West Sussex Weekly ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website westsussexweekly.com.
We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Please read this privacy policy carefully.
1. Data Controller
West Sussex Weekly is the data controller responsible for your personal data. If you have any questions about this privacy policy or our data practices, please contact us at:
Email: privacy@westsussexweekly.com
2. Information We Collect
2.1 Information You Provide
- Account Information: When you sign in with Google, we receive your email address, name, and profile picture from Google.
- Preferences: Your saved events, cookie preferences, and marketing opt-in choices.
2.2 Information Collected Automatically
- Device Information: Browser type, operating system, and device identifiers.
- Usage Data: Pages visited, time spent on pages, and interactions with the website (only if you consent to analytics cookies).
- Location Data: Approximate location based on IP address, or precise location if you grant permission for location-based event searches.
2.3 Cookies and Similar Technologies
We use cookies and similar tracking technologies to collect information. Please see our Cookie Policy for detailed information about the cookies we use.
3. How We Use Your Information
We use your information for the following purposes:
- Provide and maintain our service: Display events, save your favourites, and enable you to use website features.
- Personalisation: Remember your preferences and provide relevant event recommendations.
- Communication: Send you marketing emails about events (only if you have opted in).
- Analytics: Understand how users interact with our website to improve the experience (only with your consent).
- Legal compliance: Comply with legal obligations and protect our rights.
Legal Basis for Processing (UK GDPR)
- Consent: For marketing emails, analytics cookies, and marketing cookies.
- Contract: To provide the service you have requested (e.g., saving favourites).
- Legitimate Interests: For essential cookies and basic website functionality.
4. Data Sharing and Third Parties
We may share your information with:
- Google: For authentication (Google Sign-In) and AI-powered event search (Google Gemini). See Google's Privacy Policy.
- Supabase: Our database provider for storing user data securely. See Supabase Privacy Policy.
- Vercel: Our hosting provider. See Vercel Privacy Policy.
We do not sell your personal data to third parties.
5. Data Retention
We retain your personal data for the following periods:
- Account data: Until you delete your account.
- Cookie consent records: 1 year from the date of consent.
- Marketing consent records: 7 years (for legal compliance and audit purposes).
- Event data: 12 months after the event date.
6. Your Rights (UK GDPR)
Under UK GDPR, you have the following rights:
Right to Access
Request a copy of your personal data we hold.
Right to Erasure
Request deletion of your personal data ('right to be forgotten').
Right to Portability
Receive your data in a structured, machine-readable format.
Right to Rectification
Request correction of inaccurate personal data.
To exercise any of these rights, please contact us at privacy@westsussexweekly.com. We will respond within one month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (HTTPS/TLS)
- Secure authentication via Google OAuth
- Row-level security policies in our database
- Regular security reviews and updates
However, no method of transmission over the Internet is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security.
8. Children's Privacy
Our website is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13. If you believe we have collected data from a child under 13, please contact us immediately.
9. International Data Transfers
Our service providers may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the UK ICO
- Adequacy decisions by the UK government
- Provider-specific data protection agreements
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by:
- Displaying a notice on our website
- Updating the "Last updated" date at the top of this policy
- Sending you an email (if you have an account)
We encourage you to review this Privacy Policy periodically.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us:
Email: privacy@westsussexweekly.com
We aim to respond to all enquiries within 48 hours.