GDPR Privacy Policy – PrayerTimesLondon.com

Last Updated: Today


1. Introduction

PrayerTimesLondon.com (“we”, “us”, “our”, or the “Website”) is committed to protecting and respecting your privacy in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This GDPR Privacy Policy explains how we collect, use, store, and protect your personal data when you use our Website, which provides Islamic prayer times for London, UK, and related services.

Data Controller:


2. What Personal Data We Collect

Under GDPR, “personal data” means any information relating to an identified or identifiable natural person.

2.1 Data You Provide Directly

Table

Copy

Data TypePurposeLegal Basis
NameCommunication, identificationConsent
Email addressResponding to inquiries, updatesConsent
City/BoroughPersonalizing prayer times for London areasLegitimate Interest
Comments/FeedbackImproving servicesConsent

2.2 Data Collected Automatically

Table

Copy

Data TypePurposeLegal Basis
IP addressSecurity, analytics, fraud preventionLegitimate Interest
Browser type & versionWebsite optimizationLegitimate Interest
Device informationResponsive design improvementLegitimate Interest
Operating systemCompatibility testingLegitimate Interest
Pages viewed & time spentUser experience improvementConsent (via cookies)
Referring/exit pagesTraffic analysisConsent (via cookies)
Approximate locationDisplaying accurate London prayer timesLegitimate Interest
Cookies & similar technologiesFunctionality, analytics, advertisingConsent

3. Legal Basis for Processing (GDPR Article 6)

We process your personal data based on the following legal grounds:

3.1 Consent (GDPR Article 6(1)(a))

  • Cookie usage (non-essential)
  • Marketing communications
  • Optional user accounts (if introduced)

You have the right to withdraw consent at any time by contacting us at [email protected].

3.2 Legitimate Interests (GDPR Article 6(1)(f))

  • Website security and fraud prevention
  • Analytics and performance monitoring
  • Displaying location-based prayer times for London
  • Technical maintenance

We conduct a Legitimate Interests Assessment (LIA) to ensure your rights are not overridden.

3.3 Legal Obligation (GDPR Article 6(1)(c))

  • Compliance with UK law
  • Data retention requirements
  • Regulatory investigations

3.4 Contract (GDPR Article 6(1)(b))

  • Providing requested services
  • User support and communication

4. How We Use Your Personal Data

Table

Copy

PurposeData UsedRetention Period
Providing London prayer timesIP address, approximate location12 months
Website analyticsIP address, browser data, cookies26 months (Google Analytics)
Advertising (Google AdSense)Cookies, browsing behaviorPer Google policies
Security & fraud preventionIP address, access logs12 months
User communicationName, email24 months after last contact
Legal complianceAll relevant dataAs required by law

5. Cookies and Tracking Technologies

5.1 Types of Cookies We Use

Table

Copy

CategoryPurposeGDPR Compliance
Strictly NecessaryWebsite functionality, prayer time displayLegitimate Interest — no consent required
AnalyticsGoogle Analytics, performance monitoringConsent required
AdvertisingGoogle AdSense, personalized adsConsent required
FunctionalLanguage preferences, location settingsConsent required

5.2 Cookie Consent Management

  • UK/EU users see a cookie consent banner on first visit
  • You can accept, reject, or customize cookie preferences
  • Essential cookies cannot be disabled (required for core functionality)
  • You may withdraw consent at any time via browser settings or our cookie manager

5.3 Third-Party Cookies

Table

Copy

ProviderPurposePrivacy Policy
Google AnalyticsTraffic analysisGoogle Privacy
Google AdSensePersonalized advertisingGoogle Ads
CloudflareSecurity, performanceCloudflare Privacy

6. International Data Transfers

Your personal data may be transferred to and processed in countries outside the UK, including:

  • United States (Google services)
  • European Union (hosting services)

Safeguards We Implement:

Table

Copy

MechanismDescription
UK GDPR Standard Contractual Clauses (SCCs)For transfers to non-adequate countries
Adequacy DecisionsTransfers to EU/EEA countries
Data Processing Agreements (DPAs)With all third-party processors
EncryptionTLS 1.3 for data in transit

7. Data Security Measures

We implement appropriate technical and organizational measures to protect your data:Table

Copy

MeasureImplementation
EncryptionSSL/TLS certificates (HTTPS)
Access ControlRestricted admin access, role-based permissions
Regular BackupsEncrypted, geographically distributed
Security Monitoring24/7 threat detection
Software UpdatesRegular security patches
Staff TrainingGDPR compliance training

In the event of a personal data breach, we will notify the Information Commissioner’s Office (ICO) within 72 hours and affected users without undue delay.


8. Your Rights Under GDPR

As a data subject, you have the following rights:

8.1 Right to Access (GDPR Article 15)

  • Request a copy of your personal data
  • Receive information about how we process your data

Contact:[email protected]

8.2 Right to Rectification (GDPR Article 16)

  • Request correction of inaccurate data
  • Request completion of incomplete data

8.3 Right to Erasure (“Right to be Forgotten”) (GDPR Article 17)

Request deletion of your personal data when:

  • Data is no longer necessary
  • You withdraw consent
  • Data was unlawfully processed
  • Legal obligation requires erasure

Exceptions: We may retain data for legal compliance or legitimate interests.

8.4 Right to Restrict Processing (GDPR Article 18)

Request limitation of processing when:

  • You contest data accuracy
  • Processing is unlawful
  • We no longer need the data
  • You object to processing

8.5 Right to Data Portability (GDPR Article 20)

  • Receive your data in structured, commonly used format
  • Transmit data to another controller

8.6 Right to Object (GDPR Article 21)

  • Object to processing based on legitimate interests
  • Object to direct marketing (opt-out anytime)

8.7 Rights Related to Automated Decision-Making (GDPR Article 22)

  • We do not use automated decision-making or profiling

8.8 Right to Withdraw Consent

  • Withdraw consent at any time
  • Does not affect lawfulness of prior processing

9. Data Retention Policy

Table

Copy

Data CategoryRetention PeriodReason
Contact form submissions24 monthsCustomer service, legal claims
Analytics data26 monthsGoogle Analytics default
Advertising dataPer Google policyThird-party controller
Security logs12 monthsFraud prevention, legal compliance
Cookie consent records12 monthsProof of compliance

After retention periods expire, data is securely deleted or anonymized.


10. Children’s Privacy (GDPR Article 8)

  • We do not knowingly collect data from children under 13
  • If we discover such data, we delete it immediately
  • Parents/guardians may contact us to request data removal

11. Data Protection Officer (DPO)

While not legally required, we have designated a Data Protection Contact:

📧 [email protected]

For GDPR-related inquiries, please include “GDPR Request” in the subject line.


12. Supervisory Authority

If you believe we have violated your GDPR rights, you may lodge a complaint with:

Information Commissioner’s Office (ICO)

  • Website:www.ico.org.uk
  • Phone: 0303 123 1113
  • Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We encourage you to contact us first to resolve any issues.


13. Changes to This GDPR Policy

We may update this policy to reflect:

  • Changes in UK law
  • New processing activities
  • Updated third-party services

Material changes will be notified via:

  • Website banner notice
  • Email (if we have your contact details)

14. Contact Information

For GDPR-related questions, data subject requests, or privacy concerns:

📧 Email: [email protected]

🌐 Website: https://www.PrayerTimesLondon.com

Response Time: We aim to respond to all GDPR requests within 30 days.