Privacy Policy

This Privacy Policy explains how Clwb Nawa collects, uses, and protects your personal data. It applies to all visitors and members of our website at clwbnawa.co.uk.

We are committed to protecting your privacy and handling your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Last updated: April 2025

1. Who We Are

Clwb Nawa is an unincorporated association based in Cardiff, Wales. We are a peer-led shibari and kinbaku community.

For the purposes of data protection law, Clwb Nawa is the data controller for the personal data we process about you.

Contact us: team@clwbnawa.co.uk

2. What Personal Data We Collect

We collect the following categories of personal data:

Account data

  • Email address
  • Display name or first name
  • Unique user identifier (UID) assigned by Firebase

Membership data

  • Membership status (e.g., pending, approved, admin)
  • VIP or elevated access status

Event booking data

  • Name, email address, and booking details collected when you purchase a ticket via Ticket Tailor

Shop and payment data

  • Name, delivery address, email address, and order details when you purchase from our shop
  • Payment card details are processed directly by Stripe and are not stored by us

Usage and analytics data

  • Anonymised data about how you use our website, collected via Google Analytics (including approximate location at country/region level, browser type, pages visited, and time spent on site)

Communications

  • Any personal data you include when you contact us by email

3. Special Category Data

Participation in shibari events may reveal information about your personal or sexual interests. This type of information is considered special category data under Article 9 of the UK GDPR.

We process this data only on the basis of your explicit consent, which you provide by choosing to register and participate in Clwb Nawa events. You may withdraw this consent at any time by contacting us.

We treat special category data with the highest level of care and do not share it with third parties except where strictly necessary (for example, confirming attendance at an event).

4. How and Why We Use Your Data

Purpose Data used Legal basis
Creating and managing your account Email, name, UID, membership status Performance of a contract
Processing event ticket bookings Name, email, booking details Performance of a contract
Processing shop orders and payments Name, address, email, order details Performance of a contract
Responding to your enquiries Email, message contents Legitimate interests
Improving the website and understanding usage Anonymised analytics data Legitimate interests
Keeping the website and accounts secure UID, session data Legitimate interests
Complying with legal obligations As required Legal obligation

5. Third-Party Processors

We use the following third-party services to operate the website. Each acts as a data processor on our behalf (or as a separate data controller in their own right):

  • Firebase / Google Cloud — authentication and database services. Data may be processed in the United States.
  • Google Analytics — anonymised website analytics. Data may be processed in the United States.
  • Ticket Tailor — event ticketing and booking management. Please also review Ticket Tailor's Privacy Policy.
  • Stripe — payment processing for shop orders. Stripe is the data controller for payment card data. Please review Stripe's Privacy Policy.

Where personal data is transferred to the United States, such transfers are made under appropriate safeguards including Standard Contractual Clauses (SCCs) or the UK-US Data Bridge, where applicable.

6. How Long We Keep Your Data

  • Account data — retained for as long as your account is active. You may request deletion at any time.
  • Event booking data — retained for up to 2 years for administrative and safety purposes.
  • Shop order data — retained for up to 7 years to meet legal and tax obligations.
  • Analytics data — retained in anonymised form for up to 26 months.
  • Email communications — retained for up to 2 years from the date of last contact.

7. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access — you can request a copy of the personal data we hold about you.
  • Right to rectification — you can ask us to correct inaccurate or incomplete data.
  • Right to erasure — you can ask us to delete your data (the "right to be forgotten") in certain circumstances.
  • Right to restriction — you can ask us to restrict how we use your data in certain circumstances.
  • Right to data portability — you can ask for your data in a structured, machine-readable format.
  • Right to object — you can object to processing based on legitimate interests, including profiling.
  • Rights related to automated decision-making — we do not make automated decisions with legal or significant effects based solely on your data.

To exercise any of these rights, please contact us at team@clwbnawa.co.uk. We will respond within one calendar month.

8. Cookies

We use cookies on this website. For full details of the cookies we use and how to control them, please see our Cookie Policy.

9. Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. These include secure authentication via Firebase, HTTPS encryption, and access controls on user data.

No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee its absolute security.

10. How to Complain

If you are unhappy with how we have handled your personal data, please contact us first at team@clwbnawa.co.uk and we will do our best to resolve the issue.

You also have the right to lodge a complaint with the UK's data protection supervisory authority:

Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113

11. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated date. We encourage you to review this policy periodically.