Privacy Policy¶
Last updated: [date to be set on publication]
The British Rabbit Smallholders Association ("BRSA," "we," "us") is committed to protecting your personal data. This policy explains what data we collect, why, and how we look after it, in accordance with UK GDPR and the Data Protection Act 2018.
Who we are¶
BRSA is an unincorporated association. For data protection purposes, the Committee acts as the data controller. Our designated contact for data protection matters is our Data Protection Lead, reachable at [[email protected] — to be set up].
What data we collect¶
Depending on how you interact with us, we may collect:
- Website visitors — standard technical data (IP address, browser type, pages visited) via our hosting and security provider, Cloudflare.
- Members — name and email address when you sign up for membership; any additional information you provide via membership or committee contact forms.
- Committee contact form — name, email address, and the content of your message, submitted via our contact form.
- Payment information (future, once paid membership tiers are active) — handled directly by a payment processor; BRSA does not store your card details.
Why we collect it¶
We process your data to:
- Provide and manage your membership
- Respond to enquiries sent via our contact forms
- Send you service-related communications (e.g. sign-in links, membership confirmations)
- Maintain the security and proper functioning of our website
- Process membership payments, where applicable (future)
Our legal basis for processing¶
We rely on:
- Consent — for optional communications you opt into
- Contract — to provide membership services you've signed up for
- Legitimate interests — for website security and basic analytics, balanced against your rights
Who we share data with (data processors)¶
We use the following third-party services to operate the Association's website and membership system. Each processes data on our behalf under their own data processing agreements:
| Service | Purpose | Data involved |
|---|---|---|
| Cloudflare | DNS, hosting security, performance | IP address, technical/browsing data |
| Oracle Cloud Infrastructure | Server hosting | All data stored on the BRSA website and member database |
| [transactional email provider] | Transactional email (sign-in links, notifications) | Name, email address |
| [contact form provider] | Committee contact form | Name, email address, message content |
| [payment processor] (future) | Payment processing | Payment details (not stored by BRSA directly) |
We do not sell or share your data with third parties for marketing purposes.
How long we keep your data¶
We retain member data for as long as your membership is active, plus a reasonable period afterwards for record-keeping purposes [retention period to be confirmed by Committee — commonly 6–7 years for financial/membership records]. Contact form submissions are retained only as long as needed to resolve your enquiry, subject to the form provider's own retention settings.
Your rights¶
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data, where applicable
- Object to or restrict certain processing
- Data portability, where applicable
- Withdraw consent at any time, where processing is based on consent
To exercise any of these rights, contact us at [[email protected]]. We aim to respond within one month, as required by law.
Complaints¶
If you're unhappy with how we've handled your data, you can contact our Data Protection Lead in the first instance, or lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Changes to this policy¶
We may update this policy from time to time. The "last updated" date at the top will reflect the most recent revision.
This is a working draft prepared for BRSA's committee review. It has not been reviewed by a solicitor or data protection specialist. Placeholders marked in brackets need to be confirmed before publication, particularly the DSAR contact address, data retention period, and the named third-party processors in the table above.