Privacy policy

The Jo Cox Foundation Privacy Policy – 18th May 2018

The Jo Cox Foundation is a charity registered in England and Wales with registration number 1170836  whose registered address is at Metal Box Factory, 30 Great Guildford Street, London SE1 0HS (“JCF”)

We are committed to safeguarding your privacy. At all times we aim to respect any personal information you share with us, and keep it safe.  This Privacy Policy (“Policy”) sets out our data processing practices and your rights and options regarding the ways in which your personal information is collected and used (including through our website – www.jocoxfoundation.org).    

This Policy contains important information about your personal rights to privacy. Please read it carefully to understand how we use your personal information.

The provision of your personal information to us is voluntary. However, without providing us with your personal information, your interaction with us may be impaired.

  1. We collect personal information about you

  2. What personal information do we use?

  3. How and why will we use your personal information?

  4. Lawful bases

  5. Communications for marketing

  6. Children’s personal information

  7. How long do we keep your personal information?

  8. Will we share your personal information?

  9. Security/storage of and access to your personal information

  10. International transfers of your personal information

  11. Exercising your rights

  12. Changes to this Policy

  13. Links and third parties

  14. How to contact us

 

  1. We collect personal information about you:

    1. When you give it to us directly

For example, personal information that you submit through our website or personal information that you give to us when you communicate with us by email, phone or letter.

    1. When we obtain it indirectly

For example, your personal information may be shared with us by third parties, including sub-contractors in technical and delivery services; analytics providers and search information providers. To the extent we have not done so already, we will notify you when we receive personal information about you from them and tell you how and why we intend to use that personal information.

    1. When it is available publicly

Your personal information may be available to us from external publicly available sources. For example, depending on your privacy settings for social media services, we may access information from those accounts or services (for example when you choose to interact with us through platforms such as Facebook, Instagram or Twitter).

    1. When you visit our website

When you visit our website, we automatically collect the following types of personal information:

        1. Technical information, including the internet protocol (IP) address used to connect your device to the internet, browser type and version, time zone setting, browser plug-in types and versions and operating systems and platforms.

        2. Information about your visit to our website, including the uniform resource locator (URL) clickstream to, through and from the website (including date and time), services you viewed or searched for, page response times, download errors, length of visits to certain pages, referral sources, page interaction information (such as scrolling and clicks) and methods used to browse away from the page.

We also collect and use your personal information by using cookies on our website – please see our cookie policy.

In general, we may combine your personal information from these different sources for the purposes set out in this Policy.

 

  1. What personal information do we use?

We may collect, store and use the following kinds of personal information:

        1. your name and contact details (postal address, email address and, where applicable, social media identity);

        2. information about your computer/mobile device and your visits to and use of our website, including, for example, your IP address and geographical location;

        3. information about our services which you use/which we consider may be of interest to you;

        4. photographs of you;

        5. details of your qualifications and experience;

        6. your date of birth and gender; and/or

        7. any other personal information which we obtain as per clause 1.

Do we process special categories of personal information?

The EU General Data Protection Regulation (“GDPR”) recognises certain categories of personal information as sensitive and therefore requiring more protection, for example information about your health, ethnicity and political opinions.

In certain situations, we may collect and/or use these special categories of personal information (for example, health information to ensure equal access). We will only process these special categories of personal information if there is a valid reason for doing so and where the GDPR allows us to do so.

 

  1. How and why will we use your personal information?

Your personal information, however provided to us, will be used for the purposes specified in this Policy. In particular, we may use your personal information:

        1. to provide you with services, products and information you have requested;

        2. to communicate with you in relation to The Jo Cox Foundation;

        3. to provide further information about JCF work, services, activities and/or products (where necessary, only where you have provided your consent to receive such information);

        4. to answer your requests and complaints, for example in relation to our website, and to communicate with you in general;

        5. to analyse and improve our work, services, activities, products and/or information (including for our website), and/or for our internal records;

        6. to report on the impact and effectiveness of our work;

        7. to publish news articles and other information on our website;

        8. to register, administer and personalise online accounts;

        9. to process your application for a job with us when you apply through our website;

        10. to administer your employment/other working relationship with us (for example, to pay your salary);

        11. to provide references, for example to landlords and new employers;

        12. for training and/or quality control;

        13. to audit and/or administer our accounts;

        14. to satisfy legal obligations which are binding on us, for example in relation to regulatory, government and/or law enforcement bodies with whom we may work (for example requirements relating to the payment of tax or anti-money laundering);

        15. for the prevention of fraud or misuse of services; and/or

        16. for the establishment, defence and/or enforcement of legal claims.

 

  1. Lawful bases

The GDPR requires us to rely on one or more lawful bases to use your personal information. We consider the grounds listed below to be relevant:

        1. Where you have provided your consent for use to use your personal information in a certain way (for example, we may ask for your consent to use your personal information to send you marketing material in relation to GGT; and we may ask for your explicit consent to collect special categories of your personal information).

        2. Where necessary for the performance of a contract to which you are a party or to take steps at your request prior to entering a contract (for example, if you apply to work for us).

        3. Where necessary so that we can comply with a legal obligation to which we are subject (for example, where we are obliged to share your personal information with regulatory bodies which govern our work and services).

        4. Where it is in your/someone else’s vital interests.

        5. Where there is a legitimate interest in us doing so.

Data protection law allows us to collect and use your personal information if it is reasonably necessary to achieve our or others’ legitimate interests (as long as that use is fair, balanced and does not unduly impact your rights).

In broader terms, our “legitimate interests” means the interests of advancing the causes Jo cared about; for example providing you with information in order to take part in our work.

Where we use your personal information to achieve such legitimate interests, we consider and balance any potential impact on you (both positive and negative), and your rights under data protection law. We will not use your personal information for activities where our interests are overridden by the impact on you, for example where use would be excessively intrusive (unless, for instance, we are otherwise required or permitted to by law).

  1. Communications for marketing

We may use your contact details to provide you with information about our work, events, services and/or products which we consider may be of interest to you (for example, information about future work).

Where we do this via email, SMS or telephone, we will not do so without you prior consent (unless allowed to do so via applicable law).

Where you have provided us with your consent previously but do not wish to be contacted by us about our work, events, services and/or products in the future, you may opt out of receiving emails from us at any time by clicking the “unsubscribe” link and the bottom of our emails; or by contacting us at info@jocoxfoundation.org.  

  1. Children’s personal information

When we process children’s personal information, where required we will not do so without their consent or, where required, the consent of a parent/guardian. We will always have in place appropriate safeguards to ensure that children’s personal information is handled with care.

  1. How long do we keep your personal information?

In general, unless still required in connection with the purpose(s) for which it was collected and/or processed, we remove your personal information from our records six years after the date it was collected.

However, if before that date (i) your personal information is no longer required in connection with such purpose(s), (ii) we are no longer lawfully entitled to use it or (iii) you validly exercise your right of erasure (please see section 11 below), we will remove it from our records at the relevant time.

We review personal information that we hold at least annually in order to verify if it is still validly required in connection with the purpose(s) for which we collected it.

  1. Will we share your personal information?

We will not sell or rent your personal information with third party organisations. However, in general we may disclose your personal information to selected third parties in order to achieve the purposes set out in this Policy.

Non-exhaustively, those parties may include:

        1. suppliers and sub-contractors for the performance of any contract we enter into with them, for example IT service providers such as cloud storage providers or mailing houses;

        2. professional service providers such as accountants and lawyers;

        3. parties assisting us with research to monitor the impact/effectiveness of our work;

        4. regulatory authorities, such as tax authorities; and/or

        5. analytics and search engine providers.

In particular, we reserve the right to disclose your personal information to third parties:

  • in the event that we sell or buy any business or assets, in which case we will disclose your personal information to the (prospective) seller or buyer of such business;

  • if substantially all of our assets are acquired by a third party, personal information held by us may be one of the transferred assets;

  • if we are under any legal or regulatory obligation to do so; and/or to protect the rights, property or safety of JCF, their personnel, users, visitors or others.

 

  1. Security/storage of and access to your personal information

We are committed to keeping your personal information safe and secure and we have appropriate and proportionate security policies and organisational and technical measures in place to help protect your personal information.

Your personal information is only accessible by appropriately trained staff, and stored on secure servers with features enacted to prevent unauthorised access.

  1. Exercising your rights

Where we rely on your consent to use your personal information, you have the right to withdraw that consent at any time. This includes the right to ask us to stop using your personal information for marketing purposes or to unsubscribe from our email list at any time. You also have the following rights:

a. Right of access – you can write to us to ask for confirmation of what personal information we hold on you and to request a copy of that personal information. Provided we are satisfied that you are entitled to see the personal information requested and we have successfully confirmed your identity, we will provide you with your personal information subject to any exemptions that apply.

b. Right of erasure – at your request we will delete your personal information from our records as far as we are required to do so.  

c. Right of rectification – if you believe our records of your personal information are inaccurate, you have the right to ask for those records to be updated. You can also ask us to check the personal information we hold about you if you are unsure whether it is accurate/up to date.

d. Right to restrict processing – you have the right to ask for processing of your personal information to be restricted if there is disagreement about its accuracy or legitimate usage.

e. Right to object – you have the right to object to processing where we are (i) processing your personal information on the basis of the legitimate interests basis (see paragraph 4), (ii) using your personal information for direct marketing or (iii) using your information for statistical purposes. If you object to direct marketing, we will retain certain limited personal information about you to ensure that we do not contain you again.

f. Right to data portability – to the extent required by the GDPR, where we are processing your personal information (that you have provided to us) either (i) by relying on your consent or (ii) because such processing is necessary for the performance of a contract to which you are a party or to take steps at your request prior to entering into a contact, and in either case we are processing using automated means (i.e. with no human involvement), you may ask us to provide the personal information to you – or another organisation – in a machine-readable format.

g. Rights related to automated decision-making – you have the right not to be subject to a decision based solely on automated processing of your personal information which produces legal effects or similarly significantly affects you, unless such a decision (i) is necessary to enter into/perform a contract between you and us/another organisation; (ii) is authorised by EU or UK law (as long as that law offers you sufficient protection); or (iii) is based on your explicit consent.

Please note that some of these rights only apply in limited circumstances. For more information, we suggest that you contact us using the details in section 14 below.

We encourage you to raise any concerns or complaints you have about our data processing by contacting us using the details provided in section 14 below.  You are further entitled to make a complaint to the Information Commissioner’s Office – www.ico.org.uk. For further information on how to exercise this right, please contact us using the details in section 14 below.

  1. Changes to this Policy

This Policy will be reviewed at least annually and we may update it from time to time. We will notify you of any significant changes by contacting you directly where reasonably possible for us to do so and by placing an updated notice on our website. This Policy was last updated on 24th May 2018.

  1. Links and third parties

The website contains links to other websites. We are not responsible for the privacy policies or practices of third party websites.

  1. How to contact us

Please let us know if you have any questions or concerns about this Policy or about the way in which we process your personal information by contacting us at the following channels:

Email: info@jocoxfoundation.org  

Telephone: 02039407093

Post: Privacy Officer, The Jo Cox Foundation, Metal Box Factory, 30 Great Guildford Street, London SE1 0HS