Skip to main content
Text size
Accessibility statement →
Your data, your rights

Privacy policy

This policy explains what personal information MusTPAD collects, why we collect it, how we use it and the rights you have over it under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Last updated: May 2026

1. Who we are

We are MusTPAD (Music Tuition and Performance Accessibility for the Disabled), a charity registered in England & Wales (charity number 1234567). Our office is in Peterborough, Cambridgeshire.

For the purposes of UK GDPR, MusTPAD is the data controller for the personal information described in this policy. You can contact us about anything to do with your data by:

2. What personal data we collect

We only collect personal data that you give us directly. We do not buy contact lists. We do not track you across other websites. The categories of personal data we hold are:

  • Contact form submissions — your name, email address, the reason for contact and your message.
  • Newsletter sign-up — your email address only.
  • Donations — your name, email address, donation amount, Gift Aid declaration status, and (handled by our payment processor — see §5) the last four digits of your payment card.
  • Event bookings — your name, email address, the event you have booked and any accessibility requirements you tell us about.
  • Volunteer and referral enquiries — your name, email, phone (optional) and the information you provide in your application or referral.
  • Technical data — limited server logs (IP address, user agent) retained briefly for security and abuse prevention by our hosting provider.

We do not knowingly collect personal data from children under 13 without a parent or guardian's involvement. Where a participant is under 18, enrolment is handled with a parent or carer.

3. Our lawful basis for processing

Under UK GDPR (Article 6), every use of personal data must have a lawful basis. We rely on the following:

  • Consent (Art. 6(1)(a)) — when you sign up to our newsletter, or where the law requires opt-in consent. You can withdraw consent at any time.
  • Contract (Art. 6(1)(b)) — when you make a donation or book onto an event, processing your data is necessary to provide the service you have asked for.
  • Legal obligation (Art. 6(1)(c)) — Gift Aid records must be retained for HMRC for at least the current year plus the previous six (seven years total).
  • Legitimate interests (Art. 6(1)(f)) — to respond to enquiries you send us through the contact form, to keep records of volunteer and referral correspondence, and to maintain the integrity and security of the website.

Where we ask sensitive questions about disability or health (for example, accessibility requirements at an event), the additional lawful basis under Article 9 is your explicit consent.

4. How we use your data

We use your personal data to:

  • Reply to messages you send via the contact form.
  • Send you our newsletter, only if you have signed up for it.
  • Process donations, send a receipt, and claim Gift Aid where you have confirmed your eligibility.
  • Confirm event bookings, share access information, and arrange any accessibility support you have requested.
  • Assess volunteer applications and follow up on referrals you make on behalf of someone else.
  • Improve the safety and reliability of mustpad.org (for example, blocking spam submissions).

We do not use your data for automated decision-making or profiling. We do not sell your data to anyone. We do not share your data with anyone for marketing purposes.

5. Who we share your data with

We use a small number of carefully chosen third-party services (“processors”) to run the website and our operations. Each one only sees the data they need to do their job, and each is bound by UK GDPR compliant contracts.

  • Stripe — processes card donations. We never see or store your full card number. Stripe is PCI DSS Level 1 certified and a UK GDPR data processor. See stripe.com/gb/privacy (opens in new tab).
  • Sanity — our content management system. Holds the content of the website itself (articles, events, team profiles). Does not hold visitor data.
  • Vercel — our website hosting provider. Retains short-lived server logs (IP address, user agent) for security and performance. See vercel.com/legal/privacy-policy (opens in new tab).
  • Brevo or Mailchimp — sends our newsletter. Holds only the email addresses of people who have signed up. You can unsubscribe at any time using the link in any newsletter we send.
  • hCaptcha — protects our contact and donation forms from automated abuse. Privacy-focused alternative to reCAPTCHA. See hcaptcha.com/privacy (opens in new tab).
  • HMRC — where you have confirmed a valid Gift Aid declaration, we share the minimum information required for HMRC to process the Gift Aid claim.

Some of these providers may transfer data outside the United Kingdom. When that happens, we rely on UK GDPR approved transfer mechanisms (UK adequacy regulations, the UK Addendum to the EU Standard Contractual Clauses, or equivalent) to make sure your data continues to be protected.

6. How long we keep your data

We only keep personal data for as long as we have a legitimate reason to do so:

  • Contact form submissions — up to 2 years after our last reply, then deleted.
  • Newsletter sign-ups — until you unsubscribe. We will delete your email address from our newsletter list within 7 days of unsubscribing.
  • Donation records — at least 7 years (current year plus the previous six) where Gift Aid was claimed, as required by HMRC. Where no Gift Aid was claimed, 6 years for accounting purposes.
  • Event bookings — until the event has taken place plus 12 months for safeguarding and follow-up.
  • Volunteer applications — for the duration of your volunteering and 12 months afterwards. Unsuccessful applications are deleted within 6 months.
  • Referrals — for as long as the participant is engaged with our services, plus a safeguarding retention period of up to 6 years after their last session.

7. Your rights

Under UK GDPR you have the following rights. We will respond to any request within one calendar month.

  • Right of access — ask for a copy of the personal data we hold about you.
  • Right to rectification — ask us to correct anything that is inaccurate or incomplete.
  • Right to erasure (“right to be forgotten”) — ask us to delete your personal data, subject to legal retention obligations (for example, Gift Aid records).
  • Right to restrict processing — ask us to stop using your data for a particular purpose while still keeping it on file.
  • Right to data portability — ask for the data you have given us in a structured, commonly used and machine-readable format.
  • Right to object — object to processing that relies on our legitimate interests, including direct marketing. We will stop unless we have a compelling reason to continue.
  • Right to withdraw consent — where we are relying on your consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before that point.

To exercise any of these rights, email enquiries@mustpad.org with the words “Data request” in the subject line. We do not charge a fee, and we will not ask you to prove who you are unless we have a good reason to.

8. Cookies and similar technologies

mustpad.org uses the minimum cookies needed to make the site work. We do not use advertising or tracking cookies, so no cookie consent banner is required.

  • Strictly necessary cookies — used only when you submit a form, to maintain your session and verify the hCaptcha challenge. These cookies expire when you close your browser.
  • Accessibility preferences — your chosen font size and colour scheme are stored in your browser's localStorage(not a cookie). This data never leaves your device and is never sent to our servers.
  • Analytics — if we enable analytics, we will use Plausible (opens in new tab), a privacy-first analytics service that does not use cookies and does not collect personal data. Plausible is GDPR, CCPA and PECR compliant.

9. How we keep your data secure

We apply appropriate technical and organisational measures to protect your data, including:

  • HTTPS (TLS) on every page of mustpad.org.
  • Two-factor authentication enforced on every account that has access to our content management system or donation records.
  • No public-facing database. Our website reads content but cannot write to it.
  • Payment data is handled exclusively by Stripe (PCI DSS Level 1) — we never see or store full card numbers.
  • hCaptcha on forms to prevent automated abuse and credential stuffing.
  • Regular review of which staff and volunteers have access to personal data; access is removed promptly when no longer needed.

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and, where the risk is high, notify you directly.

10. How to make a complaint

If you have a concern about how we have handled your personal data, please tell us first by emailing enquiries@mustpad.org — we will look into it and reply within one calendar month.

You also have the right to complain directly to the Information Commissioner's Office (ICO), the UK's independent data protection authority:

  • Web: ico.org.uk (opens in new tab)
  • Phone: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Complaining to the ICO does not affect any other legal rights you may have.

11. Changes to this policy

We may update this policy from time to time — for example, when we add a new service or when the law changes. Material changes will be announced on this page, and we will update the “Last updated” date at the top. If a change significantly affects how we use data you have already given us, we will tell you directly where we can.

12. Glossary

  • UK GDPR — the United Kingdom General Data Protection Regulation, the UK's data protection law since 1 January 2021.
  • Data controller — the organisation that decides why and how your personal data is used. For mustpad.org, that is MusTPAD.
  • Data processor — an organisation that handles personal data on behalf of a controller (for example, Stripe processes donations on our behalf).
  • Personal data — any information that can identify a living person, directly or indirectly.