Who we are
York City & District Society of Model Engineers Limited (the “Society”, “we”, “us”) is the controller of the personal information described in this notice. Our registered number is 26478R and our registered office is Hill House, Stocks Hill, Huggate, York, YO42 1YQ.
For privacy questions or to exercise a data protection right, email chairman@yorkmodelengineers.co.uk. General enquiries may be sent to secretary@yorkmodelengineers.co.uk.
Information we collect
Members and applicants
- Identity and contact details, including name, title, email address, telephone number, postal or billing address and, where needed, date or month and year of birth.
- Membership information, including membership status, Society role, rules agreement and account identifiers.
- Account and security information used to authenticate you and protect the members’ area. We do not have access to your password in readable form.
- Event and workshop participation, documents or notices you submit, and associated authorship records.
- Membership applications and eligibility information, including date of birth, student declaration and, for junior members, guardian name, email address and consent. We do not request uploaded eligibility documents.
- Membership terms, honorary entitlements and audited officer decisions, renewal settings, cash receipt references, Stripe customer/subscription references and payment or reversal status.
- If you pay membership fees or make a donation through Stripe, we receive limited transaction information such as the amount, date, status and provider reference. Full payment-card or bank details are entered into and retained by Stripe, not this website.
- Read-only source identifiers and dates retained from the final membermojo migration for reconciliation, retention and legal-hold purposes.
Public visitors and correspondents
- When an event requires advance booking, the lead visitor’s name, email address, number of people attending, booking reference and check-in status.
- Information you choose to send by email or otherwise provide when contacting the Society.
- Basic technical and security information generated when the website is used, such as IP address, an event-scoped pseudonymous browser identifier, request time and security events.
Committee names, Society roles, role email addresses and photographs may be published where needed to identify current officers and provide a point of contact.
Why we use information
| Purpose | Typical lawful basis |
|---|---|
| Process applications and administer paid, cash and honorary membership, renewals, member access and benefits through the Society website | Performance of the membership agreement and the Society’s legitimate interests in running the club |
| Collect online membership subscriptions and voluntary donations through Stripe, confirm complete cash payments and maintain financial records | Performance of the membership agreement, the Society’s legitimate interests and compliance with legal obligations |
| Manage event capacity, issue visitor booking confirmations, verify arrivals, organise workshops and coordinate Society activities | Legitimate interests in operating safe, appropriately attended events; consent where the law requires it |
| Protect accounts, prevent abuse and investigate security incidents | Legitimate interests in keeping members, systems and information secure |
| Meet safety, insurance, governance and other legal requirements, or establish and defend legal claims | Legal obligation and legitimate interests |
Some identity and contact information is necessary to administer membership. If it is not provided, we may be unable to create or maintain a membership or online account. We do not use personal information for solely automated decisions that produce legal or similarly significant effects.
To protect fair access to visitor places, we compare pseudonymous, event-scoped versions of the booking browser and IP address with recently accepted bookings. A rapid attempt that would take either total above 12 places may be declined automatically and directed to the Society for offline assistance. We do not retain the submitted name or email address from a declined attempt.
Where information comes from
We normally receive information directly from you, including when you reserve event places, from a parent or guardian where appropriate, or from a Society officer acting on an application, cash payment or honorary entitlement. Membership-payment, renewal, refund and dispute confirmations may be received from Stripe. Historical membership details may come from the Society’s final membermojo export.
Who we share it with
Information is available only to members and Society officers who need it for their role. We also use carefully selected service providers, including:
- Supabase for authentication, database and file storage;
- Vercel for website hosting, delivery and operational logs;
- Stripe for hosted online membership subscriptions, payment-method management, voluntary donations, fraud prevention and associated payment records;
- Resend for transactional membership, account and visitor-booking emails; and
- Cloudflare Turnstile to distinguish genuine booking, sign-in and recovery attempts from automated abuse.
We may disclose information to insurers, professional advisers, regulators, law-enforcement bodies or other parties where the law requires or permits it. We do not sell personal information.
International processing
Some providers may process information in the UK, the EEA or other countries. Where a restricted international transfer occurs, we require an appropriate UK transfer mechanism, such as an adequacy regulation or approved contractual safeguards. Contact us if you would like more information about the safeguards relevant to your information.
How long we keep information
The core membership record is normally kept throughout membership and for up to 12 months after membership ends. Visitor booking details are normally removed or anonymised within 90 days after the event, unless they are needed for a safety incident, dispute or legal obligation. Records required for accounting, tax, insurance, safety, dispute or legal purposes may be retained for the longer period required by law or reasonably needed for those purposes. Public committee details are updated when roles change. Provider backups and security logs expire according to controlled retention schedules.
When information is no longer required, we delete it or render it anonymous.
Your data protection rights
Depending on the circumstances and our lawful basis, you may have rights to:
- ask for access to your personal information;
- ask us to correct inaccurate or incomplete information;
- ask us to erase or restrict the use of information;
- object to processing based on legitimate interests;
- receive information you provided in a portable format; and
- withdraw consent at any time where processing relies on consent.
You may object at any time to processing based on our legitimate interests. Tell us what you object to and why; we will stop unless we have compelling legitimate grounds to continue or need the information for legal claims.
There is usually no fee. We may need to confirm your identity and will normally respond within one calendar month.
Security and junior members
We use access controls, encrypted connections, role-based permissions and other organisational and technical safeguards. No internet service can guarantee absolute security, so please keep sign-in links and passwords private.
Where a junior member’s information is provided, we use it only to administer membership, activities and safety requirements, and involve a parent or guardian where appropriate.
Complaints and changes
Please contact the Chairman first so we can try to resolve a concern. You may also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
We review this notice when our services or legal obligations change. Material updates will be identified by the review date above.
