Overview

Community Action Redbridge is a local charity working to create positive change and make Redbridge a place where everyone has an equal opportunity to thrive. Our mission is to support strong and resilient communities where people lead happy, health and fulfilling lives.

Our mission is:

• Harnessing the power and potential of people and communities.

• Connecting, strengthening and championing the voluntary, community and social enterprise sector.

• Influencing meaningful change and transformation in systems, policies and practice.

To deliver our mission, it is necessary for us to collect and hold personal data. This Privacy Policy outlines how we process your data in line with GDPR and Data Protection Act and outlines your rights regarding this. We are committed to transparency and ensure we gain consent to your personal data and have processes in place to keep your data secure.

What is Personal data?

“Personal data” can be any information that identifies you as an individual such as your full name or address. Community Action Redbridge will collect, process, and use your personal data for a range of different purposes including some in the table below.

Some of our work requires us to collect and process sensitive personal data such as health and medical data, criminal records data, and race or ethnicity data.

All the personal data we process is collected directly from individuals except for referrals to our social prescribing service. Regardless of the data source, consent will always be given by you for us to hold this information.

How we use your information

Community Action Redbridge keeps information about many different people as part of the work we do. We take your privacy very seriously, and have detailed procedures regarding how that data is used. We run various different services and projects, and the details of how we use data vary between them. This document describes our procedures in detail for all the different projects and services.

Community Action Redbridge employs paid staff, but some of our work is done by volunteers, and a volunteer may process your information. We check that volunteers have the skills to do their work properly, and every volunteer is trained in how to handle information when they start working with us.

Our details and contacting us

Our organisation is called Community Action Redbridge. The person here responsible for our information systems is Abby Middleton, the Digital Development Lead. You can contact her by phone on 020 8553 1004, OR by email at abby@communityactionredbridge.org.uk or by post at Community Action Redbridge, 103 Cranbrook Road, Ilford IG1 4PU.

If you have a question or complaint

You have the right to know what information we hold about you, and to have it corrected if it is inaccurate. If you don’t want us to hold your information any more, we may be able to delete it. If you want us to change how we use your information – for example, if you want us to stop sending you mailings – please let us know. Contact Abby Middleton, Digital Development Lead, Community Action Redbridge by phone on 020 8553 1004, by email at abby@Community Action Redbridge.net or by post at Community Action Redbridge, 103 Cranbrook Road, Ilford IG1 4PU.

Community Action Redbridge has to obey laws about how we use your information. The government body which implements these laws is called the Information Commissioner’s Office. You have a right to complain to them if you feel that we have not complied with the law. You can contact the Information Commissioner’s Office by phone on 0303 123 1113, by email at casework@ico.org.uk or by post at Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

Categories of data Community Action Redbridge collect

Details of the information we hold for each of our projects and services

Staff

Community Action Redbridge holds information about our current staff. We do this to fulfil the contract of employment we have with our staff. We keep this information for six years after the end of a staff member’s employment.

• We hold information for payroll purposes including contact details, bank details, pension details, tax details, details of County Court Judgements and students loans. Payroll is processed for us by the Payroll Service Company, and we share this information with them.

• We hold personnel management information including contact details, details of an emergency contact person and personnel records. This information is protected by 2FA authentication and passwords on our computer system, and only available to the staff who need to see it. Paper documents are kept in locked filing cabinets.

This information is hosted on Microsoft's Azure cloud-based server as part of our Microsoft 365 subscription.

Job applicants

We hold information about people who apply for jobs with us, including their contact details, and information about their employment history and skills. We do this because it is in our legitimate interests to fairly and accurately assess candidates. This information is protected by 2FA authentication and passwords on our computer system, and only available to the staff who need to see it. Paper documents are kept in locked filing cabinets.

After the closing date for applications, we shortlist candidates for interview.

• If an applicant is not shortlisted, we hold their information for two weeks after the shortlisting meeting.

• If an applicant is shortlisted but not appointed, we hold their information for six months after their interview.

This information is hosted on Microsoft's Azure cloud-based server as part of our Microsoft 365 subscription.

Volunteers

Community Action Redbridge holds information about our volunteers, including their contact details, details of an emergency contact and details about their work with us. We do this because it is in our legitimate interests to manage them and their work. We keep this information for six years after a person stops volunteering for us.

The information is held in our VolunteerPlus database, which is managed for us by Pipe Media, who hold the data on their servers.

This information is protected by passwords on our computer system, and only available to the staff who need to see it. Paper documents are kept in locked filing cabinets in our office.

People associated with member organisations, individual members and people associated with supporter organisations

Community Action Redbridge holds contact details about these individuals. We do this as part of our contractual relationship with them, as part of which we provide people with information and services associated with their or their organisation’s membership, or its role as a supporter, of Community Action Redbridge. These services including sending individuals our eNews bulletin, information about Voluntary Sector Network meetings and about our AGM.

The information is held in our Aide CRM and VolunteerPlus databases, which are managed for us by Pipe Media, who hold the data on their servers.

Any individual can opt out of receiving mailings at any point by using the Unsubscribe link included at the end of all mass email messages.

If an organisation or individual leaves membership or stops being a Community Action Redbridge supporter, we will remove the data of the people associated with them after two years.

Fit for Fun

We hold data about three groups of people associated with Fit for Fun, our community exercise project:

1. People Taking Exercise as Part of the Project

We keep the contact details of some people taking part in Fit for Fun. We do this so as to send you information about the project: it is in our legitimate interests to do this. The information is hosted on Microsoft's Azure cloud-based server as part of our Microsoft 365 subscription, where only appropriate staff have access to it, and is also held in our AideCRM database, which is managed for us by Pipe Media, who hold the data on their servers. We keep this information for six years after we last contact you.

2. Instructors

We keep contact details, details of your insurance, details of DBS checks, details of activities for which you are qualified and financial details of invoices you have sent us and payments we have made. The information is hosted on Microsoft's Azure cloud-based server as part of our Microsoft 365 subscription, where only appropriate staff have access to it, and is also held in our AideCRM database, which is managed for us by Pipe Media, who hold the data on their servers. Paper documents are stored securely in our office. Financial information is processed by our finance team.

We hold this information so that we can carry out our contract with you. We will delete the information six years after we last make a payment to you.

3. Contacts at venues

We keep your contact details on our computer system, The information is hosted on Microsoft's Azure cloud-based server as part of our Microsoft 365 subscription, where only appropriate staff have access to it, and is also held in our AideCRM database, which is managed for us by Pipe Media, who hold the data on their servers.. We hold this information so that we can carry out our agreement with you. We will delete the information six years after we last make a payment to you.

Training

We hold data about people who have booked on our training courses, and about people who have told us that they are interested in getting information from us about our training services.

Information about training bookings is held by AideCRM which is managed for us by Pipe Media, who hold the data on their servers. We are processing this data in order to comply with our funder requirements (Redbridge Institute). Information about people interested in training services is held on IT systems based in our office. We are processing this data to send you information you have asked for: it is in our and your legitimate interests to do this.

If you book for training, we hold this information for six years after the date of the training session. If you ask us to stop sending information about our training courses, we will stop immediately and delete your data from our systems after two years.

Volunteering

We keep information about people interested in volunteering, and about our contacts at organisations that work with volunteers.

People interested in volunteering

We keep information about your contact details and your preferences as regards volunteering. We do this so as to match you with an appropriate volunteering opportunity: it is in our legitimate interests to do this. We may record information on sensitive topics such as your ethnicity to ensure that we provide a service equally to all parts of the community. We may record information on sensitive topics such as your health, including mental health – but only if you tell us about this, and if it is relevant to helping you find a volunteering opportunity. We hold information on sensitive topics with your consent, which you can withdraw at any time.

Information is hosted on Microsoft's Azure cloud-based server as part of our Microsoft 365 subscription, where it is only available to the staff who need to see it, and on our VolunteerPlus database, which is managed for us by Pipe Media, who hold the data on their servers. We keep this information for six years after we last have contact with you.

Organisations that work with volunteers

We keep information about your contact details on our AideCRM and Volunteer Plus database, which is managed for us by Pipe Media, who hold the data on their servers. We keep this information for six years after we last have contact with you.

We do this so that we can carry out the contractual agreement we have with you.

Social prescribing

We hold information about you and the support we give you. This will include sensitive information on issues including your physical and mental health. We do this to provide you with health and social care services. Information is held on our AideCRM database, where it is only available to the staff who need it, and on our CiviCRM database, which is managed for us by Circle Interactive, who hold the data on their servers. Access to sensitive information in the database is restricted to staff working on the Social Prescribing project. We keep this information for six years after we last have contact with you.

Health Partnerships

We work with some charities and community groups to help people access health services. Wherever possible, we encourage these organisations to apply for a supporter membership with us.

Information is hosted on Microsoft's Azure cloud-based server as part of our Microsoft 365 subscription, where it is only available to the staff who need to see it, and on our AideCRM database, which is managed for us by Pipe Media, who hold the data on their servers. We keep this information for six years after we last have contact with you.

Health projects in the community

Some of our staff work out in the community where they collect data for monitoring and reporting purposes. The data they collect is from the public but anonymised to ensure the data cannot be linked back to the individual.

Information is hosted on Microsoft's Azure cloud-based server as part of our Microsoft 365 subscription, where it is only available to the staff who need to see it, and on our AideCRM database, which is managed for us by Pipe Media, who hold the data on their servers. We keep this information for six years after we last have contact with you

Third Party and Data Sharing

We will only share personal data with third parties that is necessary to deliver our charitable objectives. We will not share personal data without your prior consent. Most Community Action Redbridge projects require us to share some data with programme funders and/or the Local Authority; we make this apparent at the point the personal data is collected.

To sign up with our Volunteer Centre you must provide consent that we can share your details with organisations who have listed their opportunities with us. If you wish to work with our Social Prescribing service, you must provide consent for us to share your details for onward referrals.

Community Action Redbridge will never sell or share your information with any third-party marketing organisations