Privacy Policy

Bamburgh Castle and Cragside Estate

Last updated: 18 February 2026


1. Who We Are

Bamburgh Castle and Cragside Estate (“we”, “us”, “our”) is the data controller responsible for your personal data.

Registered office:
Bamburgh Castle
Bamburgh
Northumberland
NE69 7AU
United Kingdom

Email: administrator@bamburghcastle.com

For the purposes of UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the “data controller”.


2. The Personal Data We Collect

We may collect and process the following categories of personal data:

A. Information You Provide to Us

  • Name

  • Postal address

  • Email address

  • Telephone number

  • Booking details

  • Payment details (processed securely via payment providers)

  • Enquiry details

  • Marketing preferences

  • Access requirements (where voluntarily provided)

B. Booking and Transaction Information

When you purchase tickets, accommodation, holiday lettings, events or other services, we collect information necessary to fulfil your booking and meet legal and accounting obligations.

C. Website Usage Data

When you use our website (www.bamburghcastle.com), we automatically collect:

  • IP address

  • Browser type and version

  • Device type

  • Operating system

  • Referral source

  • Pages visited

  • Time spent on pages

  • Clickstream data

This data may be collected via cookies (see Section 9).

D. CCTV and Visual Recordings

CCTV operates throughout the estate for safety and security purposes. Images may be recorded.

E. Information from Third Parties

We may receive your details from:

  • Event directories

  • Wedding platforms

  • Tourism marketing organisations

  • Booking platforms

  • Payment processors


3. Our Lawful Bases for Processing

Under UK GDPR, we must have a lawful basis for processing your personal data. These are:

Contract

We process your data to:

  • Fulfil bookings

  • Process payments

  • Provide tickets and services

  • Respond to service-related enquiries

Legal Obligation

We process data to:

  • Comply with tax and accounting laws

  • Prevent fraud

  • Respond to lawful requests from authorities

Legitimate Interests

We process data where it is necessary for our legitimate interests, including:

  • Operating and improving our website

  • Business administration

  • Security monitoring (CCTV)

  • Analysing visitor trends

  • Managing customer relationships

We ensure our legitimate interests do not override your rights.

Consent

We rely on consent for:

  • Email marketing

  • Non-essential cookies

  • Use of images for promotional purposes (where required)

You may withdraw consent at any time.

Special Category Data (if applicable)

If you provide information about health or access requirements, we process this:

  • With your explicit consent, and/or

  • To ensure accessibility and visitor safety.


4. How We Use Your Personal Data

We use your personal data to:

  • Process bookings and purchases

  • Provide accommodation, holiday lettings, and events

  • Respond to enquiries

  • Send marketing communications (where permitted)

  • Improve our website and visitor experience

  • Maintain site security

  • Comply with legal obligations


5. Marketing Communications

You will receive marketing communications from us if:

  • You have opted in, or

  • You have purchased from us and have not opted out (soft opt-in, where applicable).

You can:

  • Unsubscribe via the link in any email

  • Contact us to update preferences

  • Withdraw consent at any time

We do not sell your personal data.


6. Sharing Your Personal Data

We may share your personal data with:

  • Payment service providers

  • Email marketing providers (e.g. Mailchimp or equivalent)

  • Website hosting providers

  • IT service providers

  • Professional advisers (accountants, legal advisers)

  • Event partners where required

  • Law enforcement or regulatory authorities where legally required

All third-party processors are required to protect your data and process it lawfully.


7. International Data Transfers

Some of our service providers may be located outside the UK.

Where personal data is transferred internationally, we ensure appropriate safeguards are in place, such as:

  • UK International Data Transfer Agreement (IDTA)

  • UK Addendum to EU Standard Contractual Clauses

  • Adequacy regulations approved by the UK Government

You may request details of these safeguards.


8. Data Retention

We retain personal data only for as long as necessary:

  • Booking and financial records: up to 6 years (for tax/legal compliance)

  • Marketing data: until you withdraw consent or unsubscribe

  • CCTV footage: typically retained for 30–90 days unless required for investigation

  • Enquiry data: up to 24 months

Where data is no longer required, it is securely deleted or anonymised.


9. Cookies

Our website uses cookies and similar technologies.

Strictly Necessary Cookies

Required for website functionality (do not require consent).

Analytics Cookies

Used to understand how visitors use our website (e.g. Google Analytics). These are only activated with your consent.

Marketing Cookies

Used to deliver relevant advertising (if applicable).

You can manage your cookie preferences via our cookie banner and settings tool.

You may also block cookies through your browser settings. However, some parts of the website may not function properly.


10. Security of Your Data

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Secure servers

  • Encrypted payment processing

  • Restricted staff access

  • CCTV monitoring

However, transmission of information via the internet cannot be guaranteed to be completely secure.


11. Your Data Protection Rights

Under UK GDPR, you have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request erasure of your data

  • Restrict processing

  • Object to processing (including marketing)

  • Request data portability

  • Withdraw consent at any time

To exercise your rights, contact: administrator@bamburghcastle.com


12. Complaints

If you are unhappy with how we handle your data, please contact us first.

You also have the right to lodge a complaint with the
Information Commissioner’s Office
Website: www.ico.org.uk


13. Provision of Personal Data

Where we need to collect personal data by law or under the terms of a contract, and you fail to provide that data, we may not be able to perform the contract (e.g. process a booking).


14. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects.


15. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be available on our website.

Stay in touch

Sign up to our newsletter