At Somebody's Dad CIC (Company), we are dedicated to protecting your privacy. This Privacy Policy (Policy) is developed in compliance with the requirements of the Data Protection Act 1998, as subsequently replaced and superseded by the General Data Protection Regulation (EU) 2016/679, as in force from time to time (Data Protection Law). If you have any inquiries regarding this Policy or how we handle your personal data, please contact us using the provided details at the end of this Policy.
We have constructed this Policy because we understand the significance of privacy and data security for everyone who entrusts us with their data, regardless of the interaction method, whether as a visitor to our website somebodysdad.org, through social media, or in response to printed materials as a donor, fundraiser, volunteer, or grants applicant/recipient.
This Policy elucidates how we utilize the Personal Data we collect. If you do not agree with this Policy, kindly refrain from engaging with the Company in any manner that involves sharing your data, including the use of this Site.
What Personal Data Do We Collect and How Is It Used? We collect Personal Data in accordance with the definition provided by Data Protection Law (see the summary of definitions at the end of this Policy). The Personal Data we gather may include your name, date of birth, email address, postal address, and telephone number. We keep a record of your information requests and any feedback you provide. Additionally, we may collect technical information related to your usage of our Site, such as your browser type or the Internet Protocol (IP) address used to connect your computer to the internet.
We strive to ensure the accuracy and currency of your Personal Data. If any of the information you have provided changes, such as your email address or postal address, please inform us using the contact details at the end of this Policy.
For certain purposes, we require your explicit consent to use your information. However, Somebody's Dad CIC also relies on its right to hold and process data in pursuit of its legitimate interests (e.g., advancing its charitable objectives, including fundraising) without always obtaining your explicit consent. When we use this approach to contact you, we will always provide you with the option to unsubscribe from future communications.
By affirmatively accepting this Policy, you grant consent for us to process your information for the following purposes:
If you submit your Personal Data through means other than the Site, the Company may provide you with an additional statement outlining any further processing activities related to your Personal Data.
By communicating with us in person or through any medium, using this Site, making a donation, submitting a grant application, or subscribing to our newsletter, you consent to the processing of your Personal Data for the aforementioned purposes. If you wish for the Company not to use your Personal Data for direct marketing (fundraising) purposes, kindly inform us using the contact details at the end of this policy.
If you supply any visual image or sound recording containing your personal data to the Company, or if the Company acquires such an image or recording by photographing or recording you, this image or recording may be used for the Company's marketing and promotional activities. The purpose for using your image or recording will always be clearly outlined in our consent form and/or on our website.
We also collect general information about the use of this Site, but we utilize aggregated or anonymous information that does not identify you as an individual visitor. We monitor which pages are visited most frequently, which services, events, or facilities generate the most interest, and track the pages users visit when they click on links in emails. This information helps us tailor the presentation of our Site, make improvements, and provide the best service to users.
Do We Share Your Information with Anyone Else? Please note that we do not share your Personal Data with any other organization for marketing purposes.
We will only share your Personal Data in the following circumstances:
We may need to share your information with our service providers, affiliated organizations, and agents for the purposes described above.
Special Categories of Personal Data The Company collects Special Categories of Personal Data (see the summary of definitions at the end of this Policy) only when permitted by Data Protection Law.
We have implemented additional measures to safeguard the confidentiality of your Special Categories of Personal Data. We will only disclose your Special Categories of Personal Data to third parties as described in this Privacy Policy or where allowed by Data Protection Law.
Ongoing Processing The Company continues to process your Personal Data following your initial interaction with us, such as:
We retain all information in accordance with our Data Retention Policy, which is available upon request.
Your Rights You have the right to request that we do not process your Personal Data for marketing purposes.
You have the right to request the erasure of your data, often referred to as the 'right to be forgotten.' You may exercise this right for any reason, such as when your data is no longer necessary for our use, or if you withdraw your consent. Please note that we are entitled to and reserve the right to retain your data for statistical purposes. This right is not absolute, as we may need to continue processing this information, for example, to comply with our legal obligations or for reasons of public interest.
CONFIDENTIALITY POLICY for Somebody's Dad CIC
2.2. Service users have the inherent right to understand the scope and limitations of the confidentiality provided by Somebody's Dad CIC. They should be informed about the circumstances under which confidentiality may be breached, and this discussion should occur at the outset of their training, workshops, or counselling sessions.
2.3. If it becomes necessary to share information with another individual or organization, this should be done on a strict "need to know" basis. Whenever possible, consent from the person whose information is being shared should be obtained, and that person should be notified about the disclosure and its recipient.
2.4. This policy encompasses not only information intentionally provided by the individual or by others about the individual but also information obtained inadvertently or through observation.
3.2. There is also a broader duty of care towards the general public. Somebody's Dad CIC may need to notify law enforcement or statutory authorities when there is a possibility of significant harm to a specific person or persons, or to the public at large.
3.3. Regarding children and vulnerable adults, Somebody's Dad CIC employees and volunteers share a duty of care. If there is knowledge or suspicion of sexual or physical abuse of a child or vulnerable adult, the relevant safeguarding procedures, such as reporting to the Child Protection Unit or appropriate social services, must be followed.
Breach of this policy will be addressed through the appropriate Grievance and/or Disciplinary procedures.
• All personal paper-based and electronic data must be stored in accordance with the Data Protection Act 2018 and must be safeguarded against unauthorized access, accidental disclosure, loss, or destruction. • Access to personal paper-based and electronic data should be limited to authorized individuals only.
Somebody's Dad CIC GDPR Data Protection Policy
1. Data Protection Principles Somebody's Dad CIC is fully committed to processing data in strict adherence to its obligations under the GDPR (General Data Protection Regulation). Article 5 of the GDPR mandates that personal data must meet the following criteria: a. Processed lawfully, fairly, and transparently concerning individuals. b. Collected for explicit, legitimate, and specified purposes, with no further processing incompatible with these initial objectives, except for archiving, public interest, scientific research, or statistical purposes. c. Adequate, relevant, and restricted to what is necessary for the intended purposes. d. Accurate, and when needed, maintained up to date, ensuring prompt rectification or erasure of inaccurate data. e. Retained only as long as necessary for the purposes, with exceptions for archiving, public interest, scientific research, or statistical purposes, subject to appropriate safeguards. f. Processed securely to protect against unauthorized or unlawful processing, accidental loss, destruction, or damage, using suitable technical and organizational measures.
2. General Provisions This policy applies to all personal data handled by Somebody's Dad CIC. The responsibility for ongoing compliance with this policy rests with the Directors of Somebody's Dad CIC. Regular policy reviews, at least bi-annually, will be conducted.
3. Lawful, Fair, and Transparent Processing To ensure lawful, fair, and transparent data processing, Somebody's Dad CIC will maintain a Register of Systems. This register will be reviewed at least bi-annually. Individuals retain the right to access their personal data, and any such requests to Somebody's Dad CIC will be promptly addressed.
4. Lawful Purposes All data processing by Somebody's Dad CIC must align with one of the lawful bases, including consent, contract, legal obligation, vital interests, public task, or legitimate interests. The appropriate lawful basis will be documented in the Register of Systems. For consent-based processing, evidence of opt-in consent will be retained with the associated personal data. Revocation of consent should be clearly accessible to individuals, and systems will be in place to accurately reflect such revocations.
5. Data Minimization Somebody's Dad CIC will ensure that personal data collected is adequate, relevant, and limited to what is necessary for the intended purposes.
6. Accuracy To maintain accuracy, Somebody's Dad CIC will take reasonable measures to ensure that personal data is kept up to date, especially when necessary for the lawful basis of data processing.
7. Archiving and Removal To prevent data retention beyond necessity, Somebody's Dad CIC will establish an archiving policy for each data processing area, subject to annual review. This policy will consider which data should be retained, for how long, and for what reasons.
8. Security Personal data will be stored securely using modern, up-to-date software. Access to personal data will be restricted to authorized personnel, and measures will be in place to prevent unauthorized sharing of information. When personal data is deleted, it will be done securely to ensure irrecoverability. Adequate backup and disaster recovery solutions will be maintained.
9. Breach In the event of a security breach resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data, Somebody's Dad CIC will promptly assess the risk to individuals' rights and freedoms. If necessary, the breach will be reported to the ICO. This policy will undergo bi-annual reviews and be amended as required.
In order to mitigate Health & Safety risks at Somebody's Dad CIC, we are dedicated to the following objectives:
Responsibilities
The ultimate and conclusive responsibility for health and safety rests with the Principal Director. The day-to-day duty of implementing this policy lies with the Centre Manager. All employees, therapists, students, trainers, and visitors are required to adhere to this policy, collaborate on health and safety concerns, and exercise reasonable care for their own well-being. Any health and safety issues or concerns should be promptly reported to the Administrator.
Risk Assessment
The Centre Manager is responsible for conducting risk assessments. The findings of the risk assessment will be conveyed to the Principal Director, who will take action or grant approval for necessary modifications. The Administrator will conduct a reassessment of the risks. Risk assessments will be conducted at regular intervals, with a minimum frequency of once every 12 months.
Induction
Induction training for all employees will be conducted by the Principal Director and the Administrator.
Accidents and First Aid
A designated first aid kit is located in the kitchen. All accidents must be reported to the Administrator and documented in the first aid book, which is stored in the main office on the shelf behind the Administrator's desk.
Emergency Procedures and Fire Evacuation
The Administrator is responsible for overseeing the fire risk assessment and its implementation. Escape routes are routinely inspected by the Administrator, and fire extinguishers are checked and maintained annually.
Risk Assessment for Somebody's Dad CIC
i. What Hazards Exist?
ii. Who Could Be Affected?
iii. Current Precautions in Place?
iv. Implementation of Risk Assessment
This policy undergoes regular reviews, with a minimum frequency of every 18 months, and is updated as needed, at least once every 36 months.
Copyright © 2024 Somebody's Dad - All Rights Reserved.
Powered by GoDaddy