Sherburn House Charity

0191 372 2551 (Administration) | 0191 372 0421 (Care Home)

Privacy Policy

Lawful Processing of Data & Privacy Notice

Sherburn House Charity is registered with the Information Commissioners Office, as we control and process data for the purposes of employing staff to deliver housing and care services to older people.

This notice explains how we use and share your information to assure you that the information is only used to comply with our legal duties as an employer and as a housing and care provider and that the information we hold is fair and transparent.

You, (the data subject), have the right to:

  • Access your personal data;
  • Request the rectification or erasure of personal data;
  • Request that the processing of your personal data be restricted
  • The right to data portability

The General Data Protection Regulations, (GDPR), will become law as of 25th May 2018. The GDPR requires that organisations (data controllers), that process personal data demonstrate compliance with its provisions. Part of this involves publishing a basis for lawful processing and a condition, (where relevant), for processing special categories of data.

The Data Controller is: Sherburn House Charity, Ramsey House, Durham DH1 2SE  

The Data Protection Representative is: Pauline Bishop, 0191 3720421

The Purposes of the Processing of your Data

We process personal information to enable us to deliver our mission which is - to provide relief in need to people living in the beneficial area through the provision of care, housing and grant funding.

We will also process data in order to maintain our own business accounts and records.  This includes supporting and managing our employees, volunteers and trustees and in the processing of payroll functions and other legal duties required by employers. We may also use external CCTV systems on our grounds to monitor and collect visual images for security and the prevention and detection of crime.

 

Legal basis for the processing;

We process information relevant to the above reasons/purposes subject to the statutory duty under section 251B of the Health & Social Care Act 2012. The lawful basis for processing your information under the GDPR is:

s6(1)(e) " processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;"

Special Category data is processed to operate the business (sensitive data including racial or ethnic origin, sexual orientation, political opinions, religious or philosophical beliefs, or trade union membership, information about mental health or physical health and wellbeing.

Wherever possible, explicit consent will be obtained prior to your data being processed, however, where appropriate, service users’ next of kin may give explicit consent for those who lack mental capacity, otherwise “best interest” decisions will be made in line with the Mental Capacity Act 2005.

The legal basis the Charity uses for processing employees data is given in s9 (2) (b) of the GDPR , as “processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law..."  

We will process data relating to criminal convictions and offences under the lawful basis set out in Article 10 and processing of personal data relating to criminal convictions and offences shall be carried out with appropriate safeguards for the rights and freedoms of data subjects. Any information regarding criminal convictions shall be processed only for the purposes of safeguarding requirements within our recruitment process.  

Your rights

Under the Data Protection Act 2018 you have the following rights:

  • The right to be informed
  • The right of access
  • The right to rectification
  • The right to erasure
  • The right to restrict processing
  • The right to data portability
  • The right to object
  • Rights in relation to automated decision making and profiling

 

 

Purpose and legal basis

When you give us your personal data we will only use it to pursue our legitimate organisational interests:

This information may include:

Personal details such as:

  • Family details
  • Lifestyle and social circumstances
  • Goods and services purchased or required by you
  • Financial details
  • Education and employment details
  • Photographic images on personnel/ care planning files

We also process sensitive classes of information that may include:

  • Physical or mental health details
  • Racial or ethnic origin
  • Religious or other beliefs
  • Offences including alleged offences
  • Criminal proceedings, outcomes and sentences

 

We process personal information about the following people:

  • Customers and clients
  • Suppliers
  • Complainants
  • Enquirers
  • Individuals captured by CCTV images 
  • Employees

Who the information may be shared with:

We sometimes need to share the personal information we process with the individual themselves and also with other organisations. Where this is necessary we are required to comply with all aspects of the Data Protection Act (DPA).

Where necessary or required we share information with:

  • Healthcare professionals, social and welfare organisations 
  • Family, associates and representatives of the person whose personal data we are processing
  • Central and local government
  • Suppliers and service providers
  • Employment and recruitment organisations
  • Credit reference agencies
  • Debt collection and tracing agencies
  • Business associates and other professional advisers
  • Financial organisations
  • Current, past or prospective employers
  • Educators and examining bodies
  • People making an enquiry or complaint
  • Police forces and security organisations

 

Transferring information overseas

We do not transfer any personal information outside the European Economic Area (EEA) or use your data for automatic profiling.

The following is a broad description of the way this organisation processes personal information. To understand how your own personal information is processed you may need to refer to any personal communications you have received, check any privacy notices the organisation has provided or contact the organisation to ask about your personal circumstances.

Privacy Notice

Sherburn House Charity will not share your personal information with third parties unless it is for legal compliance or as part of the health & social care service provision you have requested from us.

Sherburn House Charity holds special categories of data for our employees and service users. This information is held confidentially with access limited to authorised personnel only.

You have the right to see what information SHC holds about you and may make a subject access request and you may also ask for the information to be amended if incorrect.

 

Security

We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we process

How we use cookies

A cookie consists of information sent by a web server to a web browser, and stored by the browser. The information is then sent back to the server each time the browser requests a page from the server. This enables the web server to identify and track the web browser.

We use Google Analytics to analyse the use of the Charity's website.  Google Analytics collects standard internet log information and details of visitor behaviour patterns. We do this to find out things such as the number of visitors to the various parts of the site. This information is only processed in a way which does not identify an individual.  For more information please refer to Google's privacy policy.

Most browsers allow you to reject all cookies, whilst some browsers allow you to reject just third party cookies.  For example, in Internet Explorer you can refuse all cookies by clicking “Tools”, “Internet Options”, “Privacy”, and selecting “Block all cookies” using the sliding selector.  Blocking all cookies will, however, have a negative impact upon the usability of many websites.

For further details or to  make subject access request please email:

RamseyHouseReception@sherburnhouse.org with ‘Subject Access Request’ in the subject line. Your request will be forwarded to the relevant person in the organisation and will be acknowledged. 

Your request will be carried out within one month unless there is good reason for this not to be possible.  In this event we will contact you and explain why we cannot carry out your request within one month.

If we fail to satisfy your concerns you have the right to complain to the Information Commissioner’s Office (ICO) by e-mailing them at https://ico.org.uk/