide will be transferred and stored on secure servers or cabinets in a safe, confidential and secure environment.

  1. Information about children

We collect and manage information from children, and aim to manage it in a way which is appropriate to the age of the child. The following guidelines are adopted with regard to children’s data:  

  • Children are, in the first instance, invited to provide their date of birth to ascertain their age. If they are below the age of 13 their parent or guardian are invited to sign a statement verifying their position in relation to the child, and then asked to give consent on behalf of the child. If that consent is not forthcoming we do not process the child’s personal data. If, in the absence of their parent or guardian, the child is accompanied by a teacher, the teacher’s consent will not be sufficient for these purposes.
  • Where it is established that the child is between 13 and 18 years of age we use very simple, clear, age-appropriate language to explain their rights to them and invite their consent to process their personal data. If that consent is not given, or there is any reason to believe that the child has not understood the explanation given, that child’s personal data is not processed.
  • We never use a child’s personal data in any automatic evaluation that proceeds without human intervention.
  • Any requests for data to be rectified or deleted will be dealt with immediately in the case of children, and where the data subject withdraws their consent to our holding of their personal data, we will comply with their requests straight away.
  1. Debit and Credit Card Information

All debit and credit card payments made online or over the telephone are processed in accordance with the Payment Card Industry Data Security Standards (PCI DSS). Your debit and credit card payments are processed by an approved PCI DSS payment provider and WARGM does not store or have access to any card information that you provide.

  1. How we use the information you submit?

The personal data we collect from you will be used to perform the service you have requested, for example answering your query or enquiry, fulfilling your order, registering you to our Newsletter service. In addition, it may be used for the following:

  • For customer research: we may contact you to ask you about the service you have received, why you requested it and how it can be improved
  • General administration of the services we provide
  • We may also use the personal information you provide, for internal purposes only, as a research tool to:
    • Improve our understanding of our visitors and customers
    • Develop more relevant services
    • Determine generally better ways to serve your needs

Information used in this way will be made anonymous wherever possible.

If you agree, we may also use it to tell you about changes in our services, future events and developments, or about special offers we think you'll find of interest.

Subscription to emails requires you to opt in to the service. It is voluntary and you can choose to unsubscribe at any time. Information about how to opt out of these communications will be included in every email we send you.

By submitting information to us, and giving us specific permission so to do, you are consenting to the management and use of your information as set out in this Privacy Policy.

  1. Information we collect: Cookies on the WARGM website

WARGM uses cookies to understand how you access and use the WARGM site. The information gathered in this way is anonymous and cannot be linked to you personally.  We use this data to inform the development of our services, user experience and in creating new content.

  1. Information shared with Website Provider

Your data may also be available to our website provider to enable us and them to deliver their service to us, carry out analysis and research on demographics, interests and behaviour of our users and supporters to help us gain a better understanding of them to enable us to improve our services. This may include connecting data we receive from you on the website to data available from other sources. Your personally identifiable data will only be used where it is necessary for the analysis required, and where your interests for privacy are not deemed to outweigh their legitimate interests in developing new services for us. In the case of this activity the following will apply:

  1. Your data will be made available to our website provider
  2. The data that may be available to them include any of the data we collect as described in this policy.
  3. Our website provider will not transfer your data to any other third party, or transfer your data outside of the EEA.
  4. They will store your data for a maximum of 7 years.
  5. This processing does not affect your rights as detailed in this privacy policy.
  1. Who do we share your information with?
  • Companies specifically contracted to manage data for WARGM in accordance with its instructions. On occasion these might be outside the European Economic area. Although they may not be subject to same data protection laws as companies based in the UK, we will take steps to make sure they provide an adequate level of protection in accordance with UK data protection law. By submitting your personal information to us you agree to this transfer, storing or processing at a location outside the EEA.
  • HM Revenue and Customs for the processing of Gift Aid

WARGM does not sell or share information submitted, either via the website or by any other means, with other external organisations, unless they are mentioned in this policy or if there is a legal requirement to do so.

  1. Your right to know what we know about you, make changes or ask us to stop using your data

You have a right to ask us to stop processing your personal data, and if it’s not necessary for the purpose you provided it to us for (e.g. processing your donation or registering you for an event) we will do so.  Contact us on 01992707340 or [email protected] if you have any concerns.

You have a right to ask for a copy of the information we hold about you.  If there are any discrepancies in the information we provide, please let us know and we will correct them.

If you want to access your information, send a description of the information you want to see and proof of your identity by post to Royal Gunpowder Mills, Beaulieu Drive, Waltham Abbey, Essex, EN9 1JY. We do not accept these requests by email so that we can ensure that we only provide personal data to the right person. We will deal with your request without undue delay and at the latest within one month.

If you have any questions please send these to [email protected], and for further information see the Information Commissioner’s guidance (https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/).

  1. Security

We are committed to ensuring your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect and hold. All the information you submit to us is stored securely and managed in accordance with the General Data Protection Regulations, for example our online forms are always encrypted and our network is protected and routinely monitored.

However, internet transmissions are never completely private or secure, and any message or information you send to the WARGM website may be read or intercepted by others. In line with the General Data Protection Regulations, WARGM has procedures in place to detect, report and investigate a personal data breach. We will report any breaches of security within 72 hours.

  1. Changes to this policy

We may change this Privacy Policy from time to time.  If we make any significant changes in the way we treat your personal information we will make this clear on the WARGM Website www.royalgunpowdermills.com or by contacting you directly.

If you have any questions, comments or suggestions, please let us know by contacting Royal Gunpowder Mills, Beaulieu Drive, Waltham Abbey, Essex, EN9 1JY

  1. Ownership and communication

This policy is owned by the Chief Officer of WARGM. It is to be communicated to all Trustees, staff and Volunteers and to be available on the WARGM website.

(Updated 18 September 2018)