Privacy Policy
Last updated: 18 May 2026.
This Privacy Policy explains how London Inter-Club (“LIC”, “we”, “us”) handles personal data of members and applicants. We are the data controller for the purposes of UK GDPR and the Data Protection Act 2018.
1. What data we collect
- Identity: name, title, and the London clubs you are a member of.
- Contact: email address and phone number.
- Membership history: when you joined LIC, your role (member / rep / admin), and which LIC events you have RSVP'd to or attended.
- Payments: records of payments made to LIC for event participation (amounts, dates, methods). We do not store card numbers.
- Audit trail: login events and material changes you make through the site, for security and dispute resolution.
- Proof of membership: if you applied to join LIC, the documents you uploaded to evidence your London club membership.
2. Why we hold it
- Running events: producing guest lists, knowing capacity, communicating about your RSVP.
- Communications: sending you event invitations, updates, and account-related emails (password resets, deletion confirmations).
- Audit and dispute: resolving questions about payments, attendance, and account access.
3. Lawful basis
We rely on the following lawful bases under UK GDPR Article 6:
- Contract (Art. 6(1)(b)) — to deliver the events you have agreed to attend.
- Legitimate interests (Art. 6(1)(f)) — running the LIC organisation, keeping audit records, and protecting the security of the site.
- Consent (Art. 6(1)(a)) — for any marketing communications you have specifically agreed to.
4. How long we keep it
While you are a member of LIC we keep your data as described above. After you cease to be a member:
- Personal identifiers (name, email, phone) are removed within 30 days of a deletion request being processed.
- Past event attendance is anonymised (your row remains as “Former Member” so aggregate counts stay accurate, but no personal data is retained).
- Payment records are retained for 6 years (UK financial-record law) but stripped of personal references.
- The audit log is retained for 2 years for security purposes, with your identity removed at deletion.
5. Where it lives and who can see it
Your data is stored on UK-based servers operated by Krystal Hosting Ltd. Krystal acts as a data processor on our behalf; they do not access your data except as needed to operate the server infrastructure. We do not share your data with any other party except where required by law.
Personal fields (name, email, phone) are stored encrypted at rest using AES-256-GCM. The encryption key is held separately from the data.
6. Your rights
Under UK GDPR you have the right to:
- Access — obtain a copy of the data we hold about you. Members can self-serve via the “Download my data” button on the account page.
- Rectification — correct inaccurate data. Members can edit their profile directly.
- Erasure — request deletion of your data. Members can submit this via the account page; admins process within 30 days.
- Restriction — ask us to limit how we use your data.
- Objection — object to processing based on legitimate interests.
- Portability — receive your data in a machine-readable format (the JSON export covers this).
7. Contact
To exercise any of these rights, email admin@londoninter-club.co.uk.
8. Complaints
If you are unhappy with how we handle your data you have the right to complain to the Information Commissioner's Office (ICO): https://ico.org.uk/.