Notice version: 2026-09-09-rota · Last updated: 9 September 2026
Who is responsible for your information
The Gold Cup Inn Community Benefit Society Limited is the data controller for this website. Our contact address is The Gold Cup Inn, Lead Lane, Nether Silton, Thirsk YO7 2JZ. Privacy questions and requests can be sent to [email protected].
What we collect
When you use a public contact, suggestion or volunteering form, we collect the name, email address and message you provide. When a signed-in Member posts an internal suggestion, we store their account name, message and submission time. Please do not include confidential, special-category or unnecessary information.
For security and abuse prevention, the website temporarily stores a one-way coded identifier derived from the connection address. It is not used for advertising or visitor tracking and expires automatically.
Why we use it
Our private volunteer rota stores volunteer display names, assigned dates and shifts, and relevant day notes to coordinate cover at the pub. Signed-in users can view and export it; Admin and Management maintain it. Volunteer names are separate from website login accounts. Archived names remain on existing rota records. Exported or printed copies are separate records and do not update or delete automatically with the website. Contact us using the privacy address above for questions or requests concerning rota information.
We use enquiry information to read and respond to your message, arrange volunteering where requested, and protect the service from misuse. Our lawful basis is our legitimate interests in communicating with customers, volunteers and the local community and operating a secure community-pub website. We do not use enquiry details for unrelated marketing.
Published events and minutes
Event information and approved committee minutes may include the names of organisers, committee members or action owners where this is relevant to the public community record. Administrators are instructed not to publish confidential, sensitive or unnecessary personal information. Contact us if published information about you needs to be corrected or reviewed.
How long we keep it
Website enquiries are normally deleted 90 days after receipt. Authorised Admin or Management users can delete them sooner. Signed-in Member suggestions are normally retained for 365 days and can also be deleted sooner. Deleted information may remain in protected backup sets until those backups reach their own retention limit; it is not used from backup and any required deletion must be reapplied following a disaster recovery.
Who receives it
Access is limited to authorised website administrators. The application and database are hosted on a Plesk-managed server in the United Kingdom. The hosting provider processes website traffic, and a configured email provider or optional Telegram bot may send an alert that a new enquiry is waiting. Alerts deliberately exclude the sender’s name, address and message. These suppliers act under their own contractual and data-protection arrangements; some processing may take place outside the UK with appropriate safeguards.
Cookies
Public pages do not use analytics or advertising cookies. The administration area uses only strictly necessary security cookies for signed-in sessions and two-factor authentication. See our cookie information.
Your rights
You may ask for a copy of your personal information, correction, deletion, restriction, or object to our use of it. We may need to confirm your identity before acting. We normally respond within one month. You may also complain to the UK Information Commissioner’s Office at ico.org.uk.
Security and changes
We use named administrator accounts, two-factor authentication, restricted local storage, encrypted transport, access logs, controlled backups and file validation. No internet service is completely risk free. We will update this notice when the website’s processing or suppliers materially change.