Privacy & Cookie Policy
Last updated: 20 February 2026
Keep Active ("we", "us", "our") is committed to protecting and respecting your privacy.
This Privacy & Cookie Policy explains how we collect, use, store, and protect your personal data when you visit our website and interact with us, in accordance with the UK General Data Protection Regulation (UK GDPR) and, where applicable, the EU GDPR.
1. Data Controller
Data Controller: Keep Active
Contact Email: team@keepactive.org.uk
Keep Active is the data controller responsible for your personal data.
2. What Personal Data We Collect
We may collect and process the following categories of personal data:
2.1 Technical & Usage Data
When you visit our website, we may automatically collect:
-
IP address
-
Browser type and version
-
Device type
-
Language settings
-
Pages visited
-
Date and time of access
This information is used to maintain website functionality, performance, and security.
Legal basis: Article 6(1)(f) UK GDPR – Legitimate Interest (operating and securing our website).
2.2 Contact Form Data
If you submit a contact form, we collect:
- Your name
- Your email address
- The content of your message
We use this information solely to respond to your enquiry.
Legal basis: Article 6(1)(f) – Legitimate Interest (responding to enquiries).
2.3 Marketing Communications (Opt-In)
Our contact form includes an optional marketing consent checkbox.
If you actively opt in, we may use your:
- Name
- Email address
to send you:
- News and updates
- Events
- Relevant promotions relating to Keep Active
We will only send marketing communications where you have provided clear, affirmative consent.
You may withdraw your consent at any time by:
- Contacting us at team@keepactive.org.uk
Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
Legal basis: Article 6(1)(a) – Consent.
We do not sell or share your personal data for third-party marketing purposes.
2.4 Website Administration & Login Data (If Applicable)
If you log into the website (e.g., administrators), WordPress stores authentication cookies necessary to maintain secure access.
Legal basis: Article 6(1)(f) – Legitimate Interest (security and administration).
3. Cookies
Our website uses cookies to ensure proper operation, security, and compliance.
We use the CookieYes consent management platform to allow users to manage their cookie preferences.
Cookies are small text files stored on your device when you visit a website.
3.1 Strictly Necessary Cookies
These cookies are essential for website functionality and do not require prior consent.
3.2 Google Security & Service Cookies
Our website may use Google services for security and functionality purposes. These services may set the following cookies:
These cookies help protect our website from spam, abuse, and malicious activity.
Google may process personal data in accordance with its Privacy Policy:
https://policies.google.com/privacy
Legal basis:
- Article 6(1)(a) – Consent (where required)
- Article 6(1)(f) – Legitimate Interest (security protection)
4. International Data Transfers
Some Google services may process personal data outside the UK or European Economic Area (EEA), including in the United States.
Where international transfers occur, appropriate safeguards are used, such as:
- UK International Data Transfer Agreement (IDTA)
- EU Standard Contractual Clauses (SCCs)
5. Data Retention
We retain personal data only for as long as necessary:
- Contact enquiries: Up to 12 months
- Marketing data: Until you withdraw consent or unsubscribe
- Administrative data: For the duration of account activity
- Cookies: As specified above
6. Your Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request erasure of your data
- Restrict processing
- Object to processing
- Request data portability
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
UK supervisory authority:
Information Commissioner’s Office (ICO)
https://ico.org.uk
7. Data Security
We implement appropriate technical and organisational measures to protect your data, including:
- SSL encryption (HTTPS)
- Secure hosting infrastructure
- WordPress security controls
- Restricted administrative access
- Cookie consent management via CookieYes
8. Changes to This Policy
We may update this Privacy & Cookie Policy from time to time. Any changes will be published on this page with an updated revision date.
