top of page

Privacy Policy

Twigs CIC – Privacy Policy

Last updated: June 2026

 

Twigs CIC is committed to protecting your personal information and being open about how we use it. This Privacy Policy explains what data we collect, why we collect it, how we keep it safe, and your rights under UK GDPR. Our approach is guided by our internal Data Protection Policy, which states that we process personal data “lawfully, fairly and in a transparent manner” and that data is “kept safe… and only accessed by those who need to do so.”

 

1. Who we are

Twigs CIC is a nature connection CIC who work across Suffolk and surrounding areas. We are a community‑focused organisation providing nature‑based learning, wellbeing activities, and environmental education.

Email: hello@twigscic.com

We are the Data Controller for the personal data we collect.

 

2. What information we collect

We collect information in three ways:

a) Information you give us directly

Such as:

  • Contact form details

  • Booking information

  • Emergency contacts

  • Medical or access information needed for safety

  • Consent forms (including imagery consent)

b) Information collected automatically

Such as: 

  • Cookies

  • Website analytics

  • IP address (depending on your cookie settings)

c) Information collected during sessions

This may include:

  • Attendance records

  • Accident/incident information

  • Imagery or video (only with consent)

Twigs only collects data that is “adequate, relevant and limited to what is necessary.”

 

3. Why we collect your data

  • We use your information to:

  • Manage bookings and deliver our services

  • Keep participants safe during sessions

  • Contact you about your enquiry or booking

  • Send updates or newsletters (only if you opt in)

  • Meet safeguarding, insurance, and legal requirements

  • Improve our website and services

We never sell your data or share it for marketing.

4. Our lawful basis for processing

Under UK GDPR, we rely on:

  • Consent – for newsletters, imagery, optional information

  • Contract – when you book a session or request a service

  • Legal obligation – safeguarding, health & safety, accounting

  • Legitimate interests – improving our services, ensuring safety

5. How we store and protect your data

We take data security seriously. 

Your information is stored securely using:

  • Password‑protected systems

  • Restricted access to shared folders

  • Locked storage for paper records

  • Up‑to‑date antivirus and firewall protection

  • Secure backup and recovery processes

 

6. How long we keep your data

We only keep your data for as long as necessary.

In general:

Booking and participation records: up to 6 years

Accident/incident forms: as required by law

Mailing list data: until you unsubscribe

Imagery consent: until withdrawn or no longer needed

7. Sharing your information

We only share your data when necessary, for example:

  • With trusted service providers (e.g., booking systems)

  • With emergency services if required

  • When legally required (e.g., safeguarding concerns)

  • We do not share your data for advertising or commercial purposes.

 

8. Imagery and video

We will always:

  • Ask for consent before using identifiable images

  • Explain how the image will be used

  • Allow you to withdraw consent at any time

  • Take extra care with children and vulnerable groups

9. Cookies and website analytics

Our website may use cookies to improve your experience and understand how visitors use the site. You can control or disable cookies through your browser settings. If we use analytics tools (e.g., Google Analytics), these may collect anonymised usage data such as page views and device type.

10. Your rights

You have the right to:

  • Access your personal data

  • Ask us to correct inaccurate information

  • Request deletion of your data

  • Withdraw consent

  • Restrict or object to processing

  • Request a copy of your data in a portable format

To exercise any of these rights, contact us at hello@twigscic.com

11. Children and people who cannot give consent

Some people are unable to give consent and this must be obtained from the person who is able to make decisions on their behalf. We follow this guidance in all our activities.

12. Data breaches

If a data breach occurs, we will:

  • Investigate promptly

  • Take action to prevent recurrence

  • Notify the ICO within 72 hours if required

If the breach poses a high risk, we will also inform affected individuals.

13. Complaints

If you have concerns about how we handle your data, please contact us.

We have a dedicated process for handling complaints relating to personal data. We will acknowledge receipt within 30 calendar days. If you remain unhappy, you can contact the Information Commissioner’s Office (ICO).

14. Data Protection Policy

For full details of how Twigs CIC manages data internally, please contact us for a copy of our Data Protection Policy.

Twigs does not use AI or automated decision-making to process personal data.

bottom of page