Skip to content

Privacy Policy

Field Value
Reference POL-004
Type Policy
Version 1.00
Status Approved
Owner Data Protection Lead
Approver Board
Approval Reference MIN-2026-08-02
Effective Date 2026-08-05
Next Review 2027-08-05
Review Requirements As defined in STD-001
Classification Public

Last updated: [date to be set on publication]

Purpose

To explain, in accordance with UK GDPR and the Data Protection Act 2018, what personal data BRSA collects, why, and how it is looked after. This is the public-facing transparency notice; internal practice and responsibilities are set out in POL-001 (Data Protection Policy).

Scope

Applies to anyone whose personal data BRSA processes - website visitors, members, and anyone who contacts the Association.

The British Rabbit Smallholders Association ("BRSA," "we," "us") is committed to protecting your personal data.

Who we are

BRSA is an unincorporated association. For data protection purposes, the Committee acts as the data controller. Our designated contact for data protection matters is our Data Protection Lead, reachable at [dsar@brsauk.co.uk — to be set up].

What data we collect

Depending on how you interact with us, we may collect:

  • Website visitors — standard technical data (IP address, browser type, pages visited) via our hosting and security provider, Cloudflare.
  • Members — name and email address when you sign up for membership; any additional information you provide via membership or committee contact forms.
  • Committee contact form — name, email address, and the content of your message, submitted via our contact form.
  • Payment information (future, once paid membership tiers are active) — handled directly by a payment processor; BRSA does not store your card details.

Cookies

Our website uses a small number of cookies:

  • Essential/authentication cookies — used to sign you in and keep you signed in to the member area.
  • Cloudflare cookies — set by our hosting and security provider to help protect the site from abuse and keep it running reliably.

We don't use analytics or advertising cookies. Because the cookies we use are strictly necessary for the site to work, we don't need your consent for them under the Privacy and Electronic Communications Regulations (PECR) - but you can control cookies through your browser settings if you prefer, though this may stop you being able to sign in.

Why we collect it

We process your data to:

  • Provide and manage your membership
  • Respond to enquiries sent via our contact forms
  • Send you service-related communications (e.g. sign-in links, membership confirmations)
  • Maintain the security and proper functioning of our website
  • Process membership payments, where applicable (future)

We rely on:

  • Consent — for optional communications you opt into
  • Contract — to provide membership services you've signed up for
  • Legitimate interests — for website security and basic analytics, balanced against your rights

Who we share data with (data processors)

We use the following third-party services to operate the Association's website and membership system. Each processes data on our behalf under their own data processing agreements:

Service Purpose Data involved
Cloudflare DNS, hosting security, performance IP address, technical/browsing data
Oracle Cloud Infrastructure Server hosting All data stored on the BRSA website and member database
[transactional email provider] Transactional email (sign-in links, notifications) Name, email address
[contact form provider] Committee contact form Name, email address, message content
[payment processor] (future) Payment processing Payment details (not stored by BRSA directly)

We do not sell or share your data with third parties for marketing purposes.

How long we keep your data

We retain member data for as long as your membership is active, plus a reasonable period afterwards for record-keeping purposes [retention period to be confirmed by Committee — commonly 6–7 years for financial/membership records]. Contact form submissions are retained only as long as needed to resolve your enquiry, subject to the form provider's own retention settings. See POL-007 (Records Retention Policy) for the fuller internal retention schedule covering all of BRSA's records, not only personal data.

Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data, where applicable
  • Object to or restrict certain processing
  • Data portability, where applicable
  • Withdraw consent at any time, where processing is based on consent

To exercise any of these rights, contact us at [dsar@brsauk.co.uk]. We aim to respond within one month, as required by law.

Complaints

If you're unhappy with how we've handled your data, you can contact our Data Protection Lead in the first instance, or lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Changes to this policy

We may update this policy from time to time. The "last updated" date at the top will reflect the most recent revision.

  • POL-001 Data Protection Policy
  • POL-007 Records Retention Policy
  • PROC-004 Data Subject Access Requests
  • PROC-003 Data Breach and Incident Response

Review Requirements

As defined in STD-001, or following any material change to relevant data protection guidance.

Change History

Version Date Author Summary
0.10 2026-07-23 DC Initial draft
0.10 2026-07-23 DC Added Cookies section; cross-referenced POL-007 for retention detail
0.10 2026-07-24 DC Simplified Cookies section to category/purpose rather than naming exact cookies, to avoid drift as Ghost/Cloudflare's own cookie names change
0.50 2026-07-24 DC Version -> 0.50; Status -> Review
1.00 2026-08-05 DC Version -> 1.00; Approval Reference -> MIN-2026-08-02; Status -> Approved; Effective Date -> 2026-08-05; Last Reviewed -> 2026-08-05; Next Review -> 2027-08-05

This is a working draft prepared for BRSA's committee review. It has not been reviewed by a solicitor or data protection specialist. Placeholders marked in brackets need to be confirmed before publication, particularly the DSAR contact address, data retention period, and the named third-party processors in the table above. Currently internal, needs moving to public when agreed