ΕΛ EN

Privacy Notice

How the Greek Library of London handles your personal information

Last updated: 26 Aug 2026

This notice explains what personal information the Greek Library of London collects when you use our catalogue and membership system, why we collect it, how long we keep it, and the rights you have over it. We have tried to write it in plain English. If anything is unclear, please ask. The contact details are at the end.

Who is responsible for your data

The data controller is EKIVIL - Greek Library of London, a charity registered in England and Wales (charity number 1179392). This means the charity, through its trustees, is legally accountable for the personal information described here.

Registered address: 250 Burnt Oak Broadway, Edgware, London, HA8 0GA

We are registered with the Information Commissioner's Office (ICO) as a data controller, registration number ZC229404.

What we collect

We only collect what the library actually needs to run a lending service. Specifically:

When you become a member

Your name, email address, postal address and postcode, telephone number, and date of birth. Date of birth is used to check eligibility for the reduced youth membership rate and, where relevant, to identify members under 18. We also record the date you joined, your membership number and tier, your membership expiry date, and your preferred language for our communications.

When you use the library

Records of the items you borrow, renew, return and reserve, together with due dates and any overdue fines charged, paid or waived. We also store items you add to your wishlist or favourites, any catalogue corrections you report to us, and notifications we have sent you.

When you pay

Whether your membership fee has been paid, the payment method, your membership renewal and grace-period dates, and identifiers issued by our payment provider. We do not receive or store your card number, expiry date or security code at any point. Those go directly to Stripe and never reach our systems.

When you book a visit

The date and time of your visit and whether you attended. If you book as a guest rather than as a member, we also collect the name, email address and telephone number you give us for that booking. If you tell us that children are coming with you, we store the name you give for each child, so the volunteer on duty knows who to expect. We ask for nothing else about them, we never contact them, and their names are kept and deleted on exactly the same schedule as the rest of the booking. You can ask us to correct or remove a name at any time.

When you use "Explore books"

The "Explore books" feed suggests titles you might like. To do that it records which books it showed you, which ones you swiped past, how long each was on screen, and which ones you saved, reserved or opened. It uses that, together with what you have borrowed and saved, to order what it shows you next. This record is only used to choose which books to put in front of you. It is not used to build a profile for any other purpose, is never shared, and is deleted on the schedule set out below. You can use the catalogue, search and browse the shelves without it: the feed is a separate screen you choose to open.

When you apply to volunteer

Your name, email address and, if you give it, telephone number; the areas you are interested in; your answers about your experience, your reasons for volunteering and your availability; any CV file or link you choose to share; and, if you are interested in working with children, whether you hold a DBS check. We use this only to consider your application and to contact you about it. The application is stored in our system and emailed to the library's own inbox so the team can reply to you. Your CV can only be opened by library administrators.

Technical information

Our server keeps short error logs which may include the address of the page requested and the IP address that requested it. These exist so we can fix faults, are not used to build any profile of you, and are deleted on a rolling basis.

Library staff and volunteers

For staff and volunteer accounts we hold a name, email address, role, and a securely hashed password. We record failed sign-in attempts in order to lock accounts against password-guessing.

Why we use it, and our lawful basis

UK GDPR requires us to have a specific lawful basis for each use of your information. Ours are:

Performance of a contract
Managing your membership, lending items to you, taking payment for membership, handling reservations and renewals, and contacting you about items you have borrowed. Without this information we cannot provide you with a membership.
Legal obligation
Keeping financial records of membership fees and fines for the period required of a registered charity, and responding to requests we are legally obliged to answer.
Legitimate interests
Keeping the library's collection secure, for example recovering items that are not returned, and keeping our systems safe from misuse, such as locking accounts after repeated failed sign-in attempts. It is also the basis on which we suggest books to you in "Explore books", using what you have borrowed, saved and browsed. We have considered whether these uses could prejudice your rights and consider them limited and reasonably expected. If you would rather we did not use your activity to make suggestions, tell us and we will stop.
Consent
Sending you our newsletter. This is entirely optional, is never a condition of membership, and you can withdraw it at any time from your account or by using the unsubscribe link in any newsletter. Withdrawing it does not affect anything else about your membership.

Your borrowing history

What a person reads can reveal a great deal about them: their beliefs, health, politics or personal circumstances. We treat borrowing history accordingly. It is visible only to you, and to library staff who need it to run the lending service. It is never sold, never shared for marketing, and never disclosed to anyone else except where we are legally required to do so. Other members cannot see what you have borrowed.

The same applies to what you browse. The record of which books the "Explore books" feed showed you, and which you passed over, is treated exactly like borrowing history: yours, private, never sold or shared, and used for nothing except deciding which book to show you next.

Who we share it with

We do not sell your information, and we do not share it for anyone else's marketing. We do use a small number of service providers who process data on our behalf, under contract and on our instructions:

  • Stripe: processes membership payments. Stripe receives your email address and the payment details you enter directly into their secure form. Stripe is PCI-DSS compliant; we never see or hold your card details.
  • Supabase: provides the sign-in system for member accounts. It holds your email address and an encrypted representation of your password so you can log in and reset it.
  • Mailchimp: sends our newsletter, and only if you have opted in. It receives your email address, first and last name, and your language preference. If you opt out, we mark you as unsubscribed there.
  • Our email provider: delivers service messages such as due-date reminders, overdue notices and reservation-ready alerts. These messages relate to your membership and are not marketing.
  • Our hosting provider: stores the library database and website files on our behalf.
  • Donorbox: hosts our fundraising campaign and the progress meter shown beside it. When a page carrying that meter loads, your browser fetches it from Donorbox, which means Donorbox can see your IP address and may set its own cookies, in the same way as any embedded content. We send them nothing about you, and nothing about your membership or borrowing. If you go on to donate, the details you enter go to Donorbox and their payment provider, not to us. We receive the donation and the name and email you chose to give.

We may also disclose information where we are required to by law, or to establish or defend legal claims.

One thing worth knowing: cover images in our catalogue are displayed directly from the publishers' and book databases' own servers. When you browse the catalogue, your browser fetches those images from those third parties, which means they can see your IP address, in the same way as visiting any website that shows an image from elsewhere. We do not send them any information about you or about what you have borrowed.

Where your data is stored

The library database is hosted at: United Kingdom (names.co.uk, Thames Valley). The member sign-in service stores its data in: eu-central-1 (Frankfurt, Germany).

Where any provider stores or processes personal data outside the UK, that transfer is covered by the safeguards UK data protection law requires, such as the UK International Data Transfer Agreement or an adequacy decision. If you would like details of the safeguards for a particular provider, please ask.

How long we keep it

We do not keep personal information indefinitely. Our current periods are:

  • Membership records: kept for 7 years after your membership ends, which allows us to meet charity financial record-keeping obligations and to reinstate a lapsed membership if you return.
  • Borrowing history: kept for 24 months after an item is returned, then deleted. Aggregate statistics that cannot identify you (for example how many times a title was borrowed) may be kept longer.
  • Visit bookings, including guest contact details: kept for 12 months.
  • Discovery feed activity (the record of which books were shown to you and which you skipped): kept for 6 months, then deleted automatically. Counts that cannot identify you, such as how often a title was saved from the feed, may be kept longer.
  • Volunteer applications, including any CV: kept for 12 months after we have finished considering them, then deleted. If you join the volunteer team, we keep only the contact details we need to organise your volunteering. You can ask us to delete your application at any time.
  • Technical error logs: kept only as long as needed to diagnose faults, and routinely deleted.

Where we are required to keep financial records for longer under charity or tax law, we keep only the financial record itself, not the wider membership file.

Children and young people

We welcome young readers. Under UK data protection law, a child aged 13 or over can consent to their own information being used by an online service; below that age, a parent or guardian must give consent on their behalf.

If you are under 13, please ask a parent or guardian to complete your membership with you, and to contact us using the details below so we can record their consent. If you believe a child under 13 has registered without that consent, tell us and we will resolve it promptly.

A parent or guardian may ask to see or correct the information we hold about their child. We handle those requests carefully, taking into account the child's own privacy as they get older.

Your rights

Under UK GDPR you have the right to:

  • Ask for a copy of the personal information we hold about you.
  • Ask us to correct anything that is wrong or incomplete. You can change most of it yourself under "My profile".
  • Ask us to delete your information. We can normally do this once any borrowed items are returned and any outstanding fines are settled, though we may need to keep limited financial records.
  • Ask us to restrict how we use your information while a query is resolved.
  • Object to our using your information on the basis of legitimate interests.
  • Ask for the information you gave us in a portable electronic format.
  • Withdraw consent for the newsletter at any time, without affecting your membership.

To exercise any of these, contact us using the details below. We will respond within one month. There is no charge.

Cookies

This site uses a single cookie: a session cookie that keeps you signed in as you move between pages and protects forms against cross-site request forgery. It contains no personal information, is deleted when you close your browser or sign out, and is strictly necessary for the site to work.

We use no analytics, advertising or social media tracking cookies of any kind. We do not track you across other websites, and we do not build advertising profiles. Because we only use a strictly necessary cookie, we are not required to ask for your consent, which is why you will not see a cookie banner here.

How we protect your information

The site is served over an encrypted HTTPS connection. Passwords are stored using one-way hashing and are never readable by staff or by us. Access to member records is restricted to signed-in library staff, and the most sensitive actions (deleting records, waiving fines, exporting member lists) are restricted further to administrators. Accounts lock temporarily after repeated failed sign-in attempts.

If a breach of personal data occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and we will tell you directly without undue delay where the risk to you is high.

Changes to this notice

We may update this notice as the library's services change. The date at the top shows when it was last revised. If we make a significant change to how we use your information, we will tell members directly rather than relying on you to notice.

Contact us

For any question about this notice, or to exercise any of your rights, please contact:

Data protection contact: Ioannis Kolikis, Head of Operations

Email: jkolikis@greeklibrary.org

Post: 250 Burnt Oak Broadway, Edgware, London, HA8 0GA

If you are unhappy

Please come to us first. We would rather put things right. But you always have the right to complain directly to the Information Commissioner's Office, the UK's data protection regulator, and you do not need our permission to do so.

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline 0303 123 1113. ico.org.uk