Privacy Policy
This Privacy Policy explains how CESRA collects, uses and protects your personal data. Please read it carefully. By using our website or applying for membership you confirm that you have read and understood this policy.
1. Who we are
CESRA (the Central England Society of Refrigeration and Air Conditioning) is a professional membership body representing engineers, technicians and businesses in the refrigeration and air conditioning sector.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, CESRA is the data controller for the personal information we hold about you.
Contact details:
Central England Society of Refrigeration and Air Conditioning (CESRA)
76 JILLCOT ROAD
SIOLIHULL
WEST MIDLANDS
B92 8JG
Email: info@cesra.org
Website: www.cesra.org
Our data controller registration number with the Information Commissioner’s Office (ICO) is: [Add ICO registration number here once registered at ico.org.uk/registration]
2. The information we collect
When you apply for membership
- Full name, email address, phone number
- Business / employer name and job title
- Postal address
- Membership grade applied for
- Professional qualifications and experience (if provided)
When your membership is active
- Everything collected at application
- Your CESRA membership number, grade and renewal date
- CPD (Continuing Professional Development) activity records you submit
- Payment records (when payment functionality is enabled)
When you sign up to our launch notification list
- Name and email address
Automatically when you visit our website
- IP address (via web server logs and Google Fonts — see Cookies section)
- Browser type and version, operating system
- Pages visited and time on site
CESRA does not currently use website analytics tools (such as Google Analytics).
3. How we use your information
Membership administration — lawful basis: contract
We process your membership data to manage your membership, issue your membership certificate, send renewal reminders, maintain the member directory, and provide access to member benefits and the online portal.
CPD records — lawful basis: contract / legitimate interests
We process CPD submissions to maintain your professional development record and issue CPD certificates where applicable.
Member communications — lawful basis: legitimate interests
We send renewal reminders, important membership notices, and information about CESRA events and activities. You may opt out of non-essential communications at any time by contacting us.
Website operation — lawful basis: legitimate interests
We process server log data (including IP addresses) for security, abuse prevention and troubleshooting.
Launch notification list — lawful basis: consent
We use your email address and name solely to notify you when the CESRA website and membership portal go live. You may withdraw your consent and request removal from this list at any time by emailing info@cesra.org.
4. How we share your information
Member Directory
If you are an active member, your name, membership grade, company, job title and city/county may be displayed publicly on our Member Directory. No email address, telephone number or postal address is shown publicly. You can request to be excluded from the directory at any time by emailing info@cesra.org.
Web hosting provider
Our website is hosted in the UK. Our hosting provider processes web server logs and has access to stored data as a data processor acting on our instructions, under a data processing agreement.
Google Fonts
Our website loads fonts from Google’s servers (fonts.googleapis.com). When your browser requests these fonts, your IP address is transmitted to Google Inc. Google states it does not use this data for advertising and does not set cookies via Google Fonts. For details, see Google Fonts Privacy FAQ. We intend to switch to locally-hosted fonts in the near future to eliminate this transfer.
Payment processing (future)
When payment functionality is enabled, card payments will be processed by Stripe Inc. CESRA does not store card details — all payment data is handled by Stripe under their own privacy policy and PCI DSS compliance framework.
Legal requirements
We may disclose your information where required to do so by law, court order, or in connection with legal proceedings.
We do not sell, rent or trade your personal information to any third party.
5. How long we keep your information
| Data | Retention period |
|---|---|
| Active member records | Duration of membership + 7 years |
| Pending applications (not approved) | 12 months |
| Lapsed or cancelled member records | 7 years from last activity |
| CPD records | 7 years |
| Launch notification list | Until you request removal or until the list has been used for its stated purpose |
| Web server logs | 30 days |
6. Cookies
Please see our Cookie Policy for full details. In summary:
- We use strictly necessary cookies to manage your login session when you access the Member Portal.
- We do not use advertising, tracking or analytics cookies.
- Our website loads fonts from Google’s servers, which involves a transfer of your IP address (see above).
7. Your rights
Under the UK GDPR and the Data Protection Act 2018, you have the following rights:
- Right of access — You can request a copy of the personal data we hold about you (a “subject access request”).
- Right to rectification — You can ask us to correct inaccurate or incomplete data.
- Right to erasure — You can ask us to delete your personal data where there is no overriding legal reason to keep it.
- Right to restriction — You can ask us to limit how we use your data in certain circumstances.
- Right to data portability — You can request a copy of your data in a structured, machine-readable format.
- Right to object — You can object to processing based on legitimate interests.
- Right to withdraw consent — Where we rely on your consent (e.g. the notify list), you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
CESRA does not make automated decisions about individuals (including profiling) that have a legal or similarly significant effect.
To exercise any of these rights, please contact us at info@cesra.org. We will respond within one calendar month. We may ask you to verify your identity before fulfilling a request.
8. International transfers
Your personal data is stored on UK-based servers. The only transfer of data outside the UK currently is the IP address transfer to Google when loading fonts (see Section 4). Google operates under standard contractual clauses and other safeguards approved under UK GDPR for international transfers.
When Stripe is enabled, payment data will be transferred to the United States under Stripe’s standard contractual clauses.
9. How to complain
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the UK’s supervisory authority:
Information Commissioner’s Office (ICO)
Website: ico.org.uk
Telephone: 0303 123 1113
Post: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would always appreciate the opportunity to resolve any concern directly — please contact us at info@cesra.org in the first instance.
10. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will post the updated policy on this page with a new “last updated” date. Where changes are significant, we will notify active members by email. We encourage you to review this page periodically.