Chain of Deeds ← Back to the chain

Legal

Privacy Policy

Last updated 14 September 2026 · Version 1.1

This notice explains what personal data we hold about you, why we hold it, who we share it with, how long we keep it and what you can do about it. It is written to the UK GDPR and the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025.

1. Who we are

Chain of Deeds Ltd is the data controller for the personal data described in this notice. We are registered in England and Wales under company number 15529163, with our registered office at 35 Ovington Square, London SW3 1LJ.

You can reach us about anything in this notice at admin@chainofdeeds.com, or by post at the address above marked for the attention of the Data Protection Lead.

If you would like your enquiry directed to the person responsible for data protection, mark it for the attention of the Data Protection Lead.

2. The law this notice is written to

We follow the UK General Data Protection Regulation and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, together with the Privacy and Electronic Communications Regulations 2003 for cookies and electronic marketing.

3. What we collect, why, and on what lawful basis

3.1 When you join the chain

What: your name, email address, country, chain number, membership start date, contribution amount and currency, billing anniversary, payment status, and the last four digits and card type returned to us by our payment processor. If you choose to leave a dua, that text.

Why: to create and run your membership, take payment, issue your chain number, send the notices we have promised you, and keep proper records.

Lawful basis: performance of a contract with you (Article 6(1)(b)). For fraud prevention and record keeping, our legitimate interests (Article 6(1)(f)) and our legal obligations (Article 6(1)(c)).

A dua is optional and is free text. Please do not include health information, religious detail about identifiable third parties, or anything else you would not want stored. We treat duas as ordinary personal data and do not analyse them.

3.1A When a membership is held for a child

What: the child's first name, and the chain number issued in that name. Nothing else. No date of birth, no contact details, no images.

Why: so the membership can be dedicated to them and their place in the chain recorded.

Lawful basis: performance of our contract with the adult member (Article 6(1)(b)). The contract is with the adult, not the child.

We never contact the child, never market to them, never profile them, and never share their first name with any partner organisation. It appears in no published audit report.

3.2 When you buy merchandise

What: your name, delivery address, billing address, email, phone number where you give one, order contents, sizes, order value and delivery country.

Why: to take your order, deliver it, handle returns and refunds, and meet our tax and accounting obligations.

Lawful basis: performance of a contract (Article 6(1)(b)); legal obligation for tax and customs records (Article 6(1)(c)).

3.3 When you register your interest

What: whether you are registering as an individual or an organisation, your name, organisation name, email, contact number, Instagram handle, how you would like to be involved, and your message.

Why: to respond to you and to consider working with you.

Lawful basis: your consent (Article 6(1)(a)), which you give by ticking the box on the form. You may withdraw it at any time and we will stop contacting you.

3.4 When you contact us

What: your name, email, topic, message and any file you attach.

Why: to answer you and to keep a record of what was asked and what we said.

Lawful basis: our legitimate interests in responding to enquiries and running the organisation properly (Article 6(1)(f)).

3.5 When you visit the site

What: aggregate usage statistics, and the technical data your browser sends, including IP address, device type and pages viewed.

Why: to keep the site secure and to improve it.

Lawful basis: our legitimate interests in the security and improvement of our own service (Article 6(1)(f)). See our Cookie Policy for what is stored on your device and how to refuse it.

3.6 Marketing

We will send you service messages about your membership or your order whether or not you have opted into marketing — you cannot unsubscribe from a receipt or a notice that money is about to leave your account. Marketing about the movement is separate, is never pre-ticked, and is sent on the basis of your consent or, where you have bought from us, the soft opt-in permitted by PECR for similar goods. Every marketing message carries an unsubscribe link that works.

3.7 What we never collect

We do not receive or store your full card number, expiry date or security code. Those go directly to our payment processor. We do not collect special category data, and we do not knowingly collect data from anyone under 16 other than the first name of a child a parent has dedicated a membership to.

4. Automated decision-making

We do not make decisions about you by solely automated means that produce legal effects or similarly significantly affect you. Our payment processor operates automated fraud screening on transactions; if a payment is declined on that basis you can contact us and a person will look at it.

5. Who we share it with

We do not sell your personal data. We do not share it with advertisers. There is no advertising on this site.

We put a written data processing agreement in place with every provider that handles personal data on our behalf, and we keep the list under review. You may ask us who they are at any time.

6. Sending data outside the UK

Some of our providers are based outside the United Kingdom, including in the United States and the European Economic Area. Where we transfer personal data outside the UK we rely on UK adequacy regulations where they apply, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. You may ask us for a copy of the safeguards we rely on.

7. How long we keep it

8. Your rights

Under the UK GDPR you have the right to be informed; the right of access; the right to rectification; the right to erasure; the right to restrict processing; the right to data portability; the right to object, including an absolute right to object to direct marketing; and rights relating to automated decision-making.

Where our basis is consent, you can withdraw it at any time without affecting anything we did before you withdrew it.

To exercise any of these, write to admin@chainofdeeds.com. We will respond within one month. If your request is complex we may extend that by up to two further months, and we will tell you why within the first month. We may need to confirm your identity first, and where we do, the clock pauses until you have confirmed it. There is no charge unless a request is manifestly unfounded or excessive.

9. Complaining to us about data protection

You have a statutory right, under section 164A of the Data Protection Act 2018, to complain directly to us if you think we have handled your personal data in breach of the UK GDPR. You do not have to go to the regulator first.

How to complain. Email admin@chainofdeeds.com with "Data protection complaint" in the subject line, or write to us at the registered office above. You can also raise it by any other means — a message through the contact form is enough. Please tell us what happened, when, and what you would like us to do.

What we will do. We will acknowledge your complaint within 30 days of receiving it. We will investigate it, take appropriate steps, and tell you the outcome without undue delay. Complaints are logged and owned by our Data Protection Lead.

If you are not satisfied. You may complain to the Information Commissioner's Office at any time, whether or not you have complained to us first. Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline 0303 123 1113. ico.org.uk. Complaining to the ICO does not affect your right to a legal remedy.

10. How we protect your data

The site is served over HTTPS. Payment data is handled by a PCI DSS compliant processor and does not touch our servers. Access to member records is limited to people who need it. We keep a record of processing activities, and we will notify the ICO of a reportable personal data breach within 72 hours of becoming aware of it, and tell you directly where the breach is likely to result in a high risk to your rights and freedoms.

11. Children

You must be 16 or over to become a member or to buy from us. Members aged 16 and 17 are children in data protection law, and we treat their data on that basis.

A parent or guardian may dedicate a membership to a child under 16. Where they do, we hold the child's first name only, provided to us by the adult. We do not knowingly collect any other personal data from or about a child, and we do not knowingly accept registrations made by under-16s in their own name.

We have assessed this against the Information Commissioner's Age Appropriate Design Code. Because we hold a first name and nothing else for a dedicated child membership, collect the same limited data from a 16 or 17 year old member as from any adult, do not profile, do not use location data and serve no advertising, the risk to children is low by design. We keep that assessment under review, and we carry out a data protection impact assessment before introducing any feature that would change it.

Retention: a child's first name is held for as long as the membership runs, and deleted within 30 days of cancellation, unless the young person has by then taken the membership into their own name.

If you are 16 or 17. We ask you to confirm at checkout that a parent or guardian knows you are joining. We record that confirmation and nothing else about them — no name, no contact details. We do not contact your parent.

If you are under 18 and live in California. Section 22581 of the California Business and Professions Code gives you the right to ask us to remove anything you have posted or provided. Write to us and we will remove it. This right is yours in California; we extend it to every member under 18 wherever they live, because there is no good reason not to.

If you believe we hold data about a child that we should not, write to admin@chainofdeeds.com and we will delete it.

12. Changes to this notice

We will update this page when our processing changes. Where a change is significant we will tell members by email rather than relying on you to notice. The date at the top tells you when it last changed, and we keep previous versions on request.