Privacy Policy

How we collect, use, and protect your personal data

Last updated: August 2026
This policy is reviewed annually or when our data processing practices change.

1. Data Controller

The Doctors' Association UK (DAUK) is the data controller for personal information collected through this website. We are committed to protecting your privacy and handling your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data Controller Contact:

Dr Matt Kneale
Doctors' Association UK
Email: contact@dauk.org

2. What Data We Collect

We collect and process the following categories of personal data:

Account Information

  • Registration data: Name, email address, password (encrypted)
  • Member type: Whether you are a doctor, student, or associate member
  • Regional data: UK region and work postcode prefix

Professional Information (Doctors)

  • Medical registration: GMC number
  • Career details: Grade/level, medical specialty, employer/NHS trust
  • Employment: Employment type, contract type, less-than-full-time (LTFT) status
  • Training: ARCP/CCT/CESR dates (grade-dependent), international medical graduate (IMG) status

Professional Information (Students)

  • Education: Medical school, year of study, degree type, expected graduation year

Professional Information (Associates)

  • Associate details: Associate type (retired, overseas, researcher, supporter, or other), country of practice if overseas, research institution if applicable

Payment Information

  • Subscription details: Membership tier, subscription status, billing cycle
  • Payment data: Card details are processed directly by Stripe and are never stored on our servers. We only receive a reference to your Stripe customer account.

Parental Leave Data

  • Leave type: The type of parental leave (maternity, paternity, adoption, or shared parental leave)
  • Pause status: The status of your billing pause request (pending, active, denied, or expired)
  • Pause dates: Start and end dates of your billing pause period
  • Request history: A record of previous parental leave pause requests and their outcomes

Communication Data

  • Newsletter preferences: Opt-in/opt-out status
  • Email engagement: Open and click tracking for newsletters (to improve our communications)
  • Campaign send records: Records of which membership service emails (such as profile completion reminders) have been sent to you, to avoid duplicate communications
  • Correspondence: Records of communications with us

Event & Activity Data

  • Event registrations: Events you register for and attendance records
  • CPD records: Continuing Professional Development completions and certificates
  • Poll responses: Votes and answers submitted in member polls
  • Accessibility preferences: Display settings such as high contrast mode or font scaling

Case Support Data

  • Personal details: Information you provide when requesting case support
  • Supporting documents: Files uploaded in connection with your case
  • Case notes: Records of support provided

Technical Data

  • IP addresses: For security and rate limiting purposes
  • Login records: Timestamps of account access
  • Session data: Temporary data to maintain your login state
  • Administrative audit logs: Records of administrative actions taken on your account by authorised DAUK staff, including the action performed and timestamp

3. How We Use Your Data

We use your personal data for the following purposes:

Membership Services

  • Creating and managing your member account
  • Processing membership payments and renewals
  • Providing access to members-only content and resources
  • Sending essential service communications (account updates, payment confirmations)
  • Managing parental leave billing pauses for eligible members

Communications

  • Sending newsletters about DAUK activities, campaigns, and NHS-related news (with your consent)
  • Sending targeted membership service emails based on your account status (such as reminders to complete your member profile, so we can better represent your needs)
  • Notifying you about events and webinars
  • Responding to your enquiries and support requests

Events & Webinars

  • Managing event registrations and attendance
  • Sending event reminders and follow-up information

Case Support

  • Providing confidential support to members facing workplace issues
  • Maintaining records of cases for ongoing support

Security & Improvement

  • Protecting our systems from abuse and unauthorised access
  • Analysing aggregate usage patterns to improve our services
  • Maintaining audit logs of administrative actions for accountability and security

5. Third-Party Data Processors

We use the following third-party services to help deliver our services. Each processor is bound by data processing agreements and complies with applicable data protection laws.

Stripe (Payment Processing)

  • Purpose: Processing membership payments and managing subscriptions
  • Data shared: Email address, card details (processed directly by Stripe)
  • Location: United States (with Standard Contractual Clauses)
  • Privacy policy: stripe.com/privacy

PayPal (Payment Processing)

  • Purpose: Processing membership payments for legacy subscribers
  • Data shared: Email address, subscription status
  • Location: United States (with Standard Contractual Clauses)
  • Privacy policy: paypal.com/uk/legalhub/privacy-full

Brevo (Email Delivery & Contact Management)

  • Purpose: Sending newsletters and transactional emails, managing contact lists
  • Data shared: Email address, name, member type, subscription status, email engagement metrics
  • Data sync: Member data is synchronised nightly to Brevo's contact database for list management and segmentation
  • Location: European Union
  • Privacy policy: brevo.com/legal/privacypolicy

Cloudflare R2 (File Storage)

  • Purpose: Secure, private storage of profile photos and case support documents
  • Data shared: Uploaded files and associated metadata
  • Location: European Union (configured for EU data residency)
  • Privacy policy: cloudflare.com/privacypolicy
  • Security: Profile photos are stored in private buckets with signed URL access (24-hour expiry) for GDPR compliance

SiteGround (Web Hosting)

  • Purpose: Hosting of the DAUK website
  • Data shared: All website data including account information
  • Location: European Union
  • Privacy policy: siteground.com/privacy

PostHog (Website Analytics)

  • Purpose: Understanding website usage, heatmaps, session recordings, and user journey analytics
  • Data shared: Page views, clicks, scroll depth, anonymized session recordings (with sensitive data masked)
  • Location: European Union (EU Cloud - eu.i.posthog.com)
  • Data retention: Session recordings: 1 month; Event data: 1 year
  • Privacy policy: posthog.com/privacy

6. Cookies & Tracking

Cookies We Use

We use only essential cookies required for the functioning of our website:

  • WordPress session cookies: To maintain your logged-in state
  • Security cookies: To protect against cross-site request forgery (CSRF)

Third-Party Analytics

We use PostHog, an open-source analytics platform, to understand how visitors use our website and improve user experience. PostHog helps us analyze:

  • Page views, clicks, and navigation patterns
  • Heatmaps showing where users interact with our pages
  • Session recordings (anonymized, with sensitive data masked)
  • User journey funnels and feature usage

Data Location: All analytics data is hosted on PostHog's EU cloud infrastructure (eu.i.posthog.com) for GDPR compliance.

Data Retention: Session recordings are retained for 1 month, anonymized event data for 1 year.

Privacy Protections:

  • All form inputs are masked by default
  • Sensitive content (marked with .sensitive-data class) is excluded from recordings
  • Admin areas and committee governance pages are excluded from tracking
  • Anonymous visitors are not personally identified
  • Logged-in members are identified only if they have an active membership

Your Rights: You can opt out of PostHog tracking by enabling "Do Not Track" in your browser settings. PostHog respects DNT headers. For more information, see PostHog's Privacy Policy.

We do not track your browsing behaviour across other websites or share your data with advertising networks.

Newsletter Tracking

Our newsletters include tracking pixels and links that allow us to measure:

  • Whether an email was opened
  • Which links were clicked

This helps us understand what content is most useful to our members and improve our communications. You can opt out of newsletters at any time through your member profile or by clicking the unsubscribe link in any email.

7. Data Retention

We retain your personal data only for as long as necessary for the purposes set out in this policy:

Data Type Retention Period Reason
Account data Until account deletion requested Service provision
Payment records 7 years Legal/tax requirements
Case support records 6 years (then auto-deleted) Case history and follow-up support
Newsletter analytics 1 year (then auto-deleted) Communication improvement
Webhook logs 30 days Debugging & security
Webhook error logs 90 days Debugging & security
Event registrations 2 years after event Historical records
PostHog analytics (session recordings) 1 month User experience optimization
PostHog analytics (event data) 1 year Analytics & site improvement
Parental leave pause history 3 years (then auto-deleted) Membership billing records
Administrative audit logs 2 years (then auto-deleted) Accountability & security
Campaign send records Until account deletion requested Duplicate communication prevention
CPD records 10 years (then auto-deleted) Professional development records
Cancellation feedback 2 years (then auto-deleted) Service improvement
Prize draw entry and audit records 12 months after closing for non-winners; up to 6 years for winner and payment records Fair administration, audit, accounting and dispute resolution

Prize Draws and Promotions

Profile prize draw data

For the 2026 profile prize draw, announced on 26 August 2026 and closing at 11.59 pm BST on 23 September 2026, we use existing account and professional profile information to determine whether a member meets the published entry requirements. This includes account creation date, membership status, member type, UK region and the applicable professional or medical student profile fields listed in the promotion terms.

Purpose and lawful basis

We process this information to administer the promotion fairly, improve the completeness of member information, support relevant member services and maintain an auditable record of the draw. Our lawful basis is legitimate interests. Our interests are improving the quality of information used to support and represent members, running a fair member promotion and demonstrating compliance. We have limited eligibility to proportionate professional fields and have excluded marketing choices and unnecessary sensitive information.

Automatic eligibility assessment

The website automatically checks whether the required fields are present and whether the account meets the membership and age rules. It does not evaluate the content of a member's professional views, clinical performance or conduct. The assessment does not produce a legal or similarly significant adverse effect. Members can ask us to review an eligibility decision by contacting us.

Communications

The campaign email is promotional electronic mail. We apply the relevant consent or soft opt-in requirements, honour newsletter opt-outs and include an unsubscribe facility. Members who opt out may still qualify automatically if their account and profile meet the published rules.

Random selection and audit records

At closing, eligible user identifiers are frozen, sorted and cryptographically hashed. We record the entrant count, list hash, selection method, winner and reserves, administrator, observer, timestamps and a tamper-evident audit hash chain. We do not copy all profile values into the audit record.

Winner administration

We use the winner's registered contact details to notify them and verify eligibility. UK bank details collected for payment are used only to transfer the prize and are not stored in the WordPress prize draw tables. We may publish the winner's surname and broad UK region to demonstrate that the prize was awarded. Winners may object or ask us to reduce the information published.

Retention

Non-winner entry and campaign delivery records are normally retained for 12 months after closing and then deleted or anonymised. The restricted draw audit, winner, reserve and payment records may be retained for up to six years where required for accounting, legal claims or dispute resolution. Email suppression records may be retained for as long as needed to honour an opt-out.

Your rights

Your data protection rights described below apply to prize draw processing. Where retention is necessary to establish that a fair draw occurred or to meet financial and legal obligations, we may preserve a minimal anonymised or restricted record after an erasure request.

8. Your Rights

Under the UK GDPR, you have the following rights regarding your personal data:

Right of Access (Article 15)

You can request a copy of all personal data we hold about you.

Right to Rectification (Article 16)

You can request correction of inaccurate or incomplete data. You can also update most information directly through your member profile.

Right to Erasure (Article 17)

You can request deletion of your personal data, subject to legal retention requirements.

Right to Restrict Processing (Article 18)

You can request that we limit how we use your data in certain circumstances.

Right to Data Portability (Article 20)

You can request your data in a machine-readable format to transfer to another service.

Right to Object (Article 21)

You can object to processing based on legitimate interests, including direct marketing.

Right to Withdraw Consent

Where we process data based on consent (e.g., newsletters), you can withdraw consent at any time without affecting the lawfulness of prior processing.

Exercising Your Rights

To exercise any of these rights, please contact us at contact@dauk.org. We will respond within one month of receiving your request. There is no fee for most requests, though we may charge a reasonable fee for excessive or unfounded requests.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data:

Technical Measures

  • Encryption: All data transmitted to and from our website is encrypted using TLS (HTTPS)
  • Password security: Passwords are stored using one-way cryptographic hashing
  • Secure file storage: Case support documents are stored in encrypted cloud storage with EU data residency
  • Webhook verification: All incoming webhooks are verified using cryptographic signatures
  • Rate limiting: Protection against brute-force and abuse attacks

Organisational Measures

  • Access control: Access to personal data is limited to authorised personnel only
  • Data minimisation: We only collect data necessary for our stated purposes
  • Regular review: Our security practices are reviewed regularly

Incident Response

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office (ICO) within 72 hours as required by law.

10. International Data Transfers

Some of our third-party processors are located outside the UK. We ensure appropriate safeguards are in place:

Transfers to the United States

  • Stripe: Operates under Standard Contractual Clauses (SCCs) approved by the UK ICO
  • PayPal: Operates under Standard Contractual Clauses (SCCs)

European Union Storage

  • Brevo: Email delivery and contact data stored in EU data centres
  • Cloudflare R2: Configured for EU data jurisdiction for case support documents
  • SiteGround: Website hosted in EU data centres
  • PostHog: Analytics data stored exclusively in EU cloud (eu.i.posthog.com)

Standard Contractual Clauses are legal contracts that ensure your data receives the same level of protection as required by UK law when transferred internationally.

11. Children's Privacy

Our services are intended for medical professionals and medical students who are at least 18 years of age. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected such information, please contact us immediately.

12. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will:

  • Update the "Last updated" date at the top of this policy
  • Notify active members by email where required
  • Post a notice on our website

We encourage you to review this policy periodically.

13. Contact & Complaints

Contact Us

If you have any questions about this privacy policy or how we handle your data, please contact:

Dr Matt Kneale
Doctors' Association UK
Email: contact@dauk.org

Complaints

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk
Helpline: 0303 123 1113

We would appreciate the opportunity to address your concerns before you approach the ICO, so please contact us first.