Privacy Policy
Last updated: 17 July 2026
1. Introduction and scope
This Privacy Policy explains how Wexford Lodge ("the Lodge", "we", "us", "our") collects, uses, discloses, and protects personal information when you use the Masonic Lodge Digital Platform (the "Platform") - the member web portal, the public website, and the companion mobile application - and how you can exercise your privacy rights.
This policy applies to prospective members submitting an enquiry, members and officers of the Lodge, and visitors to the Lodge's public website. It does not apply to third-party websites you may reach through links on our site.
2. Who controls your data
Wexford Lodge is the data controller for the personal information of its own members, officers, and prospective members - it decides why and how that data is used. The Platform is provided as software by ATH SOLUTIONS (PTY) LTD ("ATH Solutions"), which acts as a data processor hosting and operating the underlying technology on the Lodge's instructions. Each lodge using this Platform has its own separate, isolated set of member data - your data is never mixed with, or made visible to, another lodge unless your own lodge officers explicitly link your record to another lodge because you hold membership at more than one lodge.
3. Personal data we collect
Depending on how you interact with the Platform, we may collect:
- Identity and contact data - full name, preferred name, email address, phone number, physical address.
- Membership data - member number, member class, status, current degree, degree-conferral history, offices held, and lodge career history.
- Financial data - dues, invoices, payment status, credit-wallet balances and transaction history, raffle purchases. The Platform does not currently process online card payments - amounts owed are settled outside the Platform and recorded by a treasurer.
- Event and attendance data - RSVP responses, dietary notes, guest counts, attendance and minutes records.
- Communications - messages sent and received through the Platform, and any correspondence you send us directly (e.g. an enquiry or facility-hire request).
- Welfare information - where relevant to Masonic welfare/almoner support, notes recorded by authorised officers. This category of information receives narrower internal access than the rest of your profile (see §8).
- Account and technical data - login credentials (stored as a one-way cryptographic hash, never in plain text), session and device information, IP address, and, for the mobile app, device identifiers needed for push notifications.
We collect this data directly from you (e.g. when you register, complete your profile, or submit a form), from Lodge officers acting on the Lodge's behalf (e.g. recording a degree conferral), and automatically through your use of the Platform (e.g. login timestamps).
4. How we use your data
- To administer your membership, including degree progression, offices, and status.
- To organise and communicate about Lodge meetings, events, and festive boards, and to record attendance.
- To manage dues, invoices, credit-wallet balances, and other Lodge financial administration.
- To send you circulars, notices, and summonses relevant to your membership.
- To provide welfare support where you or the Lodge's almoner have indicated a need.
- To maintain the security, integrity, and audit trail of the Platform (e.g. login records, an append-only audit log of sensitive actions).
- To respond to enquiries from prospective members and facility-hire requests from the public.
- To comply with legal, regulatory, or Grand Lodge reporting obligations.
5. Legal bases for processing (GDPR)
Where the GDPR applies to our processing of your data, we rely on the following legal bases:
- Contract / membership relationship - processing necessary to administer your Lodge membership.
- Consent - for optional communications, and wherever a form on the Platform asks you to explicitly opt in (e.g. the POPIA consent checkbox on our public enquiry and facility-hire forms). You may withdraw consent at any time.
- Legitimate interests - for Platform security, fraud prevention, and the day-to-day administration of Lodge business, balanced against your rights and freedoms.
- Legal obligation - where we must retain or disclose data to comply with the law or a Grand Lodge's governing requirements.
7. How long we keep your data
We retain your personal data for as long as you remain a member, and for a reasonable period afterwards to satisfy Lodge record-keeping, historical, financial, and legal obligations (financial records in particular are typically kept for several years to satisfy tax and audit requirements). Welfare notes and audit-log entries are retained under the same principle - no longer than reasonably necessary for the purpose they were recorded for. You may ask us about the specific retention period that applies to a category of your data using the contact details in §16.
8. How we protect your data
We apply technical and organisational measures appropriate to the sensitivity of your data, including tenant data isolation so one lodge can never see another's members, role-based access controls (for example, welfare notes are visible only to the almoner, secretary, worshipful master, and platform administrators - not to the general membership), encrypted transport (HTTPS/TLS), one-way hashed passwords, and an append-only audit log of sensitive actions. Full detail is published in our Security Policy.
9. Your privacy rights
Subject to the law that applies to you, you generally have the right to:
- Ask us to confirm what personal data we hold about you and receive a copy of it (access/portability).
- Ask us to correct inaccurate or incomplete data (rectification).
- Ask us to delete your data, subject to our legitimate need to retain certain records (erasure).
- Object to, or ask us to restrict, certain processing.
- Withdraw consent you previously gave, without affecting processing carried out before the withdrawal.
- Lodge a complaint with your local data protection regulator.
To exercise any of these rights, contact your Lodge secretary or use the details in §16. We will respond within the timeframe required by the law that applies to your request. To request erasure specifically, a signed-in member can use the "Request Account Deletion" action on their own profile page (or the equivalent action in the mobile app's Profile screen) - this submits a request that an officer reviews before anything is erased.
10. GDPR - additional information for EU/EEA members
If you are located in the European Union or European Economic Area, the General Data Protection Regulation (EU) 2016/679 ("GDPR") gives you the rights described in §9, plus the right to lodge a complaint with your national supervisory authority. Where we transfer your data outside the EU/EEA (for example, to hosting infrastructure located in South Africa), we do so on the basis of appropriate safeguards, such as standard contractual clauses, or another lawful transfer mechanism.
11. CCPA/CPRA - additional information for California residents
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), gives you the right to know what personal information we collect, use, disclose, and (where applicable) sell about you; the right to delete personal information we hold about you, subject to certain exceptions; the right to correct inaccurate personal information; and the right to opt out of the sale or sharing of personal information. We do not sell or share your personal information for cross-context behavioural advertising. We will not discriminate against you for exercising any of these rights. You, or an authorised agent acting on your behalf, may submit a request using the details in §16.
12. POPIA - additional information for South African data subjects
If you are located in South Africa, the Protection of Personal Information Act, 2013 ("POPIA") gives you the rights described in §9, plus the right to object to the processing of your personal information in certain circumstances, and the right to lodge a complaint with the Information Regulator (South Africa). Where we process special personal information (for example, welfare information that may touch on health) or the personal information of a data subject, we do so only with an appropriate justification recognised by POPIA, such as your consent or a legitimate Lodge purpose, and with the narrower access controls described in §8.
14. Children's privacy
The Platform is intended for adult members of a Masonic lodge and is not directed at, or knowingly used to collect personal information from, children. If you believe a child has provided us with personal information, please contact us using the details in §16 so we can delete it.
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the Platform or applicable law. We will update the "Last updated" date at the top of this page when we do, and, for material changes, we will take reasonable steps to notify members directly.
16. Contact us
For questions about this policy or to exercise a privacy right, contact your Lodge secretary through the Platform, or reach the Lodge directly using the details on our Contact page. For questions about the Platform's technology, security, or ATH Solutions as the processor, contact info@ath.solutions.