Rotary Club of Chipping Sodbury Privacy Notice

GDPR and Personal Privacy

 

Rotary International in Great Britain and Ireland

Rotary Club of Chipping Sodbury

Privacy Notice

 

Rotary International in Great Britain and Ireland and the Rotary Club of Chipping Sodbury (“Club”/“we”) promise to respect the confidentiality of any personal data you share with us, or that we have access to through Rotary International.  We will keep it safe, and we will always take every effort to protect your privacy. 

[For the purpose of this privacy notice, Rotary International in Great Britain & Ireland (RIBI) also includes Rotary Foundation United Kingdom (RFUK) and the RIBI Donations Trust].

We pride ourselves on our honesty and openness and will always be clear how, when and why we collect and process your information; we promise we will never do anything with your details that you wouldn’t reasonably expect.

It is expected that the club may also process member personal data on behalf of Rotary International in Great Britain and Ireland and the Rotary organisation and it too will also be bound by this privacy notice.

The notice encompasses data handling for members of the Rotary Club, those who participate in our events and activities, those who volunteer to help us and those who make application to us for grants and support.  It also includes data held about third parties.  The legal basis of holding this data differs for the different groups and can overlap.  This is explained more fully below.

We collect information in the following ways:

When you give it to us DIRECTLY

There are many ways you may give us your information. For example, when you join as a member, begin volunteering, make a donation, apply of a grant, communicate with us either by phone, in writing, including email or in person. We are responsible for your data at all times.

 

When you give it to us INDIRECTLY

Your information may be shared with us by independent organisations. These independent third parties will only share your information when you have consented. You should check their Privacy Notice when you provide your information to understand fully how they will process your data.

 

Via Social Media

Depending on your settings or the privacy notices for social media and messaging services like Facebook, WhatsApp, LinkedIn or Twitter, you might give us permission to access information from those accounts or services.

 

Via information available publicly

This may include information found in places such websites (club, district, action groups etc), Companies House and information that has been published in articles/newspapers.

 

Cookies

Like most websites, we use “cookies” to help us make our site, and the way you use it, better. We do not store any personal data in the cookies that we use.

Cookies mean that a website will remember you. They’re small text files that sites transfer to your computer (or phone or tablet). They make interacting with a website faster and easier – for example by automatically filling your name and address in text fields.

In addition, the type of device you’re using to access our website or apps and the settings on that device may provide us with information about your device, including what type of device it is, what specific device you have, what operating system you’re using, what your device settings are. Your device manufacturer or operating system provider will have more details about what information your device makes available to us.

The type and quantity of information we collect and how we use it depends on why you are providing it. You should be able to control what cookies are placed on your device through your browser settings. Go to https://www.aboutcookies.org/to find out more about cookies, including how to see what cookies have been set and how to manage and delete them.

To opt out of being tracked by Google Analytics across all websites visit https://tools.google.com/dlpage/gaoptout.

The legal basis for holding your data

Rotarians have a contractual relationship with Rotary and the Club.  To protect us and our charitable status data concerning your membership must be retained and processed for the duration of your membership or longer if a legal or statutory obligation exists.  You have the right to ask us to delete your data from our records, by doing so we will not be able to extend your membership and your membership will be deemed lapsed with settlement of any debts required. 

We have a legitimate interest in holding data from those who volunteer to support the Club, enter Club events or seek to participate in Club activities or seek grants or other financial support from the Club.  You have the right to ask for your data to be erased and our retention policy set out below applies. 

If we hold your data or we seek your data as a third party for the Club’s purposes then we will renew your active consent at regular periods, usually annually, and erase your data at your request at any time, subject to any legal or statutory duty that prevents us from doing so.

 

What personal information we collect and how we use it

We will only ever capture the minimum amount of information that we need to in relation to your dealings with us and we promise to keep your information secure. The personal data we will usually collect for membership is:

  • Your name

  • Your contact details
  • Your date of birth
  • The name of your Spouse/Partner
  • Your previous service within Rotary, if applicable
  • Where appropriate, your UK tax status in relation to Gift Aid

We may also ask for additional information, for example but not exclusively, to assist The Treasurer, to process and manage your entry into any Club event or activity or to be able to assess properly any application for a grant or support that you might make to us.

For those who volunteer their help, participate in our events and activities, or seek grants or support from us, we will collect from you only data relevant to those activities.   The scope and nature of the data requirements will be specific to the particular need and will be made clear from the forms or information request sheets we send you.

 

How we will use your data

We will use your personal data for the legitimate interest of conducting core business activities, these will include:

  • Administering your membership (Rotarians only)

  • Communicating organisational messages and information to members, district and club officers  
  • To present our website and its contents to you and to allow you to participate in interactive features on our website
  • Managing, administering and publicising Club events and activities, including details of entrants
  • In any other way we may describe when you provide the information   
  • For any other purposes with your consent

Sensitive information

We do not collect any personal information on members classified as ‘sensitive’ under GDPR.  If you provide us with sensitive information in relation to a grant application or for any other purpose we will keep this secure and confidential and delate the information in keeping with our data retention policy set out below.

 

Data Sharing

1)Our service/host providers

In the course of our legitimate business activities, there may be a need for us to share, or give access to, your personal data to third parties that provide us with services or host our applications/software that you may access. We will ensure that data processing agreements, compliant to GDPR, are in place before sharing with, or giving access to, your data with any of our service/host providers.

 

2)Sharing within the Rotary organisation

The Rotary organisation is made up of Rotary International, The Rotary Foundation (TRF), Rotary International in Great Britain and Ireland, the Rotary Foundation United Kingdom (RFUK) and the RIBI Donations Trust.

When you give information to us as a member of Rotary it will be shared within the wider organisation to facilitate your membership or donations and to provide the service afforded to you as part of that membership/donation. We will ensure that data processing agreements, compliant to GDPR, are in place before sharing your data within the wider organisation.

The Rotary Club of Chipping Sodbury and districts within Rotary International in Great Britain and Ireland are data processors for some of your personal information associated with your membership and will process your data in accordance with the RIBI privacy notice. We also collect personal data for our individual club and district activities and are therefore also independent data controllers. This means we are also legally responsible for protecting your data under GDPR legislation whilst in our safekeeping.

If you have made a grant application or request for support from us we may need to share your data within the Rotary organisation to assist in acquiring additional or matching funding.  We will only ever do this if we have your explicit and informed consent at the time of collection or before any sharing takes place.

 

3)Sharing with third parties

We will never commercially sell your personal data to anyone else.

We will only ever share your personal data in other circumstances, not listed above, if we have your explicit and informed consent at the time of collection or before any sharing takes place if that becomes necessary.  However, we may need to disclose your details if required to the police, other agencies, for example HMRC, regulatory bodies or our legal advisors.

 

How we keep your information safe and who has access to it

We ensure that there are appropriate physical and technical controls in place to protect your personal details. We undertake regular reviews of who has access to information that we hold to ensure that your personal information is only accessible by appropriate staff, Rotary members and our service/host providers. We have a duty to report certain types of personal data breaches to the relevant supervisory authority, and where feasible, we will do this within 72 hours of becoming aware of the breach. If a breach is detected and likely to result in a high risk of adversely affecting you, we will inform you without undue delay.

 

Where we store your information

For Rotarians, your personal information will be hosted securely within the UK or the EU by Rotary International in Great Britain & Ireland.

At Club level, your personal membership information is held securely on password protected systems.

However, Rotary International run its operations outside the European Economic Area (EEA). Although they may not be subject to the same data protection laws as organisations based in the UK, we will take steps to make sure they provide an adequate level of protection in accordance with UK data protection law. By submitting your personal membership information to us you understand your personal data will be transferred, stored and processed at a location outside the EEA. You can view Rotary International’s privacy notice by visiting their website:

https://my.rotary.org/en/privacy-policy

For all our dealings with non-members, we promise to hold your data securely and with appropriate controls over access.  This will case specific, for example different groups of Rotarians may consider differing grant applications, but data protection processes will apply in all circumstances. 

 

How long we retain your information and how we keep it up to date

We will only keep your information for as long as we need it to assist you with your enquiry, process your membership, donation, event registration or other services associated to your Rotary membership. There are statutory timescales on how long we should keep your information.  We shall delete your information according to these statutory limits, or according to guidance issued by the Information Commissioner.

Individual members are responsible for keeping their own personal data up to date and have access to the RIBI Data Management System (DMS) or My Rotary on the RIBI website for this purpose. In addition, where necessary, we will keep your information accurate and up-to-date.

 

Your rights

The General Data Protection Regulations gives you certain rights and these are listed below for your convenience, further clarification of your rights is available on the Information Commissioners website https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/

  • You have a right to be informed when your personal data is being collected, what is collected and how it will be used or shared.

  • You have a right of access to your personal data: the right of access allows you to be aware of and verify the lawfulness of the processing of your personal data. Members and donors have access to their personal data via self-service systems such as the RIBI Data Management System (DMS) or My Rotary via the RI website. You can also request a copy of the information which we hold on you. This information will be provided free of charge, unless the request is found to be manifestly unfounded or excessive then a reasonable fee will be charged. The application should be made in writing, by letter or email, and addressed to the Club Secretary, enclosing two proofs of identification, unless you are already known to us.
  • You have a right in certain circumstances to have inaccurate personal data rectified, blocked (restrict processing), erased (right to be forgotten), or destroyed.
  • You have a right in certain circumstances to object to the processing of your personal data for such reasons as direct marketing, automated decision making, profiling; although we can confirm we make no decisions on you using an automated process.
  • You have a right in certain circumstances to data portability.

In certain situations, these rights may not apply, for example

  • if you are a valid member we will need to communicate with you about your membership and those services afforded to you as part of that membership; 
  • if you hold a club or district office and we need to communicate with you in relation to that office, in which case you will not be able to unsubscribe from these communications.

Finally, if you are unhappy with how we have processed your information, you have the right to lodge a complaint with the Office of the Information Commissioner, contact details below.

 

Changes to this privacy notice

We may change this privacy Notice from time to time. If we make any significant changes in the way we treat your personal information we will make this clear on our website www.rotarygbi.org or by notifying you directly.

  Complaints

If you are unhappy with how we have processed your personal information, please firstly contact the Club Secretary. If you are still unhappy you may contact the following:

Information Commissioner’s Office

Wycliffe House

Water Lane

Wilmslow

Cheshire, SK9 5AF

Helpline: 0303 123 1113 (local rate) or ++44 1625 545 745

  

This document was last reviewed and updated 30 April 2018

The document will be reviewed annually.

Cookies:

Like most websites, we use “cookies” to help us make our site, and the way you use it, better. We do not store any personal data in the cookies that we use. Cookies mean that a website will remember you. They’re small text files that sites transfer to your computer (or phone or tablet). They make interacting with a website faster and easier – for example by automatically filling your name and address in text fields.

In addition, the type of device you’re using to access our website or apps and the settings on that device may provide us with information about your device, including what type of device it is, what specific device you have, what operating system you’re using, what your device settings are. Your device manufacturer or operating system provider will have more details about what information your device makes available to us.

The type and quantity of information we collect and how we use it depends on why you are providing it. You should be able to control what cookies are placed on your device through your browser settings. Go to www.aboutcookies.org to find out more about cookies, including how to see what cookies have been set and how to manage and delete them.