Legal

Privacy policy

How The Graham Keene Foundation looks after information on this website.

Who we are

This website address is https://grahamkeene.com/.

It is operated by Pencombe Associates Ltd, a private limited company registered in England and Wales (company number 05132289). The registered office is Melrose House, Pynes Hill, Rydon Lane, Exeter, Devon, EX2 5AX.

Graham Keene is a director of the company and the speaker this site is about. The data controller is the company, not Graham in a personal capacity.

To ask about your information, use the contact form. Please do not send payment-card details or special-category data through the forms.

If we are required to pay the Information Commissioner’s data protection fee, we will give you the registration number on request.

Comments

This site does not accept comments. There is no comment form, and we do not collect comment data, IP addresses for comment spam, or Gravatar profile pictures.

If you want to get in touch you use a contact form — general enquiries, speaking bookings, or Drop Your Dreams. We collect the fields you type (typically name, email address, telephone number and your message). Drop Your Dreams also stores the dream, country, timeframe and whether you consented to publication. The longer “what’s your Everest” answer and your contact details are stored for review and are not published.

Form submissions are checked for spam. That check may include your IP address and browser user agent.

Media

Visitors cannot upload images to this website. Any photographs on the site were added by an administrator. If an image includes embedded location data (EXIF GPS), a visitor who downloads it could read that data. We do not add location data to images we publish.

Cookies

This site has no comments and no visitor accounts. There is no public login page. Only administrators sign in to WordPress to edit the site. We do not set comment cookies, and we do not set login cookies for ordinary visitors.

We use Google Analytics to see how the site is used (which pages are read, how people arrive, and where they leave). The cookies it sets — _ga, _ga_* and _gid — can last up to two years. They are optional. They are not set, and Google is told not to store analytics data, until you accept the analytics category on the cookie banner.

A necessary cookie (gk_consent) remembers that choice for six months. WordPress may set a temporary wordpress_test_cookie to check that the browser accepts cookies; it holds no personal data and is discarded when you close the browser. Login and screen-option cookies are set only when an administrator signs in, and are removed when they sign out (or expire).

You can accept all optional cookies, reject them, or choose by category. Accept and reject are equally available. Change your mind at any time from Cookie settings in the footer. The full list is on the cookie policy.

Embedded content from other websites

Some pages include a YouTube video. We do not load YouTube until you accept marketing cookies and press play. Until then, a still image and a link to watch on YouTube are shown instead.

Once a video plays, YouTube behaves as if you had visited youtube.com. Google may collect data about you, set cookies, and measure how you use the player. That is described in Google’s own privacy policy. Other optional embeds would work the same way; we do not use them at present.

Who we share your data with

We do not sell your information. We use other organisations only to run the site:

  • Our website host and email provider, to deliver the site and form notifications.
  • Gravity Forms, which collects the form submissions on this WordPress site.
  • CleanTalk, which checks submissions for spam.
  • Google, for Google Analytics (if you accept analytics cookies) and for YouTube (if you play an embedded video after accepting marketing cookies).
  • Vu Digital, who built and maintain the site, if they need access to fix a problem.

There are no visitor accounts, so we never send a password-reset email to the public. Speaking fees from bookings go to the Graham Keene Foundation. The Foundation is not the controller of this website and does not receive your form data unless you have asked us to involve them.

How long we retain your data

We do not retain comments, because the site has none.

  • Enquiry and booking messages — for as long as the conversation is live, then a limited period for our records (usually up to two years, or longer if a booking is still current).
  • Dream submissions — while they are under review, and for as long as a published dream stays on the site. Unpublished contact details are not kept indefinitely.
  • Security logs — according to the host’s normal rotation, typically a matter of weeks.
  • Google Analytics — user-level data is kept according to the property’s retention setting (typically up to 14 months). The cookies themselves can last up to two years, until they expire or you reject analytics.
  • Cookie choices — for six months, after which we will ask again.

Administrators who sign in to edit the site have a WordPress user profile. Visitors cannot register.

What rights you have over your data

Under UK GDPR you can ask us to access, correct, erase or restrict your information, object to processing that relies on legitimate interests, and receive a copy of information you gave us (for example a form submission). Where we rely on consent — including Google Analytics cookies and publication of a dream — you can withdraw it at any time. That does not affect anything already done lawfully.

We do not have to erase information we are obliged to keep for administrative, legal or security reasons.

Use the contact form to make a request. You can also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint.

Where your data is sent

Form submissions are checked through an automated spam detection service (CleanTalk).

Google Analytics and YouTube may process information in the United States. Where that happens, they rely on an approved transfer mechanism such as the UK Extension to the EU–US Data Privacy Framework or standard contractual clauses.