Legal
Privacy Policy
1. Who we are
Experience History is operated by Heritage Social, a platform dedicated to connecting people across the UK with museums, galleries, historic sites, heritage events, and local history communities. We can be reached at [email protected].
We are registered with the Information Commissioner's Office (ICO) under registration number ZB[XXXXXX]. [Update this when registration is confirmed.]
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what your rights are in relation to it. It applies to all users of the Experience History website at experiencehistory.co.uk.
2. Data we collect
We collect minimal personal data. The types of data we may collect are:
- Email address and name — if you sign up for our newsletter or submit an enquiry via our contact form.
- Browsing data — anonymised data about how you use our website, collected through Google Analytics. This includes pages visited, time spent on the site, approximate geographic location (country/region level), device type, and browser. IP addresses are anonymised before storage.
- Postcode — if you use the location search feature on our map, local history, or events pages. Your postcode is used only to perform the search and is not stored by us.
- Museum listing information — if you submit or claim a museum listing, we collect the details you provide about the institution. This may include a contact name and email for correspondence purposes.
We do not collect payment information directly. Any payments are processed by third-party providers whose own privacy policies apply.
3. How we use your data
We use the data we collect to:
- Send our newsletter to subscribers who have opted in to receive it.
- Respond to enquiries submitted through our contact form.
- Understand how visitors use Experience History so we can improve the platform.
- Manage museum listings submitted to or claimed through the platform.
- Comply with legal obligations.
We do not sell, rent, or trade your personal data with third parties for marketing purposes.
4. Legal basis for processing
Under the UK General Data Protection Regulation (UK GDPR), we rely on the following legal bases for processing personal data:
- Consent — for newsletter subscriptions. You may withdraw your consent at any time by clicking the unsubscribe link in any newsletter email or by contacting us directly.
- Legitimate interests — for analytics data used to understand and improve the platform. We have assessed that our legitimate interest in improving the service does not override your rights and freedoms, given that the data is anonymised.
- Contract — for processing data related to museum listings where a subscription agreement exists.
- Legal obligation — where we are required by law to process or retain data.
5. Third-party services
We use a small number of third-party services that may process data on our behalf or set their own cookies:
- Google Analytics (Google LLC) — we use Google Analytics to collect anonymised data about how visitors use the site. Google Analytics anonymises IP addresses. Google may process data in the United States under standard contractual clauses. You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on.
- OpenStreetMap / Leaflet — our interactive map uses map tiles served by OpenStreetMap contributors. Tile requests may include your IP address as part of a standard web request. See the OpenStreetMap Foundation Privacy Policy.
- postcodes.io — we use this free, open API to convert UK postcodes to geographic coordinates for location-based searches. No personal data is stored by postcodes.io in connection with these requests.
6. Data retention
We retain personal data only for as long as necessary for the purpose for which it was collected:
- Newsletter subscriber data is retained until you unsubscribe.
- Enquiry data is retained for up to 24 months, after which it is deleted unless an ongoing relationship requires it to be kept longer.
- Google Analytics data is retained for 26 months, as per our Google Analytics configuration.
- Museum listing data is retained for the duration of the listing and for up to 12 months after it expires or is removed, unless you request earlier deletion.
7. Your rights
Under UK GDPR, you have the following rights in relation to your personal data:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may ask us to correct inaccurate data.
- Right to erasure — you may ask us to delete your personal data in certain circumstances.
- Right to restriction — you may ask us to restrict how we process your data in certain circumstances.
- Right to data portability — where processing is based on consent or contract, you may request your data in a structured, machine-readable format.
- Right to object — you may object to processing based on legitimate interests.
- Rights related to automated decision-making — we do not make solely automated decisions that have legal or similarly significant effects on you.
To exercise any of these rights, please contact us at [email protected]. We will respond within one month. If you believe we have handled your data unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk or by calling 0303 123 1113.
8. Cookies
We use cookies and similar technologies. For full details of the cookies we use and how to manage them, please see our Cookie Policy.
9. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "last updated" date at the top of this page. For significant changes, we will make reasonable efforts to notify affected users. Continued use of Experience History after changes are posted constitutes acceptance of the revised policy.
10. Contact us
If you have any questions about this Privacy Policy or the way we handle your personal data, please contact us:
Email: [email protected]
Website: experiencehistory.co.uk
Privacy questions?
Get in touch with us at [email protected] and we will respond within one month.