Privacy Policy

Last update: 30 July 2026

1. Who we are

This website is https://lacae.org.uk.

The site is operated by Latin American Community Association of Edinburgh a registered charity in Scotland (SC054391) Regulated by the Scottish Charity Regulator OSCR (“LACAE”, “we”, “us”, or “our”).

Our contact details are:

  • Email: edinburghlatincommunity@gmail.com
  • Postal address: 10 Heath Road, Edinburgh, EH4 4UX
2. What this policy covers

This policy explains what personal data we collect, how we use it, the lawful bases we rely on, who we share it with, how long we keep it, and the rights available to you.

3. What personal data we collect

Depending on how you use the site, we may collect:

  • Identity data, such as your name, username, or account name.
  • Contact data, such as your email address, telephone number, billing address, and shipping address.
  • Transaction data, such as order details, booking details, payment-related information, refunds, and donation or purchase history.
  • Account data, such as login details and profile information.
  • Event submission data, such as event and location information you send to us for publication.
  • Communications data, such as messages sent through forms, emails, or support requests.
  • Technical data, such as IP address, browser type, device information, referrer, and user agent.
  • Usage data, such as pages visited, products viewed, cart activity, and interactions with features on the site.
  • Comment data, such as the information entered into the comments form.
  • Marketing data, such as your preferences for receiving updates, where you have chosen to receive them.
4. How and why we use your personal data

We use personal data for the following purposes:

  • To operate and maintain the website.
  • To manage user accounts.
  • To receive and moderate comments.
  • To process shop orders, payments, refunds, and customer support requests.
  • To manage event bookings, attendance records, and event submissions.
  • To respond to enquiries sent through contact forms or email.
  • To improve website functionality, usability, and security.
  • To detect spam, fraud, abuse, and other malicious activity.
  • To comply with legal, tax, accounting, and regulatory obligations.
  • To send marketing communications only where you have consented or where the law otherwise allows it.
5. Lawful bases for processing

Under UK GDPR, we rely on one or more of the following lawful bases, depending on the activity:

  • Contract: where processing is necessary to provide an order, booking, account, or other service you request.
  • Legal obligation: where we must keep records or process data to comply with legal, tax, accounting, safeguarding, or regulatory duties.
  • Legitimate interests: where processing is reasonably necessary for running, protecting, and improving the site and services, provided your rights do not override those interests.
  • Consent: where you actively agree, such as for optional marketing, optional cookies, or where a plugin or form asks for specific consent.

Where we rely on legitimate interests, these may include:

  • Running and administering the website and related services.
  • Preventing spam, fraud, misuse, and security incidents.
  • Managing events, attendance, and related communications.
  • Improving site content, performance, and user experience.
  • Handling customer service and administrative queries.

Where we rely on consent, you can withdraw that consent at any time by contacting us, changing your settings where available, unsubscribing from marketing emails, or rejecting optional cookies through our cookie settings.

6. If you do not provide personal data

Sometimes we need certain information to provide a service.

  • If you do not provide required checkout or booking information, we may be unable to process your order, booking, refund, or enquiry.
  • If account information is required for a feature, you may be unable to create or use that account.
  • Providing optional information is voluntary, and not providing it should not stop you using the basic parts of the site unless that information is necessary for the service requested.
7. Comments

When visitors leave comments on the site, we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymised string created from your email address, also called a hash, may be provided to the Gravatar service to see if you are using it. The Gravatar privacy policy is available at https://automattic.com/privacy/. After approval of your comment, your profile picture may be visible to the public in the context of your comment.

We also use Akismet anti-spam services. Akismet may process data such as the commenter’s IP address, user agent, referrer, site URL, name, username, email address, and comment content for spam detection purposes.

Lawful basis:

  • Legitimate interests, to moderate comments and protect the site from spam and abuse.
8. Contact forms and direct communications

If you contact us through a form or by email, we may collect your name, email address, and any other information you include in your message.

We use this information to:

  • Respond to your enquiry.
  • Provide support or follow-up.
  • Keep administrative records of communications.

We do not use contact form messages for marketing unless you separately consent.

Lawful basis:

  • Legitimate interests, to respond to enquiries and manage communications.
  • Contract, where your message relates to a booking, order, or service request.
  • Consent, where a form asks for optional consent.

Retention:

  • Contact form submissions are kept for 12 months, unless a longer period is needed for a related service, safeguarding, complaint, or legal issue.
9. Events and bookings

When you make an event booking, we collect and store the information you submit in order to reserve your requested spaces and maintain attendance records.

We may also use cookies to temporarily store information about a booking in progress, as well as error or confirmation messages whilst submitting or managing events and locations.

Events Manager may use Google services to generate maps and provide place autocompletion when searching by location. Google may collect data via your browser in accordance with its privacy policy: https://policies.google.com/privacy.

Lawful basis:

  • Contract, to process and manage bookings.
  • Legitimate interests, to manage events, attendance, submissions, and website administration.
  • Legal obligation, where records must be retained.
  • Consent, where a specific form asks for consent.

Retention:

  • Booking and event records are kept for 6 years.
  • Financial or tax-related records linked to bookings are kept for 6 years.
10. Shop, donations, and WooCommerce

When you browse or purchase from the site, we may collect and store:

  • Products viewed.
  • Location, IP address, and browser type.
  • Billing address.
  • Shipping address.
  • Name.
  • Email address.
  • Phone number.
  • Account username and password, if you create an account.
  • Order details, including what you bought, when you bought it, and where it should be sent.
  • Payment-related information needed to process the transaction.

We use this information to:

  • Process orders, donations, or related transactions.
  • Send account and order information.
  • Arrange delivery or fulfilment.
  • Process refunds and handle complaints.
  • Prevent fraud and misuse.
  • Comply with tax, accounting, and other legal obligations.
  • Improve store performance and customer experience.
  • Send marketing communications only if you choose to receive them.

If you create an account, we store your name, address, email, and phone number so checkout can be completed more easily in future.

Lawful basis:

  • Contract, to process purchases and related support.
  • Legal obligation, to keep accounting and tax records.
  • Legitimate interests, to run and improve the store and prevent fraud.
  • Consent, for optional marketing.

Retention:

  • Order information is kept for 6 years for tax, accounting, and audit purposes.
  • Customer account information is kept until the account is deleted, unless we need to retain it longer for legal or administrative reasons.
11. Payments

Payments are processed by third-party providers, including:

When processing payments, some of your personal data will be shared with the relevant payment provider, including information required to process or support the payment, such as the purchase total, billing details, and transaction information.

We do not store full card details on our WordPress site unless this is explicitly enabled by a payment provider integration and documented here.

Lawful basis:

  • Contract, to process payments.
  • Legal obligation, where transaction records must be kept.
  • Legitimate interests, to prevent fraud and manage payment disputes.
12. Mailchimp and cart recovery

The site may keep a record of your email address and basket contents for up to 30 days on the server so that your cart can be restored if you switch devices or return later.

Mailchimp’s privacy policy is available at https://mailchimp.com/legal/privacy/.

Where you subscribe to our mailing list, we use your contact details and marketing preferences to send updates, newsletters, or promotions. You can unsubscribe at any time using the unsubscribe link in any email or by contacting us.

Lawful basis:

  • Legitimate interests, for cart recovery and store operation.
  • Consent, for email marketing subscriptions.
13. Cookies

We use cookies and similar technologies for several reasons, including essential site operation, account login, shopping basket functionality, booking sessions, saving user preferences, and optional analytics or marketing.

Examples may include:

  • Comment cookies, if you choose to save your name, email address, and website when leaving a comment.
  • Temporary cookies to check whether your browser accepts cookies.
  • Login cookies and screen preference cookies for registered users.
  • Editor cookies used when editing or publishing content.
  • Basket or cart cookies used by WooCommerce.
  • Booking-related cookies used by Events Manager.
  • Optional analytics or third-party cookies, if enabled.
  • Embedded content cookies from third-party services.

Where required by law, non-essential cookies are used only after you give consent through our cookie banner or cookie settings tool.

You can manage cookies through:

  • Our cookie banner or preferences tool.
  • Your browser settings.
  • Relevant third-party opt-out tools where available.

For more detail, add a separate Cookie Policy or expand this section with a cookie table if you use analytics, advertising, video embeds, or social plugins.

Lawful basis:

  • Essential cookies: legitimate interests or contract, where strictly necessary for requested services.
  • Non-essential cookies: consent.
14. Analytics

We do not currently use a separate website analytics platform beyond basic server or hosting logs used for security and performance purposes.

15. Embedded content from other websites

Articles or pages on this site may include embedded content such as videos, images, maps, forms, or social media content. Embedded content from other websites behaves in the same way as if you had visited those websites directly.

These third-party services may collect data about you, use cookies, and monitor your interaction with the embedded content, especially if you are logged into their service.

Lawful basis:

  • Legitimate interests, where the content is necessary to present site content effectively.
  • Consent, where non-essential third-party cookies or tracking technologies are used.
16. Who we share your data with

We may share personal data with the following categories of recipients, where necessary:

  • Hosting and website service providers.
  • WordPress plugin providers and technical support providers.
  • Payment processors, including PayPal and Stripe.
  • Email and marketing providers, including Mailchimp.
  • Spam and security providers, including Akismet.
  • Mapping and location providers, including Google.
  • Delivery, fulfilment, or service partners, if applicable.
  • Professional advisers, insurers, auditors, regulators, or authorities where required by law or to protect legal rights.

If you request a password reset, your IP address may be included in the reset email.

We do not sell your personal data.

17. International transfers

Some of our third-party providers may process personal data outside the UK. This can include countries that may not provide the same level of data protection as the UK.

Where personal data is transferred internationally, we rely on appropriate safeguards where required, such as:

  • UK adequacy regulations.
  • The UK International Data Transfer Agreement (IDTA).
  • The UK Addendum to international standard contractual clauses.
  • Other lawful transfer mechanisms recognised under UK data protection law.

You can request more information about relevant safeguards by contacting us.

18. How long we retain your data

We keep personal data only for as long as necessary for the purposes for which it was collected, including legal, accounting, safeguarding, reporting, and dispute-resolution requirements.

Current retention periods include:

  • Comments and their metadata: retained indefinitely unless removed.
  • Registered user profile information: retained while the account remains active, and for up to 12 months after closure where necessary.
  • Contact form submissions: retained for 12 months.
  • Event bookings and attendance records: retained for 6 years.
  • Event submissions and related location records: retained for 6 years.
  • Order and transaction records: retained for 6 years.
  • Cart recovery data via Mailchimp for WooCommerce: up to 30 days.
  • Technical logs and security records: retained for up to 12 months.
  • Marketing records and consent logs: retained for up to 6 years or until consent is withdrawn, plus any period needed to maintain suppression records.

If exact periods are not yet fixed, use:

  • We review retention regularly and keep personal data only for as long as necessary based on the nature of the data, the purpose of processing, legal requirements, and the need to resolve disputes or enforce agreements.
19. Your rights

Under UK data protection law, you may have the right to:

  • Request access to your personal data.
  • Request correction of inaccurate or incomplete personal data.
  • Request erasure of your personal data.
  • Request restriction of processing.
  • Object to processing based on legitimate interests.
20. Your right to object

You have the right to object to processing carried out on the basis of legitimate interests. Where you object, we will stop processing unless we have compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing is needed for legal claims.

You also have the right to object to direct marketing at any time. If you object, direct marketing processing will stop.

Other rights may include:

  • Request data portability, where applicable.
  • Withdraw consent at any time, where processing is based on consent.
  • Request human review if a decision with legal or similarly significant effect is ever made solely by automated means.

To exercise your rights, contact us.

21. Complaints

If you have a concern about how your personal data is handled, please contact us first.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues.

ICO website: https://ico.org.uk

22. Children’s data

Some of our activities may involve children or young people. Where this applies, we process personal data with appropriate safeguards and, where required, parental or guardian consent.

23. Automated decision-making and profiling

We do not currently carry out solely automated decision-making, including profiling, that produces legal effects or similarly significant effects on individuals.

If this changes, this policy will be updated to explain the logic involved, the significance of the processing, and the rights available.

24. Security

We use reasonable technical and organisational measures to protect personal data, such as:

  • Access controls and role-based permissions.
  • Secure hosting and software updates.
  • Encryption in transit, such as SSL/TLS.
  • Security plugins, backups, and monitoring, where used.
  • Staff or volunteer access limited to what is necessary.

No internet-based service can ever be completely secure, but reasonable steps are taken to reduce risk and respond to incidents.

25. Data breach procedures

We maintain procedures to identify, investigate, contain, and respond to suspected personal data breaches.

Where required by law, relevant breaches will be reported to the ICO and, where necessary, to affected individuals.

26. Changes to this privacy policy

This policy may be updated from time to time to reflect legal, technical, or operational changes.

The latest version will always be posted on this page with the updated date shown at the top.