Privacy Policy

Introduction

The Susan Vickers Foundation is committed to protecting your privacy and processing your personal data in accordance with the UK Data Protection Act 2018 and UK General Data Protection Regulation (UK GDPR). This policy explains how we collect, use, and safeguard your personal information.

Data Controller

The Susan Vickers Foundation is the data controller for the personal information we process. We are registered with the Information Commissioner's Office (ICO).

Information We Collect

We collect and process these categories of personal data:

- Personal identifiers (name, contact details, date of birth)

- Care experience information (where voluntarily provided)

- Financial information for donors and grant recipients

- Special category data (only where relevant to our support services and with explicit consent)

- Website usage data through cookies and similar technologies

Lawful Basis for Processing

We process personal data under the following lawful bases:

- Consent: For marketing communications and processing special category data

- Contract: For processing grant applications and donations

- Legal obligation: For compliance with charity and tax laws

- Legitimate interests: For improving our services and communicating with stakeholders

How We Use Your Information

Your information helps us:

- Process and manage grant applications

- Deliver support services to care experienced individuals

- Maintain donor records and process donations

- Communicate about our services and support

- Meet our legal obligations as a UK registered charity

Data Protection

We implement appropriate technical and organisational measures to protect personal data, as required by UK GDPR. This includes:

- Regular staff training on data protection

- Secure data storage systems

- Access controls and encryption where appropriate

- Regular security assessments

Information Sharing

We share data only:

- With your explicit consent

- To fulfil our charitable purposes

- With trusted UK-based service providers

- When required by UK law or regulators

International Transfers

If we transfer personal data outside the UK, we ensure appropriate safeguards are in place in accordance with UK data protection laws.

Your Rights Under UK Law

You have the right to:

- Access your personal information

- Rectify inaccurate data

- Erase your data (where legally permissible)

- Restrict or object to processing

- Data portability

- Withdraw consent

- Lodge a complaint with the ICO

Children's Privacy

We process children's personal data only with parental/guardian consent and in compliance with UK safeguarding requirements and data protection laws.

Data Retention

We retain personal information in line with our retention schedule and UK legal requirements. Different retention periods apply to different types of data.

Cookies

Our website uses cookies. You can manage your cookie preferences through your browser settings. For more information, please see our separate Cookie Policy.

Changes to This Policy

We review this policy regularly and will place any updates on this webpage. Material changes will be notified to you directly where required.

Contact Us

For privacy-related queries or to exercise your rights:

- Data Protection Officer

- Email: julia@susanvickersfoundation

Last Updated: February 2025