This Privacy Policy describes how Church Academy (“we,” “our,” or “us”) collects, uses, and shares personal information when you use our website www.churchacademy.co.uk (the “Site”) and interact with our services.
1. Data Controller
The data controller responsible for the processing of your personal data under this Privacy Policy is Church Academy. If you have any questions or concerns regarding the processing of your personal data or this Privacy Policy, you can contact us at hello@churchacademy.co.uk.
2. Types of Personal Data We Collect
We may collect the following types of personal data when you use our Site or interact with our services:
- Name
- Email address
- Mailing address
- Payment information
- Any other information you provide to us voluntarily
3. Legal Basis for Processing
We will only process your personal data when we have a legal basis to do so. The legal bases for processing your personal data may include:
- Your consent to the processing of your personal data for specified purposes;
- The necessity of processing your personal data for the performance of a contract with you or to take steps at your request prior to entering into a contract;
- Compliance with our legal obligations under applicable laws and regulations.
4. Purposes of Processing
We may process your personal data for the following purposes:
- Providing and personalising our services to you;
- Processing transactions and payments;
- Communicating with you, including responding to your inquiries and providing customer support;
- Sending you newsletters, marketing communications, and other promotional materials that may be of interest to you.
5. Sharing of Personal Data
We may share your personal data with third-party service providers who assist us in operating our website, conducting our business, or servicing you. We may also share your personal data in response to legal process or when required by law.
6. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including countries that may not provide the same level of data protection as your home country. When we transfer your personal data to third parties outside the EEA, we will ensure that appropriate safeguards are in place to protect your personal data, such as standard contractual clauses approved by the European Commission.
7. Data Subject Rights
Under the General Data Protection Regulation (GDPR), you have certain rights regarding your personal data, including the right to:
- Access your personal data and obtain a copy of your personal data;
- Rectify any inaccurate or incomplete personal data;
- Erase your personal data under certain circumstances;
- Restrict the processing of your personal data under certain circumstances;
- Object to the processing of your personal data under certain circumstances;
- Data portability, i.e., receive your personal data in a structured, commonly used, and machine-readable format and transmit it to another controller;
- Withdraw your consent to the processing of your personal data at any time, where we rely on your consent as the legal basis for processing your personal data.
8. Data Security
We take appropriate technical and organisational measures to ensure the security of your personal data and protect it against unauthorised or unlawful processing, accidental loss, destruction, or damage.
9. Data Retention
We will retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.