The websites
We collect statistical information about access to and use of our websites through our server logs, but this information is not reported or used in such a way as to reveal personal information about you, nor will such information be shared with a third party.
This website runs on the WordPress software, which uses cookies as part of its normal functioning.
Comments and Malvern Connections
When visitors leave ‘comments’ or ‘Add a Connection’ on the site we collect the data shown in the form, and the visitor’s IP address and browser user agent string to help spam detection.
An anonymised string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service Privacy Policy is available here. After approval of your comment or connection, your profile picture is visible to the public.
Media
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website. Please ensure you own the copyright for the image or have a licence to use it.
Cookies
If you leave a comment on our site, you may opt in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our administrator login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When an administrator logs in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
MRATHS and data protection law
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
The Malvern and Radar Technology History Society (‘the Charity’) needs to collect and use certain types of information about individuals who contact the Charity during its work and servicing its membership. Any personal information, whether collected and stored in electronic or paper form, must be appropriately dealt with. The Charity fully complies with the General Data Protection Regulation, or GDPR, which is the UK’s Data Protection Act 2018.
Because the Charity is not a public authority, and its core activity does not involve large-scale monitoring of data subjects, or large-scale holding of protected personal data as defined in Articles 9 or 10, GDPR does not require us to employ a Data Protection Officer (see Article 37.1). As a small organisation with relatively little personal data, we have therefore chosen not to do so.
In the interests of good charity governance, the Board of Trustee will take responsibility for data protection issues as they arise, and to oversee the work of our data controllers and processors. In particular, the Board of Trustee oversees implementation of measures to ensure compliance with GDPR, and ensures that trustees, members, volunteers and others acting in the Charity’s name are handling data in accordance with the Principles of Data Protection laid out in Articles 5 to 11 of GDPR. A policy document has been written which details how MRATHS implements GDPR and the Board of Trustee can be contacted at Board of Trustees and is happy to respond to any concerns or questions from members and other data subjects of the Charity.
This policy will be periodically reviewed and updated to reflect best-practice developments and to comply with GDPR as implemented under UK Law.
Your rights as a data subject
In general we hold as little data as possible that could cause any harm if breached, and is relatively harmless (for example, we hold names, email addresses. If you are a Trustee, member, or volunteer, then we may hold more data. You have the following rights:
- Under GDPR Article 15 you have the right to ask us if we do hold data on you, and if so, what, and on what basis. Any such enquiries should be made to Board of Trustees. We will reply within 30 calendar days. Should it prove that data on you is mistaken, under Article 16 you then have a right to ask us to correct such an error.
- Under GDPR Article 17 you have the ‘right to be forgotten’: to require us to delete data which is no longer needed, or held only by your consent. We hold little or no data by consent, so the scope for Article 17 is limited. However, we will look at any Article 17 request case by case so that your rights are fully upheld. Such a request should be made to: Board of Trustees.
Under GDPR Article 13 you have the right to know what we keep, why, and for how long, whenever you provide us with data on yourself. Article 13.1 requires the Charity to declare the Data Controller for our data: we are a small organisation, and the Data Controller is the Charity itself (as it was also under the terms of the Data Protection Act 1998). Article 13.2 provides that you may, if not satisfied with our response, complain to the regulator. Since the Charity is based in the UK, this is the Information Commissioner’s Office or ICO.
Our full policies as they affect you are available in response to an Article 15 request (see above), but in brief: If you join the Charity, which is a CIO, we are required to keep membership records by law. If you then leave, or your subscription lapses, your contact details will be kept for a reasonable period in case the lapse was accidental, since many members do forget to renew but then rejoin. After this period, the record of your membership will be deleted.
How long we retain your data
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognise and approve any follow-up comments automatically instead of holding them in a moderation queue.
If you Add a Connection, the Connection and its metadata will be retained indefinitely unless you request modification or deletion by emailing Connections. Please state the modification required and the reason for it.
For administrators that register on our website, we also store the personal information they provide in their user profile. All administrators can see, edit, or delete their personal information at any time (except they cannot change their username). This can be removed by the Webmaster.
Third parties
The Charity does not sell or pass your data, to any third party unless required to do so by law.