Privacy Policy
How Corpus Christi, St. Justus and St. Peter's Parish collects, uses, and protects your personal data in accordance with UK GDPR and the Data Protection Act 2018.
About This Policy
This Privacy Policy explains how Corpus Christi, St. Justus and St. Peter's Parish ("the Parish", "we", "us") collects, uses, stores, and protects your personal data when you use our website or interact with our services. We are committed to handling your information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
1. Who We Are
Corpus Christi, St. Justus and St. Peter's Parish is a Roman Catholic parish within the Diocese of Southwark, serving the communities of Tonbridge, Hadlow, and Southborough.
| Parish Name | Corpus Christi, St. Justus and St. Peter's Parish, Tonbridge |
|---|---|
| Data Controller | The Parish Priest, Fr. Philip, acting on behalf of the Parish |
| Email Address | tonbridge@rcaos.org.uk |
| Telephone | 01732 353984 |
| Diocese | Roman Catholic Diocese of Southwark |
2. What Personal Data We Collect
We collect personal data in several contexts across our website and parish activities.
2.1 General Website Visitors
- IP address and browser type (collected automatically via server logs)
- Pages visited and time spent on the website
- Device type and operating system
- Referring website or search engine
2.2 Contact Form Submissions
- Full name, email address, and telephone number (optional)
- The subject and content of your message
- Department you are contacting
2.3 Newsletter Subscribers
- Full name and email address
- Date of subscription and consent record
- Unsubscribe date (where applicable)
2.4 Fisher Hall Bookings
- Full name and contact details (email, telephone)
- Organisation name (if applicable), event type, date, time, and expected guest numbers
- Payment information — processed securely via SumUp; we do not store card details
- Booking history and cancellation records
2.5 Online Donations
- Full name, email address, and postal address (required for Gift Aid declarations)
- Donation amount, frequency, and designated fund
- Gift Aid declaration status and eligibility
- Payment details — processed securely via SumUp; we do not store card details
- Donation history and tax receipt records
2.6 Sacramental and Pastoral Services
- Names, dates of birth, and contact details of individuals receiving sacraments
- Sponsor or godparent details; marriage preparation records
- Bereavement support group participation (where consent is given)
3. Legal Basis for Processing (UK GDPR)
Under the UK GDPR, we must have a lawful basis for processing your personal data. We rely on the following bases:
| Legal Basis | Description | Applies To |
|---|---|---|
| Consent | You have freely given explicit consent to receive communications or have your data processed in a specific way | Newsletter subscription; marketing communications |
| Contractual Necessity | Processing is necessary to fulfil a contract with you or take pre-contractual steps | Fisher Hall bookings; donation processing; refund requests |
| Legitimate Interests | Processing is necessary for the Parish's legitimate interests, balanced against your rights | Website analytics; fraud prevention; service improvement |
| Legal Obligation | Processing is required by law, including financial and tax record-keeping obligations | Gift Aid records; financial transaction logs; safeguarding compliance |
| Vital Interests | Processing is necessary to protect someone's life or safety | Safeguarding and child protection matters |
4. How We Use Your Personal Data
We use your personal data only for the purposes for which it was collected, or for compatible purposes where you would reasonably expect us to do so.
4.1 Website Operation & Improvement
- To monitor performance, detect errors, and improve usability
- To protect the website against abuse, spam, and security threats
4.2 Communications
- To respond to enquiries submitted through our contact form
- To send our weekly parish newsletter (where consent has been given)
- To send booking confirmations, reminders, and receipts
- To send donation receipts and annual Gift Aid tax acknowledgements
4.3 Fisher Hall Booking Management
- To process and confirm hall bookings and associated payments
- To enforce our cancellation policy and process eligible refunds
- To maintain an audit trail of all bookings for financial and legal purposes
- To send automated reminders (7 days and 1 day before your booking)
4.4 Donation Processing
- To process one-time and recurring donations securely
- To issue donation receipts and tax acknowledgement letters
- To manage Gift Aid declarations and report to HMRC as required
- To maintain financial records as required by UK law (minimum 6 years)
4.5 Pastoral and Sacramental Ministry
- To support the administration of sacraments and record their completion
- To maintain registers required by Canon Law and civil law
- To support bereavement and pastoral care services
5. Security Measures & Data Protection
We take the security of your personal data extremely seriously. We have implemented the following technical and organisational measures:
5.1 Infrastructure Security
- All website traffic is encrypted using HTTPS
- Daily automated backups are maintained with off-site storage
5.2 Application Security
- Industry-standard HTTP security headers protect against common web vulnerabilities
- Rate limiting protects against brute-force and denial-of-service attacks
- All user inputs are validated and sanitised to prevent malicious data entry
- Protection against cross-site request forgery is implemented across all forms
- Strict security policies prevent unauthorised script execution
- All software components are regularly reviewed for known vulnerabilities
5.3 Payment Security
- All payments are processed by SumUp, a PCI DSS Level 1 compliant payment processor — the highest level of payment security certification
- We do not store, transmit, or log any card details or payment credentials on our own servers
- All payment transactions use tokenised processing — card data never passes through our systems
- Payment webhook endpoints are protected by cryptographic signature verification to prevent tampering
- All payment flows are handled exclusively via encrypted connections to SumUp's API
All payment-related features are subject to mandatory professional penetration testing before deployment. No payment feature is made available publicly without passing penetration testing.
5.4 Access Controls
- Access to the admin portal and parish data is restricted to authorised staff only
- Access controls ensure staff can only access data relevant to their role
- All administrative logins are protected by strong passwords and industry-standard authentication
- All admin actions are logged in a secure audit trail for accountability
- Staff access is reviewed periodically and revoked promptly upon departure
5.5 Organisational Measures
- Parish staff who handle personal data are given appropriate data protection training
- Data is shared with third-party processors only where a Data Processing Agreement (DPA) is in place
- A Data Protection Impact Assessment (DPIA) is conducted for any new high-risk processing activity
6. Who We Share Your Data With
We do not sell, rent, or trade your personal data. We share your data only as necessary and only with trusted parties as described below.
| Third Party | Purpose | Safeguard |
|---|---|---|
| SumUp | Secure payment processing for bookings and donations | PCI DSS Level 1 certified; DPA in place |
| Email service provider | Transactional emails (receipts, confirmations) | GDPR-compliant; DPA in place |
| HMRC | Gift Aid claims on qualifying donations | Legal obligation; only where consent given |
| Diocese of Southwark | Pastoral and administrative oversight | Diocesan data sharing agreement applies |
7. How Long We Keep Your Data
We retain personal data only for as long as is necessary for the purpose it was collected, or as required by law.
| Data Type | Retention Period | Reason |
|---|---|---|
| Contact form enquiries | 2 years | To enable follow-up and track pastoral needs |
| Newsletter subscriber data | Until unsubscribed + 1 year | To maintain consent records |
| Fisher Hall booking records | 6 years | UK financial record-keeping legal requirement |
| Donation and payment records | 6 years | HMRC requirements and Gift Aid compliance |
| Gift Aid declarations | 6 years after last donation | HMRC statutory requirement |
| Sacramental registers | Permanent | Canon Law requirement; civil registration |
| Safeguarding records | As per Diocese policy | Typically until the individual turns 25 or longer |
| Website access logs | 90 days | Security monitoring and abuse investigation |
8. Your Rights Under UK GDPR
As a data subject, you have a number of rights under the UK GDPR. We are committed to facilitating these rights promptly and free of charge (subject to any applicable exemptions).
8.1 Right to be Informed
You have the right to be informed about how we collect and use your personal data. This Privacy Policy fulfils that obligation.
8.2 Right of Access (Subject Access Request)
You have the right to request a copy of the personal data we hold about you. We will respond within one calendar month.
8.3 Right to Rectification
If any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct it.
8.4 Right to Erasure ("Right to be Forgotten")
You may request deletion of your personal data where there is no compelling reason for us to continue processing it. This right does not apply where we are required to retain data by law (e.g., financial records, safeguarding records, canonical registers).
8.5 Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as while a dispute about its accuracy is being resolved.
8.6 Right to Data Portability
Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your data in a structured, machine-readable format.
8.7 Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes. Objections to newsletter communications will always be honoured without requiring a reason.
8.8 Right to Withdraw Consent
Where we process your data on the basis of your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Exercising Your Rights
To exercise any of your rights, please contact us by email at tonbridge@rcaos.org.uk or by telephone on 01732 353984.
We will respond within one calendar month. We may ask you to verify your identity before processing your request. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
9. Cookies & Tracking Technologies
Our website uses cookies and similar technologies to improve your browsing experience, analyse website usage, and ensure the website functions correctly.
| Cookie Type | Consent Required? | Purpose |
|---|---|---|
| Essential / Strictly Necessary | No — required for operation | Authentication, session management, security tokens. The website cannot function without these. |
| Functional | No — legitimate interests | User preferences such as language or accessibility settings. |
| Analytics | Yes | We use analytics to understand how visitors use the website. No personally identifiable data is shared without consent. |
| Payment | Yes (implicit in transaction) | Set by SumUp during checkout to enable secure payment. We have no control over these cookies. |
You can manage your cookie preferences at any time through your browser settings.
10. Children's Privacy & Safeguarding
Our website is not directed at children under the age of 13, and we do not knowingly collect personal data directly from children without parental or guardian consent.
Where personal data relating to children is collected in connection with sacramental programmes (such as First Holy Communion or Confirmation), consent is obtained from a parent or guardian, and the data is handled in accordance with our Safeguarding Policy and the Diocese of Southwark's safeguarding framework.
All parish staff and volunteers who work with children and vulnerable adults have undergone appropriate DBS (Disclosure and Barring Service) checks. Our Parish Safeguarding Representative can be contacted via the parish office.
11. International Data Transfers
Where data is processed by third-party providers whose infrastructure may be located outside the UK or the EEA, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs), adequacy decisions, or equivalent certifications.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Reviewed" date at the top of this document
- Post a notice on the website homepage for 30 days
- Notify newsletter subscribers by email where the changes are significant
13. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please contact us:
- Email: tonbridge@rcaos.org.uk
- Telephone: 01732 353984
- Diocese: Roman Catholic Diocese of Southwark
If you are not satisfied with our response, you have the right to raise the matter with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
Questions about your data?
Contact the parish office and we will respond to your request within one calendar month.