Clay Family Society, Inc.
Adopted by the Board of Directors on May 5, 2026
Last updated: May 5, 2026
This GDPR Statement supplements the Privacy Policy by describing how the Clay Family Society applies GDPR principles where applicable as well as data protection principles for individuals covered by the EU General Data Protection Regulation.
1. Purpose and Scope
This GDPR Statement explains how the Clay Family Society (“CFS,” “we,” “our”) complies with the EU General Data Protection Regulation (GDPR) and the UK GDPR in relation to personal data processed through the Clay Family Society WordPress website (“the Site”).
This Statement applies to visitors, members, donors, researchers, and correspondents located in the European Union or United Kingdom, or whose personal data is otherwise subject to GDPR protections. It supplements—but does not replace—our Privacy Policy.
2. Data Controller
For GDPR purposes, the Clay Family Society is the Data Controller for personal data processed through the Site.
Contact for data protection matters:
admin@clayfamilysociety.org (subject: GDPR Request)
Due to its size and nonprofit nature, CFS does not appoint a formal Data Protection Officer. Privacy and data protection responsibilities are managed by designated officers of the Society.
3. Lawful Bases for Processing
CFS processes personal data under one or more lawful bases under GDPR, including:
• Consent (e.g., newsletters, voluntary submissions, DNA-related participation where applicable)
• Contractual necessity (e.g., membership administration, registrations)
• Legitimate interests (e.g., maintaining Society records, genealogical research support, site security and fraud prevention), balanced against individual rights
• Legal obligation (e.g., financial and accounting requirements) CFS does not engage in automated decision-making producing legal or similarly significant effects on individuals.
4. Categories of Personal Data
Depending on interaction with the Site, CFS may process:
- Identification and contact information (name, email address)
- Membership and donation records
- Genealogical information voluntarily submitted by members or researchers
- Website usage data (IP address, browser type, cookies)
Sensitive personal data (such as genetic test results) is processed only when explicitly provided by the data subject and is handled with heightened care. CFS does not sell or commercially exploit personal data.
Where special category data is provided (including genetic or health-related information), it is processed only with explicit consent and subject to appropriate safeguards.
5. Data Sharing and International Transfers
CFS uses third-party service providers (e.g., web hosting, email services, and related infrastructure) to operate the Site. These providers act as Data Processors and are expected to maintain appropriate data protection standards. Where personal data is transferred outside the EU/UK, CFS relies on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses where applicable.
CFS selects service providers based on their published data protection commitments but does not control their underlying infrastructure.rty platforms but selects providers with published GDPR compliance commitments.
6. Data Retention
Personal data is retained only for as long as necessary for the purposes for which it was collected, including membership administration, legal obligations, and legitimate archival and historical purposes.
Where data is retained for archival or genealogical purposes, it is subject to safeguards intended to respect data protection principles, including access limitation and contextual relevance.
7. Your Rights Under GDPR
If you are subject to GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate or incomplete data
- Request erasure (“right to be forgotten”)
- Restrict or object to processing
- Request data portability
- Withdraw consent at any time (where consent is the lawful basis)
Requests should be submitted via email to admin@clayfamilysociety.org. We aim to respond within 30 days, as required by GDPR.
You also have the right to lodge a complaint with your local data protection authority.
8. Cookies and Tracking
The Site uses cookies for essential functionality, security, and limited analytics. Where required, users are provided with consent options in accordance with applicable law.
9. Updates to This Statement
This GDPR Statement may be updated periodically to reflect regulatory changes or operational updates. The “last updated” date will be revised accordingly. Continued use of the Site constitutes acknowledgment of the current version.