This is the privacy notice for email newsletters distributed on behalf of Voluntary Norfolk (UK registered charity number 1112017, company registration number 05616120), including our trading arm CBR Business Solutions.
Our registered address is: St Clements House, 2-16 Colegate, Norwich, NR3 1BQ.
We are registered with the Information Commissioner’s Office (ICO), reference no.: Z632337X
PURPOSE OF THIS NOTICE
This notice sets out how we will collect, process and use the information we hold about you. We are committed to protecting your privacy and being clear about how we use personal information that we hold. We understand that you are entitled to know that your personal data will not be used for any unintended purpose.
You have rights and we have obligations in regard to the processing and control of your personal data. You can learn more about your rights here: www.knowyourprivacyrights.org/
Our policy complies with UK law, including that required by the UK General Data Protection Regulation (UK GDPR). This notice is effective from 20th June 2023.
HOW DO WE COLLECT PERSONAL INFORMATION ABOUT YOU?
We will collect personal information about you:
- When you give it to us directly
For example, personal information that you provide when you self-refer to one of our services, when you register as a potential volunteer or when you sign up to our email newsletter on one of our websites, or any personal data that you share with us when you communicate with us in person, by email, phone or post.
WHAT TYPE OF INFORMATION DO WE COLLECT?
We may collect, store and otherwise process the following kinds of personal information:
- Your name, job title, postal address, telephone number, email address
- Your date of birth, gender, employment status
- Your volunteering interests, skills and experience, photographic image
- Your service needs and information about the services we have provided to you
- Information about your computer/ mobile device, including, for example, your IP address and geographical location; social media identity
As Data Controller we are required to have one or more lawful grounds to collect and process the personal information we have outlined above. We consider the grounds listed below to be relevant:
The law allows us to use personal information on the condition that to do so is reasonably necessary for our legitimate interests (and the use of your personal information is fair, balanced, and does not unduly impact your rights). We may rely on this ground to process your personal information when we believe that it is more practical or appropriate than asking for your consent.
For instance, we rely on the legitimate interest ground to process data about our service users and participants in our projects or to protect the security of our networks e.g. when we receive external emails we will scan such emails for any threats, based on a legitimate interest assessment.
HOW WE USE YOUR PERSONAL INFORMATION
Voluntary Norfolk may use your personal information:
- to provide you with services, products or information that you have requested
- to provide updates about our work, services, or activities (where necessary, and only where you have provided your consent to receive such information)
- to answer your questions/ requests and communicate with you in general
- to further our charitable aim in general, including asking for volunteer and/or fundraising support
- to analyse and improve our services, activities or information (including our website) or for our internal records
- to process your application for a job or volunteer role
- to audit and/ or administer our accounts
- to satisfy legal obligations which are binding on us, for example in relation to regulatory, government and/ or law enforcement bodies with whom we may work, or due diligence checks before entering into contracts or agreements
- for the prevention of fraud or misuse of service
DO WE SHARE YOUR PERSONAL INFORMATION?
Voluntary Norfolk will not sell, rent or lease your personal information. However, we may share your personal information within Voluntary Norfolk and with selected contracted third party processors for the purposes outlined above. Any such third parties will be obligated under a formal contract to use any personal data they receive in accordance with our instructions and to protect it as we would. Your data will be shared as part of profiling that will allow us to run social media campaigns. This will not affect the content you see on social media but will instead help us reach new audiences.
INTERNATIONAL DATA TRANSFERS
As we sometimes use third parties to process personal information, it is possible that personal information we collect from you will be transferred to and stored in a location outside the UK or the European Economic Area (“EEA”).
Please note that certain countries outside of the UK or EEA have a lower standard of protection for personal information, including lower security protections. Where your personal information is transferred, stored, and/or otherwise processed outside the UK or EEA in a country which does not offer an equivalent standard of protection to the UK or EEA, we will take all reasonable steps necessary (including entering into standard contractual clauses to protect your personal information or relying on the Privacy Shield for transfers to organisations in the US) to ensure that the recipient implements appropriate safeguards designed to protect your personal information. If you have any questions about the transfer of your personal information, please contact our Data Protection Lead, using the details at the end of this policy.
SECURING YOUR PERSONAL INFORMATION
Voluntary Norfolk will take reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal information; we store all personal information on secure servers.
Voluntary Norfolk undertakes the following procedures to ensure good working practice when processing data:
- When unattended PCs will be locked using a password
- All cabinets containing hard copies of personal data are locked and the keys kept in a secure locked environment
We audit our procedures to ensure compliance on an at least six monthly basis. We will notify the ICO without undue delay should a data breach of significant scale be detected that warrants this.
HOW LONG DO WE KEEP YOUR PERSONAL INFORMATION?
We will generally remove your personal information from our records six years after the date that it was collected unless (a) we are required to hold for longer for legal or regulatory purposes; or (b) it is still required in connection with the purpose for which it was collected and/or processed, for example you still work or volunteer for us.
However, we will remove your personal information from our records before this date if we become aware that (a) your personal information is no longer required in connection with such purpose(s); (b) we are no longer lawfully entitled to process it; or (c) you validly exercise one of your rights of erasure.
YOUR RIGHTS AND PREFERENCES
Voluntary Norfolk may contact you by post unless you request otherwise, and by telephone, email, social media or other electronic means depending on any communication preferences you have previously indicated.
You have the right to:
- Ask us for confirmation of what personal information we hold about you, and to request a copy of that information. If we are satisfied that you have a legal entitlement to see this personal information, and we are able to confirm your identity, we will provide you with this information.
- Request that we delete the personal information we hold about you, as far as we are legally required to do so.
- Ask that we correct any personal information that we hold about you which you believe to be inaccurate.
- Object to the processing of your personal information where we: (i) process on the basis of the legitimate interests ground; (ii) use the personal information for direct marketing; or (iii) use the personal information for statistical purposes.
- Ask for processing of your personal information to be restricted if there is disagreement about its accuracy or legitimate usage.
To request a copy of your personal data please contact our Data Protection Lead, using the details at the end of this policy. At any point you can request to unsubscribe from our e-newsletter or request that your personal information is removed from our databases by contacting us at firstname.lastname@example.org
Please note that where you ask us to delete your personal information we will maintain a skeleton record comprising your name and organisation to ensure that we do not inadvertently contact you in the future. We may retain some financial records for statutory purposes, for example Gift Aid.
Please note that you also have the right to lodge a complaint with the Information Commissioner’s Office at www.ico.org.uk/concerns
More detailed information on how we protect your privacy can be found via the following links:
Voluntary Norfolk may update this privacy notice by posting a new version on this website. If we update this privacy notice in a way that significantly changes how we use your personal information, we will use reasonable efforts to bring these changes to your attention where we have your contact details. Otherwise, we would recommend that you periodically review this privacy notice to be aware of any other revisions.
HOW TO CONTACT US
Our Data Protection Lead is David Crinson, who is responsible for monitoring compliance with relevant legislation in relation to personal data.
You can contact him if you have any questions about this privacy notice or our treatment of your personal information by: