English Heritage, including our subsidiary, English Heritage Trading Limited, (also referred to as “we, “us” or “our”) is fully committed to the protection of your rights and your privacy.
English Heritage cares for over 400 historic buildings, monuments and sites – from world-famous prehistoric sites to grand medieval castles, from Roman forts on the edges of the empire to a Cold War bunker. Through these, we bring the story of England to life for over 10 million people each year. We are a charity, no. 1140351, and a company, no. 07447221.
English Heritage Trading Limited (Registered company no. 02970369) is a wholly-owned subsidiary that carries out a range of commercial trading activities to generate income for English Heritage, including retail, catering, and sponsorship.
Our Privacy Promise
We are committed to protecting the privacy of our supporters. We take your privacy seriously and treat all the information you give us with great care.
We value and respect all the people whose support helps us to care for over 400 historic sites across the country and to keep the story of England alive for future generations.
We are recorded on the ICO Data Protection Register under registration number ZA111846.
English Heritage Trust
100 Wood Street
Registered Charity 1140351
- to be clear about why we need to collect your personal information and what we are going to use it for
- to make it easy for you to tell us how you would like us to keep in touch
- to only collect the information we need to make sure we deliver the best service
- to never sell your personal information, and never share it with other organisations for their own marketing purposes
- to take good care of your personal information, and make sure it is up to date, safe and secure at all times
- to make sure that any suppliers or partners who carry out work on our behalf meet the same high standards that we adhere to when handling your personal information.
We collect information about members, visitors to our historic sites, supporters, customers, website visitors, owners, tenants and other site stakeholders such as neighbours and key-holders. We do this both electronically and in paper format.
In addition, we also collect details automatically about the pages you visit on our website. Please see our Cookies Policy below for more information.
In choosing to share your personal information with us, you will be agreeing to our collection and use of your information as described in this policy.
We use the information you share with us to:
- make sure you receive the product, service or information you have requested or bought
- carry out reasonable administration of your membership, donations, bookings, and volunteering
- manage our sites effectively and to deliver community involvement
- to keep in touch with you in the way that you want us to
- to better understand our supporters so that we can personalise and improve the services we offer.
For details of how we do this, please see the full policy below.
We will need to make changes to this policy from time to time, to make sure that we are always providing you with the latest information about what is happening to your personal information. The current version will always be posted on our website.
This policy was last updated on 29 April 2019.
What information do we collect and how?
We collect personal information about you that helps us to deliver and improve our services. This includes:
- name and address
- email address and telephone numbers
- date of birth
- payment information such as credit card and bank details
- how you would like to hear from us
- English Heritage historic sites you have visited
- details of purchases, membership, Gift Aid Declarations, donations and gifts in your will
- details of job applications and your volunteering activity
- enquiries and feedback, including via web forms, call centre, emails and webchat
- interaction with our digital channels, including the website, members' area, public wifi, and social media pages (inclusive of any log in via a social media account.
Under our membership scheme we also ask for details of your children who you would like to include on the membership. We use this information to better understand how to provide the best service to your family in terms of offers and events, and we will not contact your children directly.
If you have provided details for someone else - for example, by buying a gift for them - we will not contact that person until they have been given the opportunity to let us know their communication preferences.
If you have contacted us on behalf of an organisation - for example, making an Educational Booking or a Travel Trade enquiry - we will also store details of individuals in their professional capacity.
When visiting our website, we also collect information about your IP address and the pages you visit. This helps us to understand which areas of our website are most useful to our supporters and make improvements. This does not tell us who you are and where you live until you choose to provide us with that information. Please see our Cookies Policy below for more information.
Some of our sites are protected by CCTV and you may be recorded when you visit them. We use CCTV to help provide a safe environment for our members, visitors and staff and to help detect and prevent crime. The systems are operated in accordance with our Security Manual and will only be viewed when necessary. We use signs to alert people that they are in an area where CCTV surveillance is being carried out.
We may use a number of sources to carry out our work, including printed and online newspapers and publications, charity and company websites, and the websites of organisations similar to us. From time to time we may use specialist companies to help us identify individuals who we think might be interested in supporting us and the work we do. This will only be done when individuals give permission to the relevant third party organisations to share the data they hold on them, or if the data is already publicly available.
What do we do with your information?
MEMBERSHIP AND FINANCIAL PROCESSING
We will make sure that you receive the product or service you have requested, process any payments and send you information relating to that service.
If you have joined as a Member, this will include sending you confirmation of your purchase and membership materials such as membership cards, information on how to use your membership, regular magazines, handbook and email newsletters. We will also send you information about membership renewal and information relating to your Direct Debit payments.
If you have donated money or objects, this will include thanking you for your support, letting you know how your contribution has helped us, managing the custody of our collection, and carrying out due diligence to meet our compliance obligations.
If you have been recorded as part of an oral history project, we will only use your information with your consent. If you are a tenant of a let estate, we will use your information to fulfil our contract with you and to keep in contact about issues or activities relating to your lease.
If you live locally to an English Heritage property, we may use your contact details to keep you up to date with local activities and to provide you with the opportunity to be involved. We will also do our best to keep your information up to date. This includes monitoring returned mail to let us know if you no longer live at the addres we hold for you. In addition, we use information from the Royal Mail's National Change of Address database, the telephone preference service, the mailing preference service, the Bereavement Register and other similar suppression lists to make sure we do not send communications to the wrong place or person.
Please do let us know if your details have changed.
MARKETING AND COMMUNICATIONS
Receiving marketing information from English Heritage will always be your choice, and you can choose how you would like to receive that information from us.
You can also change your mind at any time, and we will keep your preferences up to date. If you would like to update how you would like to hear from us, please use our Preferences Form.
We limit the number of marketing communications we send to make sure we are not sending you too much.
We will only contact you for marketing purposes by telephone or text message (SMS) if you have told us we can.
We will only contact you by email for marketing purposes if you have told us you would like to hear from us this way, or to let you know about services you have previously bought. Every email will have a link to help you unsubscribe if you wish to stop this.
We may occasionally contact you by post if you have told us you would like to hear from us this way.
English Heritage operates on a number of social media platforms, such as Facebook and Instagram, in accordance with their own terms and conditions. We may try to match your email address with your social media account so that we can tailor any advertising and reach you (and others like you) with relevant information about how you can support our cause. This data is always provided in an encrypted format. If you do not want to receive targeted advertising from us, please refer to the privacy settings and instructions provided by the social media site.
If you have applied to work for English Heritage, your personal information will only be processed for the purposes of recruitment, including processing your application and tracking recruitment statistics. You will not receive marketing communications, but you may receive job alerts by email if you have signed up to this service.
Volunteers are part of our collective movement to ensure the past is protected for future generations and the historic environment is understood, valued, cared for and enjoyed. If you volunteer with English Heritage then we will keep information about you to ensure we provide you with the best volunteer experience we can. This may include special category data about medical conditions.
USER SUPPORTER PROFILES
In addition to respecting your communication preferences, we know it is important to our supporters to use our resources in a responsible and cost effective way. For this reason we use automated profiling and targeting to help us understand our supporters and make sure that:
- our communications and services are relevant, personalised and interesting to you
- our services meet the needs of our supporters
- we only ask for further support and help from you if it is appropriate
- we use our resources responsibly and keep our costs down.
To do this we will analyse how you interact with us and use both geographic and demographic information to let you know what is happening in your local area and understand your interests.
If you have agreed that we can contact you we may also gather additional information about you from external sources - for example, updates to address and contact information - or publicly available information regarding your wealth, earnings, or employment. We may use this information to assess your capacity to support us and invite you to do so. If you would prefer that this did not happen simply let us know.
This analysis may be carried out by English Heritage or by third parties organisations working for us.
WHO WILL HAVE ACCESS TO MY INFORMATION?
We will never sell your personal information, and we never share it with other organisations for their own marketing purposes.
We will only share your personal information where:
- we are legally required to, or as a result of a lawful request by a governmental or law enforcement authority
- we have engaged a supplier or contractor to carry out services on our behalf, such as order fulfilment, sending our communications, supporting our systems, or carrying out research and analysis.
We only work with trusted suppliers who have agreed to treat your information as respectfully as we do and in accordance with data protection legislation.
How do we keep your information safe?
The security of your information is paramount to us. We use encryption for transfer of data and our networks are regularly monitored to ensure they remain secure.
We also regularly review our measures to ensure they are up to date and in line with latest developments, particularly when we are handling payment information.
If you have a password to allow access to certain parts of our website, you must keep that password safe and not share it with anyone or your personal information could be at risk.
Data that is transmitted via the internet or in email cannot be 100% secure. As a global environment, transmitting data to us may take place outside the European Economic Area.
We will take every reasonable precaution to keep your information safe but it cannot be guaranteed and so please be aware that any information you do transmit to us is at your own risk. Once we have received your information we will use our best effort to ensure its safety within our network, which sits within the European Economic Area.
We will keep your personal data for no longer than is necessary for the purposes for which it is processed, in accordance with our internal policies. How long personal information will be stored depends on the information in question and what it is being used for.
If we dispose of your information, it will always be done securely.
How to get in touch and understanding your rights
We want to ensure you remain in control of your personal data. Part of this is making sure you understand your legal rights, which are as follows:
- the right of access to a copy of the information we hold about you (this is known as a subject access request)
- the right to have your data erased (though this will not apply where it is necessary for us to continue to use the data for a lawful reason e.g. HMRC and Gift Aid auditing)
- the right to have inaccurate data rectified
- the right to object to your data being used for marketing or profiling
- the right to personal data (where technically feasible) that you have provided to us, which we process automatically on the basis of your consent or the performance of a contract. The information will be provided in a common electronic format.
Please bear in mind that there are exemptions to the rights above and though we will always try to respond to your requests there may be situations where we are unable to do so.
If you would like further advice or information on your rights, or wish to exercise them, please write to the Information Governance Manager (who is our Data Protection Officer) at English Heritage Trust, The Engine House, Fire Fly Avenue, Swindon, SN2 2EH or email firstname.lastname@example.org
You may wish to use our template subject access form which includes guidance on how to make your request.
If you are not happy with our response or you believe that your data protection or privacy rights have been infringed, you can complain to the UK Information Commissioner’s Office which regulates and enforces data protection law in the UK. Details of how to do this are available at the Information Commissioner’s Office website at www.ico.org.uk.
When we provide services, we want to make them easy, useful and reliable. Where services are delivered on the internet, this sometimes involves placing small amounts of information on your device - for example, computer or mobile phone. These include small files known as cookies. They cannot be used to identify you personally. These pieces of information are used to improve services for you through, for example:
- enabling a service to recognise your device so you don't have to give the same information several times during one task
- recognising that you may already have given a username and password so you don't need to do it for every web page requested
- measuring how many people are using services, so they can be made easier to use and there's enough capacity to ensure they are fast.
Third Party Cookies
To make it easy for you to use and share our website we embed features from other websites, such as Facebook, Twitter and TripAdvisor. Browsing the English Heritage website may place cookies from these third party websites on your computer. English Heritage have no control over these cookies - as a result, it is not always possible to list them and they are liable to change without notifying us.
We aim to conform to level Double-A of the World Wide Web Consortium (W3C) Web Content Accessibility Guidelines 2.0, which help make the web more user-friendly for all people.
While we strive to adhere to standards for accessibility and usability, there are areas we are still working on to improve, such as providing video and audio transcripts, audio captions and audio descriptions. If you have concerns or issues you wish to raise, please contact our customer services team at email@example.com.