Data Protection Policy – Tyn-Y-Nant Christian Centre
Who we are and how we process your personal data
Tyn-Y-Nant Christian Centre is the data controller. This means it decides how your personal data is processed and for what purposes. Tyn-Y-Nant Christian Centre uses personal data about living individuals for the purpose of general centre administration and communication.
Tyn-Y-Nant Christian Centre recognises the importance of the correct and lawful treatment of personal data. All personal data, whether held on paper, on computer or other media, will be subject to the appropriate legal safeguards as specified in the General Data Protection Regulation (GDPR).
Tyn-Y-Nant Christian Centre fully endorses and adheres to the eight principles of the GDPR. These principles specify the legal conditions that must be satisfied in relation to obtaining, handling, processing, transportation and storage of personal data. Employees, Volunteers and any others who obtain, handle, process, transport and store personal data for Tyn-Y-Nant Christian Centre must adhere to these principles.
The Principles of GDPR
The principles require that personal data shall:
1. Be processed fairly and lawfully and shall not be processed unless certain conditions are met.
2. Be obtained for a specified and lawful purpose and shall not be processed in any manner incompatible with that purpose.
3. Be adequate, relevant and not excessive for those purposes.
4. Be accurate and where necessary, kept up to date.
5. Not be kept for longer than is necessary for that purpose.
6. Be processed in accordance with the data subject’s rights.
7. Be kept secure from unauthorised or unlawful processing and protected against accidental loss, destruction or damage by using the appropriate technical and organisational measures.
8. Not be transferred to a country or territory outside the European Economic Area, unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
Tyn-Y-Nant Christian Centre will treat all your personal information as private and confidential and not disclose any data about you to anyone other than those with a relevant leadership responsibility in order to facilitate the administration of the centre activities.
All Tyn-Y-Nant Christian Centre staff and volunteers who have access to Personal Data will be required to agree to the Data Protection Policy.
There are four exceptional circumstances to the above permitted by law:
1. Where we are legally compelled to do so.
2. Where there is a duty to the public to disclose.
3. Where disclosure is required to protect your interest.
4. Where disclosure is made at your request or with your consent.
Use of Personal Information
Tyn-Y-Nant Christian Centre will use your data for five main purposes:
1. For the day-to-day administration of the centre and associated activities, including administration relating to Merseyside Christian Youth Camps (MCYC), lettings, preparation of rotas, maintaining financial records and records of giving for audit and tax purposes.
2. To fundraise and promote the interests of the charity
3. To manage our employees and volunteers
4. To contact you to keep you informed of Tyn-y-nant and MCYC activities and events.
5. For statistical analysis; gaining a better understanding of centre uses and demographics.
N.B. although collated data, for example the number of individuals attending MCYC camps, may be transferred to a third party for analysis, no personal data will be disclosed.
The website database
Information contained on the website database will not be used for any other purposes than set out in this section. The database is accessed through the cloud and therefore, can be accessed through any computer or smart device with internet access. The server for the database is located in the UK.
1. Access to the database is strictly controlled through the use of passwords, which are selected by the individual.
2. Those authorised to use the database only have access to their specific area of use within the database. This is controlled by the Data Controller and other specified administrators. These are the only people who can access and set these security parameters.
3. People who will have secure and authorised access to the database are limited to those with a leaderships responsibility as determined by designated Tyn-Y-Nant Christian Centre Trustees.
4. The database will NOT be accessed by any authorised users outside of the EU, in accordance with the Data Protection Act and the GDPR, unless prior consent has been obtained from the individual whose data is to be viewed.
5. All access and activity on the database is logged and can be viewed by the Database Controller.
6. Subject Access – all individuals who are the subject of personal data held by Tyn-Y-Nant Christian Centre are entitled to:
- Ask what information the centre holds about them and why
- Ask how to gain access to it
- Be informed how to keep it up to date
- Be informed what Tyn-Y-Nant Christian Centre is doing to comply with its obligations under the Data Protection Act / the GDPR
7. Personal information will not be passed onto any third parties outside of the organisation.
8. Subject Consent – The need to process data for normal purposes has been communicated to all data subjects. In some cases, if the data is sensitive, for example information about health, race or gender, express consent to process the data must be obtained.
If we wish to use your personal data for a new purpose, not covered by this policy, then we will provide you with a new policy explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, we will seek your prior consent to the new processing.
Rights to Access Information
Employees and other subjects of personal data held by Tyn-Y-Nant Christian Centre have the right to access any personal data that is being held in certain manual filing systems. This right is subject to certain exemptions: Personal Information may be withheld if the information relates to another individual.
Any person who wishes to exercise this right should make the request in writing to the Tyn-Y-Nant Christian Centre Data Controller, using the standard letter which is available online from www.ico.gov.uk. If personal details are inaccurate, they can be amended upon request.
Tyn-Y-Nant Christian Centre aims to comply with requests for access to personal information as quickly as possible, but will ensure that it is provided within 30 days of receipt of a completed form unless there is good reason for delay. In such cases, the reason for delay will be explained in writing to the individual making the request.
Tyn-Y-Nant Christian Centre will ensure that your personal information will not be kept for longer than is necessary for that purpose. Our retention of your personal data is as follows:
|Record Type||Retention Period|
|Email address for marketing purposes||Until consent is withdrawn|
|Information required for activities that you have participated in||Until end of camp season|
|Financial information, including information relating to payments or donations you have made||As per statutory requirements|
|Medical Information relating to any care that has been administered to you during a specific activity you have participated in||10 years from date of activity or until 25 birthday, whichever is the longer|