Privacy Policy

Last updated: 17 July 2026

Draft template notice. This page is a starting-point privacy policy drafted for Wexford Lodge's use of this platform. It is not legal advice and has not been reviewed by qualified legal counsel. Before relying on this page as your published policy, have it reviewed by a lawyer familiar with the data protection laws that apply to your lodge's members (which may include the EU General Data Protection Regulation, the California Consumer Privacy Act, and/or South Africa's Protection of Personal Information Act, depending on where your members are located), and update the bracketed contact details below with your lodge's own.

1. Introduction and scope

This Privacy Policy explains how Wexford Lodge ("the Lodge", "we", "us", "our") collects, uses, discloses, and protects personal information when you use the Masonic Lodge Digital Platform (the "Platform") - the member web portal, the public website, and the companion mobile application - and how you can exercise your privacy rights.

This policy applies to prospective members submitting an enquiry, members and officers of the Lodge, and visitors to the Lodge's public website. It does not apply to third-party websites you may reach through links on our site.

2. Who controls your data

Wexford Lodge is the data controller for the personal information of its own members, officers, and prospective members - it decides why and how that data is used. The Platform is provided as software by ATH SOLUTIONS (PTY) LTD ("ATH Solutions"), which acts as a data processor hosting and operating the underlying technology on the Lodge's instructions. Each lodge using this Platform has its own separate, isolated set of member data - your data is never mixed with, or made visible to, another lodge unless your own lodge officers explicitly link your record to another lodge because you hold membership at more than one lodge.

3. Personal data we collect

Depending on how you interact with the Platform, we may collect:

  • Identity and contact data - full name, preferred name, email address, phone number, physical address.
  • Membership data - member number, member class, status, current degree, degree-conferral history, offices held, and lodge career history.
  • Financial data - dues, invoices, payment status, credit-wallet balances and transaction history, raffle purchases. The Platform does not currently process online card payments - amounts owed are settled outside the Platform and recorded by a treasurer.
  • Event and attendance data - RSVP responses, dietary notes, guest counts, attendance and minutes records.
  • Communications - messages sent and received through the Platform, and any correspondence you send us directly (e.g. an enquiry or facility-hire request).
  • Welfare information - where relevant to Masonic welfare/almoner support, notes recorded by authorised officers. This category of information receives narrower internal access than the rest of your profile (see §8).
  • Account and technical data - login credentials (stored as a one-way cryptographic hash, never in plain text), session and device information, IP address, and, for the mobile app, device identifiers needed for push notifications.

We collect this data directly from you (e.g. when you register, complete your profile, or submit a form), from Lodge officers acting on the Lodge's behalf (e.g. recording a degree conferral), and automatically through your use of the Platform (e.g. login timestamps).

4. How we use your data

  • To administer your membership, including degree progression, offices, and status.
  • To organise and communicate about Lodge meetings, events, and festive boards, and to record attendance.
  • To manage dues, invoices, credit-wallet balances, and other Lodge financial administration.
  • To send you circulars, notices, and summonses relevant to your membership.
  • To provide welfare support where you or the Lodge's almoner have indicated a need.
  • To maintain the security, integrity, and audit trail of the Platform (e.g. login records, an append-only audit log of sensitive actions).
  • To respond to enquiries from prospective members and facility-hire requests from the public.
  • To comply with legal, regulatory, or Grand Lodge reporting obligations.

6. How your data is shared

We do not sell your personal information. We may share it with:

  • ATH Solutions, as the processor hosting and operating the Platform on the Lodge's behalf, under a data-processing agreement.
  • Accounting/bookkeeping integrations a treasurer chooses to connect (e.g. Xero, Sage, or QuickBooks), limited to the financial ledger data needed to keep the Lodge's books synchronised.
  • Email delivery infrastructure used to send you notices, circulars, and password-reset emails.
  • Allied lodges, only where an officer has explicitly created a cross-lodge communication or a plural-membership link involving your record, and only to the minimal extent that link requires.
  • Regulators, Grand Lodge bodies, or law enforcement, where required by law.

7. How long we keep your data

We retain your personal data for as long as you remain a member, and for a reasonable period afterwards to satisfy Lodge record-keeping, historical, financial, and legal obligations (financial records in particular are typically kept for several years to satisfy tax and audit requirements). Welfare notes and audit-log entries are retained under the same principle - no longer than reasonably necessary for the purpose they were recorded for. You may ask us about the specific retention period that applies to a category of your data using the contact details in §16.

8. How we protect your data

We apply technical and organisational measures appropriate to the sensitivity of your data, including tenant data isolation so one lodge can never see another's members, role-based access controls (for example, welfare notes are visible only to the almoner, secretary, worshipful master, and platform administrators - not to the general membership), encrypted transport (HTTPS/TLS), one-way hashed passwords, and an append-only audit log of sensitive actions. Full detail is published in our Security Policy.

9. Your privacy rights

Subject to the law that applies to you, you generally have the right to:

  • Ask us to confirm what personal data we hold about you and receive a copy of it (access/portability).
  • Ask us to correct inaccurate or incomplete data (rectification).
  • Ask us to delete your data, subject to our legitimate need to retain certain records (erasure).
  • Object to, or ask us to restrict, certain processing.
  • Withdraw consent you previously gave, without affecting processing carried out before the withdrawal.
  • Lodge a complaint with your local data protection regulator.

To exercise any of these rights, contact your Lodge secretary or use the details in §16. We will respond within the timeframe required by the law that applies to your request. To request erasure specifically, a signed-in member can use the "Request Account Deletion" action on their own profile page (or the equivalent action in the mobile app's Profile screen) - this submits a request that an officer reviews before anything is erased.

10. GDPR - additional information for EU/EEA members

If you are located in the European Union or European Economic Area, the General Data Protection Regulation (EU) 2016/679 ("GDPR") gives you the rights described in §9, plus the right to lodge a complaint with your national supervisory authority. Where we transfer your data outside the EU/EEA (for example, to hosting infrastructure located in South Africa), we do so on the basis of appropriate safeguards, such as standard contractual clauses, or another lawful transfer mechanism.

11. CCPA/CPRA - additional information for California residents

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), gives you the right to know what personal information we collect, use, disclose, and (where applicable) sell about you; the right to delete personal information we hold about you, subject to certain exceptions; the right to correct inaccurate personal information; and the right to opt out of the sale or sharing of personal information. We do not sell or share your personal information for cross-context behavioural advertising. We will not discriminate against you for exercising any of these rights. You, or an authorised agent acting on your behalf, may submit a request using the details in §16.

12. POPIA - additional information for South African data subjects

If you are located in South Africa, the Protection of Personal Information Act, 2013 ("POPIA") gives you the rights described in §9, plus the right to object to the processing of your personal information in certain circumstances, and the right to lodge a complaint with the Information Regulator (South Africa). Where we process special personal information (for example, welfare information that may touch on health) or the personal information of a data subject, we do so only with an appropriate justification recognised by POPIA, such as your consent or a legitimate Lodge purpose, and with the narrower access controls described in §8.

13. Cookies and similar technologies

The Platform uses only what is strictly necessary to operate: a session cookie to keep you signed in, a CSRF token to protect forms from cross-site request forgery, and a local, on-device preference (such as your light/dark theme choice) stored in your browser. We do not use third-party advertising or analytics trackers, and all fonts, scripts, and libraries the Platform needs are hosted on our own infrastructure rather than loaded from third-party content-delivery networks.

14. Children's privacy

The Platform is intended for adult members of a Masonic lodge and is not directed at, or knowingly used to collect personal information from, children. If you believe a child has provided us with personal information, please contact us using the details in §16 so we can delete it.

15. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to the Platform or applicable law. We will update the "Last updated" date at the top of this page when we do, and, for material changes, we will take reasonable steps to notify members directly.

16. Contact us

For questions about this policy or to exercise a privacy right, contact your Lodge secretary through the Platform, or reach the Lodge directly using the details on our Contact page. For questions about the Platform's technology, security, or ATH Solutions as the processor, contact info@ath.solutions.