Your information

Privacy notice.

Last updated 31 August 2026

This notice explains what personal information Carlisle Makerspace collects, why we use it and the choices you have. It applies when you use this website, book an event, become a member, visit the workshop or contact us.

Who is responsible

Carlisle Makerspace is the data controller for the information described in this notice. We are still establishing the organisation and will open as a Community Interest Company. You can contact us about privacy at hello@carlislemakerspace.com, or write to Carlisle Makerspace, Unit 5, Carlisle Enterprise Centre, James Street, Carlisle, CA2 5BB.

What we collect

  • Event bookings: your name, email address, chosen event, booking status, attendance status and a private booking-management identifier.
  • Membership: your name, email address, optional telephone number, broad age group, membership plan, status, concession status and acceptance of workshop rules.
  • Membership payments: Stripe customer and subscription identifiers, the plan and amount, payment status, billing contact details, and limited transaction information needed to manage the membership and our accounts.
  • Emergency contacts: up to two people’s names, relationships to you and telephone numbers.
  • Member requests: the member making the request, its subject, the reason given and its progress.
  • Safety and workshop records: general and tool-specific inductions, supervision or authorisation status, accidents, near misses, equipment checks, faults, repairs, maintenance, compliance documents, and the names or administrator email addresses of people who carried out or recorded the work.
  • Administration and security: administrator email addresses, roles, actions taken in the system, and technical information such as IP address, browser details and request logs.
  • CCTV: images of people in monitored areas if CCTV is installed and operating at the workshop.
  • Messages you send us and any information you choose to include in them.

We do not ask for your full date of birth, medical history, identity documents, payment-card details or bank details through this website. Membership payments will be completed on a secure Stripe-hosted page. Stripe collects and processes the payment method details, so Carlisle Makerspace does not store full card or bank account details.

Where the information comes from

We usually receive information directly from you. A member gives us their emergency contacts’ details and should tell those people that we hold them. Safety information may also come from a person who witnessed or reported an incident, an inductor, or an authorised administrator.

Why we use your information

  • Events and membership. We use your information to handle bookings, membership and requests, and to take steps before or carry out our agreement with you. Our lawful basis is contract.
  • Workshop safety. We use induction, equipment and incident records to run the workshop safely, investigate problems and manage access to equipment. Our lawful bases are our legitimate interests in operating a safe community workshop and, where it applies, our legal obligations.
  • Emergency contacts. We collect these details because it is in our legitimate interests to be able to contact someone if a member has an emergency. In a serious emergency, we may use or share relevant information to protect someone’s vital interests.
  • Security and administration. We use access records, audit information and technical logs to protect the website, members, administrators and workshop. Our lawful basis is our legitimate interests in keeping these systems secure and accountable.
  • CCTV. If CCTV is in operation, we use it to help keep people and the premises safe, deter theft and damage, and investigate specific incidents. Our lawful basis is our legitimate interests in safety and security.
  • Legal and financial records. We use Stripe payment and subscription information to collect membership fees, manage refunds and failed payments, reconcile our accounts and keep required financial records. Our lawful bases are contract and legal obligation. We also keep and share information when it is needed to establish, exercise or defend legal claims under our legitimate interests.

Our legitimate interests are running a safe, secure and accountable community workshop, managing our relationship with members and visitors, and protecting people, equipment and the organisation. We consider the effect on people before relying on these interests.

Safety and health information

An accident record may sometimes need to include limited information about an injury or a person’s health. We only record what is needed to respond, investigate, meet health and safety duties, deal with insurance, or establish, exercise or defend a legal claim. Please do not put medical histories or unrelated health information into general messages or forms.

If you do not provide information

You do not have to give us personal information simply to read the public pages. We need the required booking details to reserve an event place, the required membership details to administer a membership, and the relevant induction information before we can allow access to restricted equipment. We may be unable to provide that service if the information is not supplied.

Who can see your information

Access inside Carlisle Makerspace is limited by role and need. Membership administrators handle membership and event details. Safety administrators see relevant member details and handle emergency contacts, inductions and safety records. Finance administrators see information needed for financial administration. Directors have organisational oversight. Technical administrators maintain the system but do not receive routine access to member records.

We may also share information with:

  • Cloudflare, which provides website hosting, security, administrator access, form-abuse protection and database services;
  • Stripe, which will process membership payments, subscriptions, refunds, fraud checks and related payment administration;
  • insurers, professional advisers and service providers when needed to run and protect the organisation;
  • emergency services, regulators, courts or other authorities when required by law or necessary to protect someone; and
  • another organisation if Carlisle Makerspace is reorganised, provided that the information remains protected and is used for compatible purposes.

We do not sell personal information and do not share it for advertising.

CCTV

CCTV may be used in monitored areas at the workshop for safety and security. Clear signs will tell you when CCTV is operating and how to contact us. Cameras will be positioned to record only the areas needed for these purposes.

Access to footage is limited to authorised people responsible for safety, security or investigating a specific incident. We may share a relevant recording with the police, emergency services, our insurer or legal advisers when necessary.

International processing

Cloudflare is a global provider and may process information outside the UK. Where UK personal information is transferred internationally, Cloudflare uses recognised safeguards, including the UK Extension to the EU-US Data Privacy Framework or standard contractual clauses with the UK addendum. You can ask us for more information about these safeguards.

Stripe is also a global provider and may process payment information outside the UK, including in the United States. Stripe uses recognised transfer safeguards, including the UK Extension to the EU-US Data Privacy Framework and the UK international data transfer addendum where applicable. Stripe also uses payment information for its own legal, security and fraud-prevention responsibilities as explained in its privacy policy (opens in a new tab).

How long we keep information

  • Event booking records are normally removed or anonymised within 30 days after the event. We may keep the non-personal event details as part of the makerspace's history.
  • A pending membership that never becomes active is normally deleted six months after its last update.
  • Active membership records are kept while membership continues. Phone numbers and emergency contacts are normally removed within 30 days after membership ends. The remaining core membership and rules-acceptance record is kept for up to six years after membership ends for contract and legal-claim needs.
  • Stripe subscription and financial transaction records are normally kept for six years from the end of the company financial year they relate to, or longer if a tax enquiry, chargeback or legal duty requires it.
  • Member requests and ordinary correspondence are normally kept for two years after the last activity on the request or after the matter closes. A record that forms part of a financial, safety, complaint or legal matter follows the longer period for that record.
  • General and tool-specific inductions are normally kept for six years after membership ends. Accident and near-miss records are normally kept for six years after closure. They may be kept longer when required for RIDDOR, insurance, an active legal claim, or a record concerning someone who was under 18.
  • Equipment checks, faults, inspections, maintenance and repairs are normally kept for six years after the equipment or check is retired. Compliance records are normally kept for six years after they are marked as superseded. Personal attribution and potentially identifying free text are removed when they are no longer needed.
  • Administrator access is disabled as soon as it is no longer needed. Inactive role assignments are kept for up to 12 months, application audit records for two years, and routine technical security logs for up to 90 days.
  • When CCTV is operating, routine footage is kept for no more than seven days and is then overwritten or deleted. A short, relevant clip may be kept for longer when needed to investigate an incident, respond to a request, support an insurance claim, meet a legal duty or assist the police. Any retained clip is deleted when it is no longer needed.

We review records and delete or anonymise personal information when it is no longer needed. We may keep a record longer if a complaint, incident, safeguarding matter, legal claim, tax enquiry or legal duty requires it. We record and review any such hold. Cloudflare D1 recovery history is limited by the service plan, currently seven or 30 days. Any separate backup export is kept for no more than 90 days, and due deletions are reapplied after a restore.

Cookies, security checks and the map

We do not use advertising or analytics cookies. Cloudflare may use strictly necessary cookies or similar technology to protect forms, prevent abuse and secure administrator access. These are needed for the website to work safely.

When membership payments are enabled, the Stripe-hosted payment page may use cookies and similar technology needed to process the payment, prevent fraud and keep the service secure. Stripe is responsible for the information it collects directly on that page.

The location section contains an embedded map from OpenStreetMap. When the map loads, OpenStreetMap receives technical information such as your IP address, browser and the page requesting the map. OpenStreetMap Foundation handles that information under its own privacy policy (opens in a new tab).

Automated decisions

We do not use personal information for automated decision-making or profiling. Decisions about membership and access to restricted equipment are made by people.

Your rights

Depending on the circumstances, you can ask us for a copy of your information, ask us to correct it, delete it or restrict how we use it, and ask for information you provided in a portable format. These rights are not absolute and depend on why we use the information. We normally respond within one month and do not charge a fee unless a request is clearly unfounded or excessive.

You have the right to object when we use your information on the basis of legitimate interests. Tell us what you object to and why using the contact details above.

Questions and complaints

Please contact us first if you have a privacy question or complaint so we can try to put things right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk (opens in a new tab), by telephone on 0303 123 1113, or by post to Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

Changes to this notice

We will update this page if our services or use of personal information changes. We will explain significant changes before they take effect where practical.