Privacy Policy
1. Our Commitment to Your Privacy
At Wirral Women and Children’s Aid, we are deeply committed to protecting your privacy and handling your personal data with care and respect. This policy explains how we collect, use, and look after your information when you interact with us. Whether you are a resident seeking support, a valued community member, a dedicated staff member, a trustee, or a trusted partner organisation, your privacy matters to us.
We adhere to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018). These laws set out strict rules about how organisations like ours handle personal data, which is any information that can identify you, directly or indirectly.
This policy outlines our obligations and your rights regarding your personal data. Our aim is to be transparent about how we handle your information, ensuring it’s always done lawfully, fairly, and with the utmost integrity.
2. Our Data Protection Principles
We follow these key principles to ensure your personal data is always protected:
- Fair, Lawful, and Transparent: We use your data honestly, legally, and in a way that is clear and open to you.
- Specific Purposes: We collect data only for specific, explicit, and legitimate reasons, and we don’t use it for purposes incompatible with those reasons.
- Data Minimisation: We collect only the data that is necessary for the stated purpose – no more, no less.
- Accuracy: We ensure your data is accurate and kept up-to-date. If it’s inaccurate, we’ll correct or delete it promptly.
- Retention Limits: We keep your data only for as long as it’s needed for the purposes we collected it for.
- Security: We process your data in a way that ensures its appropriate security, protecting it from unauthorised access, loss, or damage.
3. What Information We Collect and Why
We collect personal data to effectively provide our services and manage our operations. The type of information we collect depends on your relationship with Wirral Women and Children’s Aid. We get this information either directly from you or, in some cases, from third parties with your consent or where legally permitted.
For Residents Receiving Support:
- What we collect: Names, contact details, dates of birth, emergency contacts, health information (including mental and physical health), risk assessments, support needs, financial details, information about children, and details from referral agencies.
- Why we collect it: To assess your needs, provide safe accommodation and tailored support, manage your stay, fulfil our safeguarding duties, comply with legal obligations, and ensure your well-being.
- Our lawful basis for processing: This is usually based on your explicit consent (especially for sensitive health data), fulfilling a contract with you (to provide support), or where necessary for reasons of substantial public interest (e.g., safeguarding vulnerable individuals).
For Staff and Trustees:
- What we collect: Names, contact details, employment history, qualifications, bank details, emergency contacts, and Disclosure and Barring Service (DBS) check results.
- Why we collect it: To manage employment contracts, pay salaries/expenses, ensure safeguarding, comply with employment law, and manage our organisational governance.
- Our lawful basis for processing: This is typically based on fulfilling an employment contract, complying with legal obligations (e.g., safeguarding checks), or our legitimate interests in managing our workforce.
For Donors and Supporters:
- What we collect: Names, contact details, donation history, and Gift Aid declarations.
- Why we collect it: To process your donations, claim Gift Aid (if applicable), send you updates (if you’ve opted in), and thank you for your generous support.
- Our lawful basis for processing: This is usually based on your consent (for marketing communications), fulfilling a contract (to process your donation), or our legitimate interests in fundraising and maintaining donor relationships.
For Partner Organisations:
- What we collect: Contact details for key personnel.
- Why we collect it: To facilitate collaboration, manage agreements, and communicate effectively about our joint work.
- Our lawful basis for processing: This is often based on fulfilling a contract or our legitimate interests in partnership working.
Website Usage Data:
When you visit our website, our website provider also collects certain data to help us understand how our site is used and to improve our services. This may include information about your device, your Browse activity, and how you interact with our site. This data helps us analyse trends and user behaviour. While this information is used for analysis, we ensure your privacy interests are protected. Our website provider does not transfer your data to any other third party or outside of the UK/EEA, and they store this data for a maximum of 6 years. For more details on this, please see our Cookie Policy.
4. How We Handle Sensitive Personal Data
Given the nature of our work, we often process ‘special category’ personal data (also known as sensitive personal data). This includes information about racial or ethnic origin, health (physical or mental), or sex life. We only process this data when strictly necessary and with additional safeguards, typically because:
- You have given us your explicit consent.
- It’s essential to protect your vital interests (e.g., in an emergency where you can’t give consent).
- It’s necessary for providing health or social care or treatment, or managing related systems.
- It’s required for reasons of substantial public interest, such as safeguarding vulnerable individuals, as permitted by UK law.
5. How We Keep Your Data Secure
We are absolutely committed to keeping your personal data safe. We use a variety of robust technical and organisational measures to protect your information from unauthorised access, use, or disclosure, and against accidental loss, destruction, or damage. These measures include:
- Restricted Access: Only staff who genuinely need access to your data for their duties can view it.
- Security Training: All our employees, agents, contractors, and partners receive regular, appropriate training on data protection and confidentiality.
- Strong Passwords and Encryption: We use robust, regularly changed passwords and encryption for all electronic data. Emails containing personal data are encrypted and marked “confidential.”
- Secure Storage: Electronic data is stored securely using encryption, and it’s backed up daily with backups stored off-site. Hard copies of personal data are kept in locked cabinets.
- Secure Communications: Personal data is transmitted over secure networks only. If data is physically transferred, it’s done directly to the recipient in a suitable container marked “confidential.”
- Device Security: We strictly control what personal data can be stored on mobile devices, requiring formal approval and adherence to strict guidelines. No personal data is transferred to personal employee devices without explicit authorisation.
- Ongoing Vigilance: We continuously evaluate and review our security practices, and our IT systems are kept up-to-date with security patches.
6. How Long We Keep Your Data (Data Retention)
We will only keep your personal data for as long as necessary to fulfil the purposes we collected it for, including for any legal, accounting, or reporting requirements.
To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process your personal data, and applicable legal requirements.
For example:
- Resident records and support information: Typically retained for 6 years after the resident leaves our service, to meet safeguarding and regulatory requirements.
- Employment records: Held for 6 years after an employee leaves, in line with employment law.
- Financial and donation records: Kept for 6 years for tax and accounting purposes.
When your personal data is no longer required, we take all reasonable steps to securely erase or dispose of it without delay. You can find more detailed information in our internal Data Retention Policy.
7. Your Data Protection Rights
Under the UK GDPR, you have important rights regarding your personal data:
Rights with respect to Automated Decision-Making and Profiling: If we make decisions that significantly affect you using only automated processes, you have the right to challenge the decision, request human intervention, and obtain an explanation. We may use profiling (e.g., to understand supporter preferences for fundraising) and will always ensure clear information is provided about its significance and likely consequences.
The Right to Be Informed: You have the right to know how your personal data is being used. This privacy policy aims to provide that information.
The Right of Access: You can ask for a copy of the personal data we hold about you. This is known as a Subject Access Request (SAR).
The Right to Rectification: You can ask us to correct any inaccurate or incomplete personal data we hold about you.
The Right to Erasure (also known as ‘the right to be forgotten’): You can ask us to delete your personal data in certain circumstances (e.g., if it’s no longer necessary for the purpose it was collected for).
The Right to Restrict Processing: You can ask us to limit how we use your personal data in certain situations (e.g., if you’re contesting its accuracy).
The Right to Data Portability: If your data is processed by automated means based on consent or a contract, you can request to receive your personal data in a structured, commonly used, and machine-readable format, and have it transferred to another organisation. Our Oasis database provides reports in an accessible format for this purpose.
The Right to Object: You can object to us processing your personal data where we are relying on legitimate interests or for direct marketing purposes.
8. How to Exercise Your Rights
To make a Subject Access Request (SAR), request rectification, erasure, restriction, data portability, or to object to processing, please contact our Data Protection Officer:
Data Protection Officer: Helen Leigh (Business Manager) Email: admin@wwaca.org Availability: Office hours only
We aim to respond to all requests within one month of receipt. If your request is complex or you make numerous requests, it may take up to two additional months, but we will always inform you if this is the case. We do not charge a fee for standard requests.
9. Sharing Your Data with Third Parties
We will not sell or rent your personal data to third parties. We may, however, share your data with trusted third parties who provide services to us, such as:
- Our website provider: As explained in section 3, they assist us in delivering and improving our website services.
- IT support providers: To maintain our systems securely.
- Accountants/Auditors: For financial management and legal compliance.
- Partner agencies: Where necessary for providing support services to you (e.g., with your consent for referrals).
We ensure that all third parties we work with are contractually obliged to protect your data to the same high standards we do, and they are only allowed to use your data for the specific purposes we define.
10. Transfers Outside the UK or EEA
We generally do not transfer your personal data outside the UK or the European Economic Area (EEA).
If, for any specific reason, we ever need to transfer your data to a country outside the UK or EEA, we will ensure that appropriate safeguards are in place to protect your data, such as:
- Transferring to countries deemed to have adequate data protection laws by the UK government.
- Using Standard Contractual Clauses approved by the Information Commissioner’s Office (ICO).
- Relying on your explicit consent.
11. Data Breach Notification
We have robust procedures in place to manage any personal data breaches.
- All personal data breaches must be reported immediately to our Data Protection Officer.
- If a breach is likely to result in a risk to your rights and freedoms (e.g., financial loss, breach of confidentiality), our Data Protection Officer will inform the Information Commissioner’s Office (ICO) without delay, and in any event, within 72 hours of becoming aware of it.
- If a breach is likely to result in a high risk to your rights and freedoms, we will inform all affected individuals directly and without undue delay.
Breach notifications will include information about the nature of the breach, the categories of data and individuals concerned, the likely consequences, and the measures we have taken or propose to take to address it.
12. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. Any changes will be posted on this page, and we encourage you to review it periodically.
13. Contact Us & Complaints
If you have any questions about this privacy policy or our data protection practices, please contact our Data Protection Officer, Helen Leigh, at admin@wwaca.org.
If you are not satisfied with our response to a privacy concern, you have the right to make a complaint to the UK’s supervisory authority for data protection:
Information Commissioner’s Office (ICO) Website: www.ico.org.uk Helpline: 0303 123 1113