Data Processing Agreement
Last updated: 24 April 2026
This Data Processing Agreement ("DPA") sets out the terms under which personal data is processed by the Waymark platform on behalf of St Winnold Lodge No. 3955. It supplements the lodge's Data Protection Notice and is intended to meet the requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Definitions
- Controller means St Winnold Lodge No. 3955, the Masonic lodge that determines the purposes and means of processing personal data.
- Processor means the Waymark platform, the software service that processes personal data on behalf of the Controller.
- Data Subject means any identified or identifiable individual whose personal data is processed. This includes lodge members, visiting brethren, and prospective members.
- Personal Data means any information relating to a Data Subject, as defined by the UK GDPR.
- Sub-processor means any third-party service engaged by the Processor to assist in carrying out processing activities.
2. Personal Data Processed
The Processor handles the following categories of personal data on behalf of the Controller:
- Full names and Masonic titles
- Email addresses and telephone numbers
- Postal addresses
- Masonic records, including rank, lodge roles, and progression history
- Meeting attendance records
- Photographs (where uploaded by authorised officers)
- Communication and contact-sharing consent preferences
- Dietary and accessibility requirements (where provided voluntarily)
3. Purpose of Processing
Personal data is processed solely for the following purposes:
- Administration of lodge membership and records
- Planning, scheduling, and managing lodge meetings
- Sending meeting summonses, agendas, and other lodge communications
- Recording attendance at meetings and events
- Managing prospective member applications
- Facilitating contact between members (subject to individual consent)
4. Data Storage
All personal data is stored within Supabase hosted infrastructure. Data is encrypted at rest using AES-256 encryption and in transit using TLS 1.2 or higher. Database backups are encrypted and retained in accordance with Supabase's standard retention policies.
The Processor does not store personal data outside the hosted infrastructure except where necessary for email delivery (see Section 5) or application hosting (see Section 8).
5. Email Processing
Transactional emails (such as meeting summonses, login links, and notifications) are sent via the Brevo email service. Brevo processes recipient email addresses and message content solely for the purpose of delivery. Brevo acts as a sub-processor and is bound by its own data processing terms. Email addresses are not used by Brevo for marketing or any purpose beyond delivery.
6. Data Retention
Personal data is retained for as long as the Data Subject remains an active member of the lodge or has an ongoing relationship with it (for example, as a prospective member).
Upon resignation, exclusion, or written request, personal data will be removed or anonymised within a reasonable timeframe. Certain records may be retained in anonymised form for historical and statistical purposes, in line with the lodge's legitimate interest in maintaining its history.
7. Data Subject Rights
Under the UK GDPR, Data Subjects have the following rights in relation to their personal data:
- Right of access. You may request a copy of the personal data held about you.
- Right to rectification. You may request correction of inaccurate or incomplete data.
- Right to erasure. You may request deletion of your personal data, subject to any overriding legal obligations.
- Right to data portability. You may request your data in a structured, commonly used, machine-readable format.
- Right to restrict processing. You may request that processing be limited in certain circumstances.
- Right to object. You may object to processing based on legitimate interests.
To exercise any of these rights, please contact the lodge Secretary (see Section 10 below). Requests will be responded to within one calendar month.
8. Security Measures
The Processor implements appropriate technical and organisational measures to protect personal data, including:
- Row Level Security (RLS) policies ensuring members can only access data they are authorised to view
- Encrypted connections (TLS) for all data in transit
- Encryption at rest for all stored data
- Consent-gated contact sharing, so personal contact details are only visible to other members when the individual has opted in
- Authentication via secure magic link tokens, with no passwords stored
- Role-based access controls restricting administrative functions to authorised officers
9. Sub-processors
The Processor engages the following sub-processors to deliver the service:
| Sub-processor | Purpose | Data processed |
|---|---|---|
| Supabase | Database hosting, authentication, file storage | All personal data listed in Section 2 |
| Brevo | Transactional email delivery | Email addresses, message content |
| Vercel | Application hosting and edge delivery | Request metadata, server-side rendered page data |
Each sub-processor is bound by its own data processing terms and processes data only as necessary to provide its service. The Controller will be notified of any material changes to sub-processors.
10. Contact
The lodge Secretary acts as the primary point of contact for all data protection matters. If you have questions about this agreement, wish to exercise your data rights, or need to report a concern, please get in touch via the contact page.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
