Privacy Policy
Our promise to you
This Privacy Policy explains how NHS-R collect and process your personal data through your use of this platform. The policy is intended to meet our duties of transparency under the “General Data Protection Regulation” or “GDPR”. We will post any modifications or changes to this Privacy Policy on this page.
We care about your privacy and are committed to protecting your personal data. Here are our promises to you:
- To only collect personal information from you when it improves your experience of our platform.
- To ask for and record your consent for collecting personal information.
- To never sell your personal information to third parties.
- To explain why we are asking for personal information when we ask for it (unless it is obvious).
- To protect your data and store it safely.
- To respect your wishes and rights in regard to our storage of your data.
- To only send emails relevant to your use of the website.
- To never send you marketing related emails without your express consent.
What personal data we collect
All the personal data we collect is outlined in the table below:
Data Type | What this means |
Identity Data | Your username or name (mandatory) What you do (optional) A short biography (optional) A profile image of you (optional) Your account type (mandatory) Social media links (optional) |
Contact Data | Your email address (mandatory) Your phone number (optional) |
Location Data | Your neighbourhood or region (optional) |
Financial Data | None |
Marketing Data | Your public profile (optional) |
Behavioural Data | Your skills (optional) Your interests (optional) |
Activity Data | Activity information (automatic) |
Exchange Data | Additional data required to join the timebank (mandatory) |
Technical Data | Internet protocol (IP) address (automatic) Your login data (automatic) Browser type and version (automatic) Time zone setting and location (automatic) Browser plug-in types and versions (automatic) Operating system you use to access this platform (automatic) |
Professional Data | Additional data is collected from those members who opt into our research study. This data includes: Employment details Education background Experience and expertise in conducting research Ethnicity Members who are part of the study can also optionally provide the following: Gender Age Country of birth Disability Sexual orientation |
Aggregated Data
We also collect, use and share “aggregated data” such as statistical or demographic data for any purpose. Aggregated data may be derived from your personal data but it will not constitute personal data for the purposes of the GDPR as this data does not directly or indirectly reveal your identity.
We will treat any data that can directly or indirectly identify you as personal data which will be used in accordance with this Privacy Policy.
No special categories of personal data
We do not collect any “special categories of personal data” about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.
How we use your personal data
We will only use your personal data for the purposes for which we collected it as listed below, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.
If we need to use your personal data for an unrelated purpose, we will update this Privacy Policy and we will explain the legal basis which allows us to do so.
What is our “legal basis” for processing your personal data?
The General Data Protection Regulation (GDPR) requires us to ensure that we have a legal basis for using your personal data. Most commonly, we will rely on one of the following legal bases:
- Where we need to perform a contract we are about to enter into or have entered into with you (“Contractual Necessity”).
- Where it is necessary for our legitimate interests and your interests (“Legitimate Interests”). More detail about the specific legitimate interests we use your personal data for is set out in the table below.
- Where we need to comply with a legal or regulatory obligation (“Compliance with Law”).
- Where we have your specific consent to carry out the processing for the purpose in question (“Consent”).
Generally, we do not rely on your consent as a legal basis for using your personal data (other than in the context of direct marketing communications).
We have set out below, in a table format, the legal bases we rely on in respect of the relevant purposes for which we use your personal data:
Purpose | Categories of personal data involved | Why do we do this | Our legal basis for this use of data |
Registering an account | Identity and contact data: Your name (optional) Your email (mandatory) Who you are registered as (mandatory) | To register you as a member of the platform. To send you platform- specific notifications (e.g. forgotten password, activity alerts). To contact you if a need arises. | Contractual necessity |
Setting up your profile | Identity and marketing data: Your name (optional) Outline of what you do (optional) Description of yourself (optional) Adding a profile image (optional) Adding a cover image (optional) Describing in mode detail who you are registered as (optional) Links to your website / social media / email accounts (optional) | To raise your profile to other users of the platform. | Legitimate interest |
Setting up your Best Match | Behavioural data: Your region (optional) Your interests (optional) Your skills (optional) Marketing data: Your saved tags (optional). | To quickly match you to relatable activities and members using the ‘Best Match’ button. To allow you to share some or all of your location, skills and interests onto your public profile. | Legitimate interest |
Your activities | Activity and contact data: Your activity location (optional) Availability of your activity (optional) Your contact details – phone number or email address (mandatory but doesn’t need to be publicly visible) | To describe your activity in more detail and enable other members or a platform administrator to contact you. | Legitimate interest |
Your messages | Activity data: Your messages (optional – recorded on database but not visible elsewhere) | To let you message other members. To ensure any inappropriate messaging is recorded for safeguarding and legal purposes. | Legitimate interest Compliance with law |
Your connections | Activity data: Members you are connected with (automatic) | To let you manage your connections. | Legitimate interest |
Joining the exchange | Identity data: Your first / last name (mandatory) | To help the platform administrator determine whether you are eligible to join the exchange. | Legitimate interest |
Member management | Identity, contact, behavioural and marketing data: About your account – main or sub user (automatic) Is your account activated? (automatic) Are you approved to use the exchange? (automatic) Your email (mandatory) Admin notes Your profile (optional) | To keep our platform and our services operational, safe and secure. To understand and monitor user behaviour. To form a view on what we think you may want or need, or what may be of interest to you. | Contractual necessity Legitimate interest |
Communications | Contact information: Your name Your email | To be able to provide technical support. To be able to provide updates about your activity on the website. To share important updates to privacy policies, terms and conditions. To share important information about website changes and updates. To promote activities that you may be interested in. | Contractual necessity (updates to privacy policy, data breaches etc) Legitimate interest |
Research Data | Employment details Education background Experience and expertise in conducting research Ethnicity Gender Age Country of birth Disability Sexual orientation | We collect this data as part of an NIHR funded study to use of Timebanking to increase inclusivity in research. | Consent |
How we secure your personal data
We respect people’s data and take care to ensure that your personal data is stored safely and securely. We store all your personal information on our secure UK based servers, which:
- Use strong password protection.
- Have regular security patches and system updates.
- Have an industry standard Firewall policy.
- Use authentication.
- Apply user auditing.
We have industry recognised security measures in place to prevent our platform from being hacked including: password hashing and salting, SQL injection projection techniques applied to all data input forms, regular updates and security reviews.
Transmitting information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to the site. Any transmission is at your own risk.
You are responsible for keeping your password and user details confidential. We will not ask you for your password (except when you log in). We ask you not to share your password with anyone.
How long we store your personal data for
We will only retain your personal data until either of the following happens (or unless a longer retention period is required by law):
- You decide to delete your account.
- You wish to enact your right to be forgotten.
- The website is terminated.
Your personal data rights
By law you have the right to:
- Request access to your personal data. This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
- Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
- Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have exercised your right to object to processing (see below).
- Object to processing of your personal data. This right exists where we are relying on a Legitimate Interest as the legal basis for our processing and there is something about your particular situation, which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal data for marketing purposes.
- Request the restriction of processing of your personal data. This enables you to ask us to suspend the processing of personal data about you; for example, if you want us to establish its accuracy or the reason for processing it.
- Request the transfer of your personal data. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. This right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
- Withdraw consent. This right only exists where we are relying on consent to process your personal data (“Consent Withdrawal”). If you withdraw your consent, we may not be able to provide you with access to the certain specific functionalities of our platform. We will advise you if this is the case at the time you withdraw your consent.
Things to be mindful for
Our policy on children
This platform is not intended for children below 16 and we do not knowingly collect data relating to such children.
Personal data from third parties
This platform does not currently collect any personal data from third parties. For members joining our exchange, our administrators may reference check you from third party sources. This will only be done with your permission, using the references you have provided. This is to protect your and our legitimate interests – allowing you to make exchanges freely once authorised, and allowing our administrators to provide an extra safeguarding check for the benefit of all our members.
This platform may also include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share your personal data. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our platform, we encourage you to read the privacy policy of every site you visit.
What happens if we need more personal data?
Where we need to process your personal data either to comply with the law, or to meet the terms and conditions of use we have with you, and you fail to provide that data when requested, we may have to stop you using our platform. We will notify you if this is the case at the time.
Marketing preferences
This platform does not and will not send out any marketing messages from third parties. You can ask us to stop sending you marketing messages at any time by signing into the platform and checking or unchecking relevant boxes to adjust your marketing preferences and / or by following the opt-out links on any marketing messages sent to you.
Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of use of our platform.
How to exercise your rights
If you want to exercise any of the rights described above, please contact us by emailing nhs.rcommunity@nhs.net.
Typically, you will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, except in relation to Consent Withdrawal, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive, or, we may refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Making a complaint
If you would like to make a complaint regarding this Privacy Policy or our practices in relation to your Personal Data, please contact us at: nhs.rcommunity@nhs.net. We will reply to your complaint as soon as we can.
If you feel that your complaint has not been adequately resolved, please note that the GDPR gives you the right to contact your local data protection supervisory authority, which for the UK, is the Information Commissioner’s Office.