St Mary’s Westerham Heritage Trust is committed to safeguarding and preserving the privacy of all those who, by whatever means, provide the Trust with any personal data, including any data that it collects when you visit its website.

This policy sets out what we collect and how we use it.

It is updated from time to time so please do review this Policy regularly

Who we are?

St Mary’s Westerham Heritage Trust, a registered charity (1096839) was founded in 2002 with the sole aim of maintaining and preserving Westerham’s Parish Church which dates from the thirteenth century.  Its Data Protection Officer is the Trust’s Treasurer who can be reached via email or by writing to The Trust Membership Secretary, St Mary’s Church, The Green, Westerham, Kent, TN16 1AS

What information do we collect?

From members of the trust

Names, addresses, email addresses taken from the membership application form completed by members.  From those who pay their annual subscription by standing order, we also collect and store details of the bank account from which the subscription is paid.

From those who attend or display at Trust events

Names, addresses, email addresses.  Where appropriate these link individual names to the organisations they represent.

For those who have booked tickets to events via our website, details are held in GDPR compliant Ticketsource database.  For those who have contacted us directly, details are held in GDPR compliant Mailchimp.

All financial details are held securely in a password protected spreadsheet

The Trust collects no data from third parties

How do we use personal information?

We use your personal data to:

  • administer membership records;
  • fundraise and promote the interests of the charity;
  • inform you of news, events and activities organised by The Heritage Trust

What legal basis do we have for processing your personal data?

You consent to us processing your data for the purposes described above.

Should you at any time wish to withdraw your consent to us processing your data in this way, you can withdraw your consent by:

  • clicking on the ‘unsubscribe’ button in communications received via Mailchimp
  • emailing
  • writing to The Trust Membership Secretary, St Mary’s Church, The Green, Westerham, Kent, TN16 1AS

We NEVER share your personal data

Where do we store and process personal data?

Both databases used, Mailchimp and Ticketsource are GDPR compliant

Any financial information held by the Trust remains and is processed in the UK

How do we secure personal data?

Personal data not held within the two applications above are held securely in shared drives, are password protected and are only accessible to nominated Trustees

How long do we keep your personal data for?

Personal data is held only for the period required by HMRC for Gift Aid and Charitable Organisations Accounts purposes.

Non financial personal data is held until such time as individuals notify the Trust that they no longer wish to remain on the Trust’s database.  Such requests will be auctioned within a calendar month.

Your rights in relation to personal data

You have the right to:

  • request a copy of your personal data which the Trust holds about you;
  • request that the Trust corrects any personal data if it is found to be inaccurate or out of date;
  • request your personal data is erased where it is no longer necessary for the Trust to retain such data;
  • withdraw your consent to the processing at any time
  • should there be a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing;
  • lodge a complaint with the Information Commissioners Office

How to contact us?

  • emailing
  • writing to The Trust Membership Secretary, St Mary’s Church, The Green, Westerham, Kent, TN16 1AS
  • You can contact the Information Commissioners Office on 0303 123 1113 or via email at the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire. SK9 5AF.

Use of cookies and other technologies

The Trust uses Google analytics linked to its website.  This enables us to understand which part of the website visitors are accessing and which information is most frequently accessed.  It does not enable any access to personal data.

Linking to other websites

The website provides links to other relevant websites.  This does not imply support for or endorsement of the content of those websites.

October 2019

(next review October 2020)