Privacy Policy
Last updated: May 2026
This policy explains what personal data Woodies’ Workshop collects, why we collect it, and what rights you have. We only collect what we genuinely need to run your membership.
1. Who We Are
Woodies’ Workshop operates the website at woodies-workshop.co.uk and is the data controller for the personal information collected through it.
Contact: luke@woodies-workshop.co.uk
2. What Data We Collect
When you create an account
- Display name
- Email address
- Username
- Password (stored as an encrypted hash — we cannot see your actual password)
When you use the site
- Login timestamps and session data
- IP address (held in server logs for security purposes)
- Browser type and device type (held in server logs)
When you contact us
- Your name and email address as provided
- The content of the message
We do not collect payment card details. If membership payments are introduced in future, they will be handled by a third-party payment processor under their own privacy terms, and this policy will be updated.
3. Why We Collect It
Under UK GDPR, we must have a lawful basis for processing personal data. We rely on the following:
- Contract performance — to create and manage your account and send transactional emails (welcome email, password reset).
- Legitimate interests — to maintain site security and prevent unauthorised access, including server log retention.
- Legal obligation — where we are required to retain data by law.
4. How We Use Your Data
- To create and manage your member account
- To send transactional emails relating to your account
- To respond to any enquiries you send us
- To maintain site security and prevent unauthorised access
We do not use your data for automated decision-making or profiling.
5. Who We Share It With
We do not share your personal data with any third parties. Your data is held on the servers hosting this site and is not passed to marketing, analytics, or advertising platforms.
If this changes, we will update this policy and notify you before any sharing takes place.
6. How Long We Keep It
- Account data — retained for as long as your account is active. Deleted within 30 days of account closure.
- Server logs — retained for up to 90 days for security purposes, then deleted.
- Email communications — retained for up to 2 years, then deleted.
7. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right of access — request a copy of the data we hold about you.
- Right to rectification — ask us to correct inaccurate or incomplete data.
- Right to erasure — ask us to delete your data, subject to any legal retention obligations.
- Right to restrict processing — ask us to pause processing your data in certain circumstances.
- Right to data portability — request your data in a structured, machine-readable format.
- Right to object — object to processing carried out on the basis of legitimate interests.
To exercise any of these rights, email luke@woodies-workshop.co.uk. We will respond within 30 days.
8. Cookies
For details on how we use cookies, see our Cookie Policy.
9. Data Security
We take reasonable technical and organisational steps to protect your data. Passwords are never stored in readable form. Access to site administration is restricted and secured.
If you believe your account has been compromised, contact us immediately at luke@woodies-workshop.co.uk.
10. Changes to This Policy
If we make material changes to how we handle your data, we will update this page and revise the date at the top. We will notify you by email if changes significantly affect your rights.
11. Complaints
If you are unhappy with how we have handled your data, please contact us first at luke@woodies-workshop.co.uk and we will do our best to resolve it.
You also have the right to complain to the UK’s data protection authority:
Information Commissioner’s Office (ICO)
ico.org.uk/make-a-complaint
0303 123 1113
