PRIVACY POLICY CLEAR · PRACTICAL · UK GDPR
Last updated: 16 December 2025
Who we are (Data Controller)
We use a role-based Data Protection Lead and don’t name an individual in this policy.
Who this website is for
This website is intended for people aged 16+. Our content is informational harm reduction and general safety guidance, not medical advice. In an emergency, call 999 and/or go to onsite welfare/medics.
What personal data we collect
Data you give us directly
1) Volunteer enquiry / contact form (recommended minimum fields)
- Name (first name or full name)
- Email address
- Message (how you’d like to help)
- Availability (tick boxes) and area/town (we avoid full addresses)
- Age confirmation checkbox (“I am 16+”)
- Optional: phone number; relevant experience
Important
Please do not include medical information or other sensitive personal data in the volunteer form message.
2) Newsletter sign-up (Mailchimp)
- Email address
- Consent metadata (e.g., time/date of sign-up, confirmation of opt-in)
- Campaign analytics (e.g., opens/clicks)
Data we collect automatically
- Technical data such as IP address, device/browser information
- Server logs (security and troubleshooting)
- Cookie consent records (via CookieYes)
- Analytics: We do not run website analytics by default. If we add analytics later (e.g., GA4), we will update our cookie information and request consent where required.
- User accounts / logins: None on the website.
- Comments/uploads: Not enabled on the website.
How we use your data (and our legal bases)
Volunteer enquiries
Purpose: To read and respond to your enquiry, and (if relevant) progress your volunteering.
Legal basis: Legitimate interests (running our organisation and responding to messages) and, where relevant, steps prior to entering an arrangement with you as a volunteer.
Newsletter
Purpose: To send you updates such as harm reduction/safety information and volunteer opportunities. Fundraising emails will be sent only if you separately opt in.
Legal basis: Consent (we use double opt-in and keep consent records).
You can unsubscribe at any time using the link in any email.
Website security and operation
Purpose: To keep the website secure, prevent abuse, and troubleshoot issues (server logs and basic technical data).
Legal basis: Legitimate interests (maintaining a secure and reliable service).
Cookie consent management
Purpose: To store and respect your cookie preferences and maintain consent records.
Legal basis: Legal obligation (where applicable) and legitimate interests in compliance and site operation.
Cookies and similar technologies
We use CookieYes to manage cookie consent. Recommended consent categories on this site are:
- Essential
- Functional/Preferences
- Analytics and Marketing are disabled by default.
You can change your cookie choices any time using the “Cookie Settings” link in the site footer.
We also recommend a separate Cookie Policy page at /cookie-policy.
Who we share data with (processors)
We share data only when needed to run the website and communications, using trusted suppliers:
- Hostinger (website hosting, security, performance): server logs and (if stored) form submissions
- WordPress (website CMS): site content and (if stored) form data
- CookieYes (cookie banner/consent logs): consent choices and cookie identifiers
- Mailchimp (newsletter): subscriber email, consent metadata, campaign analytics
- Rank Math (SEO tooling): typically no personal data (may process limited site metadata)
We do not use advertising/remarketing pixels (e.g., Meta Pixel / Google Ads remarketing).
International transfers
Some suppliers may process data outside the UK (for example, Mailchimp often involves US processing). Where international transfers apply, we use appropriate safeguards (such as the UK IDTA and/or UK Addendum) as required, and document them.
How we keep data secure
We use practical security measures appropriate to a small organisation, including:
- HTTPS/TLS encryption in transit
- Admin access controls and MFA for WordPress/vendor accounts
- Least-privilege, role-based access
- Regular updates/patching and backups
- Data minimisation (we only collect what we need)
No website system is 100% secure, but we work to reduce risk and respond quickly to issues.
How long we keep your data (retention)
Your rights (UK GDPR)
You have rights including to:
- Access your personal data
- Correct inaccurate data
- Request deletion (in some cases)
- Restrict or object to processing (in some cases)
- Withdraw consent (where we rely on consent, e.g., newsletter)
- Data portability (in some cases)
To make a request, email miss.k@ravesafecommunity.com. We may need to verify your identity and will aim to respond within one month.
Complaints
If you’re unhappy with how we handle your data, you can contact us first at miss.k@ravesafecommunity.com. You also have the right to complain to the UK Information Commissioner’s Office (ICO).
Links to other websites
Our website may include links to third-party sites. Their privacy practices are their own, and we recommend checking their policies before sharing personal data.
Changes to this policy
We may update this Privacy Policy from time to time (for example, if we add analytics or new website features). If we make significant changes, we’ll update the “Last updated” date at the top of this page.