Mind and Wellness Privacy Policy Last updated: August 2024

Definitions

  • GDPR: Refers to the General Data Protection Regulation.
  • Responsible Person: Refers to Gemma Merna.
  • Register of Systems: A record of all systems or contexts where personal data is processed by Mind and Wellness.

1. Data Protection Principles

Mind and Wellness is dedicated to processing personal data in alignment with the responsibilities under the GDPR. According to Article 5 of the GDPR, personal data must be:

  • Processed lawfully, fairly, and transparently.
  • Collected for specified, explicit, and legitimate purposes, and not processed further in ways incompatible with those purposes.
  • Adequate, relevant, and limited to what is necessary for the purposes for which they are processed.
  • Accurate and kept up to date; inaccurate data must be corrected or deleted without delay.
  • Retained in a form that permits identification of individuals only as long as necessary for the processing purposes. Longer storage for public interest, scientific or historical research, or statistical purposes is allowed with appropriate safeguards.
  • Processed securely to protect against unauthorized or unlawful processing, accidental loss, destruction, or damage.

2. General Provisions

  • This policy applies to all personal data processed by Mind and Wellness.
  • The Responsible Person is accountable for ensuring ongoing compliance with this policy.
  • This policy will be reviewed at least once a year.
  • Mind and Wellness will register with the Information Commissioner’s Office (ICO) as an organization that processes personal data.

3. Lawful, Fair, and Transparent Processing

  • Mind and Wellness will maintain a Register of Systems to ensure lawful, fair, and transparent data processing.
  • The Register of Systems will be reviewed annually.
  • Individuals have the right to access their personal data, and any such requests will be handled promptly.

4. Lawful Purposes

  • All data processed by Mind and Wellness must be based on one of the following lawful bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests (refer to ICO guidance for more information).
  • The lawful basis for processing will be noted in the Register of Systems.
  • When consent is used as the lawful basis, proof of opt-in consent will be maintained.
  • Communication based on consent will include an option to revoke consent, and systems will be in place to ensure such revocation is accurately reflected.

5. Data Minimisation

  • Mind and Wellness will ensure personal data is adequate, relevant, and limited to what is necessary for its processing purposes. Relevant considerations include correspondence about membership schedules, overdue payments, upcoming events, and meeting requests.

6. Accuracy

  • Reasonable steps will be taken to ensure personal data is accurate.
  • Where necessary, steps will be implemented to keep personal data up to date.

7. Archiving / Removal

  • Mind and Wellness will implement an archiving process to ensure personal data is not kept longer than necessary, with annual reviews.
  • The archiving process will determine what data should be retained, for how long, and why.

8. Security

  • Personal data will be stored securely using up-to-date software.
  • Access to personal data will be restricted to authorized personnel, with security measures to prevent unauthorized sharing.
  • Personal data will be safely deleted to ensure it is irrecoverable.

9. Breach

  • In case of a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data, Mind and Wellness will promptly assess the risk to individuals’ rights and freedoms. If necessary, the breach will be reported to the ICO (more information is available on the ICO website).

END OF POLICY