Introduction
The Susan Vickers Foundation is committed to protecting your privacy and processing your personal data in accordance with the UK Data Protection Act 2018 and UK General Data Protection Regulation (UK GDPR). This policy explains how we collect, use, and safeguard your personal information.
Data Controller
The Susan Vickers Foundation is the data controller for the personal information we process. We are registered with the Information Commissioner's Office (ICO).
Information We Collect
We collect and process these categories of personal data:
- Personal identifiers (name, contact details, date of birth)
- Care experience information (where voluntarily provided)
- Financial information for donors and grant recipients
- Special category data (only where relevant to our support services and with explicit consent)
- Website usage data through cookies and similar technologies
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Consent: For marketing communications and processing special category data
- Contract: For processing grant applications and donations
- Legal obligation: For compliance with charity and tax laws
- Legitimate interests: For improving our services and communicating with stakeholders
How We Use Your Information
Your information helps us:
- Process and manage grant applications
- Deliver support services to care experienced individuals
- Maintain donor records and process donations
- Communicate about our services and support
- Meet our legal obligations as a UK registered charity
Data Protection
We implement appropriate technical and organisational measures to protect personal data, as required by UK GDPR. This includes:
- Regular staff training on data protection
- Secure data storage systems
- Access controls and encryption where appropriate
- Regular security assessments
Information Sharing
We share data only:
- With your explicit consent
- To fulfil our charitable purposes
- With trusted UK-based service providers
- When required by UK law or regulators
International Transfers
If we transfer personal data outside the UK, we ensure appropriate safeguards are in place in accordance with UK data protection laws.
Your Rights Under UK Law
You have the right to:
- Access your personal information
- Rectify inaccurate data
- Erase your data (where legally permissible)
- Restrict or object to processing
- Data portability
- Withdraw consent
- Lodge a complaint with the ICO
Children's Privacy
We process children's personal data only with parental/guardian consent and in compliance with UK safeguarding requirements and data protection laws.
Data Retention
We retain personal information in line with our retention schedule and UK legal requirements. Different retention periods apply to different types of data.
Cookies
Our website uses cookies. You can manage your cookie preferences through your browser settings. For more information, please see our separate Cookie Policy.
Changes to This Policy
We review this policy regularly and will place any updates on this webpage. Material changes will be notified to you directly where required.
Contact Us
For privacy-related queries or to exercise your rights:
- Data Protection Officer
- Email: julia@susanvickersfoundation
Last Updated: February 2025