Privacy Notice: How We Use Your Information
The privacy and security of your personal information is extremely important to the Dorset Natural History and Archaeological Society. This privacy notice explains how and why we use your personal data, to make sure you stay informed and can be confident about giving us your information.
We keep this notice updated and published on our website to show you all the things we do with your personal data. This policy applies if you’re a supporter of the DNHAS (member, donor, volunteer, visitor, customer, employee) or use any of our services, visit our website, email, call or write to us.
We never sell or rent your personal data and will only share it with organisations we work with when it’s necessary and the privacy and security of your data is assured.
2. Who are ‘we’?
In this notice, whenever you see the words ‘we’, ‘us’, ‘our’, ‘Society’ or ‘Museum’ it refers to The Dorset Natural History and Archaeological Society (DNHAS). Our Information Commissioners Office registration number is Z980795X.
The Society is a Registered Charity (No. 1062400) aiming for: the advancement of education for the benefit of the public in the areas of archaeology, natural sciences, literature, the fine and decorative arts, antiquities and local history relating to the County of Dorset; and the acquisition, preservation, conservation, exhibition and development of collections relating to the areas outlined above.
The Society is also a Company Limited by Guarantee (No. 3362107) which carries out a range of commercial trading activities to generate income. These include operating Dorset County Museum, the sale of gifts and souvenirs in a shop and online, income from commercial partnerships including sponsorship, and other commercial activities such as catering and special events.
If you have any questions in relation to this privacy notice or how we use your personal data they should be sent to firstname.lastname@example.org or addressed to the Executive Director / CEO, Dorset Natural History and Archaeological Society, Dorset County Museum, High West Street, Dorchester, Dorset, DT1 1XA.
3 What personal data do we collect?
Your personal data (any information which identifies you, or which can be identified as relating to you personally for example, name, address, phone number, email address) will be collected and used by us. We’ll only collect the personal data that we need.
We only collect personal data in connection with specific activities such as membership administration, placing an order, booking tickets, donations, volunteering, collections management and documentation, conducting research, ordering photographic images, and employment.
You can give us your personal data by filling in forms, by registering on our website, using social media functions on our website, entering a competition, promotion or survey, or by corresponding with us (by phone, email or by joining as a member/supporter/customer).
This personal data you give us may include name, title, address, date of birth, age, gender, employment status, demographic information, email address, telephone numbers, personal description, photographs, CCTV images, attitudes and opinions.
3.1 What personal data might you need to provide?
This includes information you will need to give when interacting with us, for example joining or registering,
buying a ticket, donating an object to the collection, placing an order or communicating with us. For example:
- Personal details (name, date of birth, email, address, telephone, and so on) when you join as a member
- Financial information (payment information such as credit or debit card or direct debit details, and whether donations are gift-aided)
- Your opinions and attitudes about the Museum, its activities and events, and your experiences of the Society
3.2. Automatically collected data
Using our website or social media channels may result in us automatically collecting the following information:
- Technical information, including the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform and if you access our website via your mobile device we will collect your unique phone identifier
- Information about your visit, including, but not limited to the full Uniform Resource Locators (URL) and query string, clickstream to, through and from our website (including date and time), products you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as but not limited to,scrolling, clicks, and mouse-overs), methods used to browse away from the page, and any phone number used to call our customer service number
- Information about your purchases including but not limited to revenue figures, the types of productspurchased, membership application ID, purchase ID, and ticket booking ID.
- The terms that you use to search our website
3.3 Personal data created by your involvement with us
Your activities and involvement with us will result in personal data being created. This could include details of how you’ve helped us by volunteering or being involved with our campaigns and activities.
If you decide to donate to us then we’ll keep records of when and how much you give to a particular cause.
3.4. Information we generate
We conduct research and analysis on the information we hold, which can in turn generate personal data. For example, by analysing your interests and involvement with our work we may be able to build a profile which helps us decide which of our communications are likely to interest you. The sections 4.7 Research and 4.8 Profiling gives more detail about how we use information for profiling and targeted advertising, including giving you more relevant digital content.
3.5. Information from third parties
We buy anonymous external data (e.g. census data, Experian MOSAIC, TGI) and combine it with your personal data at an aggregated level to build profiles which help us work out what you’re most likely to want to hear from us about and how.
3.6. Sensitive personal data
At times we’ll collect sensitive personal data for Equal Opportunities monitoring, as well as researching whether we deliver great experiences for everyone, but this is only ever analysed at an anonymised, aggregate level.
3.7. Volunteering data
If you’re a volunteer then we may collect extra information about you (e.g. references, criminal records checks, details of emergency contacts, medical conditions etc.). This information will be retained for legal or contractual reasons, to protect us (including in the event of an insurance or legal claim) and for safeguarding purposes.
3.8 Children’s personal data
Children aged under 18 are not included in the personal details of joint / family memberships for the Society. We do require their personal details (or those of their parents) for inclusion in the Young Archaeologists Club. We don’t ask children for consent to marketing communications, so they will not receive them. We won’t send marketing or fundraising emails, letters or telephone calls to people under the age of 18.
4 How we use your personal data
We’ll only use your personal data on relevant lawful grounds as permitted by the EU General Data Protection Regulation (from 25 May 2018), UK Data Protection Act and Privacy of Electronic Communication Regulation.
Personal data provided to us will be used for the purpose or purposes outlined in any fair processing notice in a transparent manner at the time of collection or registration where appropriate, in accordance with any preferences you express. If asked by the Police, or any other regulatory or government authority investigating suspected illegal activities, we may need to provide your personal data.
Your personal data may be collected and used to help us deliver our charitable activities, help us raise funds, or complete your order or request. Below are the main uses of your data which depend on the nature of our relationship with you and how you interact with our various services, websites and activities.
4.1 Marketing communications
Your privacy is important to us, so we’ll always keep your details secure. But we’d like to use your details to keep in touch about things that may matter to you.
If you choose to hear from us we may send you information based on what is most relevant to you or things you’ve told us you like. We may also show you relevant content online. This might be about visiting the Museum, volunteering with us, membership, events and activities, conservation work, fundraising, or offers in our shop and tea room.
We’ll only send these to you if you agree to receive them and we will never share your information with companies outside the DNHAS for inclusion in their marketing. If you agree to receive marketing information from us you can change your mind at a later date.
However, if you tell us you don’t want to receive marketing communications, then you may not hear about events or other work we do that may be of interest to you.
Personal data provided to us may also be profiled to help us with advertising targeting. For example, your membership data may be used to ensure we don’t serve you online membership advertisements. Or we may use your personal data to find online users with a similar profile to yourself who may be interested in our products or services.
We may sometimes use third parties to capture some of our data on our behalf, but only where we are confident that the third party will treat your data securely, in accordance with our terms and in line with the requirements set out in the GDPR.
We’ll always act upon your choice of how you want to receive communications (for example, by email, post or phone). However, there are some communications that we need to send. These are essential to fulfil our promises to you as a member, volunteer, donor or buyer of goods or services from the Society. Examples are:
- Transaction messaging, such as Direct Debit schedules, shop purchase confirmations and ticket
- Membership-related mailings such as renewal reminders, DNHAS Newsletter, the Proceedings of
DNHAS and notice of our Annual General Meeting
4.2 Membership including newsletters and magazines
We use the personal data you provide as a DNHAS member to service your membership. This includes sending renewal information to annual members by mail and email, sending Society magazines, Newsletters and the Proceedings, and information about our Annual General Meeting.
4.3 Fundraising, donations and legacy pledges
Where we have your permission, we may invite you to support our vital heritage, learning conservation and collections development work by making a donation, getting involved in fundraising activities or leaving a gift in your will.
Occasionally, we may invite some members and supporters to attend special events to find out more about the ways in which donations, gifts and legacies can make a difference to specific projects and to our cause.We’ll also send you updates on the impact that you make by supporting us in this way, unless you tell us not to.
If you make a donation, we’ll use any personal information you give us to record the nature and amount of your gift, claim gift aid where you’ve told us you’re eligible and thank you for your gift. If you interact or have a conversation with us, we’ll note anything relevant and store this securely on our systems.
If you tell us you want to fundraise to support our cause, we’ll use the personal information you give us to record your plans and contact you to support your fundraising efforts.
If you’ve told us that you’re planning to, or thinking about, leaving us a gift in your will, we’ll use the information you give us to keep a record of this – including the purpose of your gift, if you let us know this.
If we have a conversation or interaction with you (or with someone who contacts us in relation to your will, for example your solicitor), we’ll note these interactions throughout your relationship with us, as this helps to ensure your gift is directed as you wanted.
Charity Commission rules require us to be assured of the provenance of funds and any conditions attached to them. We follow a due diligence process which involves researching the financial soundness, credibility, reputation and ethical principles of donors who’ve made, or are likely to make, a significant donation to the Society.
As part of this process we’ll carry out research using publicly available information and professional resources. If this applies to you, we’ll remind you about the process when you make your donation.
4.4 Major donors
If you’re a current or prospective major donor, we’ll give you a bespoke privacy notice with further details of
how we look after your data.
4.5 Management of volunteers
We need to use your personal data to manage your volunteering, from the moment you enquire to the time you decide to stop volunteering with us. This could include: contacting you about a role you’ve applied for or we think you might be interested in, shifts you’ve booked on to, and to recognise your contribution.
Management could also include information about your volunteering experience. We may share this with funders to help them monitor how their funding is making a difference.
4.6 Retail sales and events management
We process customer data in order to fulfil event bookings, ticket sales and other retail activities. Your data will be used to communicate with you throughout the process, including to confirm we’ve received your order and payment, to confirm dispatch, to clarify where we might need more detail to fulfil an order or booking, or to resolve issues that might arise with your order or booking. We may also hold dietary requirements for special event catering.
We carry out research with our members, visitors, customers, staff and volunteers to get feedback on their experience with us. We use this feedback to improve the experiences that we offer and ensure we know what is relevant and interesting to you.
If you choose to take part in research, we’ll tell you when you start what data we will collect, why and how we’ll use it. All the research we conduct is optional and you can choose not to take part. For some of our research we may ask you to provide sensitive personal data (e.g. ethnicity). You don’t have to provide this data and we also provide a ‘prefer not to say’ option. We only use it at an aggregate level for reporting (e.g. equal opportunities monitoring).
Under strictly controlled circumstances we may give some of your personal data (e.g. contact information) to a research agency (e.g. The Audience Agency) who will carry out research and analysis on our behalf.
It’s important that we use our resources in a responsible and cost-effective way. So we use profiling and targeting to help us understand our members, visitors and supporters and make sure that:
- our communications and services are relevant, personalised and interesting to you
- our services meet the needs of our members, visitors and supporters
- we only ask for further support and help from you if it’s appropriate
- we use our resources responsibly and keep our costs down
To do this we’ll use profiling to analyse how you interact with us and use aggregated demographic information
to let you know what’s happening and understand your interests.
We also use specific tools to profile how you interact with us online, for example, Adobe Analytics, Google Analytics and Double Click for Advertisers. We use Adobe Analytics to collect information on the use of the Society website. Much of the information we collect is aggregated, however we may also collect some personal data for the use of personalising your experience, optimising our marketing campaigns, and to ensure the site is functioning as intended.
The personal information that is collect includes transactional information (i.e. order number) for Memberships, Donations, Renewals, Ticket Bookings and Online Shop Purchases. This information takes the form of an encrypted string.
If you’ve agreed that we can contact you for marketing purposes, we may also gather additional information about you from external sources, for example: updates to address and contact information, or publicly available information regarding your wealth, earnings and employment at an aggregate level. We may use this information to assess your capacity to support us and invite you to do so.
This analysis may be carried out by us or by third party organisations working for us. We may also host encrypted personal data on third party websites (e.g. social media platforms) to ensure that you only seerelevant, personalised and interesting content from those organisations.
Dorset County Museum has Closed Circuit Television (CCTV) and you may be recorded when you visit. CCTV is used to provide security and protect both our visitors, volunteers and staff. CCTV will be only be viewed when necessary (e.g. to detect or prevent crime) and footage is stored for set period of time after which it is recorded over. The Society complies with the Information Commissioner’s Office CCTV Code of Practice and we put up notices so you know when CCTV is used
5 Online data and e-commerce
5.2 Links to other websites
Our website may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and privacy notices and that we don’t accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites. This privacy notice applies solely to the personal data collected by the DNHAS.
5.3 Online Payment Card Security
The DNHAS has an active PCI-DSS compliance programme in place. This is the international standard for safe card payment processes. As part of our compliance to this very stringent standard, we ensure that our IT systems do not directly collect or store payment card information; for example the full 16 digit number on the front of the card or the security code on the back. Our online payment solutions are carried out using a 'payment gateway' which is a direct connection to a payment service provided by a bank. This means that when you input card data into an online payment page, you are communicating directly with the bank and the bank passes your payment to us, this means that your payment card information is handled by the bank and not processed or held by us.
6. Keeping your information
We will only use and store your information for as long as it is required for the purposes it was collected for. How long it will be stored for depends on the information in question, what it is being used for and, sometimes, statutory legal requirements.
6.1 How we secure your data
Information system and data security is imperative to us to ensure that we are keeping our customers, members, visitors, volunteers, employees and contractors safe. We operate a robust and thorough process for assessing, managing and protecting new and existing systems which ensures that they are up to date and secure against threats.
When you trust us with your data we will always keep your information physically secure to maintain your confidentiality. By utilizing encryption when your information is stored or transmitted electronically we minimize the risk of unauthorized access or disclosure.
6.2 Disclosing and sharing information
When we allow third parties acting on behalf of the Society to access to your information, we will always have complete control of what they see, how long they see it for and what they are allowed to do with it. We do not sell your personal information for other organisations to use. Personal data collected and processed by us may be shared with the following groups where necessary:
- Society employees and volunteers
- Consultants who conduct audience development and fundraising research on our behalf
- Third party cloud hosting and IT infrastructure providers who host the website and provide IT
support in respect of the website; Also, under strictly controlled conditions:
- Selected museum and heritage partner organisations
- Service Providers
- Advisors and agents
6.3 Storage of information
The Society’s operations are based in the UK and we store all our data within the European Union (EU). Some organisations which provide services to us may transfer data outside the European Economic Area but we’ll only allow this if your data is adequately protected (e.g. US Privacy Shield or Standard EU contractual clauses).
We will not keep personal data for any longer than is absolutely necessary and it will be disposed of using a secure professional destruction service. Electronic records will be deleted in such a way that they cannot be retrieved. While the length of time we retain records will necessarily vary depending on specific purposes, the main parameters are as follows:
- Financial data will be stored for 7 years for HMRC tax, VAT and Gift Aid inspection purposes
- Membership data will be retained for no longer than 6 months after a subscription is resigned or 24
months after a subscription has lapsed
- Employment and volunteering personal data will be stored for no more than 5 years after resignation
or termination of contract for safeguarding and reference request purposes
- Collections donation data will be stored as part of the object history file and transfer of title information in perpetuity.
7 Recruitment and employment
In order to comply with our contractual, statutory, and management obligations and responsibilities, we process personal data, including ‘sensitive’ personal data, from job applicants and employees.
Such data can include, but isn’t limited to, information relating to health, racial or ethnic origin, and criminal convictions. In certain circumstances, we may process personal data or sensitive personal data, without explicit consent. Further information on what data is collected and why it’s processed is given below.
7.1 Contractual responsibilities
Our contractual responsibilities include those arising from the contract of employment. The data processed to meet contractual responsibilities includes, but is not limited to, data relating to: payroll, bank account, postal address, sick pay; leave, maternity pay, pension and emergency contacts.
7.2 Statutory responsibilities
Our statutory responsibilities are those imposed through law on the organisation as an employer. The data processed to meet statutory responsibilities includes, but is not limited to, data relating to: tax, national insurance, statutory sick pay, statutory maternity pay, family leave, work permits, equal opportunities monitoring.
7.3 Management responsibilities
Our management responsibilities are those necessary for the organisational functioning of the organisation.The data processed to meet management responsibilities includes, but is not limited to, data relating to:recruitment and employment, training and development, absence, disciplinary matters, e-mail address and telephone number.
7.4 Sensitive personal data
‘Sensitive personal data’ is defined by the GDPR as information about racial or ethnic origin, political opinions, religious beliefs or other similar beliefs, trade union membership, physical or mental health, sexual life, and criminal allegations, proceedings or convictions.
In certain limited circumstances, we may legally collect and process sensitive personal data without requiring the explicit consent of an employee:
- We will process data about an employee’s health where it is necessary, for example, to
record absence from work due to sickness, to pay statutory sick pay, to make appropriate
referrals to the Occupational Health Service, and to make any necessary arrangements or
adjustments to the workplace in the case of disability. This processing will not normally happen
without the employee’s knowledge and, where necessary, consent.
- We will process data about, but not limited to, an employee’s racial and ethnic origin,
their sexual orientation or their religious beliefs only where they have volunteered such data and only
for the purpose of monitoring and upholding our equal opportunities policies and related provisions.
- Data about an employee’s criminal convictions will be held as necessary.
7.5 Disclosure of personal data to other bodies
In order to carry out our contractual and management responsibilities, we may, from time to time, need to share an employee’s personal data with one or more third party supplier.
To meet the employment contract, we are required to transfer an employee’s personal data to third parties, for example, to pension providers and HM Revenue and Customs.
In order to fulfil our statutory responsibilities, we’re required to give some of an employee’s personal data to government departments or agencies e.g. provision of salary and tax data to HM Revenue and Customs.
8. Updating your data and marketing preferences
We want you to remain in control of your personal data. If, at any time, you want to update or amend your personal data or marketing preferences please contact us in one of the following ways:
Email: email@example.com with your full name, full address and, if applicable, your DNHAS membership number
Telephone: 01305 262735. Line open 10.00am - 4.30pm Monday to Saturday (not including bank holidays)
Dorset Natural History and Archaeological Society
Dorset County Museum
High West Street
Verification, updating or amendment of personal data will take place within 30 days of receipt of your request.
8.1 Your data protection rights (DPO)
Where the Society is using your personal data on the basis of consent, you have the right to withdraw that consent at any time. You also have the right to ask the Society to stop using your personal data for direct marketing purposes. Tell us using the contact details above.
8.2 Subject access rights
If you would like further information on your rights or wish to exercise them, please write to Executive Director, Dorset Natural History and Archaeological Society, Dorset County Museum, High West Street, Dorchester, Dorset, DT1 1XA or email firstname.lastname@example.org
You will be asked to provide the following details:
- The personal information you want to access;
- Where it is likely to be held;
- The date range of the information you wish to access
We will also need you to provide information that will help us confirm your identity. If we hold personal information about you, we will give you a copy of the information in an understandable format together with an explanation of why we hold and use it. Once we have all the information necessary to respond to your request we’ll provide your information to you within one month. This timeframe may be extended by up to two months if your request is particularly complex.
8.3 What to do if you’re not happy
In the first instance, please talk to us directly using the contact information above so we can try to resolve any problem or query. You also have the right to contact the Information Commissions Office (ICO) if you have any questions about Data Protection. You can contact them using their help line 0303 123 113 or at www.ico.org.uk.
9. Changes to this Privacy Notice
We’ll amend this privacy notice from time to time to ensure it remains up to date and reflects how and why we use your personal data and new legal requirements. Please visit our website to keep up to date with any changes. The current version will always be posted on our website.