Data privacy notice
Christ Church London is a UK based Christian church. Christ Church London wants to play a significant part in the cultural, social and spiritual renewal of London. We long to build a home in the capital for those from all walks of life to see and know Jesus. We care about transforming communities, and building deep relationships in the heart of London.
Christ Church London values everyone who engages with us by whatever means, and we do all we can to protect your privacy and to make sure the personal data you provide us is kept safe. This policy explains how we collect data, how we use and store information and what it means for you.
2. Who we are
Christ Church London is the data controller (contact details below). This means it decides how your personal data is processed and for what purposes.
Christ Church London
The Matrix Complex
91 Peterborough Road
London SW6 3BU
Charity no: 1111950
Company no: 05546205
3. What information we collect
This policy explains how the church and the website comply with the DPA (Data Protection Act) and the General Data Protection Regulation (GDPR) which came into effect on 25 May 2018. Christ Church London complies with its obligations under the GDPR by keeping personal data up to date; by storing and destroying it securely; by not collecting or retaining excessive amounts of data; by protecting personal data from loss, misuse, unauthorised access and disclosure and by ensuring that appropriate technical measures are in place to protect personal data.
- Directly from us
We collect personal information each time you deal with us, for example when you provide your contact details, in writing or orally, to church staff or volunteers; make a donation; request materials or information; sign up for an event; use our check in system for Kids Work on a Sunday, or otherwise provide your personal details.
- From website interaction from us
We collect non-personal data such as IP addresses, details of pages visited and files downloaded. Website usage information is collected using cookies, see the section on Cookies below.
- Indirectly from third parties
- Where you give permission to other organisations
- Sensitive data
Where you provide the information, we may collect sensitive personal data, including, but not limited to, your religious beliefs, or your physical or mental health.
4. What we do with it
- Processing of requests/donations
We collect personal information each time you deal with us, For example when you provide your contact details, in writing or orally, to church staff or volunteers; make a donation; request materials or information; sign up for an event; use our check in system for Kids Work on a Sunday, or otherwise provide your personal details. We may use the personal data we collect to:
• To enable us to provide a voluntary service for the benefit of the public;
• To provide pastoral care to our attendees;
• To administer attendance/membership records;
• To provide an interactive website where email is used to communicate with users. (christchurchlondon.org);
• To fundraise and promote the interests of the charity;
• To manage our employees and volunteers;
• To maintain our own accounts and records (including the processing of gift aid applications);
• To inform you of news, events, activities and services running at Christ Church London;
- Basis of processing your data
So that we can provide services you have requested, and keep you informed about news, events, activities and services and process your donations we will process your personal data on the basis of the consent you provided us with. You are free to change your preferences at any time. Other processing based on legitimate interest is necessary for carrying out obligations under employment, social security or social protection law, or a collective agreement. Legitimate interest is also the basis of our processing relating to members or former members (or those who have regular contact with us in connection with these purposes) as we are a not-for-profit body with religious aims.
- Applying for a job or volunteering with us
Where you provide personal data and sensitive personal data when applying for a job or volunteer role with us, such as the information on your CV we will process, store and disclose the personal data we collect to:
• Support the recruitment process;
• Answer any questions you may have;
• Use third parties to provide services such as references, qualifications, criminal referencing, checking services, verification of information you have provided, health screening and psychometric evaluation or skills tests;
• Provide anonymised data to monitor compliance with our equal opportunities policy.
5. How and where we store your information
- How long?
We will keep your personal information only for as long as we consider it necessary to carry out each activity. We have a data retention policy to implement this. We take account of legal obligations and accounting and tax considerations as well as considering what would be reasonable for the activity concerned.
We ensure that we have appropriate technical controls in place to protect any personal data you provide. For example, we ensure that any online forms are encrypted and our network is protected and routinely monitored. We ensure that access to personal data is restricted only to those staff members or volunteers whose job roles require such access and that suitable training is provided for these staff members and volunteers. We may make limited use from time to time of external companies to collect or process personal data on our behalf. When we do so, we carry out checks on these companies, put in place contracts to make sure our requirements are clear, and carry out periodic reviews. When we do use external companies, we remain responsible for the storing and processing of your personal data.
- Credit/Debit card security
If you use your debit or credit card to donate to us, purchase something or pay for an event, whether online, over the phone or by Gift Envelope, we will process your information securely in accordance with the Payment Card Industry Data Standard. We may hold your bank account details if you have asked us to set up a standing order for you, which are stored securely and retained in line with legal requirements.
- Where we store your personal information
We use cloud-based systems to process data and therefore data may be processed outside of the European Economic Area (EEA). We adopt the Information Commissioners approved measures and therefore ensure that personal data is held in compliance with European data protection regulations. We take all reasonable steps to ensure that your data is stored and processed securely in accordance with this policy. By submitting your personal data you agree to this transfer, storing and processing of your information.
6. When we share your personal information
Your personal data will be treated as strictly confidential and will only be shared with staff and members of the church in order to carry out a service or for purposes connected with the church. We will only share your data with third parties with your consent.
- Legal duty
We may need to pass on information if required by law or by a regulatory body. For example, a Gift Aid audit by the HMRC, or if asked for details by a law enforcement agency.
- Our service providers
We do not sell or pass any of your personal information to any other organisations and/or individuals without your express consent, with the following exception – by providing us with your details you are giving the church your express permission to transfer your data to our service providers including mailing houses, such as MailChimp, to enable fulfilment of the purpose for collection. Where such details are shared we have confidentiality agreements in place that restrict the use of your information to the purpose for which it is provided and ensure it is stored securely and kept no longer than necessary. We may employ agents to carry out tasks on our behalf, such as processing donations. These agents are bound by contract to protect your data and we remain responsible for their actions. We may provide third parties with general information about users of our site, but this information is both aggregate and anonymous. However, we may use IP address information to identify a user if we feel that there are or may be safety and/or security issues or to comply with legal requirements.
- What are cookies?
- How we use them on our website
To enjoy our website to the full, we recommend that you leave cookies turned on. If you turn off cookies then you may not be able to enter parts of the site. The cookie data that we collect we may use to customise the content on our website and to help to understand visitor’s current and future needs
- Managing cookies
Most browsers allow you to turn off the cookie function. To do this you can look at the help function on your browser.
- Third party cookies
Families making use of the children’s facilities during our services are required to provide personal data for their children. This data is provided with the consent of the parent or guardian and is securely held and stored as above. We require parental consent for any child under the age of 14.
9. Your choices and telling us when things change
You can change your preferences on what you receive from us, or how we contact you, by phone or email, at any time. You can do so by:
Calling us on: 020 7384 6493
Email us at: firstname.lastname@example.org
- Updating your details
We do appreciate it if you keep your details up to date. You can do so in the same way as updating your preferences (above). We may use Post Office address search, postcode lists or other available sources to confirm data that you provide us with, where, for example, we are unsure of what you have completed on a form. We will not use these sources to create data that you have chosen not to provide, for example, if you have left a telephone number blank; nor will we automatically update changes of address, we will normally only update your address when you tell us it’s changed.
- Telling us to stop processing
You have the right to ask us to erase your personal data, to ask us to restrict our processing or to object to our processing of your personal data. You can do so at any time by emailing us at: email@example.com
10. Access to your information
You have the right to request details of the information we hold about you. To make this request, please write to us at the details above. For more information about your rights under the Data Protection Act you can visit the website of the Information Commissioner’s Office.
11. Changes to this policy
This policy was last updated in July 2020. We may amend this policy from time to time to take account of changes to our processes or changes to data protection or other legislation. If we make any significant changes to this policy we will show this clearly on our website or in our communications. By continuing to use our website you will be deemed to have accepted these changes.
12. Further processing
If we wish to use your personal data for a new purpose, not covered by this Data Protection Notice, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, we will seek your prior consent to the new processing.
13. COVID-19 assisting NHS Test and Trace
In compliance with UK Government guidelines we will be keeping temporary data records of those attending in-person services at any of our locations. We are doing this in order to assist NHS Test and Trace with requests for data if it is needed. This statement was last updated in July 2020.
14. Governing law
If you have any queries please contact us at firstname.lastname@example.org