Privacy Policy
Last Updated: 5 September 2026South London Acro (“we”, “our”, “us”) is committed to protecting your personal information and respecting your privacy. This Privacy Policy explains how we collect, use, and share information when you visit our website https://www.southlondonacro.co.uk, join our mailing list, book events, or create a member account.
Who We Are
South London Acro is a community acro organisation based in London, United Kingdom.
For any privacy-related questions, please contact us at: kwame@acrojams.co.uk
Information We Collect
We may collect the following information when you interact with us:
- Mailing list sign-ups: name, email address.
- Event bookings and forms: name, contact details, and information you provide in booking forms.
- Member accounts: if you create an account, your name, email address, membership status and your booking history.
- Community features: anything you post to our community noticeboard or suggestions box, and your votes and reactions.
- Safeguarding reports: if you report a concern, whatever you choose to tell us.
- Payments: handled securely by Stripe. We do not store card details.
- Emails and enquiries: any information you send us by email.
- Technical data: basic server logs (e.g. IP address, browser type, time of visit).
How We Use Information
We use personal data to:
- Send newsletters and updates (with your consent).
- Process event bookings, memberships and payments.
- Run member accounts and community features.
- Respond to enquiries and to safeguarding concerns.
- Maintain the security and performance of our website.
Legal Basis for Processing
Under UK GDPR, we rely on the following legal bases:
- Consent – for mailing list subscriptions.
- Contract – to process event bookings, memberships and payments.
- Legitimate interest – to respond to enquiries, run community features, and maintain website security.
- Legal obligation and vital interests – where we must act on a safeguarding concern.
Safeguarding Records
If you report a safeguarding concern, we keep a record of it so that it can be acted on and followed up. These records may include sensitive information, are visible only to our safeguarding lead, and are kept separately from our general records. We will not share them further without your consent unless we are required to do so by law or to protect someone from immediate harm.
Service Providers and Data Sharing
We share data with trusted third-party service providers who help us run our website, manage our community, and process bookings and payments:
- Webstudio – builds and delivers our public website.
- Netlify – hosts our admin portal.
- Supabase – our database and file storage: event details, bookings, memberships, member accounts, community posts and safeguarding records.
- Fillout – booking form submissions.
- Stripe – payment processing. Stripe is PCI-DSS compliant and encrypts payment data. We do not store card details.
- Resend – sends our confirmation and reminder emails.
Our database and file storage are hosted by Supabase in London, United Kingdom (AWS eu-west-2), so your account, booking, membership and community data stays in the UK. Some of our other service providers use sub-processors who may be located outside the UK/EU. We require all such parties to abide by data protection laws, to enter into appropriate contracts, and to implement technical and organisational measures to protect personal data.
We do not sell or trade your personal data.
Data Retention
- Mailing list – until you unsubscribe.
- Bookings and payment records – up to 6 years (for tax and accounting).
- Member accounts – until you close your account. Where a record must be kept (for example a booking), we remove your name and contact details from it rather than deleting the record.
- Safeguarding records – kept for as long as necessary to act on the concern and to meet our safeguarding responsibilities.
- General enquiries – usually deleted after 2 years.
- Server logs – typically deleted after 30 days.
Cookies
Our public website does not set cookies directly. Our member and admin portal sets an essential cookie to keep you signed in. Some third-party services (such as Stripe during checkout) may place essential cookies required for security and functionality. We do not use analytics or advertising cookies.
Data Security
We use SSL encryption and limit access to personal data to the people who need it. Access to member and safeguarding data is restricted by role. Our third-party providers are GDPR compliant and follow industry standards for security.
Your Rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data.
- Withdraw consent at any time (for newsletters).
- Object to or restrict our processing in certain circumstances.
- Request a copy of your data in a portable format.
To exercise these rights, please contact kwame@acrojams.co.uk.
You also have the right to complain to the Information Commissioner’s Office (ICO) if you believe we are mishandling your data.
Children
Our website and services are not directed to children under 16, and we do not knowingly collect their personal data.
Data Breaches
In the unlikely event of a personal data breach, we will assess the impact and, where legally required, notify the ICO within 72 hours and affected individuals without undue delay.
Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be available on this page, with the date of the last update shown at the top.