Some of our database (but not all) choose to join our online community by registering on this website and creating an online profile. In both instances (individuals with offline database records and individuals with online profiles), with your permission, we collect and store personal information (or “data”) about you. We are committed to protecting and respecting your privacy and this Policy sets out what information we collect about you, where and how we use (“process”) it.
We may change this Policy from time to time. If we make any significant changes we will advertise this on the website or contact you directly with the information.
For the purposes of the General Data Protection Regulations (GDPR) and any subsequent UK legislation covering data protection, the Data Controller is Michael Gibson, Bursar of John Lyon School.
What type of personal information we collect
Below is a summary of the information we may hold about you. For some of you we have this information but for many we do not have complete records:
- your personal and contact details (name, date of birth, address, email, telephone numbers);
- educational history (dates you were at John Lyon School and awards or offices you held);
- details of your interactions with the School and Old Lyonian Association, including events you have been invited to, communications from you and to you, your relationships with other alumni (e.g. relatives), and any history of giving to the School (including volunteering and financial contributions);
- your communication preferences, to help us send information in the most appropriate format;
- details about your further education, career and interests (this helps us to identify the sorts of information or events you might be interested in receiving information about).
- Donations made to John Lyon and any record of payments made via the website (but we do not store your credit/ debit card details as these are processed securely externally by a third-party payment provider) which could include event tickets, shop purchases or online donations
- Geo-location data (your geographical location based on your IP address)
- Log-ins and activity on the website
- Content (such as announcements, stories, photos, documents, comments, events, jobs) that you post on this website or provide to us by other means
- Messages that you send to other community members via the direct messaging system when logged in to this website
Where we collect information from
We collect personal information when you:
- visit this website
- create or update your online profile
- post content on to this website or other websites and social media sites managed by John Lyon School
- take part in an event
- attend a meeting with us and provide us with information
- contact us in any way including online, email, phone, SMS, social media or post
- open an email sent from this website
- send a message via the direct messaging system on this website
- leave John Lyon School and we transfer some basic details about you from the main School database iSams in to our alumni database
How we use your information
We will use your personal information in a number of ways, always with a legal basis for processing your data. These may include:
- providing you with the information or updates that you have asked for
- sending you communications (with your consent if required) that may be of interest, including invitations to events, newsletters and fundraising campaigns
- delivering our obligations under any contract between us
- seeking your views on the services or activities we carry out, so that we can make improvements
- updating our database records and ensuring we know how you prefer to be contacted
- analysing your engagement with our website and other content to help us improve our services for you
- running our mentoring programme/ club activities/ reunion events/ sports fixtures
Our legal basis for processing your information
The use of your information for the purposes set out above is lawful because one or more of the following applies:
- you have given us your consent for the information to be used
- it is necessary for us to hold and use your information to carry out our obligations under a contract entered into with you
- it is necessary for our legitimate interests to hold and use your information and we are not impacting your privacy by doing so
Updating your consent preferences
If you have an online profile on this website you can update your consent options by logging-in and clicking on “My Settings” in your profile. Scroll down to find your ‘Consent options’ where you will see a list of consents and the options “opt-in”, “opt-out” and “unspecified”.
Via ‘My Settings’ you can also choose to hide your profile from Google, limit access to your profile so that it’s only viewable to your connections and adjust some of the automatic notifications that you receive from this website. Please note that your name (but not full profile) may appear in various places around the community website, such as a ‘Recent Joiners’ box and in ‘Search’ results irrespective of the privacy settings you have selected.
If we are using consent as our legal basis for processing your data, we must have an explicit “opt-in” from you for this specific type of processing.
If we are using legitimate interests as our legal basis for processing your data, we will process your data responsibly in a way that you would reasonably expect, and you can opt-out at any stage.
If you want to contact us about your consent preferences please contact firstname.lastname@example.org.
How we keep your information safe
We understand the importance of keeping your personal information secure and take appropriate steps to safeguard it.
Your data is stored on a dedicated, secure cloud server hosted by Amazon Web Services (AWS) in the EU and managed by our website provider, ToucanTech. Industry standard firewalls, anti-virus, encryption and back-up methods are in place, as well as strict data handling protocols.
We always ensure only authorised persons have access to your information, which means only our approved employees and contractors, and that everyone who has access is appropriately trained in data management.
If you have an online profile for this website you are responsible for keeping your login details (email and password) confidential and we ask that you do not share your password with anyone.
No data transmission over the internet can be guaranteed to be completely secure. So, whilst we strive to safeguard your information, we cannot guarantee the security of any information you provide online and you do this at your own risk.
Personal information will not be shared with third parties outside the School or with any other members of the Lyonian Association without your permission. Personal information is held in accordance with the provisions of the Data Protection Act 2018. We will review consent periodically to provide the opportunity for you to amend or update your choices.
Who has access to your information?
- Third parties who provide services for us. We select our third-party service providers with care. We provide these third parties with the information that is necessary to provide the service and we will have an agreement in place that requires them to operate with the same care over data protection as we do
- Third parties if we run an event in conjunction with them. We will let you know how your data is used when you register for any event
- Web hosting, email hosting, analytics and search engine providers that enable us to run our community database and improve our website and its use
- Third parties in connection with restructuring or reorganisation of our operations, for example if we merge with another business. In such event, we will take steps to ensure your privacy rights will be protected by the third party
Other than this, we will not share your information with other organisations without your consent.
Keeping your information up to date
Please would you let us know if your contact details change. Online members can update your details directly by logging-in to the website and clicking on ‘My Settings’ under your profile. Otherwise, please send an email to email@example.com.
The law states that we can store cookies on your machine if they are essential to the operation of the website, but that for all others we need your permission to do so.
The list below explains the cookies we use and why:
|Session Cookie||John Lyon_Member_Code |
|Used to remember you as you travel from page to page in a single session (without leaving the website) in order to provide a continuous and unified experience|
|Functional Cookie||John Lyon_Identify||Used to remember your login details when you return to the website after previously logging out, by storing them in your browser. This cookie is turned off by default and is only activated when you select the ‘Remember Me’ check box during login.|
Opting out of cookies
If you do not wish to receive cookies from us or any other website, you should be able to turn cookies off on your web browser: please follow your browser provider’s instruction in order to do so. Unfortunately, we cannot accept liability for any malfunctioning of your computer or its installed web browser as a result of any attempt to turn off cookies.
Use of aggregated data
Where data can be aggregated and anonymised, our website provider (ToucanTech) might use this for research purposes without restriction. For example, they may monitor traffic patterns, site usage, response rates and data trends to help make improvement to the website software. They are entitled to do this because the resulting data will not personal identify you and will therefore no longer constitute personal data for the purposes of data protection laws.
How long we keep your information for
We will hold your personal information for as long as it is necessary for the relevant activity.
Where we rely on your consent to contact you for direct email marketing/ fundraising purposes, we will treat your consent as lasting only for as long as it is reasonable to do so. This will usually be for two years. We may periodically ask you to renew your consent.
If you ask us to stop contacting you, we will keep a record of your contact details and the limited information needed to ensure we comply with your request. If you ask us to remove your personal data from our database we will delete all the information we hold out apart from your name and the dates that you attended John Lyon.
At any time, you can request a copy of the information we hold about you, ask us to remove your personal information from our records, object to the processing of your information, and raise a concern or complaint about the way in which your information is being used. Such requests have to be made in writing by contacting us below.
If you withdraw your consent to us keeping and processing your data, we will keep a record of your preference.You also have the following rights:
- to request rectification of information that is inaccurate or out of date;
- to erasure of your information (the “right to be forgotten”);
- to restrict the way in which we are dealing with and using your information;
- to request that your information be provided to you in a format that is secure and suitable for re-use (the “right to portability”);
- in relation to automated decision making and profiling.
If you are unhappy with something that we have done or have failed to do, please do let us know. Write to us at the Lyonian Association Office, Le Beau House, 76 West Street, Harrow-on-the-Hill, HA1 3ER or Suzannah.firstname.lastname@example.org or telephone 020 8515 9410. If you are not happy with the way in which we have processed or dealt with your information,you can complain to the ICO or Fund Raising Regulator.
For a full version of the John Lyon Privacy Notice, please click here.
This Policy was last updated in March 2019.