Skip to content

Privacy policy

1. Introduction

This policy sets out the principles and processes that Arts for Dementia should apply to ensure that, in respect of all records that it keeps, as far as reasonably possible it complies with the law on data privacy, and acts in accordance with the wider expectations of our many stakeholders. Failure to manage data securely and appropriately may cause harm to staff, donors, clients and other stakeholders, and to the reputation and status of Arts for Dementia.

2. Applicability

2.1 Arts for Dementia’s policy on data protection and privacy applies to trustees, staff, contractors, volunteers and others who handle and store Personal Data on behalf of Arts for Dementia.

2.2Data Controller

  • A person or legal entity who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any Personal Data are, or are to be, processed.  For this purpose Arts for Dementia is the Data Controller.  Staff or Trustees handling Personal Data do so on behalf of the charity.

2.3 Data Processor
In relation to Personal Data, any person or organisation (other than an employee of the data controller), such as Donorfy, who processes the data on behalf of the data controller. 

3. Collecting and processing Personal Data

3.1 Legitimate purposes

  • General Data Protection Regulation (GDPR) requires that organisations process Personal Data not only fairly, lawfully but also only for legitimate purposes.  Arts for Dementia will only collect Personal Data where it has a legitimate interest, i.e. necessary to carry out its charitable purposes, for fundraising and, in the case of employees, contractors and other stakeholders, to enable it to undertake its day-to-day operations.

3.2 Individuals will be asked to Consent to their Personal Data being held. We will be transparent about how we will use the data, and give individuals appropriate privacy notices when collecting their Personal Data. 

3.3 If Consent is withdrawn Arts for Dementia will promptly remove the relevant Personal Data from its records.

3.4 Data records will be reviewed periodically (at least annually) to identify data, including Personal Data, that is no longer required for the purposes set out above.   It may be necessary to re-confirm details with the individuals concerned and this can also be used to update Consent.

4. Additional Conditions for processing Sensitive Personal Data

4.1

a)  the individual whom the sensitive Personal Data is about has given explicit Consent to the processing; and

b)  one or more of the following:

  • – The processing is necessary to comply with employment law, legal proceedings or for obtaining legal advice, to meet statutory obligations;
  • – The processing is necessary to protect the vital interests of the individual (in a case where the individual’s Consent cannot be given or reasonably obtained), or another person (in a case where the individual’s Consent has been unreasonably withheld) or for medical purposes by a health professional who is subject to a duty of confidentiality;
  • – The processing is necessary for monitoring equality of opportunity, and is carried out with appropriate safeguards for the rights of individuals;
  • – In certain situations, such as preventing or detecting crime and protecting the public against malpractice or maladministration, it is permissible to disclose sensitive Personal Data without explicit approval from the individual concerned.

5. Storing Personal Data

5.1 Personal Data will normally be permanently held in an online database (e.g. Donorfy) as this is considered more secure, as well as more useful than on a laptop. 

5.2 Where Personal Data is held in spreadsheets or other structured documents on a laptop then the application should be password protected.

5.3 Personal Data held on laptops or in hard-copy should only be held for as long as required and should be deleted or destroyed when that purpose has been served, if necessary after making necessary changes to the master data.

5.4 If Personal Data for which Arts for Dementia is responsible is transferred to a private computer, the person responsible should apply good practice in relation to the security of that computer.

5.5 If Personal Data is processed or shared in e-mails, spreadsheets or other documents, care should be taken not to copy these documents wider than necessary for that purpose.

5.6 Arts 4 Dementia will take appropriate action in the event of a breach of data by recording the breach, notifying the Information Commissioner without delay and notifying the individual concerned where there is a high risk to their rights and freedoms.

  1. 6. Sharing of Personal Data

  2. 6.1 Arts for Dementia will not collect or hold Personal Data in order to pass it on to third parties for value and will not share personal data with a third party, other than in the specific cases allowed in the legislation and referred to in 5.4 and 5.5, without the explicit agreement of the Trustees.

  3. 6.2 Arts for Dementia will only disclose Personal Data to third parties in circumstances:
    – where required by law;
    – where it is in the individual’s vital interest, i.e. cases of life and death, such as disclosure to medical practitioner in an emergency;
    – at the (written) request of the individual concerned, or in accordance with contracts that individual has entered into.

  4. 6.3 Where sensitive personal data is shared with staff and contractors (for example where information relating to the mental or physical wellbeing of clients is shared with facilitators and volunteers at workshops), they will be asked to delete or destroy the data once the immediate need has passed and to confirm that they have done so.

  5. 6.4 A third party may request Personal Data where it has a legitimate interest. Requests from a third party must always be balanced against the interests of the individual concerned. The Chief Executive will make this judgement, and consult the Chairman or other Trustees where necessary.

7. Requests for Copies of Information held

7.1 GDPR gives any individual the right to find out what information an organisation stores about them. All requests should be passed to the Chief Executive and should only be accepted in writing.

7.2 Normally Arts for Dementia will endeavour to provide a copy of any record containing Personal Data without charge, but a charge of £10 may be made at the Chief Executive’s discretion, to be paid in advance, if significant effort is required to assemble the information or to discourage frivolous or vexatious requests.

7.3 Arts for Dementia will respond to requests for information held as soon as practicable and at most within one month.

8. Contracts with data processors and other third party providers

8.1 Realistically Arts for Dementia is not in a position to dictate contract terms to large service providers, such as those who may act as Data Processor. Nevertheless it is important that we are aware of the terms on which services are provided and the risks that may follow. The Chief Executive should, to their reasonable satisfaction, ensure that the third party provides processes and systems that manage Personal Data for which Arts 4 Dementia is responsible in a manner consistent with GDPR.

8.2 Where practicable, contractors should be notified that compliance with GDPR is a requirement of our contractual relationship and failure to comply will be grounds for termination by us for breach of contract.

9. Personal Data relating to Staff and Trustees

9.1 Information collected for recruitment and selection will only be used for that purpose. It will only be retained so long as there is a clear need for it. DBS (Disclose and Barring Service) procedures will be followed where checks need to be made and Arts for Dementia will make a record only that a satisfactory/ unsatisfactory check was made, not hold detailed information on file.

9.2 Arts for Dementia will not collect or retain information that is irrelevant or excessive to the purpose for which it is collected. Information will be deleted and documents destroyed when there is no longer a clear business need for them to be retained.

9.3 Personal information on staff and trustees will always be labelled as confidential, stored securely and handled with respect.

9.4 Staff and Trustee Personal Data will not be disclosed to another organisation without express permission of the individual concerned, unless covered by the statutory exceptions listed in sections 4 and 5 above. Requests for references will only be given with that persons’ consent.

9.5 Only the Chief Executive will have access to confidential records with the following exceptions:


– the Chairman will normally hold confidential information relating to the Chief Executive and to Trustees;
– the Payroll provider and treasurer will have access to payroll information;
– the size of the charity is such that individual’s remuneration will be apparent from financial information prepared for the Trustees.


 If you use the website to submit event listings please see the additional policy below:

Who we are

Our website address is: https://artsfordementia.org.

Comments

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Cookies

If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Who we share your data with

If you request a password reset, your IP address will be included in the reset email.

How long we retain your data

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website, we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where your data is sent

Visitor comments may be checked through an automated spam detection service.