Our Privacy Policy

Introduction

1.1 We are committed to safeguarding the privacy of our website visitors. In this policy we explain how we will treat your personal information.

1.2 This Privacy Policy was created on 2nd February 2026. The latest revision of this Privacy Policy was published on 23rd March 2026.

How we use your personal data

We collect and use personal data to operate our website, deliver our services and communicate with you.

We are required by law to identify a “Lawful Basis” for every way we use your personal data. The table below outlines what we collect, why we use it, and the legal justification for doing so.

Purpose and Activity
Website Performance: To monitor site health, security and fix bugs.

Type of Data
IP address, browser type, operating system and usage patterns.

Lawful Basis for Processing
Legitimate Interests: It is necessary for us to maintain a secure and functional website.

Purpose and Activity
Service Delivery: To process your purchases, manage memberships, bookings or donations.

Type of Data
Name, contact details, billing/shipping address and transaction history.

Lawful Basis for Processing
Performance of a Contract: We cannot fulfill your order or booking without this data.

Purpose and Activity
Direct Marketing: To send you our email newsletters and updates.

Type of Data
Name, job role and email address.

Lawful Basis for Processing
Consent: You have given us clear, affirmative permission to contact you.

Purpose and Activity
Enquiry Management: To respond to your questions, applications or feedback.

Type of Data
Name, contact information and the content of your message.

Lawful Basis for Processing
Legitimate Interests: To provide high-quality user support and manage our relationship with you.

Purpose and Activity
Website Analytics: To understand our audience and improve our services.

Type of Data
Data including approximate geographical location, referral source and page navigation. More information on data collected by Google Analytics is here.

Lawful Basis for Processing
Consent: We only collect this via optional cookies if you accept them.

Purpose and Activity
Safety & Compliance: To prevent fraud and meet our legal/regulatory duties.

Type of Data
Any relevant personal data held by us.

Lawful Basis for Processing
Legal Obligation: To comply with UK law or protect your vital interests.

2.1 To ensure our communications are relevant and respectful of your time, we use “profiling” techniques. This means we use our email platform to group you by category or analyse your interactions with our emails (such as which links you click or which projects you show interest in) to better understand your preferences. This allows us to send you content that matches your interests. We process this data under Legitimate Interests, as it helps us manage our charitable resources effectively and improves your experience with us by ensuring you receive only the most relevant updates.

2.2 When you visit our website, we may collect certain technical information. This data is primarily used in an aggregated or anonymised way to help us understand how our website is used and to support our efforts in keeping the site secure.

2.3 We operate a strict opt-in only policy for marketing. We will only send you updates about our work, events, or opportunities if you have actively requested them.

Withdrawal of Consent: You can stop receiving these communications at any time by clicking the ‘unsubscribe’ link in any email or by contacting us at hello@wearebluecabin.com.

2.3 If you submit personal information for publication on our website (e.g., in a public comment or a testimonial), we will use and display that information based on the specific permission you grant us at the time of submission.

2.4 We only keep your data for as long as is necessary to fulfill the purposes listed above. For specific details on how long we hold your information, please refer to Section 6 (Retaining and deleting personal data).

Providing your personal data to others

3. To support our operations and deliver our services, we share your personal data with selected third parties. We ensure that all third-party providers act as Data Processors, meaning they are legally bound to handle your data only according to our strict instructions and in compliance with data protection laws.

3.1 We may disclose your personal data to the following categories of service providers:

  • Email and newsletter providers: We use Mailchimp to distribute our newsletters and updates.
  • Analytic services: We use Google Analytics to help us understand website usage and improve our services.
  • Hosting and technical support: Our website is hosted by Siteground, and we may share data with technical support providers to ensure the security and reliability of our digital services.

3.2 We may disclose your personal information to third parties in the following circumstances:

  • Professional Advisers: To our lawyers, bankers, auditors or insurers when necessary for professional advice or to manage legal claims.
  • Legal Obligations: Where we are legally required to do so to comply with the law, a court order or a regulatory request.
  • Business Protection: To prevent fraud, mitigate credit risk or protect the rights and safety of our organisation and our users.

3.3 We will never sell your personal data to third parties. We will not supply your personal information to any third party for their own marketing purposes unless we have obtained your explicit, opt-in consent to do so.

3.4 If you choose to submit personal information for publication on our website (such as a comment or testimonial), that information will be accessible to the public. We handle this data based on the specific license or permission you grant us at the time of submission.

Disclosing personal information

We may share your personal data with trusted third parties where this is necessary to operate our organisation, comply with the law or protect our legitimate interests. We only disclose the minimum amount of information required for each purpose, and we require all third parties to handle your data securely and in accordance with data protection legislation.

4.1 We may disclose your personal data to:

  • our employees, freelancers and trustees where access is necessary for their roles
  • our professional advisers (such as legal, financial or HR advisers)
  • our insurers
  • our suppliers and subcontractors, including our website host (Siteground), technical support providers and other organisations that support the delivery of our services

All such recipients are required to keep your information confidential and to use it only for the purposes for which it was provided.

4.2 We may disclose your personal data where required to do so by law or where we believe such action is necessary to:

  • comply with a legal obligation or regulatory requirement
  • respond to a court order, lawful request or other legal process
  • support or protect our legal rights, including the prevention of fraud or misuse of our services
  • assist with the establishment, exercise or defence of legal claims

4.3 We may disclose your personal data where necessary to protect your vital interests or the vital interests of another person. This may include sharing information with safeguarding bodies, emergency services or relevant authorities.

4.4 Except as described in this policy, we will not share your personal data with third parties for their own purposes, and we will never sell your personal data.

International transfers of your personal data

We primarily store and process personal data within the UK or the European Economic Area (EEA). However, some of our service providers operate outside the UK/EEA, which means your personal data may be transferred internationally.

5.1 Where personal data is transferred to a country that does not have an adequacy decision from the UK Government, we ensure that appropriate safeguards are in place to protect your information. These may include:

  • UK International Data Transfer Agreements (IDTAs)
  • Standard Contractual Clauses (SCCs) with the UK Addendum
  • Other legally recognised safeguards approved under UK data protection law

These measures ensure that your personal data continues to be protected to a standard essentially equivalent to UK GDPR.

5.2 Some of the third‑party organisations we use may process data in the United States or other countries. This includes:

  • Mailchimp (email newsletters and communications)
  • Google Analytics (website analytics and performance data)
  • Other technical or cloud‑based service providers where relevant

Each provider is required to implement appropriate safeguards for international transfers and to process your data only in accordance with our instructions.

5.3 Any personal information you choose to publish on our website (for example, in comments or submissions intended for publication) may be accessible worldwide via the internet. We cannot control how such information is used by others.

5.4 By using our website and services, you acknowledge that your personal data may be transferred outside the UK/EEA in accordance with the safeguards described in this section.

Retaining and deleting personal data

6.1 We will not keep your personal data for longer than is necessary. Retention periods vary depending on the type of information and the purpose for which it is processed. When data is no longer required, it will be securely deleted or anonymised.

6.2 We may retain your personal data for the following purposes:

  • Email newsletters and updates: Personal data (such as your name and email address) is retained until you unsubscribe or withdraw your consent, after which it may be kept for a short period to ensure we do not contact you again in error.
  • Enquiries, applications and submissions: Personal data provided through job applications or freelance enquiries is retained only for as long as necessary to process your request and in line with our internal retention schedules.
  • Transaction records: Personal data relating to purchases, bookings or donations may be retained for up to seven years to comply with financial, accounting and audit obligations.

6.3 We may retain personal data for longer where necessary to:

  • comply with a legal obligation
  • establish, exercise or defend legal claims
  • meet safeguarding responsibilities
  • protect your vital interests or the vital interests of another person

6.4 You may request that we delete your personal data at any time. We will comply with such requests unless we are required to retain certain information for legal, regulatory or safeguarding reasons. Where deletion is not possible, we will explain the reason and, where appropriate, restrict further processing.

Security of personal information

We take the security of your personal data seriously and use appropriate technical and organisational measures to protect it from loss, misuse, unauthorised access, disclosure, alteration or destruction.

7.1 We implement a range of safeguards designed to keep your information secure, including:

  • secure servers protected by passwords, firewalls and access controls
  • encryption and secure transfer methods where appropriate
  • regular monitoring, testing and review of our systems and security practices
  • limiting access to personal data to staff, trustees and suppliers who need it to perform their roles

All individuals with access to personal data are required to keep it confidential and to handle it in line with our policies and data protection obligations.

7.2 Personal data is stored on secure servers operated by us or by trusted third‑party providers acting on our behalf. This may include cloud‑based storage solutions that meet recognised security standards.

7.3 While we take steps to protect your information, you acknowledge that the transmission of data over the internet can never be completely secure. We cannot guarantee the security of information transmitted to or from our website, and you do so at your own risk.

7.4 If you believe your personal data may have been compromised, or if you have concerns about how we handle your information, please contact us using the details in Section 12.

Amendments

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements or the way we operate. Any updates will be published on this page, and the “last updated” date at the top of the policy will be amended accordingly.

8.1 Where changes are significant, we may also notify you directly by email or through a notice on our website. We encourage you to review this policy periodically to ensure you remain informed about how we collect, use and protect your personal data.

8.2 Your continued use of our website and services following any updates to this policy will be taken as acceptance of the revised terms.

Your rights / access to your information and correction

You can exercise your rights under UK data protection law at any time by contacting us using the details in Section 12.

9.1 You have the right to:

  • Access your personal data: You can request a copy of the personal information we hold about you.
  • Correct inaccurate or incomplete data: You can ask us to update or amend any information that is incorrect or out of date.
  • Request deletion: You can ask us to delete your personal data where there is no lawful reason for us to continue processing it.
  • Restrict processing: You can ask us to limit how we use your personal data in certain circumstances.
  • Object to processing: You can object to our processing of your personal data where we rely on legitimate interests or where your data is used for direct marketing.
  • Data portability: You can request that we provide your personal data in a structured, commonly used and machine‑readable format, or that we transfer it to another organisation where technically feasible.
  • Withdraw consent: Where we rely on your consent (for example, for email newsletters), you can withdraw this at any time. This will not affect the lawfulness of processing carried out before consent was withdrawn.

9.2 If you wish to exercise any of these rights, please contact us at hello@wearebluecabin.com. We may need to verify your identity before responding to your request. This helps us protect your information.

9.3 We aim to respond to all valid requests within one month. If your request is particularly complex, we may extend this period by up to two further months, and we will let you know if this is the case.

9.4 We may refuse a request, or charge a reasonable fee, only where a request is manifestly unfounded or excessive. If we cannot comply with your request, we will explain the reason.

9.5 Please let us know if any of the personal information we hold about you needs to be corrected or updated.

Third party websites

10.1 Our websites include hyperlinks to, and details of, third party websites. These links are provided for your convenience and information only.

10.2 We have no control over, and are not responsible for, the privacy policies, content and security of third party websites. If you follow a link to any other websites, we encourage you to read the privacy policy of that website.

10.3 This privacy policy only applies to our websites and we are not responsible for the privacy policies that govern third party websites even where we have provided links to them.

Cookies

11.1 Our website uses cookies to ensure a good user experience and to help us understand how people use it.

11.1 Some cookies are essential for the websites to function. Others (such as analytics cookies) are optional and help us improve the site. When you first visit our websites, you can choose whether to allow optional cookies. You can change your cookie settings at any time through your browser.

11.2 We use Google Analytics to collect anonymous information about how visitors use our website. Google may collect your IP address as part of this service.

Our details

12.1 This website is owned and operated by Blue Cabin.

12.2 Blue Cabin is a Charity Incorporated Organisation whose charity number is 1195152.

12.3 Our principal place of business is at 13 Brighton Gardens, Gateshead, NE8 4SN.

12.4 You can contact us:
(a) by post, to the postal address given above;
(b) by email – hello@wearebluecabin.com

12.5 Blue Cabin is registered with the Information Commissioner’s Office (ICO). Our registration number is ZB005531.

12.6 Siteground is the company that we use to host our website. Their privacy policy can be read here https://www.siteground.co.uk/privacy.html

12.7 Mailchimp is the service we use to send out regular newsletters and e-communications. Their privacy policy can be read here https://mailchimp.com/legal/privacy/

12.8 Google Analytics is the service we use to analyse the traffic to and user behaviour whilst visiting our website. Their privacy policy can be read here http://policies.google.com/privacy?hl=en

12.9 If you have any questions about this Privacy Policy or how we handle your personal data, please contact our Data Protection Lead at hello@wearebluecabin.com.

Complaints

13.1 If you wish to make a complaint about us or the treatment of your data, please contact us in the first instance using the contact details in Section 12 (above) or elsewhere on our site.

13.2 If you are not satisfied with our response, or you prefer to raise the matter directly, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection:

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
www.ico.org.uk