Our Privacy Policy

Last updated 23 February 2022

1. Our privacy policy

If you are under 18, please seek permission from a parent or guardian before giving personal information to anyone online.

If you do not agree to this policy, please do not give us your information.

2. How we obtain information

We obtain information through our interactions with you and try to be clear when we are doing so. We may also obtain your information through third parties and from public sources. Below, we have tried to list as clearly as possible how your information is obtained from each of these sources.

We may obtain information from you through your interactions with us such as when you are:

We may obtain information from third parties if you gave them permission to share it with us such as when:

  • donating through a third party (e.g. JustGiving), the third party may provide us your bank details so that we can process your donation or your home address so we can process gift aid
  • you are completing a challenge event to raise money for our charity and are using a third party to collect sponsorship, the third party may provide us your name and contact details (e.g. email, address, and/or phone number) so that we can provide you support and materials (e.g. a fundraising pack, t-shirt, etc.) and thank you for your contribution
  • using third party lists to help us find trusts, Livery Companies, and corporate foundations we can apply to for funding. We pay for memberships (Trustfunding.org.uk, Funding Central, and WealthWatch) and purchase hardcopy publications (“City of London Directory & Livery Companies Guide 2015” and “The Guide to UK Company Giving 2015/16”)

We may obtain information from public sources to help identify trusts, Livery Companies, foundations, firms, companies, and individuals for possible funding opportunities. Specific individuals may be contacted if they are whom the publicly available information directs us to (e.g. the email address for a partner at a firm).

Public sources we may use include:

  • company websites
  • social networks (e.g. LinkedIn, Facebook, and Twitter)
  • pre-compiled public lists (e.g. The Legal500)

3. The information we collect

The information collected will vary depending on the situation (e.g. donation administration, receiving our support for a court case, event registration, etc.), but is intended to be the minimal amount needed for the activity (e.g. providing the service or information requested). We will not sell or rent your personally identifiable information that you provide us.

The personal information collected may include, but is not limited to:

  • name
  • email address
  • postal address (including postcode)
  • phone number
  • bank or credit card details
  • why you have decided to support us
  • other information relevant to supporter/client surveys and/or offers

Certain types of personal information (e.g. health, race, religious beliefs, etc.) are in a special category under data protection laws, because they are considered to be more sensitive. We only collect this type of information if there is a clear reason for us to do so, (e.g. to provide appropriate facilities or support). We will also collect this type of information if you make it public or volunteer it to us (e.g. you tell us while we are supporting you during a client session). Wherever it is practical for us to do so, we will let you know why we are collecting this information and for what purpose.

For clients receiving support from our service, we may keep some of the information they choose to give us (e.g., name, phone number, email, case number etc) along with a record of how we helped them in order to better assist them if they return for more help. Additionally, clients are asked to provide us information through our ‘About You’ and ‘Feedback’ forms. The information obtained through these forms is anonymized and used to help us better understand how our client service is being used and how we can make it better. 

We do not actively collect information from children (under 18s) nor are our events aimed at children, however our supporters are of all ages. Where appropriate, we will ask a parent or guardian for consent prior to collecting their child’s information. Children can only fundraise or partake in an event to benefit our charity with a parent or guardian.

We do not actively collect and/or use information about your device (e.g. IP address, type of device, etc.) but depending on your device settings, it may be made available to us. Contact your device manufacturer or operating system provider for more information on what information is made available.

4. How we use this information

We will use your personal information to administer our website, applications, contact databases, client service and marketing material. Examples include:

  • providing information you requested
  • booking an appointment for client support
  • keeping a record of the support a client receives from our service so volunteers will be better informed when providing you support in the future
  • processing a singular or regular donation
  • claiming gift aid on a donation
  • maintaining a list of people who have previously donated or fundraised so we can contact them to see if they are interested in doing so again
  • registering you for an event
  • processing ticket purchases for events
  • maintaining a list of people interested in receiving our quarterly newsletter, Annual Report, information on events and/or information on appeals
  • understanding what activities you have had with us (e.g. donations, event participation, meetings, etc.) and how you prefer to be contacted (email, post, or phone) to ensure we only send you relevant and appropriate communications
  • maintaining a list of people who have explicitly told us that they don’t want to be contacted by us
  • analysing your website behavior in order to improve our website
  • identifying funding opportunities (e.g. trusts, foundations, Livery Companies, companies, firms, etc.)
  • create reports about our service
  • safeguard staff, volunteers, and clients
  • meet legal obligations

Most of the time, we will obtain your permission for processing your information, but occasionally we may need to process your personal data without your consent. This will only be done when it is in our legitimate interest, it is legal for us to do so, and it will not infringe your legitimate interest, rights, and/or freedoms.

5. How we protect personal information

The safety and security of your personal information is important to us and we try to implement the safeguards needed to protect it, ensure it is accurate, and keep it up to date such as:

  • Ensuring our websites have up to date SSL certificates to secure information transferred from you to the webservers.
  • Ensuring payment gateways (BT MyDonate, JustGiving, CAF) meet the Payment Card Industry Data Security Standards.
  • Ensuring contracts with third party data processors (e.g. server managers, system support, etc.) have clear expectations and requirements regarding the data they have access to
  • Regular anti-virus scanning of hardware devices.
  • Recycling hardware through certified vendors to ensure secure deletion of any information on hardware being disposed of.
  • Providing GDPR training to staff to increase their knowledge and understanding of best practices for data protection.

Unfortunately no matter what safety measure are implemented, information sent via the internet can never be guaranteed to be fully secure. Even though we do our best to ensure your personal information is safe, we cannot guarantee that the information you provide online or via email is fully secure. Information you send via internet is therefore sent at your own risk.

6. Will we disclose the information we collect to outside parties?

We will not sell, distribute or lease your personal information to third parties unless we have your permission or are required to do so by law or for regulatory reasons.

General information may be shared with partners in order to aid our research, with personal identifying information removed (e.g. we may share the total number of attendees to an event or the number of clients completing a survey).

Some of our suppliers may run their operations outside the EU where they are not subject to the same data protection regulations. Where this is the case, we will take steps to confirm they provide an adequate level of protection in line with UK data protection law.

7. Retention of your information

We aim to hold your information for only as long as necessary for the relevant activity (e.g. donation information will be kept for six years in alignment with auditing requirements).

If you opt-out of communications, we normally keep the minimal amount of personal information needed to ensure your request is carried out (e.g. name, email, and address). If you ask us to completely remove all of your information, we will do our best to carry out your request, but may not be able to if we were unable to keep the information required to track your request.

8. Your rights

For any personal information of yours that we hold, you have the right to request:

  • The right to be informed
  • The right of access
  • The right to rectification
  • The right to erasure
  • The right to restrict processing
  • The right to data portability
  • The right to object
  • Rights in relation to automated decision making and profiling.

9. Privacy policy changes

We are constantly reviewing how we process and protect data. Therefore, changes to our policy may occur at any time, and we reserve the right to amend our Privacy Policy. If we do so, we will post notice of the changes on our website. Please revisit this policy page each time you consider giving personal information.