Privacy statement

This page provides details regarding the Institute’s privacy policies, covering our data security responsibilities in both offline and online contexts.

We regularly review our privacy notices and update them where necessary. If you have any questions or concerns regarding privacy in relation to this website or the Institute’s use of personal information, please contact us at admin@royalarchinst.org. If you are not satisfied with our response, you have the right to contact the Information Commissioner’s Office (ICO).

General Privacy Statement

  1. The Institute collects, stores and uses personal data about individuals for the legitimate interests of carrying out its business as a membership organisation for the promotion of archaeology under the terms of its Royal Charter. We believe these uses are in line with the reasonable expectations of members and non-members alike.
  2. The Institute acts as a data controller in setting policies for the processing of personal data. In some circumstances, it also acts as a data processor and may contract certain processing activities to external organisations.
  3. We only process personal data supplied by the individuals concerned, except in the case of nominees for Institute prizes, where details may be supplied by the nominating university.
  4. If you are a member of the Institute, we will retain your name, contact details and membership details for seven years after your last recorded subscription year.
  5. We may supply members’ names and postal addresses to printers and publishers for distribution of the Journal, newsletter and other mailings.
  6. We may supply members’ names and financial details to financial service providers for the administration of direct debit subscriptions.
  7. We may supply members’ names and membership details to auditors for financial audit purposes.
  8. We may supply members’ names to the Society of Antiquaries of London to facilitate access to its library.
  9. We may supply members’ names to members of Council when considering nominations for Council or committees.
  10. Members’ email addresses may be stored within the Institute’s email systems solely for communication purposes.
  11. If you attend Institute meetings or events (other than lectures in London), we may retain your name, contact details and financial details for seven years after the event.
  12. We may share names and contact details with organisations providing services for the event, such as hotels or venues.
  13. If you are an employee or pensioner of the Institute, we will retain your contact and financial details for seven years after the end of that relationship.
  14. If you are an officer, Council member or committee member, we will retain your contact and financial details for seven years after the last reimbursement or honorarium payment.
  15. If you are nominated for an Institute prize, we will retain your contact details for seven years after the award decision.
  16. If you apply for a grant from the Institute, we will retain your contact details for seven years after the award decision.
  17. If successful, your contact and financial details may be retained for twenty-five years after the award decision.
  18. If you contribute to an Institute publication, we will retain your contact details for twenty-five years after publication.
  19. If you act as a peer reviewer for Institute publications, we will retain your contact details for seven years after last active contact.
  20. Personal data are stored on password-protected computer systems with anti-virus protection and appropriate backup procedures. Oversight of data processing procedures, documentation and security measures is delegated by Council to the Audit and Investment Committee as part of the Institute’s annual risk assessment process.
  21. Personal data may also be stored securely within the offices of relevant Institute officers and administrators.

Your Rights Under Data Protection Law

Under UK data protection law, you have rights including:

  • The right of access — to request copies of your personal information.
  • The right to rectification — to request correction of inaccurate or incomplete personal information.
  • The right to erasure — to request deletion of your personal information in certain circumstances.
  • The right to restriction of processing — to request restriction of processing in certain circumstances.
  • The right to object to processing — to object to processing in certain circumstances.
  • The right to data portability — to request transfer of your personal information to another organisation or directly to you in certain circumstances.

Further information about these rights is available from the Information Commissioner’s Office.

If you wish to exercise any of these rights, please contact the Institute at admin@royalarchinst.org.

You will not normally be required to pay a fee to exercise your rights. However, the Institute may charge a reasonable fee, or refuse to comply with a request, if it is manifestly unfounded, repetitive or excessive.

The Institute may request information to confirm your identity before responding to a request. This is a security measure to ensure that personal data is not disclosed to anyone without the right to receive it.

We aim to respond to legitimate requests within one month. If a request is particularly complex or numerous, we may require additional time and will notify you accordingly.

If you have concerns about the Institute’s use of your personal information, you should contact us in the first instance at admin@royalarchinst.org.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection matters.

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline: 0303 123 1113
Website: https://www.ico.org.uk

Online / Website Privacy Statement

The Royal Archaeological Institute website, hosted at the University of York, is committed to safeguarding the privacy of individuals and organisations in accordance with the UK Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR).

We use cookies (small files stored on your computer) to:

  • Enhance website functionality, including storing user preferences.
  • Collect anonymous statistical information regarding website usage, including page visits and navigation patterns, to improve usability and structure.

All information collected through cookies is anonymous. You may disable cookies within your browser settings, although some parts of the website may no longer function correctly. The Institute accepts no liability for loss of functionality arising from disabled cookies.

This website does not routinely collect personal information as part of its core functionality. However, surveys, forms or feedback mechanisms hosted on the site may occasionally request personal information. In such cases:

  • The purpose of data collection will be made clear at the point of collection.
  • Information will not be used for purposes other than those specified.
  • Information will be treated confidentially and in accordance with applicable data protection legislation.

Where personal information is collected, individuals retain the right:

  • To request access to their personal data.
  • To request correction of inaccurate information.
  • To request deletion of data no longer required.
  • To request transfer of their data in a portable format.
  • To withdraw consent where processing is based on consent.

Social Media Policy Statement

The Royal Archaeological Institute’s social media policy and guidance document is available separately for download.

Downloads

RAI social media policy

PDF
120.12 KB