Privacy Policy
We respect the privacy of visitors to our website (https://www.right-here.org/). This policy is concerned with how we collect information, what we do with it and what controls you have over your personal information. We take our duty to protect your personal information seriously. This policy explains how we collect, manage, use and protect your personal information and what controls you have over your information.
If you have questions about this Policy or our privacy practices, please contact us at:
Email: hello@right-here.org
We’re Right Here uses cookies to understand how visitors use the website with the aim of improving its overall quality and usability. We collect voluntarily given information via our newsletter sign-up form.
2. Scope and what this covers
This policy covers:
- Use of cookies and similar tracking technologies on our site (including for Google Analytics)
- Collection of personal data via our newsletter sign-up form (through Mailchimp)
- The legal basis for processing that data
- Your rights under GDPR / UK GDPR
- Data sharing, retention, security, and transfers
- Updates to this policy
- It does not cover other websites (or third-party sites) that may be linked from our site.
3. Legal bases for processing personal data
Under the GDPR and UK GDPR, personal data processing must be lawful, fair, and transparent. We rely on the following processes:
| Processing activity | Legal basis | Additional notes |
| Analytics via Google Analytics / cookies (non-essential cookies) | Consent | We ask users to opt in to non-essential cookies (see section on cookies) |
| Newsletter subscription (collecting email addresses) | Consent | Users explicitly agree to receive emails via a clear opt-in |
| Communications related to the newsletter (e.g. confirmation, welcome, information) | Consent | Covered by the same opt-in |
| Administrative / security / legitimate site functioning (where minimal personal data is involved) | Legitimate interests / necessary for our services | Where needed (e.g. protecting site, preventing abuse) |
Consent must be freely given, specific, informed and unambiguous. Users must be able to withdraw consent at any time (see section below).
4. Cookies and tracking / Google Analytics
4.1 What are cookies
Cookies are small text files stored on your device (computer, tablet, mobile) when you visit a website. They help websites remember your actions or preferences over time. Some cookies are necessary for site functionality; others help with analytics, performance, or marketing.
4.2 Which cookies we use
We use:
- Strictly necessary / essential cookies: These are required to operate the website (e.g. load balancing, security, session management). They do not require consent, though we still disclose them.
- Performance / analytics cookies: These collect aggregated, anonymised information about how visitors use the site (e.g. page views, interactions). We use Google Analytics for this purpose.
- Other non-essential cookies (if present): We do not currently use marketing or profiling cookies, but if introduced in future, they would require explicit opt-in.
We configure Google Analytics to protect user privacy. IP addresses are anonymised (masked) so that individual visitors cannot be identified, and data is stored only in aggregated form. We also limit the retention of analytics data to a maximum of 14 months.
You may disable or block cookies via your browser settings. You can also withdraw consent for our non-essential cookies using our cookie consent tool. (See section on managing your preferences below.)
4.3 Consent, withdrawal, and control
We will not set non-essential cookies unless you have given explicit consent via a cookie banner or consent management tool. You may refuse or withdraw your consent at any time by:
- Adjusting your cookie settings in our consent tool
- Disabling cookies via your browser
- Deleting stored cookies from your browser/cache
If you decline analytics cookies, we will not track you via Google Analytics (for your session).
We also keep records of consents received (timestamp, version) in case of audit.
5. Newsletter / Mailing list (Mailchimp)
5.1 What we collect and how
When you subscribe to our newsletter, we collect:
- Your email address
- (Optionally) your first and last name
- Technical data (e.g. IP address, timestamp) for logging purposes
We use Mailchimp (The Rocket Science Group, LLC) to manage the mailing list, send newsletters, and process subscription/unsubscription actions.
Mailchimp acts as a data processor. We remain the data controller. You remain in control of your data.
We enable the GDPR fields/features in Mailchimp’s forms. This ensures subscribers explicitly consent to marketing communications — i.e. they “opt in” via a checkbox or similar.
Each email we send includes an unsubscribe link so you may withdraw your consent anytime.
5.2 International data transfers
Mailchimp’s servers may be located outside the European Economic Area (EEA), such as in the U.S. In that case, we rely on appropriate safeguards (e.g. Standard Contractual Clauses, or the Data Privacy Framework) to legitimise any transfer of personal data to a third country.
5.3 Use of subscriber data
We use the subscriber data to:
- Send you the newsletter.
- Monitor open and click rates (aggregated, anonymised).
- Manage subscription preferences, unsubscriptions and bounces.
We will not use your email address for unrelated marketing (unless you specifically consent to that) nor sell your data to third parties.
6. Retention, deletion, and anonymisation
We do not store your personal data for longer than necessary.
Analytics data is retained for 14 months in Google Analytics.
Subscriber data remains in Mailchimp until you unsubscribe or request deletion.
When data is no longer needed, we securely delete or anonymise it.
For audit or compliance purposes, we may retain minimal logs (e.g. consent records) for a limited time beyond deletion.
7. Data security & integrity
We take technical and organisational measures to protect your personal data, including (but not limited to):
- Encryption (in transit / TLS)
- Restricted access (only authorised personnel)
- Strong password policies
- Regular backups and testing
- Monitoring and incident response processes
However, no system is 100% secure. If a data breach occurs that may pose a risk to your rights or freedoms, we will notify the relevant supervisory authority and you (if required) within the statutory timeframes.
8. Data sharing & third parties
We share or disclose your personal data only in limited circumstances:
- With Mailchimp (as described above)
- With third-party service providers who help us run the website or send emails (under contract / confidentiality obligations)
- If required by law, court order or to protect rights, safety, property
We do not sell your personal data to third parties for advertising or marketing purposes.
9. Your rights under GDPR / UK GDPR
You have certain rights in relation to your personal data:
- Right of access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may ask us to correct inaccurate or incomplete personal data.
- Right to erasure (“right to be forgotten”): You may request deletion of your personal data (subject to legal, contractual or security constraints).
- Right to restriction of processing: You can ask to limit processing in certain circumstances.
- Right to data portability: You may request your data in a structured, machine-readable form to transfer elsewhere.
- Right to object: You may object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of past processing.
- Right to lodge a complaint: You may lodge a complaint with a supervisory authority (e.g. the UK Information Commissioner’s Office or relevant EU authority) if you believe your rights have been violated.
To exercise these rights, please contact us via the email address above, and we will respond within legal timeframes (generally one month).
11. Changes to this policy
We may update this Privacy Policy from time to time (for example, if we change tracking technologies or mailing list practices). When changes are made, we will update the “last updated” date and, where appropriate, notify users (e.g. via newsletter or site banner). We encourage you to review this policy periodically.
12. Additional disclosures (as required by Article 13 GDPR)
Under Articles 13 and 14 of the GDPR, we also disclose:
- That provision of personal data is voluntary (i.e. you may choose not to subscribe)
- Whether decisions are made by automated processing (profiling) — we currently do not use automated decisioning/profiling
- That recipients or categories of recipients may include Mailchimp, analytics providers, site hosters, etc.
- The existence of safeguards for international transfers (e.g. SCCs)
- The storage period or criteria used to determine it