Privacy Policy

This policy is effective as of 31 December 2019.

The Elm Foundation is committed to protecting any personal information you provide to us. Any personal information you provide to us will be processed in the ways described in this privacy policy. This policy explains how we collect information, what we do with it and what rights you have over it.

Our supporters and contacts are extremely important to us. Without your support The Elm Foundation will find it much harder to continue to provide life-changing and life-saving services. It is important that we can communicate with you. We would like to keep you up to date about our work, show the amazing difference your support is making, demonstrate how you are helping us to reach more people experiencing domestic abuse and on occasion, approach supporters for further help.

We would also like to assure anyone who accesses our websites and any of our support services that The Elm Foundation is committed to the privacy and security of their personal information.

1. Who we are
In this privacy policy, The Elm Foundation means: registered charity in England and Wales (1007317), a company Limited by guarantee in England (2372121). The Elm Foundation is a ‘controller’ for the purposes of the UK General Data Protection Regulations and UK Data Protection Act 2018. As a controller we are responsible for, and control the processing of your personal information. If you require further information about our privacy practices, please contact the Data protection officer at info@theelmfoundation.org.uk or call 01246540464

2. How we collect information about you
When you interact with us directly: This could be if you ask us about our activities, register with us for an event, make a donation to us, subscribe to our newsletter or other marketing or fundraising communications, ask a question about domestic abuse, access our support services, purchase something, apply for a job or volunteering opportunity or otherwise provide us with your personal information. This includes when you phone us, visit our website, get in touch through the post, or in person.

When you interact with us through third parties: This could be if you provide a donation through a third party such as Just Giving or one of the other third parties that we work with and provide your consent for your personal information to be shared with us. When you visit our website: We gather general information which might include which pages you visit most often and which services, events or information is of most interest to you. We may also track which pages you visit when you click on links in emails from us.

We also use “cookies” to help our site run effectively. There are more details below – see ‘Use of cookies’. We use this information to personalise the way our website is presented when you visit to make improvements and to ensure we provide the best service and experience for you.

Cookies
Strictly Necessary cookies
These cookies allow our website to perform its essential functions. Without these cookies, some parts of our websites would stop working.

Blocking and Deleting Cookies
For more information about how to manage cookies, including blocking and deleting cookies please visit https://cookie-script.com/knowledge-base/cookies/ or https://cookie-script.com/knowledge-base/cookie-management/

Please note blocking all cookies may have a negative impact upon the usability of many websites. If you block cookies, you may not be able to use all the features on our website.

When you interact with us through partners or suppliers working on our behalf: This could be if you access a service delivered through a trusted organisation working on our behalf and always under our instruction. From other information that is available to the public: In order to tailor our communications with you to your background and interests we may collect information about you from publicly available sources or through third party subscription services or service providers.

3. Information we collect about you
In connection with the purposes set out in paragraph 4 below we collect some or all of the following information, as applicable to the relevant purpose:

  • your name;
  • your contact details (including postal address, telephone number, e-mail address and/or social media identity);
  • your date of birth;
  • your gender;
  • family and spouse/partner details, relationships to other supporters;
  • your bank or credit card details where you provide these to make a payment;
  • if you volunteer for us or apply for a job with us, information necessary for us to process these applications and assess your suitability (which may include things like employment status, previous experience depending on the context, as well as any unspent criminal convictions or pending court cases you may have);
  • information about your activities on our website(s) and about the device you use to access these, for instance your IP address and geographical location;
  • information about events, activities and products which we consider to be of interest to you;
  • information relating to your health (for example if you are taking part in or attending an event for health and safety purposes);
  • where you have left us a legacy, any information regarding next of kin with which you may have provided us to administer this;
  • information as to whether you are a taxpayer to enable us to claim Gift Aid;
  • age, nationality and ethnicity information for monitoring purposes; and
  • any other personal information you provide to us.

In connection with certain services offered through this site we may ask you to submit information such as your name, e-mail address, postal address, telephone number and credit/debit card details. You are under no obligation to provide such information. However, if you should choose to withhold requested information, we may not be able to offer you certain services.

Certain types of personal information are in a special category under data protection laws, as they are considered to be more sensitive. Examples of this type of sensitive data would be information about health, race, religious beliefs, political views, trade union membership, sex life or sexuality or genetic/biometric information. We only collect this type of information about our supporters to the extent that there is a clear reason for us to do so, and we will only do this in a way that is lawful and complies with the principles and requirements of the UK GDPR and the Data Protection Act 2018.

Wherever it is practical for us to do so, we will make it clear why we are collecting this type of information and what it will be used for.

4. How your information is used
The Elm Foundation uses the information you provide to us for one or more of the following purposes:

  • to provide you with the services, products or information you asked for;
  • to administer your donation or support your fundraising, including processing Gift Aid;
  • to keep a record of your relationship with us;
  • to respond to or fulfil any requests, complaints or queries you make to us;
  • to understand how we can improve our services, products or information by conducting analysis and market research;
  • to manage our events;
  • to check for updated contact details against third party sources so that we can stay in touch if you move (see “Keeping your information up to date” below);
  • to further our charitable objectives;
  • to register, administer and personalise online accounts when you sign up to products we have developed;
  • to send you correspondence and communicate with you;
  • to process applications for funding and for administration of our role in the projects we fund;
  • to administer our websites and to troubleshoot, perform data analysis, research, generate statistics and surveys related to our technical systems;
    for testing our technical systems to make sure they are working as expected;
  • to display content to you in a way appropriate to the device you are using (for example if you are viewing content on a mobile device or a computer);
  • to generate reports on our work, services and events;
  • to safeguard our staff and volunteers;
  • to conduct due diligence and ethical screening;
  • to monitor website use to identify visitor location, guard against disruptive use, monitor website traffic and/or personalise information which is presented to you;
  • to process your application for a job or volunteering position;
  • to conduct training and quality control;
  • to audit and administer our accounts;
  • to meet our legal obligations, for instance to perform contracts between you and us, or our obligations to regulators, government and/or law enforcement bodies;
  • to carry out fraud prevention and money laundering checks;
  • to undertake credit risk reduction activities; and/or
  • to establish, defend or enforce legal claims.

4.1 Building profiles of our supporters and targeting communications
We may analyse the details you have provided to us, where it is in our legitimate interest to do so. If we do this we will make sure it is compliant with GDPR. In some instances, we may make use of additional factors such as demographic information and measures of wealth.

We do this to help us understand why people are motivated to support The Elm Foundation and to help us create a fuller and better picture of our supporters. This enables us to communicate with our supporters more effectively and to reach out to individuals who may wish to give additional support with a further monetary gift. We may on occasion use third party suppliers to undertake these activities on our behalf and provide them with your information to the extent required, but this will only be done where we have a legitimate legal basis to do so. If you would rather we didn’t undertake this screening please contact us and ask to opt-out. All of our suppliers are GDPR compliant.

4.2.1 Building profiles of potential supporters and targeting communications.
We may also carry out research to identify individuals who may have an affinity to our cause, and capacity to support The Elm Foundation, but with whom we are not already in touch. Before contacting, we may use data analysis to interpret your data and predict how likely you are to be interested in or responsive to a particular campaign or fundraising message. In order to do this, we may collect information about you and analyse and compile that information into a profile of you in order to assist us in engaging with you in a more personalised way. In order to do this efficiently, we may use trusted third party specialist companies that collate and analyse information from public registers alongside statistical social-economic data to automate some of this work. This will only be done with GDPR compliant suppliers. This helps us to understand more about your interests and level of potential engagement or donation.

4.2.2 Personal information about you from service providers, the press, search engines, social media (e.g. LinkedIn) and reputable public data sources (e.g. Companies House, BoardEx, the Charity Commission, Land Registry)
Personal information we may collect via these channels may include your job title, directorships, contact information, demographic data (including estimated income and property value), date and size of previous donations to other charities, details of philanthropic activities you engage in, etc. We may use this information to build a profile of you (i.e. your interests, preferences, demographics and level of potential donations) to enable us to tailor fundraising efforts and communications based on your circumstances and interests, and how likely you are to support our work. This enables us to understand our supporters better and helps us make appropriate requests to those who might be able and willing to give more than they already do and so ensure that we are making the best use of our resources. We may combine information we have obtained about you from these third party sources with other information that we hold about you for this purpose.

We’re committed to putting you in control of your data and you’re free at any time to opt out from this activity. To find out more, please contact info@theelmfoundation.org.uk

Please note that before seeking or accepting major donations we are required to conduct a minimum level of due diligence. This is in accordance with our legal and regulatory obligations and our internal risk management policies and procedures. This means that if you opt out of analysis of your data, we may still conduct some analysis that is required to enable us to accept donations from you.

4.2.3 More on use of Social Media
The Elm Foundation uses social media to promote our life-changing and life-saving work. We have accounts on Facebook, Twitter, LinkedIn, and Instagram. If you are a social media user, we will use social media tools (outlined in paragraph 2) as part of our relationship with you. Where members of the public engage with our posts or publish content relevant to our work, we may also like the posts, follow them, reply or write to them. We conduct research on what people say on public social media platforms to better understand how people feel about our sector and to improve our work. This research may be done by staff or companies we work with.

4.3 Advertising Online
In order to ensure our online advertising is effective and cost efficient, we sometimes share data with Google and social media sites. This enables us to keep our costs down and reach the people who are more likely to support our work. We use ‘custom audiences’ and ‘lookalike’ tools to manage this.

Custom audiences allow us to exclude our existing supporters from our advertising. This reduces costs by not advertising to people who have already signed up. This involves sharing some supporter data, such as email addresses or telephone numbers. This data is always securely encrypted and is used to match supporters to their social media and Google accounts.

We use lookalike audiences to create audiences of people with similar characteristics to The Elm Foundation supporters. These people may then be shown The Elm Foundation advertising. This is a very effective way for us to find new people likely to support human rights work.

Data shared with Facebook, Twitter and Google platforms is used for no other purposes than described above and is not shared with any third parties. If you do not want your information to be used in this way, please contact us.

5. Who your information is shared with
5.1 Donation processing
When making an online donation you will be re-directed through to our Just Giving page located on the Just Giving website (https://www.justgiving.com/the-elm-foundation). You can find out more information about how Just Giving process your data at https://www.justgiving.com/about/info/privacy-policy/privacy-policy-v30.

5.2 Sending out communications
If we ever need to send data to a third party (for example to an agency carrying out telemarketing or a mailing house distributing mailings on our behalf) we will make sure the company we use has signed a data processing agreement with us.

5.3 Administering Gift Aid
If you have made a Gift Aid declaration, we will disclose the information you have provided as part of the declaration to HMRC for the purpose of reclaiming gift aid on your donation(s).

5.4 Other
The Elm Foundation may analyse and disclose aggregate statistics about our site visitors, and donations in order to describe our services to prospective partners, other reputable third parties and for other lawful purposes, but these statistics will include no personally identifying information.

The Elm Foundation may disclose personal information if required to do so by law or if it believes in good faith that such action is required by law.
This site contains links to other sites. The Elm Foundation is not responsible for the privacy policies or the content of such sites.

6. How long we keep your information for
We keep your personal information only for as long as we need to use it for the purposes set out in this Policy. We have adopted a data retention policy that sets out the different periods we retain personal information for in respect of these relevant purposes. The criteria we use for determining these retention periods is based on various legal requirements; the purpose for which we hold data and whether there is a legitimate reason for continuing to store it; and guidance issued by relevant regulatory authorities including, but not limited to, the Information Commissioner’s Office (ICO).

Personal information that we no longer need is securely disposed of and/or anonymised so you can no longer be identified from it. Some personal information may be retained by us in archives for statistical or historical research purposes although we will only do this in a manner that complies with applicable data protection law.

We continually review what personal information and records that we hold, and delete what is no longer required.

7. How we keep your information safe
The Elm Foundation places a great importance on the security of your information. We have physical, technical and organisational security measures in place to attempt to protect against the improper access, loss, misuse and alteration of personal data under our control (for example, our security and privacy policies are periodically reviewed and enhanced as necessary and only authorised personnel have access to personal information). Information you submit via this website is sent to a computer located in the United Kingdom.

If you have given us the relevant permission to do so, we may send communications to you via email. Email is not a fully secure means of communication and whilst we do our utmost to keep our systems and communications protected we cannot guarantee this. If you prefer not to receive emails from us you are under no obligation to do so.

Our websites may contain links to other sites. While we try to link only to sites that share our high standards and respect for privacy, we are not responsible for the content or the privacy practices employed by other sites. Please be aware that advertisers or Web sites that have links on our site may collect personally identifiable information about you. This privacy statement does not cover the information practices of those websites or advertisers.

8. Legal basis for using your information
According to data protection laws each use we make of personal information must have a “legal basis”. The relevant legal bases are set out in UK data protection legislation. For the data processing activities described in this policy we rely on the following bases:

Consent
Consent is given where we ask you for permission to use your information in a specific way, and you agree to this (for example when we send you marketing material via text or e-mail). Where we use your information for a purpose based on consent, you have the right to withdraw consent for this purpose at any time.

Legal obligation
We have a basis to use your personal information where we need to do so to comply with one of our legal or regulatory obligations. For example, in some cases we may need to share your information with our various regulators such as the Charity Commission, Fundraising Regulator or Information Commissioner, or to use information we collect about you for due diligence or ethical screening purposes.

Performance of a contract / take steps at your request to prepare for entry into a contract
We have a basis to use your personal information where we are entering into a contract with you or performing our obligations under that contract. Examples of this would be if you are buying something from us, or applying to work/volunteer with us, or providing a service to us. We also rely on a contract basis when you sign up for fundraising events.

Vital interests
We have a basis to use your personal information where it is necessary for us to protect life or health. For instance if there were to be an emergency impacting individuals at one of our events, or a safeguarding issue which required us to contact people unexpectedly or share their information with emergency services.

Legitimate interests
We have a basis to use your personal information if it is reasonably necessary for us (or others) to do so and in our/their “legitimate interests” (provided that what the information is used for is fair and does not unduly impact your rights). Where we use legitimate interest for marketing, fundraising and wealth screening and research you can opt-out from us processing your data for these purposes at any time.

We only rely on legitimate interests where we consider that any potential impact on you (positive and negative), how intrusive it is from a privacy perspective and your rights under data protection laws do not override our (or others’) interests in us using your information in this way. This assessment is carried out through a ‘balancing exercise’.

When we use sensitive personal information (please see the “What personal information we collect” section above), we require an additional legal basis to do so under data protection laws, so will either do so on the basis of your explicit consent or another route available to us at law for using this type of information (for example if you have made the information manifestly public, we need to process it for employment, social security or social protection law purposes, your vital interests, or, in some cases, if it is in the public interest for us to do so).

9. Your Rights
You have various rights in respect of the personal information we hold about you – these are set out in more detail below. If you wish to exercise any of these rights or make a complaint, you can do so by contacting The Elm Foundation, 6 Fairfield Road, Chesterfield / 01246 540464 or email info@theelmfoundation.org.uk You can also make a complaint to the data protection supervisory authority, the Information Commissioner’s Office, by visiting https://ico.org.uk/.

Access to your personal information: You have the right to request access to a copy of the personal information that we hold about you, along with information on what personal information we use, why we use it, who we share it with, how long we keep it for and whether it has been used for any automated decision making. You can make a request for access free of charge. Please make all requests for access in writing, and provide us with evidence of your identity.

Right to object: You can object to our processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You can object to us processing your data in certain circumstances (for example, profiling). You also have the right to object where we are processing your personal information for direct marketing purposes. Please contact us as noted above, providing details of your objection. We aim to process your objection within 30 days.

Consent: If you have given us your consent to use personal information (for example, for marketing), you can withdraw your consent at any time.

Rectification: You can ask us to change or complete any inaccurate or incomplete personal information held about you.

Erasure: You can ask us to delete your personal information where it is no longer necessary for us to use it, you have withdrawn consent, or where we have no lawful basis for keeping it.

Portability: You can ask us to provide you or a third party with some of the personal information that we hold about you in a structured, commonly used, electronic form, so it can be easily transferred.

Restriction: You can ask us to restrict the personal information we use about you where you have asked for it to be erased or where you have objected to our use of it.

No automated-decision making: Automated decision-making takes place when an electronic system uses personal information to make a decision without human intervention. You have the right not to be subject to automated decisions that will create legal effects or have a similar significant impact on you, unless you have given us your consent, it is necessary for a contract between you and us or is otherwise permitted by law. You also have certain rights to challenge decisions made about you. We do not currently carry out any automated decision-making.

Please note, some of these rights only apply in certain circumstances and we may not be able to fulfil every request.