Privacy Policy
How we collect, use, and protect your personal data
Last updated: August 2026
This policy is reviewed annually or when our data processing practices change.
1. Data Controller
The Doctors' Association UK (DAUK) is the data controller for personal information collected through this website. We are committed to protecting your privacy and handling your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data Controller Contact:
Dr Matt Kneale
Doctors' Association UK
Email: contact@dauk.org
2. What Data We Collect
We collect and process the following categories of personal data:
Account Information
- Registration data: Name, email address, password (encrypted)
- Member type: Whether you are a doctor, student, or associate member
- Regional data: UK region and work postcode prefix
Professional Information (Doctors)
- Medical registration: GMC number
- Career details: Grade/level, medical specialty, employer/NHS trust
- Employment: Employment type, contract type, less-than-full-time (LTFT) status
- Training: ARCP/CCT/CESR dates (grade-dependent), international medical graduate (IMG) status
Professional Information (Students)
- Education: Medical school, year of study, degree type, expected graduation year
Professional Information (Associates)
- Associate details: Associate type (retired, overseas, researcher, supporter, or other), country of practice if overseas, research institution if applicable
Payment Information
- Subscription details: Membership tier, subscription status, billing cycle
- Payment data: Card details are processed directly by Stripe and are never stored on our servers. We only receive a reference to your Stripe customer account.
Parental Leave Data
- Leave type: The type of parental leave (maternity, paternity, adoption, or shared parental leave)
- Pause status: The status of your billing pause request (pending, active, denied, or expired)
- Pause dates: Start and end dates of your billing pause period
- Request history: A record of previous parental leave pause requests and their outcomes
Communication Data
- Newsletter preferences: Opt-in/opt-out status
- Email engagement: Open and click tracking for newsletters (to improve our communications)
- Campaign send records: Records of which membership service emails (such as profile completion reminders) have been sent to you, to avoid duplicate communications
- Correspondence: Records of communications with us
Event & Activity Data
- Event registrations: Events you register for and attendance records
- CPD records: Continuing Professional Development completions and certificates
- Poll responses: Votes and answers submitted in member polls
- Accessibility preferences: Display settings such as high contrast mode or font scaling
Case Support Data
- Personal details: Information you provide when requesting case support
- Supporting documents: Files uploaded in connection with your case
- Case notes: Records of support provided
Technical Data
- IP addresses: For security and rate limiting purposes
- Login records: Timestamps of account access
- Session data: Temporary data to maintain your login state
- Administrative audit logs: Records of administrative actions taken on your account by authorised DAUK staff, including the action performed and timestamp
3. How We Use Your Data
We use your personal data for the following purposes:
Membership Services
- Creating and managing your member account
- Processing membership payments and renewals
- Providing access to members-only content and resources
- Sending essential service communications (account updates, payment confirmations)
- Managing parental leave billing pauses for eligible members
Communications
- Sending newsletters about DAUK activities, campaigns, and NHS-related news (with your consent)
- Sending targeted membership service emails based on your account status (such as reminders to complete your member profile, so we can better represent your needs)
- Notifying you about events and webinars
- Responding to your enquiries and support requests
Events & Webinars
- Managing event registrations and attendance
- Sending event reminders and follow-up information
Case Support
- Providing confidential support to members facing workplace issues
- Maintaining records of cases for ongoing support
Security & Improvement
- Protecting our systems from abuse and unauthorised access
- Analysing aggregate usage patterns to improve our services
- Maintaining audit logs of administrative actions for accountability and security
4. Legal Basis for Processing
Under UK GDPR, we process your personal data on the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Membership account management | Contract performance |
| Payment processing | Contract performance |
| Essential service emails | Legitimate interest |
| Newsletters and marketing | Consent |
| Event registration | Legitimate interest |
| Case support services | Contract performance / Legitimate interest |
| Parental leave pause management | Contract performance |
| Targeted membership service emails | Legitimate interest |
| Administrative audit logging | Legitimate interest |
| Security measures | Legitimate interest |
5. Third-Party Data Processors
We use the following third-party services to help deliver our services. Each processor is bound by data processing agreements and complies with applicable data protection laws.
Stripe (Payment Processing)
- Purpose: Processing membership payments and managing subscriptions
- Data shared: Email address, card details (processed directly by Stripe)
- Location: United States (with Standard Contractual Clauses)
- Privacy policy: stripe.com/privacy
PayPal (Payment Processing)
- Purpose: Processing membership payments for legacy subscribers
- Data shared: Email address, subscription status
- Location: United States (with Standard Contractual Clauses)
- Privacy policy: paypal.com/uk/legalhub/privacy-full
Brevo (Email Delivery & Contact Management)
- Purpose: Sending newsletters and transactional emails, managing contact lists
- Data shared: Email address, name, member type, subscription status, email engagement metrics
- Data sync: Member data is synchronised nightly to Brevo's contact database for list management and segmentation
- Location: European Union
- Privacy policy: brevo.com/legal/privacypolicy
Cloudflare R2 (File Storage)
- Purpose: Secure, private storage of profile photos and case support documents
- Data shared: Uploaded files and associated metadata
- Location: European Union (configured for EU data residency)
- Privacy policy: cloudflare.com/privacypolicy
- Security: Profile photos are stored in private buckets with signed URL access (24-hour expiry) for GDPR compliance
SiteGround (Web Hosting)
- Purpose: Hosting of the DAUK website
- Data shared: All website data including account information
- Location: European Union
- Privacy policy: siteground.com/privacy
PostHog (Website Analytics)
- Purpose: Understanding website usage, heatmaps, session recordings, and user journey analytics
- Data shared: Page views, clicks, scroll depth, anonymized session recordings (with sensitive data masked)
- Location: European Union (EU Cloud - eu.i.posthog.com)
- Data retention: Session recordings: 1 month; Event data: 1 year
- Privacy policy: posthog.com/privacy
7. Data Retention
We retain your personal data only for as long as necessary for the purposes set out in this policy:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data | Until account deletion requested | Service provision |
| Payment records | 7 years | Legal/tax requirements |
| Case support records | 6 years (then auto-deleted) | Case history and follow-up support |
| Newsletter analytics | 1 year (then auto-deleted) | Communication improvement |
| Webhook logs | 30 days | Debugging & security |
| Webhook error logs | 90 days | Debugging & security |
| Event registrations | 2 years after event | Historical records |
| PostHog analytics (session recordings) | 1 month | User experience optimization |
| PostHog analytics (event data) | 1 year | Analytics & site improvement |
| Parental leave pause history | 3 years (then auto-deleted) | Membership billing records |
| Administrative audit logs | 2 years (then auto-deleted) | Accountability & security |
| Campaign send records | Until account deletion requested | Duplicate communication prevention |
| CPD records | 10 years (then auto-deleted) | Professional development records |
| Cancellation feedback | 2 years (then auto-deleted) | Service improvement |
| Prize draw entry and audit records | 12 months after closing for non-winners; up to 6 years for winner and payment records | Fair administration, audit, accounting and dispute resolution |
Prize Draws and Promotions
Profile prize draw data
For the 2026 profile prize draw, announced on 26 August 2026 and closing at 11.59 pm BST on 23 September 2026, we use existing account and professional profile information to determine whether a member meets the published entry requirements. This includes account creation date, membership status, member type, UK region and the applicable professional or medical student profile fields listed in the promotion terms.
Purpose and lawful basis
We process this information to administer the promotion fairly, improve the completeness of member information, support relevant member services and maintain an auditable record of the draw. Our lawful basis is legitimate interests. Our interests are improving the quality of information used to support and represent members, running a fair member promotion and demonstrating compliance. We have limited eligibility to proportionate professional fields and have excluded marketing choices and unnecessary sensitive information.
Automatic eligibility assessment
The website automatically checks whether the required fields are present and whether the account meets the membership and age rules. It does not evaluate the content of a member's professional views, clinical performance or conduct. The assessment does not produce a legal or similarly significant adverse effect. Members can ask us to review an eligibility decision by contacting us.
Communications
The campaign email is promotional electronic mail. We apply the relevant consent or soft opt-in requirements, honour newsletter opt-outs and include an unsubscribe facility. Members who opt out may still qualify automatically if their account and profile meet the published rules.
Random selection and audit records
At closing, eligible user identifiers are frozen, sorted and cryptographically hashed. We record the entrant count, list hash, selection method, winner and reserves, administrator, observer, timestamps and a tamper-evident audit hash chain. We do not copy all profile values into the audit record.
Winner administration
We use the winner's registered contact details to notify them and verify eligibility. UK bank details collected for payment are used only to transfer the prize and are not stored in the WordPress prize draw tables. We may publish the winner's surname and broad UK region to demonstrate that the prize was awarded. Winners may object or ask us to reduce the information published.
Retention
Non-winner entry and campaign delivery records are normally retained for 12 months after closing and then deleted or anonymised. The restricted draw audit, winner, reserve and payment records may be retained for up to six years where required for accounting, legal claims or dispute resolution. Email suppression records may be retained for as long as needed to honour an opt-out.
Your rights
Your data protection rights described below apply to prize draw processing. Where retention is necessary to establish that a fair draw occurred or to meet financial and legal obligations, we may preserve a minimal anonymised or restricted record after an erasure request.
8. Your Rights
Under the UK GDPR, you have the following rights regarding your personal data:
Right of Access (Article 15)
You can request a copy of all personal data we hold about you.
Right to Rectification (Article 16)
You can request correction of inaccurate or incomplete data. You can also update most information directly through your member profile.
Right to Erasure (Article 17)
You can request deletion of your personal data, subject to legal retention requirements.
Right to Restrict Processing (Article 18)
You can request that we limit how we use your data in certain circumstances.
Right to Data Portability (Article 20)
You can request your data in a machine-readable format to transfer to another service.
Right to Object (Article 21)
You can object to processing based on legitimate interests, including direct marketing.
Right to Withdraw Consent
Where we process data based on consent (e.g., newsletters), you can withdraw consent at any time without affecting the lawfulness of prior processing.
Exercising Your Rights
To exercise any of these rights, please contact us at contact@dauk.org. We will respond within one month of receiving your request. There is no fee for most requests, though we may charge a reasonable fee for excessive or unfounded requests.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data:
Technical Measures
- Encryption: All data transmitted to and from our website is encrypted using TLS (HTTPS)
- Password security: Passwords are stored using one-way cryptographic hashing
- Secure file storage: Case support documents are stored in encrypted cloud storage with EU data residency
- Webhook verification: All incoming webhooks are verified using cryptographic signatures
- Rate limiting: Protection against brute-force and abuse attacks
Organisational Measures
- Access control: Access to personal data is limited to authorised personnel only
- Data minimisation: We only collect data necessary for our stated purposes
- Regular review: Our security practices are reviewed regularly
Incident Response
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office (ICO) within 72 hours as required by law.
10. International Data Transfers
Some of our third-party processors are located outside the UK. We ensure appropriate safeguards are in place:
Transfers to the United States
- Stripe: Operates under Standard Contractual Clauses (SCCs) approved by the UK ICO
- PayPal: Operates under Standard Contractual Clauses (SCCs)
European Union Storage
- Brevo: Email delivery and contact data stored in EU data centres
- Cloudflare R2: Configured for EU data jurisdiction for case support documents
- SiteGround: Website hosted in EU data centres
- PostHog: Analytics data stored exclusively in EU cloud (eu.i.posthog.com)
Standard Contractual Clauses are legal contracts that ensure your data receives the same level of protection as required by UK law when transferred internationally.
11. Children's Privacy
Our services are intended for medical professionals and medical students who are at least 18 years of age. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected such information, please contact us immediately.
12. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will:
- Update the "Last updated" date at the top of this policy
- Notify active members by email where required
- Post a notice on our website
We encourage you to review this policy periodically.
13. Contact & Complaints
Contact Us
If you have any questions about this privacy policy or how we handle your data, please contact:
Dr Matt Kneale
Doctors' Association UK
Email: contact@dauk.org
Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk
Helpline: 0303 123 1113
We would appreciate the opportunity to address your concerns before you approach the ICO, so please contact us first.
