Skip to main content

Your Data

Privacy Policy

Last updated: 7 August 2026

Who we are

This website is operated by the office of Cllr Danny Carter, Councillor for Pype Hayes & Erdington, Birmingham City Council ("we", "us"). We are the data controller for the personal data collected through this site. You can contact us about your data at danny.carter@birmingham.gov.uk.

Data protection registration

We are registered with the Information Commissioner's Office (ICO) as a data controller under the Data Protection Act 2018. Our ICO Registration Number is ZC211392. You can verify our registration on the ICO public register. This means our collection and use of your personal data is regulated by, and compliant with, UK data protection law.

What we collect and why

  • Account details (name, email, contact and address information you add to your profile) — to provide your resident or business account. Lawful basis: contract.
  • Donations (name, registered address, email, amount) — required by the Political Parties, Elections and Referendums Act 2000 for permissibility checks and reporting. Lawful basis: legal obligation.
  • Casework (contact details, your issue, related correspondence, any attachments) — to take up your case with the council. Lawful basis: consent, and public task for councillor casework. A contact phone number is required before using the AI Caseworker, so Danny's office can follow up on anything raised.
  • Civic Hub Messages (your message threads with Danny's office) — to hold two-way correspondence with you about your enquiries; replies are also sent to your email address. Lawful basis: public task for councillor casework.
  • Message attachments and voice notes (files, photos and audio you attach to a message) — to give Danny's office the evidence and detail needed to act. Voice notes are converted to text automatically by a third-party speech-to-text provider so your message can be read and actioned; the transcript is stored alongside the recording and shown only to you and Danny's authorised team. Attachments and transcripts are included in your data export and are permanently erased when you delete your account. Lawful basis: consent.
  • Surgery bookings (name, email, phone, topic) — to arrange and hold your appointment. Lawful basis: consent.
  • Event registrations and tickets (name, email) — to issue your ticket and manage attendance. Lawful basis: contract.
  • Book orders (email, shipping address for physical orders) — to fulfil your purchase. Payments are processed by Stripe; we never see your card details. Lawful basis: contract.
  • Petitions, surveys and forum posts — petition signatures (your name and any comment) are displayed publicly by design; survey responses are analysed in aggregate. Lawful basis: consent.
  • Newsletter signup (email, optional first name) — to send you ward news and updates you've asked for. We use double opt-in: nothing is sent until you click the confirmation link, and every email contains a one-click unsubscribe link. Lawful basis: consent.
  • Email engagement — bulk update emails contain a tracking pixel and tracked links so we can see how many recipients opened or clicked a campaign. Only a pseudonymous code is recorded, never your email address, and it is used solely in aggregate to improve our communications. Lawful basis: legitimate interest.
  • Blog comments (your display name and comment text; your email is stored but never shown publicly) — to display your comment on the post. Comments are screened by automated moderation against our Rules of Engagement, and comments that breach those rules may be hidden or permanently deleted by moderators. Lawful basis: consent.

AI processing

The AI Caseworker chat and some content tools use third-party AI providers to process the text you submit. Chat transcripts are automatically and permanently deleted after 28 days, and you can delete a conversation yourself at any time. Conversations may generate a case summary for Danny's team when follow-up is needed — this is shown to you in the consent notice before you start.

Who we share data with

  • Stripe — payment processing for donations and purchases.
  • Google — calendar entries and video-call links for surgery bookings.
  • Email delivery providers — to send you confirmations, tickets, receipts and updates you've opted into.
  • Birmingham City Council — casework details are shared with relevant council departments when you ask us to take up an issue.
  • The Electoral Commission — donation records where reporting thresholds are met, as required by law.

We never sell your data.

How long we keep your data

  • Donation records — 6 years (HMRC record-keeping rules and electoral law), even if you delete your account; personal details are anonymised on account deletion where the law allows.
  • AI chat transcripts — deleted automatically after 28 days.
  • Casework records — kept while your case is open and for up to 2 years after closure, so we can assist with follow-ups, then deleted or anonymised.
  • Civic Hub messages, attachments, voice notes and their transcripts, and office notes — kept until you delete your account, at which point they are permanently erased.
  • Forum posts and blog comments — kept while published; permanently erased when you delete your account, or earlier if removed by moderation.
  • Newsletter subscriptions — kept while you're subscribed; your record is marked unsubscribed the moment you opt out, and permanently erased if you delete an account held under the same email.
  • Account data — kept until you delete your account.

Your rights

Under UK GDPR you have the right to access, correct, export, restrict, object to processing of, and erase your personal data. Two of these are built into your account:

  • Export my data — download everything we hold about you from your privacy settings.
  • Delete my account — permanently erase your account and personal data (financial records are anonymised, not deleted, as required by law — UK GDPR Article 17(3)(b)).

For anything else, email danny.carter@birmingham.gov.uk. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

Cookies and local storage

We use strictly necessary storage to keep you signed in and remember preferences such as your theme choice and whether you've dismissed notices. We do not use third-party advertising or tracking cookies.

Security

Personal data is protected with per-record access rules — your records are visible only to you and to Danny's authorised team. Payment details are handled entirely by Stripe. Files such as receipts and tickets are stored in private storage accessible only via time-limited links.

Changes to this policy

We'll update this page when our practices change, and update the "last updated" date above.

Only essential cookies — no tracking. Privacy Policy