Ponthafren Policies

Privacy Policy

Ponthafren uses Google Analytics to monitor activity throughout our website including which pages you visit and on what type of device but we have no way of identifying any of your personal data or you personally from this information.

Your names will only be used on our website with your explicit consent. Ponthafren makes every effort to get verbal consent when taking photos in line with our in-centre privacy notices but we appreciate consent can change and can be missed in public settings. If you see a photo of yourself that you are not happy with, please don’t hesitate to contact us on admin@ponthafren.org.uk explaining who you are, which photo you want removed, and which page it appears on.

While the website processes personal information, it is not stored by the website or its provider so does not have a retention policy. All data collected via the website is sent directly to Ponthafren and stored by the organisation.

While instances will be minimal, Ponthafren may share a limited amount of your personal data with our website provider to enable us and them to deliver their service to us and carry out research on our users to help us improve our services. This may include connecting data we receive from you on the website to data available from other sources. However, the use of personally identifiable data will be limited and only used where it is necessary for the analysis/purposes required, and where your interests for privacy are not deemed to outweigh the legitimate interests in developing services. In the case of this activity the following will apply:

1. Your data will be made available to our website provider.

2. The data will be limited as much as possible, and ideally anonymised, and will never include personally identifiable special category or criminal offence data.

3. Our website provider will not transfer your data to any other third party, or transfer your data outside of the EEA without notifying you.

4. They will store your data for a maximum of 7 years but Ponthafren will request the deletion of your data as soon as possible.

5. This processing does not affect your rights as detailed in this privacy policy.

Referral Form Privacy Notice

All information requested by our referral form is required to effectively process any referral:

  • Contact information is a requirement so we can provide the service.
  • Address is required so ensure the individual is within Ponthafren’s catchment area for support.
  • Date of birth is required so that Ponthafren can verify your age is appropriate for the service.
  • Information about what support you would like and why is required for us to be able to provide that service to you. Minimal information is required at this stage and further information can be shared later if preferred.

The data collected by this form is not stored on this website. Ponthafren will securely store this data electronically via encryption. Data submitted via this form will typically be kept for 7 years (not including the first partial year) after the last contact with the individual. This may vary due to funding and contract requirements: please contact the Data Protection Officer via admin@ponthafren.org.uk for specific information.

Volunteer Application Form Privacy Notice

Most information requested by our referral form is required to effectively process any application:

  • Contact information is a requirement so we can provide the service.
  • Address is required so ensure the individual is within Ponthafren’s catchment area for service provision and Ponthafren policies.
  • Date of birth is required so that Ponthafren can verify the individual’s age is appropriate for the application.
  • Health information is requested to allow Ponthafren to arrange the best volunteering for the individual based on their needs. Health information is optional and provided via consent at this stage. Further information can be provided later if preferred.
  • Historical offences information is classified as the highest level of sensitivity and is optional at this stage. Due to the nature of Ponthafren’s work, the majority of volunteer roles we offer required a DBS check for safeguarding reasons. If you choose not to disclose criminal offences information at this stage, this will not affect your application negatively but may slow down the application process if this information is later acquired via a DBS.
  • References are required to verify your credentials and skills for the role applied for. It is the applicant’s responsibility to seek consent from your references for their information to be shared with Ponthafren.

The data collected by this form is not stored on this website. Ponthafren will securely store this data electronically via encryption. Data submitted via this form will typically be kept for 7 years (not including the first partial year) after the last contact with the individual. This may vary due to funding and contract requirements: please contact the Data Protection Officer via admin@ponthafren.org.uk for specific information.

If you have any questions or concerns regarding data protection, please
contact us on: 01686 621586 or admin@ponthafren.org.uk

General Information on Ponthafren’s Use of Personal information and Data
Protection

In order to operate effectively, Ponthafren has to collect and use relevant information on service users, carers, organisations, employees, trustees and volunteers. The information is held exclusively by Ponthafren for the purpose of providing a support
and information service to people experiencing, or at risk of, mental distress.

The General Data Protection Regulations (GDPR) contain principles affecting personal records. Information protected by the Regulations governs personally identifiable data held on computer and manual records.

The purpose of this policy is to ensure that Ponthafren do not breach the Regulations and that individuals know their rights. If there is any questions or concerns regarding Ponthafren’s use of personal information further advice should be sought from
Ponthafren’s Data Protection Officer (DPO).

Staff, volunteers, and third-party contractors are made aware that they may be criminally liable if they knowingly or recklessly disclose personal data in breach of the Regulations. A serious breach of data protection is also a disciplinary offence and will be dealt with under the disciplinary procedures.

If an employee, volunteer, or contractor accesses personnel records without authority, this constitutes gross misconduct and could lead to dismissal or legal action. Ponthafren will monitor the compliance of all other organisations with whom Ponthafren shares data and, if not satisfied, will take necessary action to protect your
data.

The Data Protection Principles

Ponthafren must comply at all times with the six principles that are central to GDPR.

In brief, the principles state that personal data must be:-

1. ‘Processed lawfully, fairly and in a transparent manner in relation to individuals’. Please refer to The Data Protection Policy or the Data Protection Act for a full explanation of lawful bases for processing personal data, special category data, and criminal offence data.

2. ‘Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with initial purposes.

3. ‘Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed’.

4. ‘Accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay’.

5. ‘Kept in a form which permits identification of data subjects for no longer than s necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of individuals’.

6. ‘Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures’.

Data Protection Officer (DPO)

Ponthafren’s DPO role resides with the role of the Impact & Governance Manager and can be reached at Ponthafren, Longbridge Street, Newtown, Powys, SY16 2DY, Tel: 01686 621 586 and e-mail: admin@ponthafren.org.uk

The DPO must retain a sense of detachment to avoid a conflict of interests and must be able to independently make decisions and provided reporting routes to the Board of Trustees. If a conflict of interests arises between their roles, either in the short- or long-term, the role of DPO must be reallocated temporarily or permanently as required. The DPO must not be coerced or punished for carrying out the responsibilities under the GDPR.

If it is thought any of these requirements are at risk, this should be reported to the Director or the Board of Trustees as required.

For further information on the role and responsibilities of the DPO, please see The Data Protection Policy or the Data Protection Act.

Rights of Individuals

There are circumstances where any or all of the following rights can be waived.

1. The right to be informed
Individuals have the right to be kept informed about the collection and usage of their data. Concise, transparent privacy notices must be supplied in plain and clear language to explain what information is held, what it is used for, who it is shared with, and how long it is kept.

2. The right of access
Individuals have a right to be able to access their own information and have a right to verify the lawful basis for processing their data. The request can be verbal or in writing and Ponthafren has one month to respond to the demand.

3. The right to rectification
Individuals have the right to demand the rectification of the data where it is found to be incorrect. The request can be verbal or in writing and Ponthafren has one month to respond to the demand.

4. The right to erasure
Individuals have the right to ask for their information to be deleted or to withdraw their consent for processing. The request can be verbal or in writing and Ponthafren has one month to respond to the demand.

5. The right to restrict processing
Individuals have the right to demand Ponthafren restrict the processing of their information; Ponthafren may still store the data but not use it. The request can be verbal or in writing and Ponthafren has one month to respond to the demand.

6. The right to data portability
Individuals have a right to reuse their personal data across multiple services and Ponthafren has an obligation to provide that data in a commonly accessible electronic format upon request. The data subject is the owner of that data, not Ponthafren.

7. The right to object
Individuals have the right to object to the use of their data in cases of direct marketing (including profiling), processing for historical/scientific research and statistics, or processing where the lawful basis has been decided as
‘legitimate interests’ or ‘public interest’.

8. Rights in relation to automated decision making and profiling
Individuals have various rights in relation to automatic decision making and profiling. These are detailed within the GDPR legislation and guidance but are not currently relevant to Ponthafren.

Periods of Retention

Different categories of data will be retained for different time periods, depending on legal, contractual, operational, or financial requirements. Please refer to the Data Protection Policy or specific service privacy notices for retention periods.

Ponthafren will not retain data for any longer than is required in order to fulfil its legal obligations or to provide its services to a satisfactory standard.

Ponthafren, under guidance from the Data Protection Officer, will proactively review its archiving and filing systems to ensure that data which is no longer required or permitted to be retained is kept.

Right of Access

Upon request, Ponthafren will provide the individual with a statement regarding the personal data held about them. This will state all the types of personal data that the organisation holds and processes about them and the reasons for which they are
processed.

If an individual wishes to access a copy of any personal data being held about them, they must make a formal subject access request (SARs) for this either in writing or verbally. Ponthafren must provide this information free of charge and within one month from the date of the request. Requests must be shared with the Data Protection Officer.

Ponthafren reserves the right to challenge persisted or excessive SARs and either refuse to comply or charge a suitable administrative fee for costs incurred. If the SAR is refused, the reasons as well as the individual’s right to complain and take remedy within one month must be explained to the individual.

If an individual wishes to make a complaint that these rules are not being followed in respect of personal data that Ponthafren holds about them, they should raise the matter with the Data Protection Officer. If the matter is not resolved to their satisfaction, it should be raised as a formal grievance under Ponthafren’s grievance procedure. The individual also holds the right to contact the Information Commissioner’s Office if they feel Ponthafren is not complying with the GDPR.

Consent to Personal Information Being Held

Ponthafren must hold various types of confidential personal data about individuals and relies primarily on consent and legitimate interests to do so. Various services within the organisation seek consent to process data in different ways ranging from verbal consent or signed consent. In some circumstances consent is not required, for example if there is a concern for the safety of the individual or someone else or a legal requirement.

Obligations to Personal Information

Ponthafren will ensure any personal data they hold is kept securely, either in a locked filing cabinet or, if computerised, it is password protected.

Compliance with the Regulations is the responsibility of Ponthafren and each employee, volunteer, and third-party contractor authorised to process that data.

Confidentiality

While spoken information is not governed by Data Protection Regulations, when working for Ponthafren, staff, volunteer, and third-party contractors must abide by Ponthafren’s Confidentiality Policy.

Staff, volunteers, and third-party contractors must only use the information they have been authorised to use, and for purposes that has been authorised.

It must be assumed that information is confidential unless it is known otherwise.

Passing information between Ponthafren offices/departments does not count as making it public, but passing information to another organisation/individual does.

Confidentiality obligations continue to apply to staff, volunteers, and third-party contractors indefinitely after they have stopped working for Ponthafren.

Ponthafren Charitable Incorporated Organisation (CIO): 1187482 (England & Wales)

Registered Charity Number: 1035326 (England & Wales)

Website Hosted by Digidol.co