Data Protection Policy {#sec:data-protection}
Last Updated 2 August 2022
Data Controller
Russ Bubley
Data Access Requests
Requests may be made in any form and via any medium. Acknowledgement of receipt will be made as soon as reasonably possible.
Searches for data will be made using search tools on our computers and also using the search tools of our cloud data storage services. Records returned will be manually checked, assembled and sent (subject to legal requirements).
We may charge for this, subject always to the statutory limits.
Data Currency
Where we become aware that personal data we hold is not up to date, we will update it as soon as reasonably practicable.
Data Storage
Data will be stored on computers belonging to the company, and on a variety of cloud services, including those offered by Google and Dropbox.
The status of data held on servers outside of the UK (or EU or EEA) has changed repeatedly over the years.
The ICO’s guide on the matter https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/international-transfers-after-uk-exit/,
Google provides extensive documentation covering UK GDPR compliance, and the Firm has opted in to the relevant options for UK/EU data protection.
Data Security
Electronic data will be accessible only via password protected devices, and IT security will be maintained at an appropriate level for the size and scope of the business we conduct.
Paper documents will be held in filing cabinets with no public access. We may utilize storage facilities in the future, in which case this policy will be updated.
Public details held by the ICO
This section contains copies of data held by the ICO, which is largely in question-answer format.
Headline information
- Organisation type: Limited company
- Company registration number: 08094327
- Company name: I For Change Ltd.
- Organisation address: I For Change Ltd., 19 Rookfield Avenue, London, London, Greater London, N10 3TS, UNITED KINGDOM,
- Customer enquiries contact details: Director, [email protected], I For Change Ltd., 19 Rookfield Avenue, London, London, Greater London, N10 3TS, UNITED KINGDOM,
- Sector: Finance, insurance and credit
- Nature of work: Consultant
- Are you a public authority? No
- Is your organisation a charity or have exempt charitable status? No
- Does your organisation have more than 249 staff? No
Details about the information you process
Nature of work - Consultant
Description of processing
The following is a broad description of the way this organisation/data controller processes personal information. To understand how your own personal information is processed you may need to refer to any personal communications you have received, check any privacy notices the organisation has provided or contact the organisation to ask about your personal circumstances.
Reasons/purposes for processing information
We process personal information to enable us to provide consultancy and advisory services, to promote our services, to make financial promotions, to maintain our own accounts and records and to support and manage our employees.
Type/classes of information processed
We process information relating to the above reasons/purposes. This information may include:
- personal details
- family, lifestyle and social circumstances
- business activities of the person whose personal information we are processing
- goods and services provided
- financial details
- education details
- employment details
We also process sensitive classes of information that may include:
- physical or mental health details
- offences and alleged offences
- racial or ethnic origin
- religious or other beliefs of a similar nature
Who the information is processed about
We process personal information about our customers, clients and employees, complainants and enquirers, suppliers, advisers and other professional experts.
Who the information may be shared with
We sometimes need to share the personal information we process with the individual themself and also with other organisations. Where this is necessary we are required to comply with all aspects of the Data Protection Act (DPA). What follows is a description of the types of organisations we may need to share some of the personal information we process with for one or more reasons.
Where necessary or required we share information with:
- business associates and other professional advisers
- family, associates and representatives of the person whose personal data we are processing
- financial organisations
- current, past or prospective employers
- educators and examining bodies
- suppliers and services providers
- traders in personal data
Additional reasons
Providing financial services and advice
Personal information is also processed in order to provide financial services and advice. For this reason the information processed may include name, contact details, family details, lifestyle and social circumstances, financial details, goods and services and sensitive classes of information that may include physical or mental health details. This information may be about clients, family and associates of clients, suppliers and enquirers. Where necessary or required this information is shared with the data subjects themselves, professional advisers and consultants, services providers, credit reference agencies.
Transferring information overseas
Do you transfer data outside the European Economic Area (EEA)?
Yes
Does this cover all your processing of personal information?
Yes
Notes on DBS checks
As a matter of good practice and regulatory compliance we obtain DBS (Disclosure & Barring Service) checks in respect of certain employees and directors. This is to help us fulfil our obligation to ensure that these individuals are fit and proper.
As with all sensitive data, it will be stored in such a way as to give access only to those with a need to access it.
In accordance with section 124 of the Police Act 1997, DBS certificate information is only passed to those who are authorised to receive it in the course of their duties. We maintain a record of all those to whom certificates or certificate information has been revealed and it is a criminal offence to pass this information to anyone who is not entitled to receive it.
Certificate information is only used for the specific purpose for which it was requested and for which the applicant’s full consent has been given.