Privacy Policy
We respect your privacy and are committed to handling personal data lawfully, fairly, and transparently in line with UK GDPR, the Data Protection Act 2018, and PECR where applicable.
GDPR means the UK General Data Protection Regulation. PECR means the Privacy and Electronic Communications Regulations.
Last updated: 08 April 2026
On this page
Quick Summary (Plain Language)
- We only collect the minimum data needed to reply to you and keep the website secure.
- We do not sell your personal data to third parties.
- You can change optional cookie choices at any time in cookie preferences.
- You can ask to access, correct, or delete your data where the law allows.
Handled in line with UK GDPR
This policy explains how we apply UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR) to our digital services.
Data Controller
Ceredigion Network
Email: privacy@ceredigion.net
What Data We Collect
- Contact data you submit via forms (e.g., name, email)
- Pseudonymous website usage data when you allow analytics cookies
- Necessary cookies to enable essential functionality
- Analytics/marketing cookies with your prior consent only
Legal Basis for Processing
We process your personal data based on:
- Consent: For analytics and marketing cookies (prior consent required)
- Contract Performance: To provide services you have requested
- Legitimate Interests: To operate, secure, and improve the website where those interests are not overridden by your rights and freedoms
- Legal Obligation: To comply with legal requirements
Cookies & Consent
We use a cookie consent banner so you can accept, reject, or tailor non-essential cookies. We do not load analytics or marketing tools until you opt in, and you can change or withdraw consent at any time.
See also our Cookie Policy for full details.
How We Use Data
We use your personal data to provide and improve services, respond to enquiries, and maintain security. We will never sell your data to third parties.
Analytics & Session Recording
When you consent to analytics cookies, we may use the following services:
- Google Tag Manager: To load analytics tags only after consent and pass consent signals to Google services.
- Google Analytics 4: To measure visits, page views, device types, and aggregate engagement trends.
- Microsoft Clarity: If enabled in our configuration, to understand user interactions (clicks, scrolls, mouse movements) and identify usability issues. Clarity supports consent withdrawal and stops writing cookies when consent is withdrawn.
We do not use advertising or remarketing tags at the time of writing. If that changes, they will stay switched off until you opt in to marketing cookies.
You can opt-out at any time by rejecting analytics cookies in your .
Data Retention
We retain personal data for as long as necessary for the purposes it was collected, or as required by law:
- Contact data: up to 3 years after last contact
- Cookie consent and language preference data: up to 12 months
- Analytics identifiers: according to the cookie lifespan or until consent is withdrawn
- Clarity data: up to 90 days
- Security/log data: up to 6 years (legal obligations)
Your Rights Under UK GDPR
You have the following rights under UK GDPR and the Data (Use and Access) Act 2025:
- Right of access: Obtain a copy of your personal data
- Right to rectification: Correct inaccurate data
- Right to erasure: Request deletion of your data
- Right to restrict: Restrict processing of your data
- Right to object: Object to processing based on legitimate interests
- Right to data portability: Receive your data in a structured format
- Right to withdraw consent: Withdraw consent at any time
- Right to complain: Complain to the Information Commissioner's Office (ICO)
We will respond to data subject requests within one month of receiving all necessary information.
International Transfers
Some service providers and the services loaded through them (for example GA4 through Google Tag Manager, or Microsoft Clarity) may process data outside the UK. We aim to handle international transfers in line with UK GDPR by using:
- Adequacy decisions (where applicable)
- Standard Contractual Clauses (SCCs)
- Transfer Risk Assessments (TRAs) to ensure protection levels are not materially lower
Security
We take appropriate technical and organisational measures to protect your personal data from loss, unauthorised use, or disclosure. This includes encryption, access controls, and regular security monitoring.
Contact & Complaints
If you have any questions about this privacy policy or would like to exercise your rights, contact us:
Email: privacy@ceredigion.net
You also have the right to complain to the Information Commissioner's Office (ICO) if you believe your data has been handled unlawfully: