DATA PROTECTION AND PRIVACY POLICY (UK GDPR)
1. PURPOSE OF THIS POLICY
Our charity collects and uses certain personal information about our volunteers and attendees to coordinate book distributions, manage hall bookings, and ensure fire safety during gatherings.
This policy ensures that our charity complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We commit to protecting the privacy of everyone whose data we hold.
2. WHAT DATA WE COLLECT AND WHY
We only collect the minimum amount of personal information necessary to run our spiritual activities safely. This typically includes:
- For Volunteers (approx. 50 people): Names, phone numbers, and email addresses so we can organise free-will book distribution rotas and send event updates.
- For Hall Gathering Attendees: Emergency contact numbers or names on a voluntary attendance/fire safety sign-in sheet.
- For Spiritual Enquiries: Contact details of individuals who actively request that we mail or deliver books and spiritual materials to them.
- For Book Mailing Requests (Website & Street Outreach): We collect names, mobile phone numbers, and physical home addresses from individuals who explicitly request a free book via our website text service or during street outreach (e.g., when a book is requested in a specific language that is not currently in stock). This data is processed strictly under the lawful basis of Consent and Contract/Performance of a Service to fulfil their request and post the book.
We do not collect sensitive financial data (like credit cards) or formal background data.
3. THE 6 DATA PROTECTION PRINCIPLES
The trustees ensure that all personal data is handled according to the core principles of UK GDPR:
- Lawfulness & Transparency: We are open about why we need data. We only collect data with an individual’s clear consent or for legitimate charity operations (e.g., event safety).
- Purpose Limitation: We only use personal details for our charity's spiritual activities. We will never sell, rent, or share data with external third parties or commercial businesses.
- Data Minimisation: We do not collect unnecessary information. If we only need a phone number, we do not ask for a home address.
- Accuracy: We keep contact lists updated and delete outdated phone numbers or email addresses when a volunteer steps down.
- Storage Limitation: We do not keep personal data forever. Sign-in sheets for hall gatherings are destroyed after 6 months. Volunteer contact sheets are deleted if they leave the group.
- Integrity & Confidentiality (Security): We keep data secure against loss or unauthorized access.
4. HOW WE STORE AND SECURE DATA
Because we do not have a physical office building, our data is stored digitally. We protect this data using the following security steps:
- Password Protection: Any digital lists containing volunteer phone numbers or emails must be saved on password-protected computers or pin-locked smartphones held by the 3 trustees.
- No Public Sharing: Volunteer contact lists must never be posted publicly online or shared in open, unmoderated group chats where non-members can see them.
- Paper Shredding: Any temporary paper sign-in sheets used at our Uxbridge gatherings must be kept in a secure folder by a trustee and cross-shredded when no longer needed.
- Digital Text Requests: Any text messages received via the charity’s website mobile number containing names and addresses must be transferred to a secure, password-protected master spreadsheet. The original text messages must be deleted once recorded.
- Street Paper Records: If a volunteer writes down an individual's address on a notepad during street book distribution, that paper must be handed directly to a trustee at the end of the day. The information must be digitized securely, and the paper slip must be cross-shredded immediately.
- Strict Deletion Rule (Data Minimisation): Once a book has been safely posted to the individual, their home address and phone number must be permanently deleted from our digital tracking spreadsheets within 30 days of delivery. We do not keep a permanent database of public home addresses for marketing or future contact.
5. INDIVIDUAL RIGHTS
Under UK GDPR, our volunteers and attendees have the right to:
- Ask to see exactly what personal information we hold about them.
- Ask us to correct any incorrect contact details.
- Request that we completely delete their information from our volunteer systems at any time.
Any such requests will be handled by the trustees free of charge within 30 days.