Client Data Privacy Notice

This is a data privacy notice explaining how Greater Change will use your personal data.

What is personal data?

Personal data is any information relating to an individual that can be used to identify that individual (e.g. name, address, date of birth etc.). Using personal data (i.e. processing it) is regulated and there is certain information that we must provide to you as a controller of your personal data.

Who are we?

The controller of your personal data is Greater Change, a Community Interest Company (i.e. Greater Change). Greater Change is a private not-for-profit social enterprise registered in England & Wales at Companies House under No: 11914487. Our registered address is 82 St John Street, London, EC1M 4JN. You can contact us by email at enquiries@greaterchange.co.uk.

What 'personal data' do we hold about you?

You are not obliged to provide your personal data, however if you do not provide the information we have requested that we have indicated is necessary, we will not be able to process your application successfully.

In connection with your application, we will collect, store, and use the following categories of personal information about you:
1. The information you provide to us in the application form, including your name and photo;
2. Information provided to us by your Support Worker, including your next of kin and living status, race, ethnic origin, health and housing data and
3. Any other information you provide to us in communications with us.

Sensitive personal data

We may process data of a category that is classified as ‘sensitive’ during the completion of your application form.  During our interaction with you, we may process personal data relating to your health, race, ethnicity, political affiliations, religious beliefs, sexual orientation, trade union membership, genetic and biometric data.  In certain circumstances, we may process personal data that requests information about any criminal convictions, although the specific details of these convictions would not normally be requested.  All of the processing of this data is requested prior to the processing and only done so with your explicit consent.

How and why do we use your personal data?

We will only use your personal data for the purposes for which we collected it, which include the following:

To register you and (optionally) to create a publicly available profile on our website;

For fundraising and for the purposes of measuring social impact.

We must have a legal basis to process your personal data. In most cases the legal basis will be one of the following:
to fulfil our contractual obligations to you, for example to process your application;
to meet our legitimate interest to support your fundraising goals.

When we process personal data to meet our legitimate interests, we have undertaken an assessment where we have balanced your rights against ours to ensure that your privacy is protected. We will only process any sensitive personal data with your consent. You may withdraw your consent at any time by contacting us. Withdrawing your consent will not affect the lawfulness of how we used this personal data before you withdrew your consent.

Automated decision making

We do not use information about you for the purposes of automated decision making.

Who do we share your personal data with?

We may share your personal data with third parties under the following circumstances:

1. Service providers and business partners. We may share your personal information with our service providers and business partners that perform services and other business operations for us. For example, we partner with researchers to understand the efficacy of our work. We may also partner with other companies to optimise our services, send newsletters and marketing emails, support email and messaging services and analyse information.

2. Law enforcement agency, court, regulator, government authority or other third party. We may share your personal information with these parties where we believe this is necessary to comply with a legal or regulatory obligation, or otherwise to protect our rights or the rights of any third party.

How long we keep your personal data

We will keep your personal data about you only for so long as is necessary to achieve the purpose for which we have collected that data, or as required by law, or as required for in order to meet any legal, or reporting requirements.

When deciding what is the appropriate retention period for your personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from any unauthorised use or disclosure of your personal data, the purposes for which we use your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

What are my rights?

You have the right to request: access to, correction of, or erasure of the personal data we hold about you. You have the right to object to how we process your personal data and to request that we restrict how we process it, and to request that we transfer your personal data to a third party. You also have the right to make a complaint to a supervisory authority, which in the UK is the Information Commissioner's Office .

How to contact us

If you want to ask us about this Privacy Notice, please email us  at  enquiries@greaterchange.co.uk or write to Greater Change, Buxton Court, 3 West Way ,Oxford OX2 0JBwww.ico.org.uk but please give us a chance to address your concerns before you contact the ICO.

Changes to privacy notice and your personal data

We keep this Privacy Notice under review. It was last updated on 26/06/2024 It is important that your personal data is accurate and up to date.
Please let us know if your personal data changes.

Data security

We may transfer your personal data outside the European Union (the EU), but we will not do so unless: 

1.  we transfer it to a country which the European Commission has decided ensures an adequate level of protection for personal data or if the recipient has entered into the Standard Contractual Clauses published by the European Commission. If you wish to see a copy of the Standard Contractual Clauses, please email us at enquiries@greaterchange.co.uk or write to Greater Change, Buxton Court, 3 West Way, Oxford OX2 0JB; 

2.  we transfer your personal data to an entity in the United States which participates in the Privacy Shield. That obliges the US entity to protect personal data shared between Europe and the US. For more information please see https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/eu-us-privacy-shield_en
3.  you have given your explicit consent to the transfer of your personal data outside the EU. (If you have given that consent you may withdraw it at any time by emailing us at enquiries@greaterchange.co.ukor writing to Greater Change, Buxton Court, 3 West Way, Oxford OX2 0JB; 

4.  we cannot perform a contract with you without making that transfer; 

5.  we cannot take the steps you have requested us to take without making that transfer; 

6.  we cannot enter into or perform a contract with someone else which is in your interests without making that transfer; 

7.  the transfer is necessary for important reasons of public interest; or
 
8.  the transfer is necessary for the establishment, exercise or defence of legal claims. 

Your personal data may be accessed by our staff when they are outside the EU, but the same safeguards will apply as though our staff were accessing your personal data from within the EU.

We have appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.

We limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will process your personal data on only on our instructions and they are subject to a duty of confidentiality.

We have procedures to deal with any suspected personal data breach and will tell the Information Commissioner’s Office and you of a breach of security involving your personal data if the law obliges us to do so.