Legal

Privacy Notice

The Wyvern Fellowship Ltd · a company limited by guarantee, registered in England and Wales, company number 17438355 · registered office 128 City Road, London, United Kingdom, EC1V 2NX
Last updated: 6 September 2026

1. Who we are

1.1 We are The Wyvern Fellowship Ltd ("Wyvern", "we", "us", "our"), a private company limited by guarantee registered in England and Wales under company number 17438355, whose registered office is at 128 City Road, London, United Kingdom, EC1V 2NX. We are established for public benefit and are not a registered charity.

1.2 This notice explains what personal data we collect about you, why, and what rights you have, whenever you visit thewyvernfellowship.org or any related domain (the "Site"), take out a Bronze, Silver, Gold or Patron Subscription, make a Donation, contribute to the Journal, contact us, or otherwise deal with us. We are the "controller" of that data for the purposes of the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.

1.3 We are not required to appoint a statutory Data Protection Officer, but we have a director acting as our data protection lead. You can contact us about privacy matters at [email protected], and about a safeguarding concern specifically at [email protected].

1.4 We are registered with the Information Commissioner's Office ("ICO") and have paid the data protection fee. Our registration reference is ZC239327.

2. How this notice fits with our other documents

2.1 This notice sits alongside, and should be read together with:

  • our Website Terms of Use, which govern your general use of the Site;
  • our Fellow Terms, which apply if you hold a paid Subscription;
  • our Donations Terms, which apply if you make a Donation;
  • our Contributor Agreement, which applies if you write for the Journal (a private agreement signed directly between Wyvern and each contributor, not published on the Site);
  • our Age Policy, which explains the age rules that apply across the Site; and
  • our Cookie Policy, which sets out our use of cookies and similar technologies in full detail; section 6 below summarises it.

2.2 Where any of those documents describes a specific data-handling commitment (for example, how a mistaken Donation is refunded), that document governs the specific point; this notice is the general statement of how we handle personal data across all of our activities.

3. The personal data we collect, and why

3.1 We only collect the personal data we reasonably need for the purpose in question. Depending on how you interact with us:

  • Anyone browsing the Site. We, or our hosting and security providers, collect technical and log data, for example your IP address, browser type and the pages you visit, to operate, secure and improve the Site. Legal basis: legitimate interests.
  • Fellows: Subscription sign-up and account. Your name, email address, password (stored as a hash, never in plain text), Subscription tier, billing interval, renewal date, the date and time you confirmed you are 18 or over (see clause 3.2) and, once card payments go live, a Stripe customer reference, to create and administer your account, deliver your Subscription, and take payment. Legal basis: contract; billing and tax records also legal obligation.
  • Fellows: account security. If you turn on two-factor authentication or change your email, a 2FA secret, hashed backup codes, trusted-device tokens and pending email-change requests, to protect your account from unauthorised access. Legal basis: legitimate interests.
  • Fellows: connecting Discord. If you choose to connect your Discord account from your account page, your Discord user ID and the membership-tier role we assign you in our Discord server, to give you the Discord access described in your Subscription's benefits. Legal basis: contract.
  • Newsletter subscribers. Your name, email address, subscriber/tier group and engagement data such as opens and clicks, to send the newsletter and understand how it is read. Legal basis: consent, or soft opt-in for existing Fellows; see clause 5.
  • Contact, Get Involved, Business enquiry and Chapter interest forms. Your name, email address, enquiry category and message, to respond to you and assess any partnership, volunteering or chapter proposal. Legal basis: legitimate interests; pre-contract steps where a contract may follow.
  • Donors. Your name and email address (both optional), the amount and date of your Donation, and the date and time you confirmed you are 18 or over (see clause 3.2), to process it and keep the financial records the law requires. Legal basis: contract; legal obligation (accounting and tax).
  • Journal Contributors. Your name, email address, submitted content, and image-rights confirmations where relevant, to manage submissions, the editorial process, and attribution. Legal basis: contract, the Contributor Agreement.
  • Anyone who raises a complaint. Your name, contact details, and the details and outcome of your complaint, to investigate and respond, and to identify recurring problems. Legal basis: legitimate interests.
  • A person who is the subject of, or who reports, a safeguarding concern. See clause 12. Legal basis: the substantial public interest condition, Article 9 UK GDPR and Schedule 1, Data Protection Act 2018.

3.2 When you sign up for a Subscription or make a Donation, we ask you to confirm — by ticking a box — that you are at least 18 years old, consistent with our Age Policy, Fellow Terms and Donations Terms. We record the fact and the date and time of that confirmation; we do not ask for or store your date of birth.

4. Where we get your personal data from

4.1 Most of the personal data we hold comes directly from you: when you create an account, subscribe, donate, submit a form, contribute to the Journal, or email us.

4.2 Some data is collected automatically as you use the Site, through the technical operation of our hosting and security providers (see clause 7).

4.3 A small amount of data comes from third parties: for example, our payment provider confirms to us that a payment has succeeded, without giving us your full card details.

5. Marketing communications

5.1 We will only send you marketing emails where we have a lawful basis to do so under the Privacy and Electronic Communications Regulations 2003 ("PECR"), typically your opt-in when you sign up, or, for existing Fellows, direct marketing about similar Wyvern content or services on a soft opt-in basis.

5.2 Every marketing email includes a working unsubscribe link and our postal address. You can opt out of marketing at any time, free of charge and without affecting your Subscription; we will still send you service communications about your account, billing and our terms, which are not marketing.

6. Cookies and similar technologies

6.1 We use cookies and similar technologies that are strictly necessary for the Site to work (for example, to keep you logged in and to process payments securely) and cookies set by our security provider, Cloudflare, to protect the Site from abuse and automated attacks.

6.2 We do not currently use non-essential cookies for analytics, advertising or tracking. If that changes, we will ask for your consent through a cookie banner with a genuine option to reject, in line with PECR, before any such cookie is set, and we will publish a full Cookie Policy setting out every cookie we use, its purpose and its duration.

7. Who we share your personal data with

7.1 We share personal data with the service providers ("processors") who help us run Wyvern, under contracts that require them to protect your data and use it only as we instruct. As at the date of this notice:

ProviderWhat they do for usWhere your data is processed
RenderHosts our website and databaseFrankfurt, Germany
CloudflareContent delivery, DNS and security/bot protectionGlobal network; EU Standard Contractual Clauses with the UK Addendum
Proton for BusinessOur organisational emailSwitzerland (a country the UK recognises as offering adequate protection)
MailerLiteOur newsletter platformEU (Germany/Netherlands); Standard Contractual Clauses with the UK Addendum
StripePayment processingInternational; safeguards under Stripe's own data processing agreement
SupabaseOur databaseLondon, UK
ResendTransactional emailsInternational; safeguards under Resend's own data processing agreement
Discord Inc.Optional community platform for the Discord benefit described in your Subscription, if you choose to connect itInternational (United States); safeguards under Discord's own data processing terms

Updated 1 Sep 2026 to reflect the Supabase migration completing: Supabase is now live (previously listed as "not yet live"), and its "where processed" column updated to London, UK.

Updated 5 Sep 2026 to reflect Stripe and Resend going live (both are now confirmed live, previously listed as "not yet live") and Render's migration completing (its "where processed" column updated to Frankfurt, Germany).

Updated 6 Sep 2026 to add Discord as a processor, reflecting the optional Discord-linking feature available from your account page.

7.2 All of the providers listed in the table above are confirmed live. We will keep this table current if that changes.

7.3 We may also share personal data: with our professional advisers (such as accountants or lawyers) where necessary; with the police, a regulator, a court or another authority where we are required to by law or believe in good faith that disclosure is necessary to protect someone's safety, including in a safeguarding context (see clause 12); and with a buyer or prospective buyer if we sell or restructure our business, on terms that protect your data. We do not sell your personal data to anyone.

8. International transfers

8.1 Where a provider in the table above is located outside the UK, we only transfer personal data to them where the transfer is protected by one of: an adequacy decision by the UK government (as with Switzerland); the UK's International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum; or another safeguard recognised under UK GDPR. Details of the relevant safeguard for each provider are given in the table at clause 7.1.

9. How long we keep your personal data

9.1 We keep personal data only for as long as we need it for the purpose we collected it for, or to meet a legal obligation. In summary:

  • Active Subscription data: for as long as your Subscription is active.
  • Closed Subscription data: we keep billing and transaction records for 6 years from the end of the financial year in which your Subscription ended, to meet our accounting and tax obligations, and delete or anonymise the rest of your account data sooner, once we no longer need it.
  • Newsletter data: until you unsubscribe, plus 30 days; we keep a suppression list indefinitely so we can honour your opt-out.
  • Contact, Get Involved, Business and Chapter interest enquiries: 24 months from your last contact with us.
  • Donation records: 6 years from the end of the relevant financial year, to meet our accounting and tax obligations.
  • Journal contributions: published work and attribution data indefinitely, reflecting the rights assigned to us under the Contributor Agreement; unpublished or declined drafts for 12 months, then deleted.
  • Complaints: 3 years from resolution.
  • Safeguarding-related information: see clause 12; we do not apply a fixed public retention period to this category.

10. Keeping your data secure

10.1 We take appropriate technical and organisational measures to protect your personal data, including: storing passwords only as irreversible hashes, never in plain text; offering two-factor authentication for your account; encrypting data in transit; and restricting internal access to personal data, and especially to safeguarding-related records, to those who need it to do their job.

10.2 We do not store your full card details ourselves: our payment provider handles and stores that information under its own security standards.

10.3 No method of transmission or storage is completely secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will act promptly, notify the ICO where the law requires it, and tell you directly where the risk to you is high.

11. Children and age

11.1 The Site itself has no browsing age minimum, consistent with our objects, which extend to families and communities of all ages. You must, however, be 18 or over to enter into any contract with us, including a Subscription, a Donation, or the Contributor Agreement. See our Age Policy for the full position.

11.2 If you are under 18, we ask that you only use the Site with the involvement of a parent or guardian, and that you do not submit personal information through a form on the Site without their knowledge. We do not knowingly collect personal data from children otherwise than as UK data protection law permits: the Data Protection Act 2018 separately sets 13 as the age at which a child can consent to an information-society service in their own right, which is a different question from our 18-and-over contracting age.

11.3 If we become aware that a child's personal data has been submitted to us without appropriate parental involvement, we will take proportionate steps, which may include deleting that data.

12. Safeguarding-related information

12.1 Because our objects extend to family and vulnerable-member support, we may sometimes hold information about a safeguarding concern raised about, or by, a Fellow, chapter participant or other contact. This can incidentally include special category data, such as information about a person's health or welfare circumstances.

12.2 We process this information only where necessary to protect the welfare of a vulnerable individual, relying on the substantial public interest condition in Schedule 1 to the Data Protection Act 2018. Access to safeguarding records is restricted to those who need it, and we do not apply the general retention periods in clause 9 to this category; we are developing a separate Safeguarding Policy, informed by specialist advice, which will set out how long we keep this information and will generally provide for longer retention than ordinary member data.

12.3 Where a safeguarding concern involves a child or vulnerable person, we may need to share information with external authorities regardless of the preference of the person who raised it; see our Code of Conduct and Complaints Procedure.

13. Automated decision-making

13.1 We do not currently use automated decision-making or profiling that produces legal or similarly significant effects about you. If that changes, we will update this notice and tell you how it works and what rights you have.

14. Your rights

14.1 Under UK GDPR, you have the right to:

  • Access: ask us for a copy of the personal data we hold about you.
  • Rectification: ask us to correct inaccurate or incomplete data.
  • Erasure: ask us to delete your data, subject to our legal obligations to keep some records (such as financial records for 6 years).
  • Restriction: ask us to limit how we use your data in certain circumstances.
  • Portability: ask us to provide certain data to you, or to another organisation, in a machine-readable format.
  • Object: object to our processing your data where we rely on legitimate interests, including for direct marketing, at any time.
  • Withdraw consent: where we rely on your consent (such as the newsletter), withdraw it at any time, without affecting anything we did before you withdrew it.

14.2 To exercise any of these rights, email [email protected]. We may need to verify your identity before acting on your request. We will respond within one month, or tell you if we reasonably need longer. We do not normally charge a fee.

15. Complaints

15.1 If you are unhappy with how we have handled your personal data, please tell us first at [email protected], or use our Complaints Procedure; we would like the chance to put things right.

15.2 You also have the right to complain to the Information Commissioner's Office at any time: ico.org.uk, telephone 0303 123 1113, or Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. This does not affect your right to bring a claim in court.

16. Changes to this notice

16.1 We may update this notice from time to time, for example to reflect a change in the law, our processors, or how we operate. The version published on the Site is the one in force. Where a change is material, we will take reasonable steps to bring it to the attention of registered Fellows before it takes effect.

17. Contact us

17.1 Data protection queries: [email protected]. Safeguarding concerns: [email protected]. Company name: The Wyvern Fellowship Ltd. Company number: 17438355. Registered office: 128 City Road, London, United Kingdom, EC1V 2NX.