Legal

Privacy Policy

What personal data the club collects, why we need it, how long we keep it, and the rights you have over it.

Last updated: this policy applies to the current version of the Masters Club International website and membership system. It is written to align with the UK GDPR and the Data Protection Act 2018.

1. Who we are

Masters Club International (“the club”, “we”) is a membership organisation based in Birmingham, United Kingdom, operating under the mission “Sharing Skills, Changing Lives”. For the personal data described here, the club is the data controller. Data protection questions can be sent through the Contact page.

2. What personal data we collect

  • Account data: email address, password (stored only as a salted hash by our authentication provider), and sign-in timestamps.
  • Application data: full name, email, phone number, country and address details, date of birth where provided, chosen membership category, occupation or organisation, the skills you can teach, the skills you want to learn, and any statement of interest you write.
  • Documents you upload: identity or eligibility documents, photographs and payment evidence (for example a bank transfer receipt) attached to your application.
  • Payment reference data: the transfer reference, amount, date and paying-account name you declare. We do not collect or store card numbers; fees are paid by bank transfer directly to the club’s account.
  • Membership record: membership number, category, status, issue date and valid-through date.
  • Correspondence: messages you send us and the emails we send you about your application or membership.
  • Technical data: minimal server logs needed to keep the site secure and available. We do not use advertising or cross-site tracking.

3. Why we use it, and our lawful basis

  • Assessing your application — necessary to take steps at your request before entering a contract.
  • Issuing and administering membership, including your membership letter and renewal reminders — performance of the membership contract.
  • Answering public verification requests with a minimum data set — legitimate interests in allowing employers and partners to confirm that a membership is genuine.
  • Keeping accounts, records and safeguarding obligations — legal obligation and legitimate interests.
  • Security, fraud prevention and abuse of the verification tool — legitimate interests.
  • Optional newsletters or event invitations — consent, which you can withdraw at any time.

4. What is visible publicly

The public verification tool returns only the member number, full name, membership category, status and valid-through date, and only when someone enters an exact membership number. It cannot be browsed or listed. Your email, phone number, address, uploaded documents, payment details and application content are never public and are not visible to other members.

5. Who can see your data inside the club

Access is limited to authorised committee members and administrators who review applications and verify payments. Every administrative action is tied to a signed-in account, and database access rules block members from reading anyone else’s record.

6. Processors and third parties

  • Hosting and database provider — stores the site, the membership database and uploaded documents.
  • Email delivery provider — sends application, approval and membership emails on our behalf.

These providers act on our instructions under a data processing agreement. We do not sell personal data or share it for marketing. We disclose data to authorities only where the law requires it.

7. International transfers

Where a provider processes data outside the UK, the transfer is covered by UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses.

8. How long we keep it

  • Unsuccessful or withdrawn applications — up to 12 months from the decision, then deleted, unless you ask us to delete them sooner.
  • Active membership records — for as long as the membership continues.
  • Lapsed memberships — up to 6 years after the membership ends, so that past membership can be verified and to meet accounting requirements.
  • Uploaded identity and payment documents — deleted once the membership has been activated and the payment reconciled, unless a longer period is legally required.

9. Security

Data is transmitted over HTTPS, stored in an access-controlled database with row-level security, and privileged operations run only through server-side code that re-checks the caller’s administrator role. Uploaded documents are held in a private storage bucket that is not publicly readable.

10. Your rights

You have the right to be informed, to access a copy of your data, to have inaccurate data corrected, to erasure, to restrict or object to processing, to data portability, and to withdraw consent where consent is the basis. Contact us and we will respond within one month. If you are not satisfied you can complain to the Information Commissioner’s Office (ico.org.uk).

11. Children

Student and youth applicants under 18 must have a parent or guardian complete or approve the application, and we collect no more data than the category requires.

12. Changes to this policy

We will post any change on this page, and notify members by email where the change materially affects how their data is used.

The registered legal entity name, registered address and named data protection contact will be inserted here once the club confirms them.