Privacy Policy
Twigs CIC – Privacy Policy
Last updated: June 2026
Twigs CIC is committed to protecting your personal information and being open about how we use it. This Privacy Policy explains what data we collect, why we collect it, how we keep it safe, and your rights under UK GDPR. Our approach is guided by our internal Data Protection Policy, which states that we process personal data “lawfully, fairly and in a transparent manner” and that data is “kept safe… and only accessed by those who need to do so.”
1. Who we are
Twigs CIC is a nature connection CIC who work across Suffolk and surrounding areas. We are a community‑focused organisation providing nature‑based learning, wellbeing activities, and environmental education.
Email: hello@twigscic.com
We are the Data Controller for the personal data we collect.
2. What information we collect
We collect information in three ways:
a) Information you give us directly
Such as:
-
Contact form details
-
Booking information
-
Emergency contacts
-
Medical or access information needed for safety
-
Consent forms (including imagery consent)
b) Information collected automatically
Such as:
-
Cookies
-
Website analytics
-
IP address (depending on your cookie settings)
c) Information collected during sessions
This may include:
-
Attendance records
-
Accident/incident information
-
Imagery or video (only with consent)
Twigs only collects data that is “adequate, relevant and limited to what is necessary.”
3. Why we collect your data
-
We use your information to:
-
Manage bookings and deliver our services
-
Keep participants safe during sessions
-
Contact you about your enquiry or booking
-
Send updates or newsletters (only if you opt in)
-
Meet safeguarding, insurance, and legal requirements
-
Improve our website and services
We never sell your data or share it for marketing.
4. Our lawful basis for processing
Under UK GDPR, we rely on:
-
Consent – for newsletters, imagery, optional information
-
Contract – when you book a session or request a service
-
Legal obligation – safeguarding, health & safety, accounting
-
Legitimate interests – improving our services, ensuring safety
5. How we store and protect your data
We take data security seriously.
Your information is stored securely using:
-
Password‑protected systems
-
Restricted access to shared folders
-
Locked storage for paper records
-
Up‑to‑date antivirus and firewall protection
-
Secure backup and recovery processes
6. How long we keep your data
We only keep your data for as long as necessary.
In general:
Booking and participation records: up to 6 years
Accident/incident forms: as required by law
Mailing list data: until you unsubscribe
Imagery consent: until withdrawn or no longer needed
7. Sharing your information
We only share your data when necessary, for example:
-
With trusted service providers (e.g., booking systems)
-
With emergency services if required
-
When legally required (e.g., safeguarding concerns)
-
We do not share your data for advertising or commercial purposes.
8. Imagery and video
We will always:
-
Ask for consent before using identifiable images
-
Explain how the image will be used
-
Allow you to withdraw consent at any time
-
Take extra care with children and vulnerable groups
9. Cookies and website analytics
Our website may use cookies to improve your experience and understand how visitors use the site. You can control or disable cookies through your browser settings. If we use analytics tools (e.g., Google Analytics), these may collect anonymised usage data such as page views and device type.
10. Your rights
You have the right to:
-
Access your personal data
-
Ask us to correct inaccurate information
-
Request deletion of your data
-
Withdraw consent
-
Restrict or object to processing
-
Request a copy of your data in a portable format
To exercise any of these rights, contact us at hello@twigscic.com
11. Children and people who cannot give consent
Some people are unable to give consent and this must be obtained from the person who is able to make decisions on their behalf. We follow this guidance in all our activities.
12. Data breaches
If a data breach occurs, we will:
-
Investigate promptly
-
Take action to prevent recurrence
-
Notify the ICO within 72 hours if required
If the breach poses a high risk, we will also inform affected individuals.
13. Complaints
If you have concerns about how we handle your data, please contact us.
We have a dedicated process for handling complaints relating to personal data. We will acknowledge receipt within 30 calendar days. If you remain unhappy, you can contact the Information Commissioner’s Office (ICO).
14. Data Protection Policy
For full details of how Twigs CIC manages data internally, please contact us for a copy of our Data Protection Policy.
Twigs does not use AI or automated decision-making to process personal data.