Nottinghamshire Hospice is committed to protecting the privacy and security of information you entrust to us. This policy sets out how and we use your information, and explains your legal rights in relation to the information we hold.
1. About us
We are Nottinghamshire Hospice. We are a data controller in respect of information you provide to us (i.e. the organisation making decisions about how and why your personal information is used).
Questions? Any questions about your personal information or this policy should be directed to our registered office at 384 Woodborough Road, Nottingham. NG3 4JF.
2.What information we collect
If you choose to join or support us (whether as a supporter, volunteer or otherwise), we need to collect certain information about you (for example, your name, address, email and telephone number).
We collect data you provide to us, for example when you:
- make a donation;
- contact us;
- attend an event;
- fill in web forms; or
- subscribe to any of our communications.
We do not normally collect or store sensitive personal data. If this does occur then we will take extra care to ensure your privacy rights are protected.
3. How we use your information
We only ever use your personal data with your consent, or to the extent necessary to:
- enter into, or perform, a contract with you (e.g. if you agree to participate in a sponsored event);
- comply with a legal duty (e.g. sharing gift aid information with HMRC);
- protect your vital interests;
- remember your preferences (e.g. if you ask not to receive news and updates from us, we will keep a record of this), or
- for our own (or a third party’s) lawful interests (such as pursuing our charitable objectives) provided your rights don’t override these.
We will only use your information for the purpose for which it was collected, or for similar/related purposes (such as record keeping). We will never sell your personal information to a third party.
We may need to share your personal information with trusted third parties for our own purposes. This will be done only where necessary, under a formal contractual agreement and only after strict due diligence processes have been followed to ensure that those we work with support our charitable aims and objectives.
Formal contractual agreements are in place to protect information security and your confidentiality and sets strict obligations as to the use of that information. Any information that is shared with those described above is through security systems like secure file transfer portals and use of encryption. They contain clauses relating to the length of time that information can be held for and strict guidelines as to the safe destruction of the information.
4. News, communications and fundraising
We contact our supporters from time to time to keep them up to date with news and developments relating to our charity, its work and activities, appeals and fundraising opportunities.
We’ll generally only contact you by post and telephone, and we do this because it is essential to continue to deliver our services to the local community. We won’t email or text you without your consent.
You can, of course, change your preferences at any time. If you decide that you wish to stop hearing from us, or change how we contact you, you can do so in any of the following ways:
- emailing email@example.com;
- telephoning 0115 910 1008 ext 239; or
- writing to us at our registered office (set out above).
We employ a variety of physical and technical measures to keep your personal data safe and to prevent unauthorised access to, or use or disclosure of it. Electronic data and databases are stored on secure computer systems and we control who has access to them (using both physical and electronic means). Our staff receive data protection training and we have a set of detailed data protection procedures which personnel are required to follow when handling personal data.
We cannot absolutely guarantee the security of the internet or external networks and any online communications (e.g. information provided by email or through our website) are at your own risk.
Online payments are handled by Secure Collections. We will also process financial information if you choose to give by direct debit, card payment over the telephone, or donation by post. In all these cases we will keep information secure, and only keep as much as we need for as long as we need it (after which it will be destroyed or deleted).
6. Data storage
We normally only store data within the European Economic Area (EEA). If one of our subcontractors (such as a payment processor) needs to transfer it outside of the EEA then we will take steps to make sure adequate levels of privacy protection, in line with UK data protection law, are in place. These safeguards will usually be contractual and/or the result of an European Union decision which allows the transfer (such as a US organisation which is certified under the EU-US Privacy Shield framework)
We continually review the personal data we hold and delete what is no longer required.
7. Updating your information
If you believe that any information we are holding on you is incorrect or incomplete, please e-mail firstname.lastname@example.org
or write to Nottinghamshire Hospice, 384 Woodborough Road, Nottingham. NG3 4JF.
8. Your rights
We want to ensure you remain in control of your personal data. Part of this is making sure you understand your legal rights, which are as follows:
- the right to confirmation as to whether or not we have your personal data and, if we do, to obtain a copy of it (this is known as a subject access request);
- the right to have inaccurate data rectified; and
- the right to object to your data being used for marketing or profiling.
- the right to ask to have your data erased in certain situations (though this will not apply where it is necessary for us to continue to use the data for a lawful reason).
If you would like further information on your rights or wish to exercise them, please e-mail email@example.com or write to: Nottinghamshire Hospice, 384 Woodborough Road, Nottingham. NG3 4JF.
Please keep in mind that there are exceptions to the rights above and, though we will always try to respond to your satisfaction, there may be situations where we are unable to do so. If you are not happy with our response, or you believe that your data protection or privacy rights have been infringed, you should contact the UK Information Commissioner’s Office, which oversees data protection compliance in the UK. Details of how to do this can be found at www.ico.org.uk.
Links to other sites
9. Changes to this policy