Privacy Policy
1 Wimpole Street is committed to safeguarding and protecting the privacy of clients, visitors, website users, venue enquirers, suppliers and other individuals whose personal data we process. This Privacy Policy explains what personal data we collect, why we use it, who we share it with, how long we keep it, how we protect it, how we obtain it, and what your rights are. 1 Wimpole Street (1WS) is owned and operated by the Royal Society of Medicine (“RSM”, “we”, “us”), a UK registered charity and Royal Charter body.
What this Privacy Policy Covers
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR), as amended by the Data (Use and Access) Act 2025 (DUAA). This policy covers personal data processed through the 1 Wimpole Street website and related venue, enquiry, marketing, supplier, CCTV and premises security activities.
Links to third-party websites or services are not covered by this policy. When you visit those services, it is recommended to review their own privacy notices.
The Royal Society of Medicine is the data controller for the personal data described in this policy. You can contact the data protection team at dpo@rsm.ac.uk or by writing to: Data Protection Officer, 1 Wimpole Street, London, W1G 0AE, United Kingdom.
Types of Personal Data We Collect
We collect and use different types of personal data depending on how you interact with 1 Wimpole Street, the website, our venue team, our suppliers, or our premises. This may include:
• Contact Information – Information you provide voluntarily, such as when you sign up to receive communications, submit an enquiry, or contact us.
• Website Usage Data – Information about how you use our website, including pages viewed, navigation behaviour, traffic sources and (where available) approximate location data.
• Technical Data – Technical information such as IP addresses and device-related data.
• Security and Surveillance Data – CCTV footage (without audio) captured at key entry points and premises areas.
We may use IP addresses and similar technical information to understand website usage, maintain website security, diagnose technical issues, support fraud prevention and produce aggregated reporting. Where necessary and lawful, information may be shared with law enforcement or other competent authorities to prevent or detect crime.
How We Obtain Personal Data
We may obtain personal data in the following ways:
• directly from you when you contact us, submit an enquiry, subscribe to communications, visit our premises, provide feedback or correspond with us;
• from your employer, organisation, event organiser, agency or other third party where they arrange or manage a venue enquiry, visit, supplier relationship or event-related interaction on your behalf;
• automatically through cookies, analytics and similar technologies when you use the 1 Wimpole Street website;
• from CCTV and premises security systems when you visit 1 Wimpole Street;
• from public bodies, law enforcement, regulators or professional advisers where relevant and lawful.
Where we receive personal data indirectly, we will process it in accordance with applicable transparency requirements and, where required, provide appropriate privacy information.
How and Why We Use Your Data
UK data protection law requires us to have a valid lawful basis for each use of personal data. We use personal data for the following purposes and lawful bases:
• Responding to enquiries and managing venue-related communications – legitimate interests and, where relevant, steps prior to entering into a contract;
• Providing venue, visitor and premises-related services – contract, legitimate interests and legal obligation where applicable;
• Sending marketing communications and newsletters – consent, legitimate interests, or PECR-permitted opt-in where applicable;
• Understanding website usage and improving website performance – consent or legitimate interests depending on the cookie or technology used and applicable PECR requirements;
• Maintaining premises security and preventing or detecting crime, including through CCTV – legitimate interests, legal obligation and, where applicable, recognised legitimate interests introduced by the DUAA;
• Managing suppliers and business relationships – contract and legitimate interests;
• Handling complaints, legal claims, investigations and compliance matters – legal obligation, legitimate interests and establishment, exercise or defence of legal claims;
• Protecting vital interests in an emergency where necessary.
Where we rely on legitimate interests, we consider whether the processing is necessary, whether individuals would reasonably expect it, and whether it has an unjustified impact on their rights and freedoms. We keep this under review and document assessments where appropriate.
Where we rely on consent, you may withdraw it at any time. Withdrawing consent does not affect any processing carried out before withdrawal.
Where we process special category data, such as health, accessibility or dietary information, we rely on an appropriate Article 9 UK GDPR condition and, where required, the Data Protection Act 2018.
Marketing Communications
Where you subscribe to 1 Wimpole Street marketing communications or otherwise provide a valid marketing preference, we may send you relevant updates about venue services, events, offers or related information. We will only send electronic marketing where permitted by PECR and UK data protection law, including where you have consented or where another lawful direct marketing route applies. You can opt out at any time by using the unsubscribe link in our communications or by contacting dpo@rsm.ac.uk.
Suppliers and Service Providers
We use external suppliers and service providers to support websites, communications, venue, security and operational services. Where suppliers process personal data on our behalf, they must do so under appropriate contractual terms. Suppliers may only process personal data for authorised purposes and must apply appropriate confidentiality and security protections.
CCTV and Premises Security
Our CCTV system and the images produced by it are controlled by the Royal Society of Medicine, as the organisation responsible for the operation and security of the 1 Wimpole Street premises. CCTV is used under UK GDPR and the Data Protection Act 2018 for the prevention and detection of crime, the protection of individuals, and the security of our premises.
CCTV footage is handled securely, access is restricted to authorised individuals, and footage is only used for compatible and lawful purposes. We keep our use of CCTV under regular review to ensure it remains necessary and proportionate. Where footage is required for an investigation, legal claim, safety issue or crime prevention matter, it may be retained for longer and shared with law enforcement, regulators, insurers, legal advisers or other relevant parties where lawful and necessary.
How long we keep your personal data
We keep personal data for as long as necessary for the purpose for which it was collected and in line with legal, accounting, reporting, operational and risk-management requirements. We do not keep personal data for longer than required.
For example, venue sales and finance records are usually retained for at least six years for statutory tax and accounting purposes. Enquiry and correspondence records are retained for as long as necessary to manage the enquiry or relationship and then for a suitable period for audit, complaint handling or legal purposes. CCTV footage is normally retained for a limited period unless it is required for an investigation, legal claim, safety matter or crime prevention purpose.
Where we use your details for marketing, we will retain your preferences and suppression records as necessary to respect opt-outs and evidence compliance. We progressively delete, de-identify or reduce data where it is no longer needed. A more detailed retention schedule is available on request where appropriate.
Your Rights and Access to Personal Data
You have the right to ask for a copy of the personal data we hold about you by making a subject access request. You can also ask us to correct inaccurate information, restrict processing, object to certain processing, request erasure in certain circumstances, request portability where applicable, withdraw consent where consent is relied upon, and challenge automated decisions where applicable.
We will typically respond to a subject access request within one calendar month. For complex or multiple requests, we may extend this period by up to two further months and will let you know. We may ask you to verify your identity and may ask you to clarify the scope of your request where reasonably required. We will conduct reasonable and proportionate searches in accordance with applicable law.
You have the right to complain to the Information Commissioner’s Office (ICO) at any time if you believe we are not handling your personal data in accordance with UK data protection law.
Cookies and Similar Technologies
We use cookies and similar technologies to make the website work, improve the user experience, understand how people use the website, maintain security, prevent fraud and support relevant communications. Cookies are small files stored in your browser or device.
Some cookies and similar technologies require consent. Others may be used without prior consent where a statutory exception applies, such as strictly necessary cookies. Even where consent is not required, we will provide clear information and, where applicable, an accessible way to opt out.
Please see our Cookie Policy for a full list of cookies and similar technologies used on this website, their purposes, durations and how to manage your preferences.
Security
We take the security of personal data seriously and use appropriate technical, physical and organisational measures. These may include encryption, secure storage, access controls, role-based permissions, confidentiality obligations, supplier contractual controls, staff awareness, monitoring, patching, and incident management and breach reporting processes where appropriate.
Although we take reasonable steps to protect personal data, no internet transmission can be guaranteed to be completely secure. Information you send to us over the internet is sent at your own risk, and we are not responsible for the security of data sent over third-party networks.
Who We Share Personal Data With
We may share personal data where necessary to provide venue-related services, manage enquiries, operate the website, maintain security, comply with legal obligations, support business administration, handle complaints or establish, exercise or defend legal claims.
Categories of recipients may include RSM staff and group entities, website and IT providers, CRM and communications providers, venue operations suppliers, security providers, professional advisers, insurers, regulators, courts, public authorities and law enforcement bodies. We only share personal data where there is a lawful basis and appropriate safeguards are in place.
Where a third-party acts as our processor, they may only process personal data on our documented instructions. Where a third-party acts as an independent controller, they are responsible for their own use of personal data under their own privacy notice.
International Transfers
Personal data may be transferred outside the UK or EEA where some of our technology, website, communications or operational providers host, access or support services internationally. Where this happens, we will ensure that appropriate safeguards are in place in accordance with UK GDPR requirements, such as adequacy regulations, standard contractual clauses, International Data Transfer Agreements or other lawful transfer mechanisms.
Automated Decision-making and Profiling
We do not currently make decisions about individuals solely by automated means where those decisions produce legal or similarly significant effects without meaningful human involvement. We may use limited analytics or profiling tools to help us understand engagement with the website, enquiries or communications and to improve relevance. This does not produce legal or similarly significant effects on you. If we introduce significant automated decision-making in future, we will explain this clearly and provide the safeguards required by law.
Job Applicants, Employees and Workers
Staff supporting 1 Wimpole Street may be employed by RSM Commercial Services Limited or another RSM group entity, depending on role and arrangements. Recruitment, employment and worker data is handled under the relevant RSM recruitment or employee privacy notice.
If you apply for a role, personal data will be processed to manage recruitment, assess your suitability, communicate with you, and prepare and make an offer of employment where appropriate. For unsuccessful applicants, recruitment data is normally retained for six months following completion of the recruitment process unless a longer period is required or permitted by law. Where an offer is made and accepted, relevant data will be retained in accordance with the applicable employee privacy notice.
For further information, please see the RSM fair processing notice for job applicants or contact hr@rsm.ac.uk with recruitment-related queries.
Links, Screenshots and Third-party Websites
Links to the 1 Wimpole Street website and use of screenshots remain subject to the applicable website terms and permissions stated on the website.
The 1 Wimpole Street website may contain links to external websites. 1 Wimpole Street and RSM are not responsible for the privacy practices of those third-party websites. You should read the privacy notice of any external website you visit.
Complaints and Contact Details
If you have a concern about how we handle your personal data, please contact the data protection team at dpo@rsm.ac.uk or by writing to: Data Protection Officer, 1 Wimpole Street, London, W1G 0AE, United Kingdom. We will take data protection complaints seriously and respond without undue delay.
You also have the right to complain directly to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection, at any time. The ICO can be contacted via its website or by telephone on 0303 123 1113.
For general enquiries, please contact enquiries@1wimpolestreet.co.uk.
Changes to this Privacy Policy
We review this Privacy Policy regularly and update it when legislation, ICO guidance, technology, website functionality or our practices change. The date of the most recent revision will appear on the website or at the top of the policy.
Where we are required by law to notify you of material changes, we will do so. We encourage you to review this policy periodically.