Privacy Policy
OnNuma – Volunteer Organisation Platform
Operated by The Media Lounge Ltd. OnNuma is a product of The Media Lounge. Find out more.
Last updated: February 2025
1. Introduction
This Privacy Policy explains how The Media Lounge Ltd ("we", "us", "our"), operator of OnNuma, collects, uses, stores, and protects personal information when you use our volunteer organisation platform and related services (the "Service"). It applies to visitors to our websites, customers who subscribe to the Service, administrators and users of organisations using the Service, and individuals whose data is processed through the Service (e.g. members, volunteers, contacts).
If your organisation uses OnNuma, it may have its own privacy notice for how it handles data within its instance (e.g. Hub Privacy Policy). This policy describes how we, as the operator of OnNuma, process personal data.
2. Who we are
OnNuma is the volunteer organisation platform operated by the entity responsible for the Service. For the purposes of data protection law, that entity is the data controller for the processing described in this policy.
Contact: For privacy enquiries, please use the contact details published on the OnNuma website or in your account/settings (e.g. support or legal email).
3. What data we collect
3.1 Data you give us
- Account and organisation: Name, email address, organisation name, and other details you provide when signing up, managing your account, or your organisation’s subscription
- Billing: Billing address and payment-related information (handled by our payment provider; we may receive limited transaction and customer identifiers)
- Support and communications: Messages you send to us, feedback, and correspondence
3.2 Data created through use of the Service
- Usage and logs: Log-in and usage information, IP address, browser/device information, and similar technical data
- Content you store: Data that you or your organisation uploads or creates in the Service (contacts, members, events, rotas, forms, etc.), which may include personal data of your members, volunteers, or other individuals
We process this data as necessary to provide and support the Service and as set out below.
3.3 Data from third parties
We may receive information from our payment provider (e.g. Paddle) and from other service providers we use to run the Service, in line with their privacy policies and our agreements with them.
4. How we use your data
We use personal data to:
- Provide the Service: Operate the platform, host your data, and deliver features included in your plan
- Manage accounts and billing: Create and manage accounts, authenticate users, process subscriptions and payments (via our payment provider)
- Support and communicate: Respond to enquiries, send important service or security notices, and (where you have agreed) send marketing or product updates
- Improve and secure the Service: Analyse usage (including in aggregated form), fix errors, improve performance, and protect against abuse and security risks
- Comply with law: Meet legal, regulatory, and enforcement obligations
We do not sell your personal data to third parties for their marketing.
5. Legal basis (UK/EEA)
Where UK GDPR or equivalent law applies, we rely on:
- Contract: Processing necessary to perform our contract with you (e.g. providing the Service and billing)
- Legitimate interests: Operating and improving the Service, security, support, and our business (e.g. analytics, fraud prevention), where balanced against your rights
- Consent: Where we ask for consent (e.g. optional marketing); you may withdraw consent at any time
- Legal obligation: Where we must process data to comply with law
6. Data sharing
We may share personal data with:
- Service providers: Hosting (e.g. Railway), email (e.g. Mailgun), payment (e.g. Paddle), and similar providers that help us run the Service, under strict confidentiality and data processing terms
- Your organisation: If you use the Service as part of an organisation, other authorised users in that organisation may see your account-related data and content as allowed by your role
- Legal and safety: Where required by law, or to protect our rights, users, or the public
We do not sell or rent personal data to third parties for their marketing.
7. International transfers
Data may be processed in the United Kingdom, the European Economic Area, and in other countries where our service providers operate. We ensure appropriate safeguards (e.g. standard contractual clauses or adequacy decisions) where required by data protection law.
8. Data retention
We retain personal data only as long as necessary for the purposes in this policy, including:
- Account and billing: For the duration of your account and as required for legal, tax, or dispute resolution
- Usage and logs: For security, abuse prevention, and improvement, typically for a limited period
- Content you store: For as long as your organisation’s account is active and you do not delete it; we may retain backups for a further limited period
After termination of an account, we may retain some data where required by law or for legitimate purposes (e.g. resolving disputes).
9. Your rights
Under UK GDPR and similar laws, you may have the right to:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data, subject to legal and contractual needs
- Restrict processing: Request that we limit how we use your data in certain cases
- Data portability: Request a copy of your data in a structured, machine-readable format where applicable
- Object: Object to processing based on legitimate interests
- Withdraw consent: Where we rely on consent, withdraw it at any time
- Complain: Lodge a complaint with a supervisory authority (e.g. the ICO in the UK: ico.org.uk)
To exercise these rights, contact us using the details in section 2. We will respond within the time required by law (e.g. one month under UK GDPR).
10. Security
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS), access controls, and secure storage. You are responsible for keeping your login credentials safe and for the security of data within your organisation’s account.
11. Children
The Service is not directed at children. We do not knowingly collect personal data from children under 16. If you believe we have collected such data, please contact us so we can delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version and change the "Last updated" date. Significant changes may be communicated by email or through the Service. We encourage you to review this policy periodically.
For privacy questions, to exercise your rights, or to make a complaint, please contact us using the details in section 2. You may also have the right to complain to your local data protection supervisory authority.