Privacy Notice

(Full version)

1. Who we are

The Board of Trustees for the Royal Botanic Garden Edinburgh (RBGE), 20A Inverleith Row, Edinburgh, EH3 5LR, is the data controller for the personal data described in this notice. RBGE is a charitable body registered in Scotland (SC007983) and is registered with the Information Commission under registration number Z5723674.

You can contact RBGE’s Data Protection Officer at: Data Protection Officer, Royal Botanic Garden Edinburgh, 20A Inverleith Row, Edinburgh, EH3 5LR, or by email at DPO@rbge.org.uk.

 

2. About this privacy notice

This corporate privacy notice explains how RBGE collects, uses, shares, keeps and protects personal data. It gives more detail than the shorter privacy information on RBGE’s website or in individual forms. It applies when you deal with RBGE as a visitor, customer, student, learner, supporter, member, donor, volunteer, job applicant, employee, researcher, professional contact, stakeholder or member of the public.

For some activities, we may give you a separate privacy notice, collection statement or consent form. If we do, you should read it alongside this notice. Where a shorter notice or form applies, it will normally explain the specific personal data being collected, the purpose, the lawful basis, any special category condition where relevant, and any choices available to you.

 

3. Personal data we may collect

Summary: The personal data RBGE collects depends on your relationship with us and the services or activities you use. It may include contact, booking, membership, donation, education, employment, volunteering, research, website or communication records and, where necessary and lawful, more sensitive information such as health, accessibility or equality monitoring information.

The personal data we collect may include identity and contact details, role or organisation details, booking, membership, donation, payment, Gift Aid or Direct Debit records, course, training or employment information, recruitment or volunteer records, references, images or recordings, online learning account details, webinar questions or forum posts, website and platform use, supporter preferences, correspondence with us, records of consent or communication choices, and any other information you choose to give us.

We may sometimes need to use more sensitive personal data, known as special category data. This may include health, disability, accessibility, equality monitoring, dietary requirements that may reveal health or religion, or other sensitive information. We will only use this type of data where the law allows us to do so, including where we have both a UK GDPR lawful basis and a separate special category condition. Depending on the activity, this may include explicit consent, employment and social protection law, health or social care, substantial public interest, archiving, research or statistical purposes, or legal claims. Where the law requires an appropriate policy document or additional safeguards, we will maintain them.

We may also create records about your contact with RBGE, such as attendance, participation, enquiry, complaint, safeguarding or incident records, access or security logs, learning progress, assessment outcomes, supporter engagement notes, publication mailing preferences, and records needed for audit, governance, finance or statutory reporting.

 

4. How we collect personal data

We may collect personal data directly from you when you contact us, visit our sites, complete a form, book or attend an event, apply for or enrol on a course, use an online learning platform, submit coursework, take part in a webinar, make a purchase or donation, complete a Gift Aid declaration, pay by Direct Debit, become a member, Friend, Life Member, Companion or Patron, pledge a legacy, enter a competition, take part in research or engagement activity, apply for a job or volunteering role, use our website or online services, or otherwise interact with RBGE.

We may also receive personal data from partner organisations, service providers, public bodies, educational institutions, funders, referees, delivery partners, emergency services, professional advisers or other third parties, but only where this is lawful and relevant.

Where we receive personal data about you from another source, we will normally tell you where it came from where this is required and practicable. Sources may include referees, partner organisations, public bodies, educational institutions, professional contacts, publicly available sources, funders, emergency services, professional advisers or service providers.

Some information may be collected automatically when you use our websites, booking systems, learning platforms or IT systems. This may include technical information such as device identifiers, browser type, IP address, access times, pages visited and platform activity. Where cookies or similar technologies are used, the relevant website or platform will normally provide more information.

 

5. Why we use personal data and our lawful bases

Summary: We use personal data only where we have a lawful reason. The reason depends on the activity, such as providing services, managing employment or volunteering, supporting education and research, fundraising, meeting legal duties, or keeping people and systems safe. In some cases we use data because it is needed for a contract, legal duty or public task; in others we may rely on consent or legitimate interests. Where we use more sensitive information, we must also meet an additional legal condition.

The information below gives an overview of the main purposes and lawful bases. The exact basis will depend on the activity, the data involved and RBGE’s legal, public, charitable or operational responsibilities. We identify and document the appropriate lawful basis before using personal data for a purpose. Where we rely on legitimate interests, we identify the interest, consider whether the use of personal data is necessary, and balance it against your rights, interests and reasonable expectations. Where we rely on consent, you can withdraw it at any time, although this will not affect anything already done lawfully.

What we use personal data for

The main lawful bases we rely on are: contract, where processing is needed to provide a service or manage a contract with you; legal obligation, where we must use the data to meet a legal duty; public task, where processing is necessary for RBGE to perform functions carried out in the public interest or in the exercise of official authority; legitimate interests, where the use is necessary, proportionate and balanced against your rights; recognised legitimate interests, where the law provides for a specific recognised public interest purpose; and consent, where we ask for your clear agreement. Where we use special category data, such as health, disability or equality information, we also identify an additional legal condition, such as explicit consent, employment and social protection law, health or social care, substantial public interest, archiving, research or statistical purposes, or legal claims, depending on the activity.

The following examples give further detail for key activities.

Our legitimate interests may include managing and improving RBGE services, maintaining accurate organisational records, supporting charitable fundraising and stewardship, engaging with supporters and stakeholders, protecting RBGE’s people, property, collections and systems, preventing fraud or misuse, managing complaints and enquiries, and demonstrating accountability. We will not rely on legitimate interests where your interests, rights or freedoms override those interests.

For education and learning, we may use personal data to manage applications, enrolments, online learning, course access, tutorials, webinars, coursework, assessment, certification, accreditation, payments and participation statistics.

For development, membership and fundraising, we may use personal data to provide benefits, administer donations, Gift Aid, Direct Debit payments and events, manage supporter relationships, send appropriate communications, record relevant accessibility or dietary requirements, provide project updates, and support legacy or alumni engagement. We will send electronic marketing only where permitted by law and will respect communication preferences, unsubscribe requests and other opt-out choices. Some service or administrative messages may still be sent where they are necessary and are not marketing.

We use Mailchimp to help manage and send some marketing and supporter communications, such as newsletters, campaign updates, event information, fundraising communications and other updates about RBGE’s work. Where Mailchimp processes personal data on RBGE’s behalf, it acts as a service provider and processes  the data in line with RBGE’s instructions and appropriate contractual and security safeguards.  The personal data processed may include your name, email address, communication preferences, mailing list membership, consent or opt-out status and limited engagement information such as whether emails have been delivered, opened or interacted with. We use this information to send relevant communications, manage preferences and unsubscribes, monitor the effectiveness of our communications, and keep our mailing lists accurate and up to date. Where this involves a transfer of data outside the UK, we will ensure that an appropriate transfer mechanism is in place.

We may carry out limited fundraising profiling to understand supporter interests and keep fundraising activity relevant and proportionate. This may include donation or membership history, event attendance, communication preferences, previous engagement with RBGE and, where appropriate, relevant publicly available information. We normally rely on legitimate interests for this activity and balance our interests against your rights, interests and expectations. Fundraising profiling does not involve solely automated decision-making with legal or similarly significant effects. You have the right to object to profiling carried out on the basis of legitimate interests and you may ask us to stop using your data for fundraising purposes at any time by contacting RBGE’s Data Protection Officer.

For marketing and fundraising purposes, we may use Meta advertising services, including Facebook and Instagram. This may involve securely sharing limited contact information, such as email addresses in a hashed format, so that Meta can check whether those details match users of its services. We may use this to show relevant RBGE adverts to existing supporters or contacts, exclude existing supporters from particular campaigns, measure campaign effectiveness, and create audiences with similar characteristics to existing supporters. Hashed contact data remains personal data where it can be linked back to an individual by RBGE or Meta. We use these services only where we consider this lawful, necessary and proportionate, and where our interests are not overridden by your rights and interests. You can object to RBGE using your personal data for Meta advertising, direct marketing or related fundraising profiling at any time by contacting RBGE’s Data Protection Officer or by using the unsubscribe or preference-management options provided in our marketing communications. We will apply your opt-out to RBGE’s own marketing lists and audience uploads. We do not receive personal information about individuals identified by Meta through these services.

Meta also processes personal data for its own purposes when providing and operating its services. More information about how Meta uses personal data is available in Meta’s Privacy Policy.

For recruitment, employment and volunteering, we may use personal data to manage applications, selection, right to work checks, references, appointments, contracts, payroll, pensions, training, absence, conduct, health and safety, occupational health, equality monitoring, safeguarding and workforce planning. We provide more detailed privacy information for staff.

For research, science, collections, conservation and public engagement, we may use personal data to manage participation, collaborations, permissions, acknowledgements, fieldwork, funder or regulatory requirements, access to collections, and reporting on the public benefit and impact of RBGE’s work.

For children and young people, we may use personal data where this is relevant to education, learning, family activities, safeguarding, events, visitor services, online learning, research participation or public engagement. We will take account of children’s best interests, use age-appropriate privacy information where required, and involve parents, carers or schools where this is appropriate or legally required.

If we need to use personal data for a new purpose that is not compatible with the original purpose, we will identify a lawful basis and give you further privacy information where required.

 

6. Sharing personal data

Summary: RBGE shares personal data only where this is lawful, necessary and proportionate, including with service providers, partners, regulators or other organisations where needed to deliver services, meet legal duties, protect people, or respond to legitimate requests.

We may share personal data with organisations that help us run services or meet our responsibilities, including IT and hosting providers, online learning and notification providers, payment processors, banks, mailing and fulfilment providers, delivery partners, event or supporter-management providers, pension or payroll providers, auditors, insurers, professional advisers, educational or research partners, accreditation or partner institutions, funders, public authorities, regulators, HMRC, law enforcement bodies, emergency services and safeguarding bodies.

Where another organisation processes personal data for RBGE, we will put suitable contractual, confidentiality and security arrangements in place. These normally require the organisation to use the data only on RBGE’s instructions, protect it properly, support RBGE in meeting data protection duties, and securely return or delete the data when the service ends. Where RBGE and another organisation jointly decide how personal data is used, we will agree how responsibilities are shared.

We may also respond to legitimate verification checks where this is lawful, necessary and proportionate. Before disclosing information, we will take reasonable steps to confirm the requester’s identity and authority, consider whether disclosure is appropriate, and share only the minimum personal data needed.

 

7. International transfers

If personal data is transferred outside the UK, we will make sure the transfer is allowed under UK data protection law and that appropriate safeguards are in place. These safeguards may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU standard contractual clauses, binding corporate rules or another lawful transfer mechanism. Where required, we will assess whether the transfer gives the personal data an appropriate level of protection.

 

8. How long we keep personal data

We keep personal data only for as long as we need it. This includes keeping records to meet legal, accounting, audit, reporting, archival, historical, research or regulatory requirements. RBGE has a retention schedule which sets out expected retention periods for different types of records and helps ensure personal data is not kept for longer than necessary. Retention periods vary depending on the type of information, why we hold it, how sensitive it is, any legal retention periods, whether we may need it to deal with disputes or complaints, and RBGE’s operational, charitable or public interest needs. Where possible, we will anonymise, aggregate or securely delete personal data when we no longer need it.

For example, we may keep financial and Gift Aid records for tax and audit purposes, education and assessment records for course administration and certification, employment and recruitment records in line with employment law and organisational requirements, and governance, research or archival records where there is an ongoing public, scientific, historical or accountability reason to keep them.

 

9. Your data protection rights

You have data protection rights, but some rights only apply in certain circumstances. You may have the right to ask us for a copy of your personal data, to correct inaccurate or incomplete data, to delete data, to restrict how we use it, to object to how we use it, to receive certain data in a portable format, and to withdraw consent where we rely on consent.

RBGE does not make solely automated decisions that have legal or similarly significant effects. We may carry out limited fundraising profiling, but this does not involve solely automated decision-making with legal or similarly significant effects. You may object to profiling where we rely on public task or legitimate interests, and you may object to direct marketing at any time.

The right to data portability applies only to certain information you gave us, where it is processed by automated means and where we rely on consent or contract. The right to object usually applies where we rely on public task or legitimate interests.

To use your rights, please contact RBGE’s Data Protection Officer using the details above. We may need to confirm your identity, clarify what you are asking for, or check your authority if you are acting for someone else. We will normally respond within one month of receiving a valid request. If a request is complex, or if you have made several requests, we may extend the response period where the law allows and will explain this to you.

 

10. Complaints

If you are concerned about how RBGE has used your personal data, please contact us first so that we can look into it. You can raise a data protection complaint with RBGE using the Data Protection Officer contact details above. Please provide as much detail as you can about your concern, including what happened, when it happened, what personal data was involved, and what outcome you are seeking.

We will acknowledge your complaint promptly, take appropriate steps to consider it without undue delay, make any relevant enquiries, keep you informed of progress where needed, and tell you the outcome.

If you remain dissatisfied, or if you consider that RBGE has not handled your complaint appropriately, you have the right to complain to the Information Commissioner’s Office (ICO), the UK regulator for data protection matters. You can contact the ICO at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, by telephone on 0303 123 1113, or through the complaints process available on its website at Make a complaint | ICO.

 

11. How we protect personal data

Summary: RBGE protects personal data through appropriate security measures, restricted access, staff and supplier responsibilities, and procedures for responding to suspected data breaches.

We use appropriate organisational and technical measures to protect personal data from unauthorised access, loss, misuse, alteration or disclosure. These measures may include access controls, secure storage, encryption or secure transfer methods, staff training, confidentiality requirements, supplier assurance, incident reporting, secure disposal, and internal policies and procedures. Access to personal data is limited to people who need it for their role. We keep our security measures under review and require service providers that process personal data for us to apply appropriate security and confidentiality controls. We also have procedures for identifying, reporting and responding to suspected personal data breaches. We expect staff, volunteers and service providers to handle personal data responsibly and securely.

 

12. Changes to this notice

We may update this privacy notice from time to time to reflect changes in the law, guidance, RBGE activities, systems, services, suppliers or how we use personal data. If we make significant changes, we will take reasonable steps to tell affected individuals, for example through RBGE’s website, direct communications, updated forms or activity-specific notices.

Effective date: July 2026

Discover more

Back to Privacy Notice