Data Privacy Notice (Draft)
Bookham Youth & Community Association Ltd (BYCA)
re: operating Bookham Youth & Community Centre (BYCC)
Data Privacy Notice
The following describes how Bookham Youth & Community Association Ltd (‘BYCA’ , ‘BYCC’ or ‘Charity’) acts as a Data Controller, how it will process personal data and your rights in accordance with the Data Protection Act 2018 (DPA 18) and the UK General Data Protection Regulation (UK GDPR).
This notice applies to current and former users of Bookham Youth & Community Association Ltd, suppliers, Trustees and other Officers and Volunteers and donors, customers and separate organisations which may interact with Bookham Youth & Community Association Ltd.
The kind of information we may hold
Personal data types stored and processed may include:
ID details: such as name, age/month of birth, photograph. - Contact details: address, email address, phone number.
Bank details: for the purposes of requesting and making payments and raising invoices.
Safeguarding information: relating to any matters that may arise with Safeguarding Officer.
Some data (e.g data revealing racial or ethnic origin, political opinions or biometric data)1 falls into special categories requiring a higher level of protection. We do not expect to process such information types. (See Safeguarding Policy). Should this change then we will ensure this is explained to you and additional information provided.
How will we use the personal data provided and what is our legal basis?
Most commonly our legal basis for processing personal data will be:
Legitimate Interests.
As part of a contract with you.
As part of a legal obligation.
To protect your vital interests – in the case of unforeseen emergencies.
With your consent.
Situations in which we will use your personal data include:
Matters directly relating to hires:
Booking forms submitted by individuals containing personal details are stored securely by the relevant Booking Officer until one year after the later of the end of the hire period or payment of any outstanding hire charges. Personal details supplied are processed using the Charity’s accounting system to prepare and submit invoices and to collect hire charges due and are also used to contact hirers about actual and prospective hire periods. Details of hirers and debtors may also be stored on the computers of the Chairman, the Treasurer, and the Booking Officers.
Bank details are not normally held by the Charity due to its third party payment system but in the event that they are held for any purpose they will be deleted within 12 months after that purpose has expired.
The Safeguarding Officer securely stores Safeguarding Compliance forms until one year after the end of the relevant hire period.
Names and hire periods may also be entered on the Charity’s internal use on-line (“non public view”) calendar.
The basis for such processing is contract, legal obligation and legitimate interest.
( See Article 9 of UK General Data Protection Regulation for further examples)
Other processing and communications
Names and email addresses are also used to send individuals information about membership and news about BYCA including fund-raising events.
The basis for such processing is consent and legitimate interest.
Potential hirers
Personal details supplied by individuals enquiring about regular hire slots are stored as a waiting list until the individual informs the Charity that he or she is no longer interested in hiring any part of BYCC. These details are used to inform the individual about availability and will be removed 12 months after last inquiry.
The basis for processing such data is contract and legitimate interest.
Trustees / Directors and other Officers, Volunteers, donors, subscribers and supporters
Personal details are recorded in a register where appropriate which, together with membership applications and other documentation supplied, are stored securely by the Company Secretary, Treasurer and/or Chair. Names and email addresses are also stored on the Charity internal IT systems. Any application forms are destroyed, and email addresses deleted from the Charity internal IT systems after the individual ceases to be a Trustee, Officer or Volunteer, donor, subscriber and supporter as appropriate.
Personal details are used to send notices of general meetings of the Charity and otherwise as required under the Charity’s Articles of Association and by law and are also used to send information about BYCA & BYCC.
Personal data of Trustees/ Directors and Officers is provided to Companies House and the Charity Commission as required by law.
The Safeguarding Officer securely stores names of those who are subject to DBS checks until one year after the end of the involvement of the Volunteer.
The basis for processing such data is consent, contract, legal obligation and legitimate interest.
Suppliers
Personal data provided by suppliers and other parties with which the Charity has business dealings will be retained securely in the form in which it is supplied and may also be entered on the Charity’s cloud accounting system.
Bank details provided for payments are input into the Charity’s online banking system for the purpose of making payments. Bank details are deleted from the online banking system six years after the ending of the business relationship or within one month of the supplier confirming that he or she has been paid all sums due by the Charity if earlier.
The basis for processing such data is contract and legitimate interest.
Storage of data
All data will be securely stored in accordance with our GDPR Policy (available on request).
Sharing of data
BYCA only uses personal data for the purposes set out above and will not share data with any other company, group or society, except where it is shared with the Charity’s agents, insurers or other bodies in connection with a claim made by or against the Charity, or where required by law.
Consent
Anyone wishing to receive future communications from the Charity, including hirers and potential hirers, will be asked to give their agreement via a request on the BYCA website or as part of the booking process/ system.
Data Rights
Unless a legal right to retain is shown. Under certain circumstances you have the right to:
Request access to your personal data, also known as a ‘Subject Access Request’.
Request correction where data is incomplete or inaccurate.
Request erasure of the data held.
Object to processing.
Request restriction of processing
Prevent automated processing. Please note we do not envisage that this will occur.
For all such requests please contact info@byca.org.uk
We may need to request information from you to confirm your identification and ensure your rights are adhered to. We will not normally charge a fee for responding to a request. Where a request is manifestly unfounded or excessive, we may charge a reasonable fee reflecting the administrative cost of responding or may refuse to act on the request where permitted by law. We will explain our decision.
If you have any concerns about our use of your personal information, please contact us at info@byca.org.uk head up “Data Privacy”.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been breached. You can contact the ICO via their website at ico.org.uk or call their helpline on 0303 123 1113.
NOTE
Data held by organisations, groups, individuals in relation to activities organised by them at BYCC are NOT the responsibility of BYCA and excluded from this policy.