Data Protection Policy
At RightGreen we are committed to being transparent about how we collect and use the personal data of our colleagues and how we meet our data protection obligations. This statement explains how RightGreen (“we” and “our”) handles and uses data we collect about our past, current, and future clients, supporters, employees, and volunteers (“you” and “your”). In broad terms, we use your data to tailor our support to our clients and inform current and future delivery practice. In addition, we use data to update you on our activities and development.
At RightGreen, we process HR-related personal data in accordance with the following data protection principles:
We process personal data lawfully, fairly and in a transparent manner.
We collect personal data only for specified, explicit and legitimate purposes.
We process personal data only where it is relevant, and we limit the data to what is necessary for the purposes of processing.
We keep accurate personal data and take all reasonable steps to ensure that inaccurate personal data is rectified or deleted without delay.
We keep personal data only for the period necessary for processing.
We adopt appropriate measures to make sure that personal data is secure, and protected against unauthorised or unlawful processing, and accidental loss, destruction, or damage.
We explain the reasons for processing your personal data, how we use such data and the legal basis for processing in our privacy notices. We do not process personal data of individuals for other reasons.
We will update personal data promptly if you advise us that your information has changed or is inaccurate.
We keep a record of our processing activities in respect of personal data in accordance with the requirements of the General Data Protection Regulation (GDPR).
1: Programme data
Throughout this policy we categorise the individuals whose data is held by RightGreen as clients, contacts, or non-enrolled clients. Below is a definition of these terms:
Clients: the beneficiaries of RightGreen’s services
Contacts: Non-service users who have an involvement in RightGreen’s’ activities in another respect. This includes:
Trust and Foundations
How RightGreen collects, shares, and stores data
Due to the varied ways in which RightGreen uses data to implement our delivery and services, for both clients and other types of contacts, it is often stored across a variety of platforms.
We collect data about you using two online platforms – Kobo Toolbox and Zoho Forms. Both platforms are password protected and have committed to complying with the GDPR. In addition, we collect data on paper forms when it is appropriate. Data from these forms is transferred to a Google Sheet, and the hard copies are kept in the RightGreen office, which is only accessible to RightGreen staff members with a key card.
Before collecting and storing data through any means, we ask you for your consent either verbally (for contact details), or as a question within the enrolment questionnaire.
We store data about you on the Kobo Toolbox server, Zoho, Dropbox, Sharepoint, work computers and Google docs. All these platforms are password protected and have committed to being GDPR compliant. We also may store a limited amount of information about you in hard copies, which are kept in our offices and only available to RG staff members with key cards.
Data will be stored by RightGreen for 10 years from the point of collection. If it is in the interest of RightGreen’s programming, data may be stored longer than this period. Data stored beyond 10 years will be anonymised.
- Customers, Donors, framework representatives, and business supporters’ details are stored on Breaking Barriers’ Gmail, Dropbox, MailChimp, GoogleDocs, and Zoho accounts.
- All storage platforms are password controlled and GDPR compliant.
- No contact details are shared without your permission.
- Data will be stored for a maximum of 5 years.
Full names contact details and work addresses.
Name and contact details.
Organisation providing employment.
We will retain your data for 10 years if you are an enrolled client, 5 years if you are a contact, and 2 months if you are a non-enrolled client, or until you request us to do otherwise.
How RightGreen uses your data
- Identifying suitable opportunities for you.
- Recording the support, you have received from RightGreen and the suggested next steps.
- Recording the outcomes, you have achieved since working with RightGreen.
- If applicable, providing updates to the organisation that referred you.
- Data analysis to inform our future services, KPI reporting, providing performance reports to be shared both internally and externally.
- Distribution of our e-newsletter.
- Promotion of events.
- Promotion of opportunities.
To inform clients of the services we provide and book their first appointment with them.
Communications to you may be sent by post, telephone, or electronic means.
If you have concerns or queries about any of these purposes, or how we communicate with you, please contact us at firstname.lastname@example.org