PRSC is committed to protecting your privacy. This policy will inform you of the following:
- Who we are
- What information we will collect
- When we will require personal information from you
- Where your information is stored
- How we use your information
- How we protect your information
- Sharing your information
- Legal basis for using your information
- PRSC’s website “Cookie” use
- Links to other websites
- How you can access information PRSC keeps about you
- How long your information will be kept
- Your rights
1. Who we are
PRSC is a “data controller” for the purposes of the Data Protection Act 1998 and (from 25 May 2018) the EU General Data Protection Regulation. This means that we are responsible for, and control the processing of, your personal information.
2. What information do we collect from you?
Mailing list and website
If you register for the PRSC newsletter, events and activities, and Stokes Croft China, we ask you for your name and email address.
If you register to comment on our blog posts, you may provide us with your email address and IP address.
When you visit our website, we may collect information about your online browsing behavior and any devices you have used to access our website (including your IP address, browser type and mobile device identifiers).
As a customer for a service
If you purchase products directly from PRSC, your contact information and a transaction history will be kept. We may use the contact information to inform you about the status of your order, as well as to let you know about upcoming products or services.
When requiring a service that we offer (including fulfilling an order from our shop or web shop, hiring our event space), we will ask you for necessary info such as your name, address and billing information to ensure successful delivery of that service.
Making a donation
If you are making a donation we will ask you for your full name and email address. Donation methods currently offered by PRSC are cash, BACS, or online via PayPal. Only necessary billing information will be collected by PRSC. Emails are securely stored and are never divulged to third parties.
We do not knowingly collect or store any personal information about children under the age of 16. If you are aged under 16 please get your parent or guardian’s permission before you provide any personal information to us.
3. When will we collect personal information from you?
When you register for our mailing list, information is processed from you to send you emails. This usually infrequent, but on occasion we may send a special edition when we have something really important to share with you. The information processed may include name, telephone number and email address. Your information is contained with a third-party partner (Mailchimp) to deliver specialized services.
When we receive your custom and during the course of service delivery, information (whether collected over the phone, in person or writing) is processed from you for service delivery purposes. For this reason, the information processed may include name, personal and contact details, and billing information. Your information is contained with a third-party partner (Shopify, Quickbooks), or documents PRSC uses to deliver its service i.e. project briefs, quotes, notice of events and other safety documents, and may be shared with our partners to deliver specialized services. For any personal information you would like published (i.e. event information for publicizing) you’ll need to give us explicit permission to publish this on our website and social media.
When you browse the PRSC website and have not registered for any of our online services, you browse anonymously and no personal information is collected from you. We will only collect personal information from you in the event that you use our online services, such as completing an online form to PRSC, publicly commenting on a blog post, or when making a donation to the organisation.
4. Where your information is stored
Storage of physical records (i.e. non-electronic records) are stored in such a way that they are both sufficiently accessible and safeguarded against environmental damage and unauthorized access in PRSC’s premises.
Management of electronic (i.e. digital) records requires a computer, server, or other digital storage equipment. With electronic records:
- All sensitive data is encrypted;
- Data is accessed by those on a strict need to know basis;
- Strong passwords are used to protect sensitive data;
Unauthorised access to information about individuals will be prevented by the protection and encryption of computerised data and the secure storage of paper records. These are dealt with under specific policies and procedures which are reviewed periodically to ensure continued effectiveness.
5. How we use this information?
PRSC will only use the personal information collected in support of the services you have requested.
6. How do we protect personal information?
PRSC takes the protection of personal information very seriously. When you provide your personal information through our website, this will be via a non-secure internet connection which is the responsibility of the Internet browser you use. Unfortunately, the transmission of information using the internet is not completely secure. Although we do our best to protect your personal information sent to us this way, we cannot guarantee the security of data transmitted to our site and this will be provided at your own risk. Once, however, the information has been received by PRSC it will be filed and stored securely by us in accordance with the Data Protection Act 1998 and GDPR.
7. Will we share the information we collect with other parties?
PRSC will not share any personal information with third parties, except where other third-party agencies are believed to be of assistance in delivering the requested service (i.e. informing the police of a licensed event). Just like with other third parties we work with, these third-party service providers enter into a contract that requires them to use your personal information only for providing services to us in a manner consistent with this policy.
PRSC complies with all law enforcement agency requests for information.
The personal information we collect about you will mainly be used by our staff (and volunteers) at PRSC so that they can deliver the requested service.
We will never sell or share your personal information with organisations so that they can contact you for any marketing activities. Nor do we sell any information about your web browsing activity.
8. Legal basis for using your information
We will only collect and use your personal information in accordance with date protection laws.
In some cases, we will only use your personal information where we have your consent or because we need to use it in order to fulfil a service with you.
However, there are other lawful reasons that allow us to process your personal information and one of those is called ‘legitimate interests’. This means that the reason that we are processing information is because there is a legitimate interest for PRSC to process your information.
The use of ‘cookies’ does not give PRSC access to your computer or the information that may be stored on it. If you want to prevent our cookies being stored on your computer in the future, you may do so by referring to your internet browser instructions. We suggest consulting the Help section of your browser or taking a look at the About Cookies website which offers guidance for all modern browsers.
Whenever you request a page through your browser, navigation and clickstream data such as:
- your IP address
- browser and version
- operating system
- date and time
- the site from which you came
- the search term you entered
are stored in a log file and/or database via Google Analytics. Any search terms that you enter into any site search are also logged. This information cannot be used to identify specific individuals, and is only used for:
- website and system administration
- research and development
This information is kept on a secure server hosted by our third party hosts as well as servers within Google, and on occasion locally.
10. Links to other websites
The PRSC website includes links to other websites, not owned or managed by PRSC. PRSC shall not be held responsible for the privacy of data collected by websites not owned or managed by PRSC.
11. Can I access the information you collect from me?
12. How long your information is kept
Up to 5 years after a contact has unsubscribed from our mailing list, a customer has had a service delivered, a donation has been received, a staff member or volunteer has left the organization, as per PRSC’s document management and retention policy.
Even if we delete your personal information it may persist on back-up or archival media for legal, tax or regulatory purposes.
Your Rights and How You can Use Them (regarding your personal information)
Right to Be Informed: We must provide you with a privacy notice to tell you how we are using your personal data, why we are using it and how long we are likely to use it for.
Right to rectification: You can change your personal data if it is inaccurate or incomplete. Please contact us if any of your personal information changes.
Right to restrict data processing: Under certain circumstances, you can ‘block’ us from using your personal data. We are then allowed to store your personal data, but nothing more.
Right to Complain: You have the right to complain to a supervisory body (ICO) if you feel we have failed to meet our duties to you in any way in relation to your personal data.
The information you have provided will be kept in accordance with our Confidentiality and Data Protection Policy and will be used by PRSC to provide you with the service you have requested.
No automated-decision making: Automated decision-making takes place when an electronic system uses personal information to make a decision without human intervention. You have the right not to be subject to automated decisions that will create legal effects or have a similar significant impact on you, unless you have given us your consent, it is necessary for a contract between you and us or is otherwise permitted by law. You also have certain rights to challenge decisions made about you. PRSC does not currently carry out any automated decision-making.
Contacting Us: Please contact us to make any requests in relation to your rights, or if you have any other queries about the Data Protection Act, GDPR or PRSC’s Data Protection Policy please contact our data protection officer using the following details: