5Rights Foundation (“5Rights”) is committed to processing data in accordance with its responsibilities under the EU General Data Protection Regulation. The only lawful bases for collecting and processing personal data are: consent, contract, legal obligation, vital interests, public task or legitimate interests.
All personal data that we collect and process will be:
processed lawfully, fairly and in a transparent manner
collected for specified, explicit and legitimate purposes only
adequate, relevant and limited to what is necessary
accurate and kept up to date
kept no longer than necessary
You have the right to:
object to the processing of your personal data by 5Rights
be told that we are collecting and processing your personal data, what personal data we are collecting and processing, why we are collecting and processing it and who we are sharing it with. We must provide this information in a way that is concise, transparent, intelligible and easily accessible
have inaccurate or incomplete personal data that we hold on you corrected
request the erasure and disposal of personal data we hold about you
restrict the way that 5Rights processes your personal data
obtain and reuse your personal data for your own purposes across different services including moving, copying or transferring personal data that we hold digitally to another digital environment in a safe and secure way.
We must action any request to activate your rights without delay (within a month at the latest). If exceptional circumstances mean that it will take longer for us to respond to your request or that we have to make a charge, we must explain why.
We may need to verify that a request to activate your rights originated from you before actioning it.
If we decide that we cannot comply with your request, we must explain why.
Anyone who believes that 5Rights collects or processes their personal data may activate any of their rights at any time by emailing us at email@example.com.
In addition, we want to make it as easy as possible to opt-out or unsubscribe from communications. You may opt-out of all further communications at any time. If you request to opt-out we will remove your personal data from our database. Group emails to our database include an ‘unsubscribe’ button.
Circumstances In Which We Collect And Process Personal Data
When you visit our website:
Our website is hosted by CloudCannon. When you visit our website, CloudCannon collects information to identify and track visitors, usage and access preferences. This information is collected to enable CloudCannon to understand more about how visitors use our website.
CloudCannon does not provide 5Rights with any personal data about visitors to our website. The only information that we have access to is anonymised analytics on website traffic (e.g. number of visitors). We do not routinely access this data.
If you want to receive further information from 5Rights about our work, you can submit an email address. We will add your email address to our contacts database (see paragraph 16).
If you, or the organisation, you represent become a 5Rights signatory:
If you, or the organisation that you represent, would like to become a signatory to the 5Rights, we will ask for your first and last name, your email address and, if relevant, the name of your organisation. We will also ask if you want to receive our newsletter. You will then be added to our database of signatories and our contacts database.
We may wish to add your name (if signing as an individual) or the organisation you represent to the list of signatories on our website. If so, we will contact you before doing so to verify your identity, to upload a logo (where appropriate) and to confirm that you are happy for your name to be published.
If you are a supplier, sub-contractor or delivery partner:
If you supply goods or services to 5Rights we will collect and process your personal data to the extent that it is required for us to manage our relationship.
If you are included in our contacts database:
5Rights maintains a contacts database of relevant people with whom we come into contact in the course of pursuing our charitable objectives. The types of personal data we collect in our contacts database includes: name, job title, organisation, email address, address, phone numbers, video conferencing ID, mutual interests or contacts.
In addition to our main contacts database, we may collect and process personal data in our internal office management systems (including email accounts, address books, cloud storage facilities and document management systems) of those who work for or represent 5Rights. For example, we may store email addresses from emails we receive so that we can contact that person again, we may file business cards, we may follow up on introductions to individuals and organisations with relevant expertise or similar interests or we may record the publicly available contact details of individuals and organisations with whom 5Rights should engage. We are often introduced by other organisations, and we sometimes introduce people in our network.
At any time you may request to activate any of your rights (see above) including the right to have your personal data deleted. Please contact firstname.lastname@example.org.
Data Reviews and Expiry
We carry out annual data reviews to ensure that our data processing procedures are still up to scratch and to ensure that data that is no longer needed or which is out of date is archived or removed.
5Rights ensures that personal data is stored securely. Our security software is kept up-to-date and appropriate back-up and recovery solutions are in place. Personal data stored in hardcopy is stored in our secure office.
In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data, we will promptly assess the risk to people’s rights and freedoms and if appropriate report this breach to the relevant parties and to the regulator (Information Commissioner’s Office).
Children’s and Young People’s Data
Where we hold the personal data of a person under the age of 18, for example a child who contributes to a workshop, we will make certain that the child (and/or the parent of the child is under 13)1 understands beyond doubt the ways in which their data may be used. It is our policy not to share a child’s data unless it is prearranged, and for reasons that are transparent, accountable, understood and in the child’s best interests.
5Rights registered with the Information Commissioner’s Office (ICO) as an organisation that processes personal data. 5Rights’ ICO registration number is: ZA399046 and expires 10th June 2019.