Skip to content
fanbrief

Legal

Privacy notice

Last updated 14 August 2026. This notice covers the personal data handled by an editorial desk that writes about Westminster Abbey fan-vault hours: enquiry correspondence, the contact form and ordinary web serving. Westminster Abbey and other venues named in our articles publish their own documents, and those govern any arrangement you make with them.

Who we are and what this notice covers

This notice explains how the fanbrief editorial desk (fanbrief.pro) handles personal data when you read these pages, write to us about a Westminster Abbey fan-vault hour, or use the contact form. It covers the website published at this domain and the email correspondence that follows an enquiry. It does not cover Westminster Abbey, the Dean and Chapter of Westminster, or any other venue named in our briefs; each of those is a separate organisation with its own notices, and any arrangement you make with them is governed by their documents rather than ours.

Controller contact for privacy requests: [email protected], phone +44 20 3594 2176, postal address 11 Marsham Street, London SW1P 4PA, United Kingdom. Editorial enquiries: [email protected].

We are a small editorial operation based in London. Our processing is deliberately narrow: we publish articles, we answer correspondence, and we keep the minimum record needed to do both consistently. This notice is written under the UK GDPR and the Data Protection Act 2018.

What personal data we collect

From the contact form: your first and last name, country of residence, email address, an optional phone number, the month of a planned visit, the group type you select, the content of your message about hours or sequence, and the fact that you ticked the privacy consent box. From email correspondence: whatever you choose to send us, including any listings or leaflets you attach voluntarily so that we can comment on a date.

From ordinary web serving: technical data such as IP address, user agent, requested page and timestamps, processed by our hosting provider in server logs for security and reliability. We do not operate advertising trackers, we do not build behavioural profiles, and we do not attempt to identify readers who have not written to us.

How the contact form actually behaves

The form on this site validates in your browser and stores a copy of your entry in your own browser storage so that a mistyped address is not lost. That local copy sits on your device and is not a transmission to us. Where a message reaches the desk, it arrives as email and is handled as correspondence.

If you would rather not use the form at all, write directly to the address published in the footer. An email is exactly as effective and gives you a copy of your own words in your sent folder.

Why we process it, and our lawful basis

To answer your enquiry about a fan-vault hour, we rely on your consent and on the performance of the informal arrangement created when you ask us a question. To keep the site secure and available, we rely on legitimate interests. To retain correspondence that documents an editorial correction or a factual dispute, we rely on legitimate interests in maintaining an accurate published record.

We do not use your data for automated decision-making, and we do not profile readers for advertising. Nothing in your enquiry is used to build a marketing list unless you have asked to be added to one.

Who has access to it

Access is limited to the editorial team members who answer correspondence. Our processors are the hosting provider that serves these pages and the email provider that carries our correspondence. Both act on documented instructions and provide their own security commitments. Web fonts may be requested from a third-party font service; that request reveals your IP address to the provider, which is described in the cookie policy.

Enquiry contents are not shared with venues, and your address is not passed to a tour operator. If you ask us to introduce you to somebody, we will tell you what we would send before sending it.

International transfers

We are based in the United Kingdom. Our providers may process data outside the UK. Where that happens, transfers rely on the UK's adequacy regulations, the Information Commissioner's Office's standard contractual clauses, or another lawful transfer tool, together with the technical measures those tools require. If you would like to know which providers are involved at the time you read this, ask and we will tell you.

How long we keep things

Enquiry correspondence is kept for up to twenty-four months from the last message, which is long enough to recognise a follow-up question about the same month of travel. Server logs are retained for a short period defined by our host, typically weeks rather than months. Correspondence that documents a published correction is kept for as long as the correction remains relevant to the article.

Anything stored locally in your browser by the consent banner or the form remains on your device until you clear site data.

Your rights under UK GDPR

You can ask for access to your data, correction of inaccurate data, erasure, restriction of processing, and portability where it applies. You can object to processing based on legitimate interests, and you can withdraw consent at any time; withdrawal does not affect processing already carried out. To exercise any of these, write to the address in the footer and describe the request in your own words. We do not require a form.

We answer within one month. If a request is complex we will say so and explain the delay. You may also complain to the Information Commissioner's Office, which is the UK supervisory authority for data protection.

Complaints to the Information Commissioner's Office

If you are unhappy with how we have handled your personal data, you may complain to the ICO. The Commissioner provides guidance on making a complaint, including contact details and what information helps an investigation. We would rather put a mistake right ourselves first — write to the privacy address above — but that preference does not limit your right to go to the ICO at any time.

The ICO is concerned with data protection law, not with whether you agree with an editorial judgement about a fan-vault sequence or photography notices. Editorial complaints follow the corrections policy in the terms of use.

Children and school groups

School visits are a frequent subject of correspondence, which means teachers and parents write more often than pupils. This site is not directed at children, and we ask that enquiries about a school party come from an adult. Where you tell us about a young visitor — an age band, a need for seating, a quieter path — we treat that information as sensitive context, keep it inside the correspondence thread, and do not repeat it in published material.

Security

Pages are served over encrypted connections. Correspondence is held in accounts protected by strong authentication. Access is restricted to the people who need it. We minimise what we hold, which is the only security measure that never fails: data that was never collected cannot be exposed.

Editorial material, comments and changes

We publish visitor comments. Those are used with permission, edited for length rather than sentiment, and attributed only by first name and city unless the writer asks otherwise. If you have sent us a comment and want it removed or anonymised further, write and it will be done without argument.

Where an article discusses Westminster Abbey or another named place, we are writing about organisations and buildings rather than private individuals. Where an individual is named in a complaint sent to us, we do not publish that name. If our processing changes, this page changes with it. The current version is dated 14 August 2026.

Related

Other legal pages