North Derbyshire Green Party

Privacy Policy

How we collect, use and protect your personal data — and the rights you have over it.

Latest update: 1 August 2026

Owner and Data Controller

Controller
North Derbyshire Green Party (“NDGP”, “we”, “us”) — the local Green Party for the districts of Bolsover, Chesterfield and North East Derbyshire.
Status
A local party of the Green Party of England and Wales (“GPEW”). See Who we share your data with for how responsibility is split between us.
Data protection contact
Louis Hollingworth — louis@hollingworth.nl
Postal address
Available on request by email.
ICO registration
Registered with the UK Information Commissioner’s Office, registration number ZB839159. You can verify this on the ICO register.
This policy covers
This website (ndgp.uk), its member dashboard, the connected services listed below, the contact we make with local members and activists by email and telephone, and the surveys and canvassing we carry out with residents of Bolsover, Chesterfield and North East Derbyshire. It does not cover GPEW’s own processing of your membership record, which is governed by GPEW’s privacy policy.
Where our email comes from
Automated messages from this website — sign-in links, RSVP confirmations — come from ndgp.uk. Campaigning and organising email comes from northderbyshire.greenparty.org.uk, a domain operated for us by GPEW. Both are genuinely us.

Summary

We keep data collection to the minimum needed to run a local party. We do not sell your data, we do not advertise, and we do not track you across other websites. There is no cookie banner on this site because we set no cookies that require your consent — see Cookies and similar technologies. We do use what residents tell us on the doorstep to decide which leaflet goes to which address; that is set out in Surveys and canvassing rather than buried.

Most of this policy is about this website. Three things happen off it: our members and activists list lives on Action Network, a platform GPEW provides; we contact people by email and telephone from there; and we survey and canvass residents across our three districts, which is how most people who are not members come to be on our records. All three are covered below.

Data we collect automatically

  • Your IP address and browser user-agent string, in server and security logs
  • Pages you visit, the referring page, and your approximate country, via cookieless analytics
  • The date and time of requests, for debugging and abuse prevention
  • Your IP address, when a map is displayed on an in-person event page (see OpenStreetMap below)

Data you give us

  • Your email address, when you sign in or RSVP to an event
  • Your name, when you complete your profile or RSVP to an event
  • A passkey public key and its device label, if you enrol one
  • Committee, councillor and candidate profile details, if you hold one of those roles
  • Photographs and files you upload through the dashboard
  • Anything you choose to put in an email to us
  • Your contact details and campaigning preferences, if you are on the members and activists list GPEW holds for us
  • Your answers, if you take part in a doorstep or telephone survey — including how you intend to vote, which you are free to decline

Data we get elsewhere

  • Your elector number, name and address, from the full electoral register supplied to political parties
  • Your membership status and contact details, from GPEW's national membership records
  • Nothing bought from a data broker — we do not purchase personal data or append commercial datasets to our records

What we collect, why, and on what legal basis

Each block below describes one processing activity: what it involves, why we do it, the lawful basis under UK GDPR and EU GDPR, and how long we keep the data.

Visiting the website

Everyone
Personal data
IP address, user-agent, requested URL, timestamp, referrer.
Purpose
Serving the site, keeping it available and secure, diagnosing faults and detecting abuse.
Lawful basis
Legitimate interests (Art 6(1)(f)) — running a secure, working website for the public.
Retention
Container logs are rotated automatically and the oldest are discarded, so only recent activity is retained. They are never indexed or used to build a profile.

Audience measurement

Everyone
Personal data
Page URL, referrer, browser, operating system, device type, country. No cookies, no cross-site identifier, no profile.
Purpose
Understanding which pages are useful so we can improve the site. Aggregate figures only.
Lawful basis
Legitimate interests (Art 6(1)(f)) — we use a privacy-preserving, cookieless tool precisely so this does not override your rights. You may object at any time.
Retention
Plausible stores aggregated statistics; no individual-level record is retained.

Member account and sign-in

Account holders
Personal data
Email address, first and last name, derived display name and username, roles, team memberships, sign-in method, passkey public key and label.
Purpose
Creating and securing your account, showing you the right parts of the dashboard, and signing you in to connected NDGP services.
Lawful basis
Contract / steps at your request (Art 6(1)(b)) for running the account; legitimate interests (Art 6(1)(f)) for access control. Where it reveals political opinions, Art 9(2)(d) and DPA 2018 Sch 1 Pt 2 para 22 apply.
Retention
For as long as you hold an account. Ask us and we will delete it, subject to anything we must keep by law.

Sessions and sign-in links

Account holders
Personal data
Session token, IP address, user-agent, expiry time; single-use sign-in links.
Purpose
Keeping you signed in, letting you see and revoke your own active sessions, and detecting suspicious sign-ins.
Lawful basis
Contract (Art 6(1)(b)) and legitimate interests (Art 6(1)(f)) in account security.
Retention
Sign-in links expire five minutes after they are issued and can be used once; spent links are erased after 1 day. Sessions end when they expire or when you sign out, and the record is erased 7 days later.

Administrative audit log

Account holders
Personal data
Who made a change, their email, IP address, user-agent, session reference, what changed, and the before and after values.
Purpose
Accountability for changes to party content and member records, and the ability to undo mistakes.
Lawful basis
Legitimate interests (Art 6(1)(f)) — protecting the integrity of party data. Also supports our accountability duty under Art 5(2).
Retention
365 days, after which entries are deleted automatically by a nightly sweep.

Event RSVPs

Anyone attending an event
Personal data
Your name, email address, which occurrence you are attending, and your response.
Purpose
Managing attendance, telling you about changes, sending you joining details for online events, and letting you change or withdraw your response.
Lawful basis
Contract / steps at your request (Art 6(1)(b)) — you asked us to book you a place.
Retention
Deleted automatically 180 days after the event you booked. You can withdraw an RSVP at any time from the link in your confirmation email, or ask us to erase it sooner.

Calendar subscriptions

Members
Personal data
Your email address and a random, unguessable subscription token.
Purpose
Providing a personal calendar feed that includes members-only events.
Lawful basis
Consent (Art 6(1)(a)) — you asked for the feed.
Retention
Until you ask us to revoke it, or automatically after 365 days without your calendar app fetching it; a revoked token is erased 30 days later. Anyone holding the link can see your member events, so keep it private.

Committee, councillor and candidate profiles

Elected members and postholders
Personal data
Name, role or ward, biography, photograph, public contact links, and a private linking email address.
Purpose
Telling residents who represents them and how to get in touch — these profiles are deliberately public.
Lawful basis
Legitimate interests (Art 6(1)(f)) and, for candidates and elected representatives, the public interest in democratic accountability. Political opinions are processed under Art 9(2)(d) and, where the information has manifestly been made public by you, Art 9(2)(e).
Retention
While you hold the role, and for a reasonable archive period afterwards for historical accuracy.

Sign-up list and invitations

Members and activists
Personal data
Email address, the permissions and teams assigned in advance, any note an organiser adds, and when the invitation was claimed.
Purpose
Restricting account creation to people entitled to one — there is no open registration on this site.
Lawful basis
Legitimate interests (Art 6(1)(f)) in keeping the member area closed. Art 9(2)(d) applies where it reveals political opinions.
Retention
Deleted the moment the account is created, or when an admin withdraws the invitation. An invitation nobody takes up lapses automatically after 90 days. We keep no record of claimed invitations.

Photographs and uploads

Dashboard users
Personal data
The image itself, its dimensions and format, any alternative text, and who uploaded it.
Purpose
Illustrating news articles and events.
Lawful basis
Legitimate interests (Art 6(1)(f)) in publishing party news. Where an image identifies someone, we rely on consent or on the public interest in reporting party activity.
Retention
Until deleted from the dashboard. Uploads are re-encoded on the server, which strips embedded metadata such as GPS coordinates.

Correspondence with us

Anyone
Personal data
Your email address, your message, and anything you choose to include in it.
Purpose
Answering your question and following it up.
Lawful basis
Legitimate interests (Art 6(1)(f)) in responding to people who contact us; consent for anything extra you volunteer.
Retention
Up to two years from our last exchange, unless it needs to be kept longer as a party record.

Members and activists list

Members and activists
Personal data
Name, email address, telephone number, postal address or area, membership status, and organiser tags — including tags showing membership of a GPEW Special Interest Group.
Purpose
Knowing who our local members and activists are, so we can involve them in party activity and confirm who is entitled to a dashboard account.
Lawful basis
Legitimate interests (Art 6(1)(f)) in organising a local party. Art 9(2)(d) for information revealing political opinions and for Special Interest Group tags; DPA 2018 Sch 1 Pt 2 para 22 where the activity reaches beyond members.
Retention
Held on GPEW's Action Network platform under GPEW's retention policy, not ours — our automated deletion schedule below does not reach it. We remove people from local organising lists when they leave or ask us to.

Campaigning contact by email and phone

Members and activists
Personal data
Your name, email address, telephone number, and a record of what we sent you or discussed, plus whether you opened or clicked an email.
Purpose
Telling you about campaigns, actions and local party news, and inviting you to take part.
Lawful basis
Consent (Art 6(1)(a)) for campaigning email and calls, as PECR requires; legitimate interests (Art 6(1)(f)) for organising contact you have asked for. Art 9(2)(d) and Sch 1 Pt 2 para 22 for the political content.
Retention
Send and response records are kept on Action Network under GPEW's policy. An opt-out is honoured immediately and kept on record so we do not contact you again by mistake.

Events run through Action Network

Anyone attending an event
Personal data
Whatever the sign-up form for that event asks for — usually name and email address, sometimes a telephone number.
Purpose
Running events we organise on GPEW's platform rather than on this website.
Lawful basis
Contract / steps at your request (Art 6(1)(b)) — you asked for a place. Art 9(2)(d) and Sch 1 Pt 2 para 22 where attendance reveals political opinions.
Retention
Held on Action Network under GPEW's retention policy. This is separate from the RSVP system on this website, which deletes bookings automatically as described above.

The electoral register

Everyone registered to vote locally
Personal data
Elector prefix and number, name and address, as they appear on the full register for our three districts.
Purpose
Knowing who the electors in an area are, so that canvassing and campaign literature reach the right households and are not sent twice.
Lawful basis
Legitimate interests (Art 6(1)(f)). Supplied to registered political parties under reg 106 of the Representation of the People (England and Wales) Regulations 2001, which permits use for electoral purposes and for complying with donation controls, and makes any other use a criminal offence.
Retention
Each new register supersedes the previous one, which is destroyed. We keep no historic copies and do not merge the register with commercial or purchased data.

Surveys and canvassing

Residents we canvass
Personal data
Elector number, name and address, your views on the local area, your voting method, your previous and expected vote, our canvasser's estimate of how likely you are to support a Green candidate, and any email address or telephone number you choose to give.
Purpose
Judging whether an area is worth campaigning in as a target, and choosing which campaign literature is delivered to which address.
Lawful basis
Legitimate interests (Art 6(1)(f)). Your answers reveal political opinions, so DPA 2018 Sch 1 Pt 2 para 22 applies — para 22(4) names political surveys and campaigning as political activities. Art 9(2)(d) does not reach residents who are not members or regular contacts, so this is the processing that genuinely depends on para 22.
Retention
One electoral cycle — up to four years and no more than five — after which the record is deleted, and a later canvass of the same area replaces it. This is longer than the twelve months applied to website records and is enforced by us, not by the automatic sweep.

Political opinions and special category data

Data revealing political opinions is “special category” data under Article 9 of the UK and EU GDPR, and it needs an extra condition on top of a lawful basis. Being a Green Party member or activist, or holding an account on this site, may reveal your political opinions.

Where that is the case we rely on:

  • Article 9(2)(d) — processing carried out in the course of the legitimate activities of a not-for-profit body with a political aim, relating solely to its members, former members, or people in regular contact with it in connection with its purposes, and not disclosed outside the party without your consent; and
  • Schedule 1, Part 2, paragraph 22 of the Data Protection Act 2018 (UK) — processing of personal data revealing political opinions by an organisation on the register of political parties, where necessary for its political activities. We rely on this for the political activity that reaches beyond our own members — campaigning, and case-work for residents who are not members. NDGP is an accounting unit within GPEW’s registration rather than a separately registered party, so this condition is available to us as a constituent organisation of the registered party. Paragraph 5(1) of that Part requires us to keep an appropriate policy document while we rely on it; ours is published at Appropriate Policy Document, which explains this in full.

Article 9(2)(d) is the condition we lean on for members and regular contacts, and it stands on its own regardless of the paragraph 22 position.

Paragraph 22 gives you a right specific to political parties, in addition to your general right to object: if you give us written notice requiring us to stop processing your data, and allow a reasonable period to comply, we may no longer rely on that condition once the period has ended. The same paragraph also stops us relying on it at all where the processing would be likely to cause you substantial damage or substantial distress.

We do not ask for, and you should not send us, any other special category data. If you volunteer it to us in an email or an event message, we will delete it unless we need it for a specific purpose you have asked us to carry out — for example an accessibility requirement for an event you are attending, which we process with your explicit consent under Article 9(2)(a) and delete after the event.

Special interest group tags

There is one place where we can see special category data without having asked for it. GPEW’s organising platform, Action Network, applies tags to a record when someone joins a Special Interest Group affiliated with GPEW. Those tags are visible to local organisers, and because of what some of those groups are about, a tag can imply something about your ethnicity, religion or belief, disability or health, sex or sexual orientation, or trade union membership.

We treat that as special category data even though it is inferred rather than collected. Our rules for it are:

  • we do not copy these tags into this website’s database — there is no field for them and they stay in Action Network;
  • we do not use them to decide who to contact, or to tailor what we say to you locally;
  • we do not disclose them outside the party without your consent; and
  • the condition we rely on is Article 9(2)(d), not paragraph 22, which covers political opinions only.

The tags belong to your GPEW record. If you want one removed, or want to know what is on your record, GPEW is the place to ask — though you can raise it with us and we will pass it on.

Surveys and canvassing

From time to time we knock on doors and telephone residents across Bolsover, Chesterfield and North East Derbyshire to ask what people think about their area and how they intend to vote. This is the one part of this policy that is likely to concern you even if you have never been a member, visited this website, or heard from us before, so it is set out in full.

What we record

When someone takes part, we may record:

  • your elector prefix and number, the reference the electoral register uses to identify you;
  • your first name, surname and address;
  • your views on the local area — whatever you tell us about the issues where you live;
  • how you vote — in person, by post, by proxy, that you do not vote, or that you are not entitled to;
  • which party you voted for before and which you expect to vote for next;
  • how likely you are to vote for a Green candidate, recorded as our canvasser’s estimate from the conversation; and
  • your email address and telephone number, if you choose to give them.

You do not have to answer any of it. Declining is common and has no consequence — we simply record that no view was given, and you can ask us not to call again.

Where your name and address come from

The elector number, name and address are not things we ask you for on the doorstep. They come from the full electoral register, which electoral registration officers supply to registered political parties under regulation 106 of the Representation of the People (England and Wales) Regulations 2001. Because we did not obtain that part from you, the law requires us to tell you its source, which is what this paragraph does.

The full register is not the version anyone can buy. Parties may use it only for electoral purposes and for complying with donation controls, and it is a criminal offence to pass it on or use it for anything else. We do not use it for fundraising appeals unrelated to an election, we do not disclose it outside the party, and we do not merge it with purchased or commercial datasets.

Why we do it and on what basis

We use canvass returns for two things, and we would rather say so plainly than describe them vaguely:

  • Deciding where to campaign. Aggregated returns tell us whether an area is worth fighting as a target, which is how a small local party decides where to put limited effort.
  • Deciding who receives which leaflet. We use what you told us to choose which of our campaign literature reaches your address, so that what lands on your doormat relates to the issues raised locally.

Our lawful basis is legitimate interests (Article 6(1)(f)) — a political party understanding and communicating with its electorate. Your answers about voting reveal political opinions, so they also need an Article 9 condition, and here it is Schedule 1, Part 2, paragraph 22 of the Data Protection Act 2018. Paragraph 22(4) names political surveys and campaigning as political activities, so this is the situation the condition was written for. Article 9(2)(d) does not help us here: it reaches only members and people in regular contact with us, and a resident answering the door is neither. Canvassing is therefore the main thing we do that depends on paragraph 22, which our Appropriate Policy Document examines in detail.

Your email address and phone number

If you give us contact details at the door, they are used only to follow up the matter you raised, or to send you campaigning messages where you have specifically agreed to that and we have recorded your agreement. Handing over an email address to a canvasser is not by itself consent to a campaigning mailing list, and we do not treat it as one. PECR requires consent for campaigning email and calls, and the “soft opt-in” is not available to political parties.

What we do not do

  • We do not sell, rent or share canvass records outside the party.
  • We do not buy commercial data or append it to what you told us.
  • We do not use canvass records to target online or social media advertising, and we do not upload them to any advertising platform.
  • We do not record anything about your ethnicity, religion, health, sex life or sexual orientation. If you mention something of that kind in passing, it does not belong in a canvass record and we remove it.

How long we keep it and who can see it

Canvass records are held by us as files in our own systems, not on this website, and access is limited to the organisers who need them for the campaign in question. We keep them for one electoral cycle — up to four years, and in no event more than five — after which they are deleted, and a later canvass of the same area replaces the earlier one. This is longer than the twelve months we apply to records held on this website, because a canvass is only useful across the run-up to an election; it is the one exception, and it is enforced by us rather than by the automatic deletion described elsewhere in this policy.

Your rights over a canvass record

Everything in Your rights applies. Three are worth pointing out here:

  • You can object. Tell us to stop sending you campaign literature and we stop — this is not weighed against anything.
  • You can ask what we hold. Give us your name and address and we will tell you what is on your canvass record, including the support estimate, and correct it if it is wrong.
  • You can give notice under paragraph 22. Written notice requiring us to stop, with a reasonable period to comply, ends our ability to rely on that condition for your data.

Who we share your data with

We do not sell your personal data and we do not share it for anyone else’s marketing. Beyond the recipients listed here, we disclose personal data only where you ask us to, or where we are required to by law.

Green Party of England and Wales (GPEW)

Party sharing agreement
Role
Separate controller. NDGP is an accounting unit within GPEW, and information is shared between the two under that relationship. GPEW maintains the membership and activist lists from which our eligibility to sign up is drawn; it decides its own purposes for that data and is responsible for it. GPEW also provides the Action Network platform we organise through, and operates the email domain we send campaigning mail from.
Personal data
Membership and activist records — name, contact details and membership status. We do not send GPEW your website analytics, RSVPs from non-members, or your session data.
Place of processing
United Kingdom
Lawful basis
Legitimate interests (Art 6(1)(f)) in running a local party within a national party; Art 9(2)(d) for information revealing political opinions, which is not disclosed outside the party without your consent.
Privacy policy
greenparty.org.uk/privacy-policy/

Action Network (Action Squared, Inc.)

Organising platform
Role
Processor, engaged by GPEW rather than by us. Holds the local members and activists list, sends our campaigning email, and runs sign-ups for events we organise there instead of on this website. Local organisers have access to the records for our area.
Personal data
Name, email address, telephone number, area, membership status, organiser tags, event sign-ups, and email open and click records.
Place of processing
United States
Lawful basis
Processing on the party's instructions under Art 28 GDPR. Consent (Art 6(1)(a)) for the campaigning messages themselves.
Transfer safeguard
Action Network states that it complies with the EU–US Data Privacy Framework and its UK Extension, and uses the European Commission's Standard Contractual Clauses. The contract is GPEW's, so these safeguards are maintained by GPEW.
Privacy policy
actionnetwork.org/privacy

Hetzner Online GmbH

Hosting
Role
Processor. Provides the servers and database that run this website.
Personal data
All data stored by the site, plus server logs.
Place of processing
Finland (European Union)
Lawful basis
Processing on our instructions under Art 28 GDPR.
Transfer safeguard
UK–EU transfers rely on the mutual adequacy decisions between the UK and the European Commission. No additional safeguard is required.
Privacy policy
www.hetzner.com/legal/privacy-policy/

Plausible Insights OÜ

Analytics
Role
Processor. Cookieless audience measurement, proxied through our own server so your browser never contacts Plausible directly.
Personal data
Page URL, referrer, browser, operating system, device type, country. No cookies and no cross-site identifier.
Place of processing
European Union
Lawful basis
Legitimate interests (Art 6(1)(f)).
Privacy policy
plausible.io/data-policy

Resend, Inc.

Email delivery
Role
Processor. Delivers the transactional emails listed above.
Personal data
Recipient email address and the content of the message.
Place of processing
United States
Lawful basis
Processing on our instructions under Art 28 GDPR.
Transfer safeguard
Resend's data processing addendum places transfers out of the UK under the Standard Contractual Clauses as amended and completed by the UK International Data Transfer Addendum, on the controller-to-processor module. Resend also states that it is certified under the EU–US Data Privacy Framework and its UK Extension. We rely on the contractual clauses, which bind Resend in their own right and would continue to protect the transfer if that certification ever lapsed.
Privacy policy
resend.com/legal/privacy-policy
Their sub-processors
resend.com/legal/subprocessors

OpenStreetMap Foundation

Maps
Role
Separate controller. Supplies the map tiles shown on event pages that have a physical venue. Your browser requests these directly, so OSMF receives your IP address.
Personal data
IP address, user-agent, referring page and the map area requested. This happens only on event pages with an in-person location, and only if you have not blocked it.
Place of processing
United Kingdom and European Union
Lawful basis
Legitimate interests (Art 6(1)(f)) in showing people where an event is. The venue address is always shown as text, so you can find the location without loading the map.
Privacy policy
osmfoundation.org/wiki/Privacy_Policy

NDGP Cloud and NDGP Office

Connected services
Role
Our own self-hosted file storage and document editing, which use this website to sign you in. Available only to accounts holding the relevant permission.
Personal data
Your name, username, email address, and your roles and team memberships, released as identity claims when you sign in.
Place of processing
Same hosting as this website (Finland, European Union)
Lawful basis
Contract (Art 6(1)(b)) — providing the services you have an account for.

what3words and OpenStreetMap Nominatim

Address lookup
Role
Used by organisers when setting an event's venue. Requests are made by our server, not your browser.
Personal data
None of your personal data. Only venue coordinates or a venue search entered by an organiser.
Place of processing
United Kingdom and European Union
Lawful basis
Legitimate interests (Art 6(1)(f)) in describing venues accurately.

Cookies and similar technologies

The Privacy and Electronic Communications Regulations (PECR) in the UK, and the ePrivacy Directive in the EU, require your consent before storing information on your device or reading information already stored there — unless that storage is strictly necessary to provide a service you have explicitly requested.

Everything this site stores on your device falls into that strictly necessary exemption, which is why you are not asked to accept cookies. We set no advertising, tracking, profiling or third-party analytics cookies.

Cookies and local storage used by this website
NameTypePurposeDurationConsent
ndgp.session_tokenCookieKeeps you signed in to the member dashboard.Until it expires or you sign outStrictly necessary — exempt
ndgp.dont_rememberCookieRecords that you asked not to stay signed in, so your session ends when you close your browser.Until you sign out or close your browserStrictly necessary for a feature you requested — exempt
ndgp.passkey_challengeCookieHeld for a few minutes while you set up or sign in with a passkey, to tie your device's response to the request that started it.Five minutes, or until the passkey step finishesStrictly necessary — exempt
ndgp.admin_sessionCookieSet only while an administrator is viewing the dashboard as another member for support, so their own session can be restored afterwards. Never set during ordinary use.Until the administrator stopsStrictly necessary — exempt
ndgp-member-emailLocal storageRemembers the email address you entered to reveal members-only events, so you do not retype it.Until you clear it or select ClearStrictly necessary for a feature you requested — exempt
ndgp-install-dismissedLocal storageRemembers that you dismissed the dashboard install prompt, so it is not shown again.Until browser storage is clearedStrictly necessary for a feature you requested — exempt
Dashboard offline cacheService worker / Cache StorageStores the dashboard's own files so it loads quickly and works offline. Dashboard only; it is not used on public pages.Until browser storage is clearedStrictly necessary for a feature you requested — exempt

If you inspect these cookies in your browser you will see the names above carrying a __Secure- prefix. That is a standard browser marker meaning the cookie is only ever sent over an encrypted connection; it is the same cookie.

Analytics without cookies

We use Plausible Analytics to count visits and see which pages are useful. Plausible sets no cookies and stores nothing on your device, so it falls outside the consent requirement in PECR. It does not track you between websites and does not build a profile of you. Requests are proxied through our own server, so your browser never contacts Plausible directly. We rely on legitimate interests for this, and you can object at any time using the contact details above.

You can also block analytics entirely by enabling Do Not Track or a content blocker in your browser, or by using your browser’s Global Privacy Control setting where available.

Managing storage

You can clear or block cookies and site storage through your browser settings. Blocking the session cookie will prevent you from signing in to the member dashboard, but the public parts of the site will continue to work normally.

Emails and phone calls

Automated email from this website

This website sends transactional email only — messages you have asked for or that are needed to operate an account or booking:

  • sign-in links, when you request one;
  • RSVP confirmations, containing your booking details, a link to change or withdraw it, and — for online events — the joining link;
  • personal calendar-subscription links, when you request one; and
  • invitations to the member dashboard, sent by an organiser to an email address already held on our members or activists list.

No campaigning email is sent from this website, and no address collected here is passed to anyone else for marketing.

Campaigning and organising email

Separately from this website, we email local members and activists about party activity — campaigns, actions, local news and invitations to get involved. Those messages are sent through Action Network, the organising platform GPEW provides to local parties, from northderbyshire.greenparty.org.uk.

  • Consent. Under PECR, campaigning email to individuals needs your consent. That consent is collected and recorded through GPEW and Action Network when you join or sign up to hear from us — the “soft opt-in” that applies to businesses selling products is not available to political parties, so we do not rely on it.
  • Unsubscribing. Every message carries an unsubscribe link, which takes effect immediately and without charge. You can also reply to any message, or use the contact address at the top of this policy, and we will action it.
  • Withdrawing consent costs you nothing else. Opting out of campaigning email does not affect your membership, your account on this website, or transactional messages such as sign-in links.

Replies to people who contact us

If you email us — including through a contact link on a committee member’s or councillor’s profile — we will reply, and we may follow the matter up with you. That is correspondence, not marketing: we rely on legitimate interests, and we do not add you to a campaigning list because you got in touch.

Phone calls

We sometimes telephone members and activists — to invite people to an action, to follow up on something you have raised, or as part of local campaigning. Numbers come from the Action Network record, not from this website, which never asks for a phone number.

  • You can tell us to stop at any time, on the call itself or using the contact details above, and we will record that against your details.
  • Telephone Preference Service. PECR treats campaigning calls the same way it treats marketing calls. We do not make live campaigning calls to numbers registered with the TPS unless you have told us you are happy to hear from us.
  • No automated calls. We do not use recorded-message or auto-dialled calls, which would need your specific prior consent.

Where your data is processed

Our servers and database are hosted in Finland, in the European Union. We are established in the United Kingdom, so personal data routinely moves between the UK and the EU in both directions. Those transfers rely on the adequacy decisions the UK and the European Commission have made about each other, so no additional safeguard is required.

Two providers are based in the United States: our email delivery provider, and Action Network, the organising platform. Transfers there are made under the safeguards set out in the recipients table above. You can ask us for a copy of the relevant safeguards using the contact details at the top of this policy.

Our providers engage sub-processors of their own — a hosting company behind an email service, for example. They are bound by the same obligations down the chain, and each provider publishes its current list; where one is available we have linked it in the table above, so you can see who is involved rather than take our word for it.

The contract with Action Network is held by GPEW rather than by us, so the transfer safeguards for that platform are maintained by GPEW. We have set out what we understand them to be; GPEW’s own privacy policy is the authoritative account.

How we protect your data

  • All traffic to this site is encrypted in transit with HTTPS, and the database is not reachable from the public internet.
  • We never store passwords. Sign-in uses passkeys (cryptographic keys held on your own device) or single-use links sent to your email address. A passkey stores only a public key on our side; your biometrics and device PIN never leave your device and are never sent to us.
  • Access to the member dashboard and its administrative areas is restricted by role, and changes made through it are recorded in an audit log so misuse can be detected and undone.
  • Photographs uploaded through the dashboard are re-encoded on the server, which removes embedded metadata such as EXIF GPS coordinates before the image is published.
  • Joining links for online events are not shown publicly. They are sent only to people who have RSVP’d, to signed-in members, and to personal calendar subscriptions.
  • Canvass records and copies of the electoral register are held in our own party systems, and access is limited to the organisers running the campaign they relate to. They are never shared outside the party, and paper canvass sheets are destroyed once their contents have been recorded.

No online service can be completely secure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours and tell you directly where the risk is high.

Your rights

Under the UK GDPR and the EU GDPR you have the following rights. They are free to exercise, and we will respond within one month.

Your data protection rights
RightWhat it means here
AccessAsk for a copy of the personal data we hold about you, and information about how we use it.
RectificationHave inaccurate data corrected or incomplete data completed. You can edit your own name and profile in the dashboard.
ErasureAsk us to delete your data where we no longer need it, where you withdraw consent, or where you successfully object.
RestrictionAsk us to pause processing while a dispute about accuracy or our legitimate interests is resolved.
ObjectionObject to processing based on legitimate interests — including our analytics, and including our holding a canvass record about you — on grounds relating to your particular situation.
Stop campaigning contactTell us to stop emailing you, phoning you, or addressing campaign literature to you. This right is absolute — we do not weigh it against anything, and it takes effect straight away. Use the unsubscribe link in any message, say so on a call or at the door, or email us.
See your canvass recordAsk what we recorded when we canvassed you, including our estimate of how likely you are to support us, and have it corrected or deleted. Give us your name and address so we can find it.
Notice under paragraph 22Give us written notice requiring us to stop processing your data, with a reasonable period to comply. This is a right specific to political parties under the Data Protection Act 2018, and once the period ends we can no longer rely on that condition.
PortabilityReceive the data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller.
Withdraw consentWithdraw consent at any time where we rely on it, such as your personal calendar feed. This does not affect processing already carried out.
ComplainLodge a complaint with the ICO in the UK, or your local supervisory authority in the EU or EEA.

Some of these you can exercise yourself at any time: the member dashboard lets you edit your name, manage and revoke your passkeys, sign out of individual sessions, and withdraw consent you have granted to connected applications. Every RSVP confirmation email contains a link that lets you change or withdraw that RSVP without signing in.

To exercise any other right, email louis@hollingworth.nl. We may ask you to confirm your identity before we act, so that we do not disclose your data to someone else.

Complaints

If you think we have handled your data incorrectly, please tell us first so we can put it right. You also have the right to complain to a supervisory authority:

  • United Kingdom — the Information Commissioner’s Office, ico.org.uk, helpline 0303 123 1113.
  • European Union / EEA — the data protection authority in your country of residence, place of work, or where the issue occurred. The European Data Protection Board lists them all.

Children

This website is aimed at adults. We do not knowingly collect personal data from children under 13 through this site. Under the Data Protection Act 2018, 13 is the age at which a child in the UK can consent to information society services on their own behalf; in most EU countries that age is between 13 and 16. Young Greens membership is handled by GPEW, not through this website. If you believe a child has given us personal data, contact us and we will delete it.

Automated decision-making and profiling

We make no automated decisions that produce legal effects concerning you or similarly significantly affect you. Nothing is decided about you by an algorithm, and no software judges you.

We should be straightforward about one thing that does look like profiling, because it is. When we canvass, our canvasser records an estimate of how likely you are to support a Green candidate, and we use that estimate — along with what you told us about local issues — to decide which campaign leaflet is delivered to your address. That is political targeting, and calling it anything else would be misleading.

Its limits are worth stating precisely:

  • the estimate is a person’s judgement of a conversation, typed in by hand — it is not calculated, scored or inferred by software;
  • it decides which piece of party literature reaches your doormat, and nothing else — it affects no service, entitlement or decision about you;
  • it is built only from what you told us and the electoral register. We buy no commercial data, append nothing from data brokers, and use no Special Interest Group tags to segment anyone; and
  • it is never used to target online or social media advertising, and we upload no record of you to any advertising platform.

You can object to this at any time, and we will stop — see Surveys and canvassing for how, and what else you can ask for.

Separately, our organising platform is capable of segmenting a contact list by tag or by past activity. We use that only to send relevant organising messages — for example inviting people in one district to something happening there.

Changes to this policy

We may update this policy as the website changes or as guidance develops. The date at the top always shows when it was last revised. Where a change materially affects how we use your data, we will tell account holders by email before it takes effect.

Definitions and legal references

Personal data
Any information relating to an identified or identifiable living person — including an email address, an IP address, or an online identifier.
Special category data
Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation. Party membership falls into this category. Data that reveals one of these things by inference counts too, even if nobody set out to record it.
Accounting unit
A constituent organisation of a registered political party that is responsible for its own financial affairs, under section 26 of the Political Parties, Elections and Referendums Act 2000. NDGP is an accounting unit of GPEW rather than a separately registered party.
Full electoral register
The complete list of registered electors, including people who opted out of the publicly available version. Electoral registration officers supply it to registered political parties under reg 106 of the Representation of the People (England and Wales) Regulations 2001. It may be used only for electoral purposes and for complying with donation controls; any other use, or passing it to someone not entitled to it, is a criminal offence.
Canvassing
Asking electors, usually at the door or by telephone, what they think about local issues and how they intend to vote. The answers are recorded against the elector's entry and used to plan campaigning. Paragraph 22(4) of Schedule 1 to the Data Protection Act 2018 treats political surveys and campaigning as political activities of a party.
Special Interest Group
A group affiliated with GPEW for members with a shared identity or interest. Joining one is recorded as a tag on your GPEW record, which local organisers can see.
Controller
The organisation that decides why and how personal data is processed. For this website, that is North Derbyshire Green Party.
Processor
An organisation that processes personal data on the controller's instructions and cannot use it for its own purposes — for example our hosting and email providers.
Legitimate interests
A lawful basis under Article 6(1)(f) which requires us to balance our interest in processing against your rights, interests and reasonable expectations.
Cookie / local storage
Small pieces of information stored by your browser on your device. PECR treats both the same way, and both are covered by the table above.
Passkey
A cryptographic credential stored on your device that replaces a password. We hold only the public half; your biometrics never leave your device.
Supervisory authority
The regulator responsible for enforcing data protection law — the Information Commissioner's Office in the UK, and the national authority in each EU or EEA country.

In this policy, “UK GDPR” means the retained EU General Data Protection Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland, read with the Data Protection Act 2018. “EU GDPR” means Regulation (EU) 2016/679. “PECR” means the Privacy and Electronic Communications (EC Directive) Regulations 2003.