Last Updated On 09-Feb-2026

Effective Date 01-Jan-2023


Privacy Policy (CA Kent)

Effective date: 9 February 2026
Last updated: 9 February 2026

This Privacy Policy explains how Cocaine Anonymous Kent District (“CA Kent”, “we”, “us”, “our”) collects, uses, shares and protects personal data when you use any CA Kent website, service, or page that links to this policy, including:

This policy applies to the cakent.org domain and ALL subdomains, including any subdomains added in the future (for example, any new services we launch under *.cakent.org). Where a separate service has its own additional privacy notice, that notice will supplement this policy.

We process personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1) Controller and contact details

For data protection purposes, CA Kent is the data controller for personal data collected via CA Kent websites.

Contact for privacy queries & rights requests:
Email: it@cakent.org

2) Personal data we collect

Depending on how you use our sites, we may collect:

A) Data you provide

  • Contact details (name, email address, telephone number) when you email us or submit a form.
  • Order and booking details (billing/shipping address, products purchased, tickets booked, order/booking IDs, communications about your order/booking).
  • Bank transfer payment details needed to reconcile payment (payer name as shown on bank records, payment amount/date, payment reference).
    Please do not send card details by email.

B) Data collected automatically

  • Technical and usage data (IP address, device and browser type, pages viewed, approximate location derived from IP, date/time, referral source).
  • Cookie and similar technology data (see “Cookies” below).

3) Payments (Stripe and bank transfer)

A) Card / online payments via Stripe

Online payments on the Shop and/or Events Site are processed by Stripe. When you pay online, Stripe processes payment and related personal data (such as transaction details and identifiers) in accordance with Stripe’s own policies and security standards.

We do not store full card details on our servers. Card data is handled by Stripe.

Stripe acts as an independent controller for certain processing and as a processor in other contexts depending on the Stripe product and configuration. In all cases, we use Stripe to provide secure payment processing, fraud prevention and transaction management.

B) Bank transfer payments

Where bank transfer is offered, your bank and our bank will process the payment. We record the minimum needed to reconcile the transfer to an order/booking (e.g., payer name, amount, date, reference).

4) Special category data (sensitive information)

Our sites generally do not require sensitive data. However, because CA is a recovery fellowship, you may choose to include sensitive information in an enquiry (for example, health/addiction information).

Please avoid including unnecessary sensitive details. Where you voluntarily share special category data, we will only process it when permitted by law and necessary to handle your request (typically relying on explicit consent or another lawful basis if applicable).

5) How we use personal data and lawful bases

We process personal data only where we have a lawful basis under UK GDPR:

A) Operating, securing, and improving our websites

  • Purpose: site administration, troubleshooting, fraud prevention, security monitoring, service improvement.
  • Lawful basis: legitimate interests (running and protecting our services).

B) Responding to enquiries

  • Purpose: reply to your messages, support requests, and questions.
  • Lawful basis: legitimate interests (responding to communications) and/or contract (if your enquiry relates to an order/booking).

C) Shop purchases (literature) and fulfilment

  • Purpose: take orders, process payments, ship items, manage returns/refunds (where applicable), customer service.
  • Lawful basis: contract and legal obligation (record-keeping).

D) Event ticketing and administration

  • Purpose: ticket booking, confirmations, event admin, refunds/changes (where applicable).
  • Lawful basis: contract and legitimate interests (event administration).

E) Legal and compliance

  • Purpose: comply with legal obligations, respond to lawful requests, accounting/audit, and protection of rights.
  • Lawful basis: legal obligation and/or legitimate interests.

6) Who we share data with

We do not sell your personal data.

We may share personal data with service providers where necessary to operate our websites and deliver orders/bookings, including:

  • Website hosting and infrastructure providers
  • Ecommerce and ticketing systems/plugins used on the Shop and Events Site
  • Stripe (payment processing and fraud prevention)
  • Banks (for bank transfer processing and reconciliation)
  • Delivery/postal providers (to ship Shop orders)
  • Email service providers (to send order/booking confirmations and respond to enquiries)
  • IT/security providers (for maintenance, monitoring, incident response)

Providers acting as processors are required to protect personal data and process it only on our documented instructions.

7) International transfers

Some suppliers (including payment and infrastructure providers) may process personal data outside the UK. Where this happens, we ensure appropriate safeguards are used (for example, adequacy regulations or approved contractual protections such as the UK International Data Transfer Addendum).

8) Retention (how long we keep your data)

We keep personal data only as long as necessary for its purpose and legal requirements.

Typical retention periods:

  • Enquiries: up to 24 months after last contact (unless longer is needed to resolve issues).
  • Orders and event bookings: typically up to 6 years for accounting/tax and audit purposes (where applicable).
  • Security logs: typically up to 12 months, unless needed longer for investigating security incidents.

9) Your rights (UK GDPR)

You have rights including:

  • Access (a copy of your data)
  • Rectification (correct inaccurate data)
  • Erasure (“right to be forgotten”)
  • Restriction (limit processing)
  • Portability (receive certain data in a usable format)
  • Objection (to processing based on legitimate interests; and to direct marketing if applicable)
  • Automated decision-making/profiling rights (we do not typically carry out automated decision-making producing legal/similar significant effects)

To exercise rights, email it@cakent.org. We may need to verify your identity.

10) Cookies and similar technologies (PECR)

We use cookies and similar technologies to make the sites work and (where enabled) to understand usage and improve performance.

  • Strictly necessary cookies support core functionality (including checkout/basket/ticket booking).
  • Analytics/performance cookies may be used if enabled.
  • Preference cookies remember settings where applicable.

Where required by UK law (including PECR), we will request consent before placing non-essential cookies.

(If you have a dedicated Cookie Policy page, link it here.)

11) Security

We use reasonable technical and organisational measures to protect personal data. No online transmission can be guaranteed 100% secure.

12) Third-party links

Our sites may link to third-party websites. Their privacy practices are their responsibility—please review their policies.

13) Children

Our websites are not intended for children and we do not knowingly collect children’s personal data.

14) Changes to this policy

We may update this policy. The “Last updated” date shows the most recent revision.

15) Complaints

If you have concerns, contact us at it@cakent.org first.

You may also complain to the UK supervisory authority, the Information Commissioner’s Office (ICO).