Privacy statement

Amaze's privacy policy 2023 - version 2

Who are we?

Amaze is a charity (registered charity number 1078094) established in 1997, that offers a range of information, advice and support services to families of children and young people with special educational needs or disabilities, across Sussex. Amaze also manages the Compass Brighton and Hove scheme (Disability Register) which provides discounts on a wide range of leisure offers.

Amaze takes your privacy seriously and this Privacy Policy sets out how we will use and store your data, in full accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Regulators Code of Fundraising Practice (2016).  Amaze is registered with the ICO.

What information will you collect about me?

We currently collect and process the following information:

  • Personal identifiers, contacts and characteristics (for example, name and contact details)
  • Diversity information about you and any child/ren with SEND we support a parent carer with, such as gender, ethnicity, religion, disabilities, sexual orientation and age or age range
  • Details about your, or your child’s, health issues
  • Details about your, or your child’s, school and GP
  • If we are helping you or your child to apply for benefits, we may need to ask for information such as hospital number, national insurance number and bank details for you to receive payments.

Most of the personal information we process is provided to us directly by you/your parent carer in order for us to provide a service.  The lawful bases we rely on for processing this information are your consent and legitimate interests.  We will always ask for your consent to store and process your personal information and you may give this consent verbally or in writing. You are able to remove your consent at any time. You can do this by emailing us info@amazesussex.org.uk.

We may also receive personal information indirectly, from the following sources, in the following scenarios:

  • If you are a child or young person and we are working with your parent carer, we may receive this information directly from the person(s) who has Parental Responsibility for you. If you are over 16 years, we will ask your parent/carer to check with you that you consent to us processing your data.  Where a person over 16 does not have capacity to make this decision we will follow the principles set out in the Mental Capacity Act 2005 and take consent from the appropriate decision maker. For this decision, this is likely to be the primary carer.
  • From an external agency referring you to access one of our services. They must obtain consent from you first, before they pass us your data.  We will request personal contact details, and details about why the referral is being made.
  • From other agencies working with you/your child. If we are supporting you to apply for benefits or to make an appeal against a benefits decision, we may need more information.  With your consent, we may gather supporting information on your behalf such as clinic letters, assessments, reports and therapy programmes.

What are we going to do with your information?

We will use your personal information to provide services or information to you. We will also collate your personal details with that of others, to create anonymised data for general reporting about our work and the impact it has to our funders, or to identify and provide trends about the needs of families with children and young people with SEND to service providers/partners.

What will you ask me to consent to?

When you contact Amaze we will ask you for basic personal information in order to support you and to collect information that we report in an anonymised format to our funders.  If we need to share information such as with a benefits application, we will ask for this additional/explicit consent from you.

Will you be sending me emails?

Within the course of supporting your family, workers may email you but if you choose not to be contacted in this way, please let us know.

We ask for permission from you to contact you about other things, these all require your separate permission:

  • Newsletters/Updates
  • Targeted Emails: These are emails about things we think you may be interested in, such as surveys, consultations, new groups. We may use the data we store about you or your child to decide whether to contact you.  For example, when a child with Learning Disabilities reaches 14 years they are eligible to go on the Learning Disability register; we therefore email the parent carers of eligible children on the Compass register, around their 14th birthday to let them know.
  • Fundraising – see fundraising section for more details.

You can opt in or opt out of all or any of these options at any time.  You can unsubscribe from all emails by using the unsubscribe link in emails sent from Brevo (our email campaign software), or email us at info@amazesussex.org.uk to specify your choices.

Fundraising

We have a designated fundraising database called Beacon CRM.  We always ask for specific consent to communicate with you about fundraising.  We do not hold bank account or card details, we use third party software to do this.   We do keep a record of what you have donated and any direct debit reference.  The lawful bases for processing your data are ‘consent’, ‘legitimate interests’ and ‘contract’.  We will process your data on our fundraising database if:

  • You have consented to receive communications about Amaze fundraising.
  • You are fundraising for Amaze.
  • You have donated to Amaze through a third party site such as ‘Just Giving’ and agreed to share your details with us.
  • You have contacted us directly about making a donation or leaving a legacy.
  • You have taken part in the Amaze Lottery.

Lottery

The Amaze Lottery is hosted by a third party, Sterling Management Centre Ltd trading as Unity.  By signing up to the lottery you will agree to their privacy policy which can be viewed here, https://www.unitylottery.co.uk/privacy-policy/.  From their site you can choose how Amaze communicate with you about fundraising.  All personal data, except bank details, are passed securely from Unity to Amaze to be stored safely on our fundraising database.

Will we share your information with anyone else?

No. Unless we have your permission to do so, we won’t share your personal information with any organisations or individuals outside of Amaze. The only exception would be where a failure to share your personal information would lead to a risk of significant harm to you or others.

There will be some occasions we will need your consent to pass on personal information in order to submit or process applications on your behalf e.g. for DBS checks, registering trustees with Charity Commission, supporting applications for disability benefits etc. These are ‘legitimate interests’ where an individual would reasonably expect us to use their information.

We will never sell, rent, or trade your personal data.

Specific Consent

If you access our Family Support Service, NDP Family Training and Navigation Service, Face 2 Face or Amazing Futures we will ask for some additional consent.  If you consent data will be shared very securely, electronically.

NHS Mental Health Data Set

The services listed above, receive funding from the NHS.  In order that the NHS can monitor the value of the services, they ask us to share anonymised information about who is accessing our service.  Data sharing is optional and we check with every individual that they and or their young person consent to this data sharing.  For more details of what is shared, please see this page, https://amazesussex.org.uk/data-sharing-nhs/.

Where is your data stored?

All details about our clients (children and young people with special educational needs and disabilities, and their families) provided to Amaze staff or volunteers are input carefully and stored securely on a database called Charitylog.  In addition, data may be stored in Excel spreadsheets contained within the Amaze server.  Email addresses may also be stored on ‘Brevo’ which we use to send bulk email messages.

We scan and save other supporting documentation (reports, letters etc) into the secure Amaze electronic filing system. We are trying to move to a paperless office, but where hard copies are provided to us, including any personal data, these are stored in locked filing cabinets before being returned/shredded.

Sometimes you may be asked to access a third-party site for example to complete a survey, enrol on a workshop or submit a form.  Where possible we minimise the amount of personal data we ask for and we check the website’s security meets UK GDPR before asking you to use it.

How long do we hold your data for?

We follow national best practice and retention periods vary according to the nature of the record.

Casework records: Records held by Amaze about you and your related child or young person will be made inactive and anonymised by removing all personal data after 7 years of our last contact with you.  We keep records for this period to facilitate ongoing support for you or your child as they go through key developmental stages.
Non-Casework records and exceptions. For those not receiving casework support, for example, with a Compass Card.  Records will be anonymised 3 years after the Compass Card has expired or the last contact with us.

In addition, if we supported a young person (either directly or via a parent carer) who is now over 25 years with no ongoing support, their records will be anonymised after a 3-year period.

 

What are your rights about the information we hold about you?

You can ask to see the personal information that Amaze holds about you, this is called a subject access request, and you can choose to receive that personal information in paper or electronic form. You have the right to ask us to correct any inaccuracies in the personal information that we hold about you and you can also choose to reuse your personal information for your own use, e.g. give it to another organisation. You can also ask us to delete any of the data we hold about you or restrict how we use it. We follow strict GDPR guidelines and our internal policies whenever handling your data.   You also have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.

You can find more information about GDPR on this link https://ico.org.uk/your-data-matters/. You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you, contact us at info@amazesussex.org.uk.

What about our websites?

Amaze operates the following websites www.amazesussex.org.uk; www.compasscard.org.uk; www.registercompasscard.org.uk; www.paccbrighton.org.uk; www.espcf.org.uk  and at the bottom of each website there is a link to the privacy statement for that website. These will tell you what information Amaze gathers from visitors to our websites, and what we do with it.

How can you get in touch with us?

If you would like to know more how we look after your personal information, or would like to request a copy of the personal information that we hold about you, you can contact our Data Protection Officer in the following ways:

phone: 01273 772289

email: info@amazesussex.org.uk

post: Amaze, Community Base, 113 Queens Road, Brighton, BN1 3XG

How to complain

If you have any concerns about our use of your personal information, you can make a complaint to us at info@amazesussex.org.uk or using the contact details above.

You can also complain to the ICO if you are unhappy with how we have used your data.

The ICO’s address:

Information Commissioner’s Office; Wycliffe House; Water Lane; Wilmslow; Cheshire; SK9 5AF

Helpline number: 0303 123 1113

ICO website: https://www.ico.org.uk

Related

resources

Sign up to our newsletter

Translate »