Privacy Policy

1. Purpose

The purpose of this policy is to ensure compliance with data protection law; protection of rights of staff (employed or self-employed), clients/participants and partners; openness about how individuals’ data is stored and processed; and protection from data protection risks such as breaches of confidentiality, failure to offer choice and reputational damage

This policy will outline:

  • What personal information is collected
  • How it is collected
  • What it is used for
  • How it is kept secure
  • Third party sharing
  • Controls users have
  • Reporting data breaches

Under Open Sky Ltd is an annual organisational member of the Information Commissioner’s Office (ICO)

Definitions:

The General Data Protection Regulation (GDPR) replaces the Data Protection Act 1998 from 25th May 2018. It applies to both data controllers and data processors, which have day-to-day responsibility for data protection. 

A controller is the natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data. 

A processor is a natural or legal person, public authority, agency or any other body that processes personal data on behalf of the controller. 

The data subject is the individual who is the subject of the relevant personal data.

The GDPR applies to personal data meaning any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier. This definition provides for a wide range of personal identifiers to constitute personal data, including name, identification number, location data or online identifier, reflecting changes in technology and the way organisations collect information about people. 

Personal data that has been pseudonymised can fall within the scope of the GDPR depending on how difficult it is to attribute the pseudonym to a particular individual. 

The GDPR applies to both automated personal data and to manual filing systems where personal data are accessible according to specific criteria. This could include chronologically ordered sets of manual records containing personal data. 

The GDPR refers to sensitive personal data as special categories of personal data. The special categories specifically include genetic data, and biometric data where processed to uniquely identify an individual. 

The GDPR does not apply to data that are rendered anonymous in such a way that individuals cannot be identified from the data.

2. Persons affected

This policy applies to:

  • Under Open Sky Ltd
  • Directors
  • Staff (employed or self-employed)
  • Clients/participants engaging in activities
  • Contractors
  • Volunteers
Data protection officerGenevieve Rudd, Founder/Director

3. Principles of GDPR

The lawful bases for processing are set out in Article 6 of the UK GDPR. At least one of these must apply when processing personal data:

(a) Consent: the individual has given clear consent for Under Open Sky Ltd to process their personal data for a specific purpose.

(b) Contract: the processing is necessary for a contract Under Open Sky Ltd have with the individual, or because they have asked Under Open Sky Ltd to take specific steps before entering into a contract.

(c) Legal obligation: the processing is necessary for Under Open Sky Ltd to comply with the law (not including contractual obligations).

(d) Vital interests: the processing is necessary to protect someone’s life.

(e) Public task: the processing is necessary for Under Open Sky Ltd to perform a task in the public interest or for Under Open Sky Ltd’s official functions, and the task or function has a clear basis in law.

(f) Legitimate interests: the processing is necessary for Under Open Sky Ltd’s legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.

4. What personal information is collected

Personal data collected includes:

  • Name
  • Address
  • Email address
  • Phone number
  • Payment details, e.g. debit/credit card

Special category personal data collected includes:

  • Ethnicity
  • Health/disability status
  • Gender status
  • Benefits/income status
  • History of criminal conviction
  • Other similar information

5. How it is collected

Data will be collected using the following methods:

  • Online systems, e.g. Google Forms, Mailchimp, social media
  • Paper forms

6. What it is used for

Personal data will be used for:

  • Contacting clients/participants, staff or partners to confirm details of events, activities or information they have signed-up to receive
  • Sending marketing materials, such as email newsletters 

Special category personal data will be used for:

  • At the specific request of external funders, for which the events or activities are targeted at a protected characteristic as part of the terms of the funding
  • History of criminal conviction data may be used to assess safety to work/volunteer for Under Open Sky Ltd, in line with Safeguarding Policy/Procedure

7. How it is kept secure

Data will be stored on the following ways:

  • Online/electronic data:
    • Password protected devices and online accounts
    • Secure encrypted online systems
    • Passwords and login information will only be accessible by specific Directors/staff to perform a specific job (e.g. send email newsletter)
  • Paper data:
    • Locked cabinets/cases

8. Third party sharing

Data collected by Under Open Sky Ltd will never knowingly be shared with third parties and diligence will be applied to protect information from reaching these sources

9. Controls users have

Under Open Sky Ltd has processes in place to ensure that it can facilitate any request made by an individual to exercise their rights under data protection law. All staff are aware of the rights of data subjects. Staff can identify such a request and know who to send it to

All requests will be considered without undue delay and within one month of receipt, as far as possible

9.1 Subject access:
The right to request information about how personal data is being processed, including whether personal data is being processed and the right to be allowed access to that data and to be provided with a copy of that data along with the right to obtain the following information:

  • Purpose of the processing
  • Categories of personal data
  • Recipients to whom data has been disclosed or which will be disclosed
  • Retention period
  • Right to lodge a complaint with the Information Commissioner’s Office
  • Source of the information if not collected direct from the subject, and
  • Existence of any automated decision making

9.2. Rectification:
The right to allow a data subject to rectify inaccurate personal data concerning them.

9.3. Erasure:
The right to have data erased and to have confirmation of erasure, but only where:

  • Data is no longer necessary in relation to the purpose for which it was collected, or
  • Where consent is withdrawn, or
  • Where there is no legal basis for the processing, or
  • There is a legal obligation to delete data

9.4. Restriction of processing:
The right to ask for certain processing to be restricted in the following circumstances:

  • If the accuracy of the personal data is being contested, or
  • If our processing is unlawful but the data subject does not want it erased, or
  • If the data is no longer needed for the purpose of the processing but it is required by the data subject for the establishment, exercise or defence of legal claims, or
  • If the data subject has objected to the processing, pending verification of that objection

9.5 Data portability:
The right to receive a copy of personal data which has been provided by the data subject and which is processed by automated means in a format which will allow the individual to transfer the data to another data controller. This would only apply if Under Open Sky Ltd was processing the data using consent or on the basis of a contract.

9.6 Object to processing:
The right to object to the processing of personal data relying on the legitimate interests processing condition unless Under Open Sky Ltd can demonstrate compelling legitimate grounds for the processing which override the interests of the data subject or for the establishment, exercise or defence of legal claims.

10. Reporting data breaches

All Under Open Sky Ltd staff and volunteers have an obligation to report actual or potential data protection compliance failures. This allows us to: 

  • Investigate the failure and take remedial steps if necessary
  • Maintain a register of compliance failures
  • Notify the ICO (Information Commissioner’s Office) of any compliance failures that are material either in their own right or as part of a pattern of failures 

Breaches of this Policy may result in disciplinary action, up to and including dismissal

Section 170 (1) of the Data Protection Act 2018: Unlawful obtaining etc of personal data, states it is an offence for a person knowingly or recklessly: 

(a) to obtain or disclose personal data without the consent of the controller 

(b) to procure the disclosure of personal data to another person without the consent of the controller, or 

(c) after obtaining personal data, to retain it without the consent of the person who was the controller in relation to the personal data when it was obtained

Want to keep up to date?

Please use the form here to join our newsletter, which will keep you up to date with all our latest news and activities. We promise we won't spam you!
* indicates required