Privacy
The Hilltop Park Residents' Association is the data controller for the personal information described here. We keep data collection to a minimum and never sell or rent your details to anyone.
The mailing list
If you join our mailing list, we ask for your full name, email address, house name or number, and postcode.
Why we ask for your address. We check it against the estate so that only people who actually live here can join. We do not use it for anything else, and we never publish it.
Who else sees it. We do not sell your details, and we do not share them for anyone else's purposes. We do rely on two suppliers to run this website on our behalf: Cloudflare, which hosts the site and stores the mailing list, and our email provider, which sends the confirmation message and our newsletters. They process your details only to provide those services to us.
Our lawful basis is your consent. You give it by ticking the box on the form and then clicking the link in the confirmation email we send — you are not added to the list until you do both.
The record we keep of that. We store when you signed up and when you confirmed, so that if anyone ever questions whether you agreed, we can show what happened rather than just asserting it. Alongside it we store a scrambled (hashed) version of the internet address your device was using at the time. We do not store the address itself in the mailing-list record. The scrambling uses a separate secret, reducing the risk if the database alone is disclosed; this is still personal information, not anonymous data. We use it only to tell sign-ups apart if a complaint is raised — never to work out where you are.
We also keep delivery records for welcome and article emails: whether each is waiting, sent, failed or suppressed, when a delivery was attempted, and the message reference returned by our email provider. This lets us retry a failed message without sending duplicates. We do not use tracking pixels in the welcome or article emails.
Unsubscribing. Every email we send has an unsubscribe link. You can use it at any time, without giving a reason, and we will stop emailing you.
How long we keep it. While you are on the list, we keep your details until you unsubscribe or ask us to delete them. Beyond that we delete things on a schedule, automatically:
- If you start signing up but never click the confirmation link, we delete what you entered on the first successful daily cleanup after 30 days from your most recent signup attempt, unless the committee has rejected the request, when the period below applies.
- If the committee decides you are not eligible, that record is deleted after 90 days, at the next successful daily cleanup.
- After you unsubscribe, we clear your name and address at the first successful daily cleanup after 30 days. We retain your email address and the date you left to prevent accidental mail, along with linked consent, administrative and delivery records. These records still contain personal information.
You can also ask us to delete everything at any time; see Your rights below.
Emailing the committee
If you email us, we hold your message and email address for as long as we need to deal with what you've raised.
Who else is involved
- Cloudflare hosts the website and stores the mailing list. Like most hosts, it processes basic technical information such as IP addresses to serve the site securely.
- An email provider sends our confirmation emails and newsletters on our behalf.
- Our community Facebook group is operated by Meta under its own privacy policy. We link to it, but it is not run by us.
- When our fundraising campaign is running we link to Crowdfunder. Donating happens on their site, under their privacy policy — we never see or hold your payment details.
We do not use tracking or advertising cookies, and there are no analytics scripts on this site.
Cookies and what's stored on your device
This site sets no cookies for ordinary visitors. There is nothing to accept and no banner to dismiss, because there is nothing being collected about you.
Three things do involve your device, and none of them identify you or follow you anywhere:
- The sign-up form uses Cloudflare Turnstile to check you're a person rather than a bot. It's a security measure and replaces the puzzles you'd otherwise have to solve. It runs only on the sign-up page.
- Closing the mailing-list bar stores a single note in your browser saying you closed it, so it stays closed. That's all it holds — no identifier, no record of who you are — and clearing your browsing data removes it.
- Committee members signing in get a session cookie from Cloudflare Access. It exists to keep them signed in, applies only to the committee area, and no ordinary visitor ever receives one.
That's the complete list. If any of it changes, this page changes with it.
Documents we publish
We publish association documents here, including meeting minutes. Minutes show who attended by their initials rather than by name, and we check documents for personal information — such as home addresses — before publishing them. If you think something published here identifies you and shouldn't, tell us and we will look at it.
Membership records
Membership of the association is separate from the mailing list. Being on the mailing list does not make you a member, and being a member does not automatically put you on the mailing list.
The register of members. The managing agent keeps the official register, and that document stays theirs. We need to check whether someone signing up for emails lives on the estate, so the website stores a protected matching copy.
Instead, each entry is converted into a scrambled value using a secret key held separately from the database. The confirmed matching table holds these values rather than readable names or addresses. This reduces the risk from a database disclosure without the secret; it does not make the records anonymous. When somebody signs up we apply the same process to their details and look for a match. A confirmed updated register replaces the previous matching copy.
During an upload, the original CSV is temporarily stored so the committee can check a preview. It is consumed on confirmation. An abandoned preview expires after 30 minutes and is deleted on the next upload attempt or daily cleanup; expiry is not immediate deletion. Mailing-list subscribers' own names and addresses are stored separately under the retention rules above.
Your rights
You can ask us to show you what we hold about you, correct it, delete it, or stop using it. Just contact the committee and we will deal with it promptly and free of charge.
If you are unhappy with how we have handled your information, you can complain to the Information Commissioner's Office at ico.org.uk.
Questions
If you have any questions about privacy, please contact the committee.