Join

Privacy Policy for Visitors and Customers

What information do we hold about you and why?

*If you are a member or a donor, please see our Supporter Privacy Policy.

Purchasing a product from our gift shops or online

When you purchase a product from one of our gift shops or online, we will collect the following information from you:

  • Your payment card details (if paying by credit or debit card) to pay for the products or services ordered
  • Your email address (for online purchases only) – to send you a copy of your order confirmation
  • Your telephone number (for online purchases only) – to contact you regarding your order

Our legal grounds in relation to this processing is contract, in that the processing is necessary for the performance of a contract (the provision of the product or service).

If you have registered for a My Trust account and are logged in when you purchase a product, we will retain a record of the transaction on your record. Our legal grounds in relation to this processing is our legitimate interests because we think you would expect us to retain this information in order to better understand and support your relationship with us.

If we use your personal information to tailor our communications to you, for example by letting you know that we have certain offers available on similar products or services, we will only do so because you have told us you would like to receive these communications. Our legal grounds in relation to this processing is your consent and you have the right to withdraw your consent at any time.

Booking an event (including corporate events and weddings) or other activity*

*For holiday accommodation bookings, please see our Property Occupier Privacy Policy.

When you book an event or other activity with us, either online or directly with a property, we will collect the following information from you:

  • Your full name and the names of anyone participating in the event/activity – to manage the booking
  • Your date of birth – only when this is required for a particular event/activity (e.g. entry to a race)
  • Your email address – to send you a copy of your booking
  • Your telephone number – to contact you regarding your booking
  • Your payment card details (if paying by credit or debit card) to pay for the booking

We may also receive your information from third party events booking sites.

Our legal grounds in relation to this processing is contract, in that the processing is necessary for the performance of a contract (the provision of the service/activity).

We will retain a record of the transaction on your record. Our legal grounds in relation to this processing is our legitimate interests because we think you would expect us to retain this information in order to better understand and support your relationship with us.

If we use your personal information to tailor our communications to you, for example by letting you know that we have certain offers available on similar products or services, we will only do so because you have told us you would like to receive these communications. Our legal grounds in relation to this processing is your consent and you have the right to withdraw your consent at any time.

Please see our full Privacy Policy for Event Participants.

Travel trade

When you contact us regarding travel trade, we will collect the following information from you:

  • Your full name – to manage your enquiry and travel trade arrangements
  • Your email address – to contact you regarding your enquiry and travel trade arrangements
  • Your telephone number – as above
  • Your payment details – to pay for the travel trade arrangements

We may also receive your information from third party booking agents.

Our legal grounds in relation to this processing is contract, in that the processing is necessary for the performance of a contract (the provision of the service/travel trade activity).

If you apply for credit facilities with us, we will collect your name, address, telephone number and email address. We may also seek references from third parties. This is for the purposes of considering your application and, if successful, for supporting your trade account with us. If successful, we will retain your data for 6 years from the closure of the account. If unsuccessful, your data will be destroyed after 6 months.

We will retain records of your travel trade arrangements with us for a period of 6 years after your last booking. Our legal grounds in relation to this processing is legal obligation in that we are required to retain summary transaction information in line with the Charities and Trustee Investment (Scotland) Act 2005 and Finance Acts of 2005 and 2010; and also our legitimate interests, in that we consider it necessary for supporting our relationship with you.

Registering for a My Trust account

When you register for a My Trust account on our website, we will collect the following information from you:

  • Your full name – to set up your online account with us
  • Your email address – to enable you to log in to your account online
  • Your chosen account password – to enable you to log in to your account online
  • Your postcode – to enable us to link your account to a new customer record

Our legal grounds in relation to this processing are our legitimate interests, in that we consider it necessary to process your information to provide you with an online account and to ensure that we can link your account to a new customer record.

When we use your email address to send you other communications about the Trust, we do so because you have told us that you would like to receive these communications. Our legal grounds in relation to this processing is your consent and you have the right to withdraw your consent at any time.

Visitor surveys

When you visit a property or place we may invite you to complete a feedback survey. Completion of surveys will be entirely optional, and we will tell you every time what the purpose of the survey is and how we will process your data. Our legal grounds for this processing are our legitimate interests so we can understand how we are performing and where we can improve.

CCTV (Closed Circuit Television)

We operate CCTV/video surveillance cameras at some of our properties. CCTV is used for maintaining the security of property and premises; for preventing and investigating crime; and for detecting, apprehending and prosecuting offenders.

If CCTV is in operation, appropriate signage will be in place and the operating procedures will be regularly audited by the property manager to ensure compliance with relevant standards and legislation.

Where we host a CCTV system for which another organisation is responsible, there will be an agreement in place to cover:

  • agreed responsibilities for compliance with data protection law
  • named contacts responsible for the operation of the CCTV system in each organisation
  • a procedure for handling requests for access to CCTV footage

Contacting us with enquiries

When you contact us with an enquiry, we will collect the following information from you:

  • Your name – to effectively process your enquiry
  • Your preferred contact details to respond to your enquiry
  • The details of your enquiry – to respond to your enquiry
  • We may also ask for your email address and postcode, to help identify you and retain a record of your enquiry on your record, but this is optional.

When we process information about you to respond to comments, questions and queries you have raised with us, our legal grounds for processing are our legitimate interests in that it is necessary to process your information to effectively respond to your enquiry and manage any additional enquiries in future.

If you call us with a general enquiry, we will use a third party to handle your call. They will collect the same categories of information as highlighted above and will record all calls to verify our quality of customer service. This is for the purposes of improving our customer service and enabling us to follow up when problems arise.

Our eNewsletters

If you subscribe to our eNewsletter, we will collect your name, email address and postcode. This is necessary to deliver the newsletter to you and link your newsletter subscription to your customer record.

We need your consent to provide this service. This means you have the right to withdraw your consent at any time. If you wish to unsubscribe you can do so by clicking on the unsubscribe link at the end of any eNewsletter you have received from us.

We will also send service eNewsletters so we can keep members up to date about their membership and services that relate to their membership. You can withdraw from these emails by unsubscribing. If you wish to unsubscribe you can do so by clicking on the unsubscribe link at the end of any eNewsletter you have received from us.

We use a third-party provider to deliver our eNewsletter. We gather statistics around email opening and clicks using industry standard technologies to help us monitor and improve our eNewsletter.

Photography and filming

If we plan to take photographs or film individuals or small groups at an event you have booked, we will ask for your consent to take and use these images, before doing so. You have a right to withdraw your consent at any time, but you should note that it might be difficult to remove images if they have been published.

If we plan to take photographs or film large events, we will inform you that photography or filming is due to take place at the point of booking and will ensure there is clear signage on the day. If you would prefer not to be included in any images, or do not want your image to be published, please contact us and we will find ways to manage this carefully on the day.

Who will have access to your data and who will we share it with?

Access to your personal data will be restricted to Trust employees and volunteers on a need-to-know basis only. Access will be provided for the purposes of supporting your customer experience with us. Access to CCTV images is restricted to authorised members of staff for the purposes of ensuring the equipment is in good working order and images are being recorded accurately.

We will never sell your data to third parties.

Where necessary or required, CCTV images may be shared with CCTV service providers, security organisations, and individuals or organisations making an enquiry under the appropriate sections of the Data Protection Act 2018. We will only provide access when we consider there to be a lawful basis for doing so and we have documented this.

We will share your information with third parties to support your customer experience and relationship with us. To make your interactions with us as efficient as possible we will share your information with:

  • Our call handling company – for the purposes of handling telephone enquiries
  • Our website host – for the purposes of managing your My Trust account and enquiries submitted through our website
  • Our affiliate marketing partner for the purposes of recording, validating and reporting on successful transactions after clicking on a Trust advertisement on another website. Please refer to their Privacy Policy for further information.
  • Our payments processors – for the purposes of processing secure card payments at tills, contactless points and online. Please refer to the Privacy Policies of Sage Pay, Worldpay and Verifone for further information.
  • Our electronic newsletter provider – for the purposes of delivering our newsletter and gathering statistics around email opening and clicks to help us monitor and improve content
  • Our core systems provider – for the purposes of maintaining accurate customer records
  • Our survey provider – for the purposes of collating and reporting on any feedback you provide
  • Our events booking providers – for the purposes of facilitating bookings and informing you of any changes to bookings
  • Our data quality partners, including postcode lookup agencies and address verification providers – for the purposes of ensuring we collect and process accurate address data

Where these third parties are acting as data controllers, they are required to handle your personal data in accordance with all applicable data protection laws. For further information about how they do this, please refer to their privacy policies.

Where the third parties are acting as data processors, processing personal data on behalf of the Trust, we have contracts in place with these third parties which require them to process your personal data on our instructions only. They will not process your personal data for any other purpose and they will retain it securely.

In some cases, your data will be processed outside of the UK. Where this is the case, we will ensure that there are adequate safeguards in place (for example, the use of Standard Contractual Clauses and International Data Transfer Agreements) for the protection of your personal data.

How long will we keep your personal data?

  • Information held on your record (including contact details and enquiries): 6 years from the end of our financial year
  • Recorded calls: 3 months
  • Email address and password for My Trust account: held for as long as the account exists
  • Credit/Debit Card payments: held until the transaction is successfully completed
  • Bank details (account number and sort code) where a regular Direct Debit is arranged: 6 years from the end of our financial year during which the Direct Debit came to an end
  • CCTV images: one calendar month, unless a crime or incident has been reported and the images are to be retained in line with the investigation. Also, if we receive a request for access to CCTV images, a copy of the images provided will be retained for 2 years.
  • Photographs/video footage: permanently unless you ask us to delete your information