Privacy Policy.

GENERAL PRINCIPLES.

All information relating to our staff, client group and our organisational operations is confidential.

Staff and contractors are expected to treat NRH paper-based and electronic information with utmost care and as confidential unless told otherwise by your line manager.

As an employee, intern, volunteer, or contractor (who is handling NRH data), you should exercise due care when collecting, processing or disclosing any personal data and only process personal data on behalf of the NRH where it is necessary for your duties.

Any member of staff, intern or volunteer who takes a computer offsite, must undertake a duty of care with that equipment and exercise the same care of the data it contains as if it were in the office. No equipment must be left at risk. Any such risk must be reported immediately to the Co-Directors.

It is the responsibility of the user to ensure that his/her computer is appropriately protected and up to date, with appropriate anti-virus installed. If in doubt, the issue should be raised with the Co-Directors.

Care must also be taken when using e-mail or social media as a means of communication as all expressions of fact, intention and opinion via these activities may bind you and/or the NRH and can be produced in court in the same way as oral or written statements.

NRH is exempt from registration with the Information Commissioner.

Staff records will be kept electronically under password protection. Staff may see their own records by requesting that, to the NRH Co-Directors.

Privacy Policy.

WHO WE ARE.

The National Retrofit Hub is a Community Interest Company (CIC) limited by guarantee without share capital, registered in England (Company No. 16834381). Registered address: Lelliott & Co Limited, Heath Place, Ash Grove, Bognor Regis, West Sussex, PO22 9SL.

For the purposes of UK data protection law, the National Retrofit Hub is the Data Controller of your personal data. 

We have assessed that we are not required to appoint a Data Protection Officer (DPO) under UK GDPR, as we are not a public authority and our core activities do not involve large-scale systematic monitoring of individuals or large-scale processing of special category data. Responsibility for data protection compliance sits jointly with the NRH Co-Directors. 

HOW WE USE Data.

This section of the policy explains when and why we collect personal information, how we use it, the conditions under which we may disclose it to others and how we keep it secure.

All data is managed by the NRH in a manner that is compliant with the GDPR requirements. 

HOW DO WE COLLECT INFORMATION AND FROM WHO.

We may collect information from people when that are attending one of our events (when registering via email or booking online); apply to become a Partner or Sponsor; submit an enquiry via the ‘contact us’ form on our website; or express an interest in our activities at a conference or trade show or directly with any member of the NRH Board or NRH team. We also collect information when people sign-up to our mailing list on our website. 

To stay up-to-date on NRH activities, people must provide explicit consent by ticking the relevant tick-box when signing-up to our mailing list on our website, when completing the contact us form on our website or when registering for an event.

WHAT TYPE OF INFORMATION IS COLLECTED.

The personal information we collect might include names, company role, company type, company name, address, email address and telephone number. 

If people pay for an activity via BACS or cheque, we will also collect their payment information. If organisations charge us for a product or service, we will collect details of how they receive payment. See below for details of how we collect and store financial information.

Legal Basis for Processing.

We process personal data on the following legal bases under UK GDPR: 

  • Consent — where individuals have explicitly opted in to receive communications, for example by ticking the relevant box when signing up to the mailing list or completing the contact form. 
  • Legitimate Interests — where it is necessary for the purposes of managing our organisation and activities, such as administering Partner or Sponsor applications, running events, or keeping records. 
  • Legal Obligation — where we are required to retain information by law, such as financial records. 

HOW IS THIS INFORMATION USED?

We may use the information sent to send out communications about our latest news, events, research and campaign updates.

We may email Partners/Sponsors/Supporters to process applications. By becoming a Partner/Sponsor/Supporter, they agree to receive non-marketing emails from us in order to manage their application.

WHO HAS ACCESS TO YOUR INFORMATION?

Information is stored on a secure database managed by the National Retrofit Hub.  Your information is visible to the NRH team and Board and will only be used for the purposed of the Hub.  

We use the following third-party data processors who may have access to your personal data as part of the services they provide to us: 

  • Eventbrite — event registration and payment processing 
  • NatWest — banking services 
  • QuickBooks — accounting and financial records 
  • Eco Accounts — bookkeeping services 
  • KKP Accountants — external accountancy services 
  • ActiveCampaign — CRM and mailing list management 

We will not sell or rent your information to third parties. We will not share your information with third parties for marketing purposes. We may send you information about activities by third parties where we deem this to be of specific interest. 

How Long We Keep Your Data.

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Our retention periods are as follows: 

  • Financial records — minimum six years, as required by current legislation. 
  • Mailing list and contact records — for as long as you remain an active contact. If we have had no meaningful contact for two years or more, we will delete or anonymise your data unless required by law to retain it.  
  • Event attendee records — two years following the event. 
  • Enquiries submitted via our website — two years from the date of the enquiry. 

After the relevant retention period, your data will be securely deleted or anonymised. 

Your Rights.

Under UK data protection law, you have the following rights: 

  • Right of access — you can request a copy of the personal data we hold about you. 
  • Right to rectification — you can ask us to correct inaccurate or incomplete data. 
  • Right to erasure — in certain circumstances, you can ask us to delete your personal data. 
  • Right to restriction — you can ask us to limit how we use your data in certain circumstances. 
  • Right to data portability — where processing is based on consent or contract, you can request your data in a portable format. 
  • Right to object — you have the right to object to processing based on legitimate interests. 
  • Right to withdraw consent — where we rely on your consent, you can withdraw it at any time, without affecting the lawfulness of earlier processing. 

To exercise any of these rights, please contact us at info@nationalretrofithub.org.uk.

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO): www.ico.org.uk or 0303 123 1113. 

HOW DO WE MANAGE FINANCIAL INFORMATION?

Payments to us 

If a person registers for one of our events online, their payment information is not held by us, it is collected and processed by the online event booking company Eventbrite, who have secure and encrypted processing methods for credit/debit card transactions. See Eventbrite’s privacy policy here and security guide here

If a person pays us directly, then their bank account details (account name, sort code and account number) will be stored by our bank, currently NatWest, who have secure and encrypted processing methods.

Payments by us 

If an organisation invoices us directly, then their bank account details (account name, sort code and account number) will be stored on our accounts system, currently Quickbooks, which is accessible by the NRH’s bookkeeper (Eco Accounts)and external accountant (currently KKP Accountants). This information is stored on a secure cloud-based server. We will store this information for at least six years, as required by current legislation. 

Links to Other Websites.

Our website may contain links to websites operated by our Partners, Sponsors, and other organisations. This Policy applies only to the National Retrofit Hub website. We are not responsible for the privacy practices of other websites and encourage you to read their privacy policies. 

Cookies.

Our website uses cookies to help it function and to understand how visitors use it. For full details please see our Cookie Policy [link]. 

Children’s Privacy.

Our services are not directed at children. If you are under 16, please obtain your parent or guardian’s permission before providing us with any personal information. 

Co-working and shared workspaces.

When working from a coworking or other shared workspace, employees must comply with the following additional controls:

  • Devices must be locked whenever left unattended, even briefly. 
  • Screens must be positioned so that they cannot be overlooked; printed material containing personal/business data must not be left on desks or in shared printers. 
  • Phone or video calls involving personal information must take place in a private room, not in open coworking areas. A headset must be used for all calls to minimise the risk of overheard conversations. 
  • Employees must carry out secure disposal (e.g., shredding) of any handwritten notes containing personal data. If shredding facilities are not available at the coworking space, notes must be brought back securely to an approved office location for disposal.
  • Employees must immediately report any loss, theft or suspected compromise of devices, papers or credentials used in a coworking space through the company’s data breach / incident reporting procedure.

Appendix.

Staff UK GDPR 7 Key Principles.

Article 5 of the UK GDPR sets out seven key principles. These principles lie at the heart of the general data protection regime. 

Article 5(1) requires that personal data shall be: 

  1. “(a) processed lawfully, fairly and in a transparent manner in relation to individuals (‘lawfulness, fairness and transparency’); 
  1. (b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes (‘purpose limitation’); 
  1. (c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’); 
  1. (d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’); 
  1. (e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of individuals (‘storage limitation’); 
  1. (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).” 
  1. “The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).” 

Sign up to our newsletter.

FOR UPDATES ON NRH PROJECTS, NEW RESOURCES, EVENTS, AND MORE!

SUBSCRIBE TO RECEIVE EMAIL NEWS AND UPDATES FROM THE NRH.