GDPR Policy (CIC)
Digital Voice for Communities CIC Policy 107
Reviewed annually or in case of changes in law or near misses.
Last Updated: January 2026
Next Update: January 2027
Supervisory body: Information Commissioner's Office (ICO)
Who this policy applies to:
All staff, including but not limited to the Director, the board of Directors, paid staff, volunteers, freelance associates and anyone working for or on behalf of Digital Voice for Communities.
Individuals who engage with Digital Voice for Communities: those that attend and help coordinate our courses and events or contact us via email, post, telephone or social media platforms (including but not limited to our website, facebook, instagram, LinkedIn and TikTok).
The purpose of this policy:
● To provide genuine control for the individual and transparency about processing of data.
● To provide staff and volunteers with the overarching principles that guide our approach to general data protection regulation.
● To provide explicit purpose and use of any data collected.
● Ensure collected data is relevant and has storage limitations
● Ensure appropriate security and safeguarding methods have been established.
Digital Voice for Communities identifies that general data protection regulation is not limited to how the data is collected but also how it is used, retained and monitored. We are committed to protecting your personal information and being transparent about what information we hold for you.
Information collection
Information you give us
“Personal data meaning any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier.” - ICO
For example, whenever you sign onto a course we will store the personal data you give us such as your name, email address, postal address and telephone number, any paper copies are disposed of immediately after the information is recorded
Information about your interactions with us
For example when you like a post or contact us on our Facebook page there will be a record of our interaction. Equally, when we send you a mailing via post we store a record of this, and in the case of emails we keep record of any interaction within our emailing platforms: Outlook and Google Mail.
Information about third parties
We may occasionally receive information about you from third parties.
For example, we may be given your personal data by a local authority, who has specific consent from you, to allow us to contact you about a course or event.
We do not sell or intentionally share data but some data may still be processed by third party services that we use.
Sensitive personal data
Data Protection law recognises that certain categories of personal information are more sensitive such as health information, race, religious beliefs and political opinions. We do not normally collect this type of information unless there is a clear reason for doing so.
For example, we may collect health information about participants on our courses if it were going to ensure their safety.
Maintaining your personal information
We store your personal information for up to ten years so that any subsequent contact can be fulfilled in a relevant, timely and respectful manner.
If there are any aspects of your record that are inaccurate or you would like to be removed from our records you can do this by contacting us using the contact details at the end of this policy.
Any objections you make regarding the processing of your data will be stored or your records will subsequently be deleted from our files.
Security of your personal data
We will put into place appropriate physical and digital measures (both in terms of our procedures and technology we use) to keep your personal data as secure as possible.
Our files are in both physical and digital format. Physical files are protected in a secure location monitored by CCTV. Electronic data and databases are store on secure computer systems within Google Drive and we control who has access to the information.
The way we use your information
We use the information you provide about yourself strictly to contact you directly.
We use return email addresses to answer the email we receive. Such addresses are not used for any other purpose and are not shared with outside parties.
Finally, we never use or share the personal data provided to us via our website.
Your rights to your personal information
You have a right to request a copy of the personal information we hold about you and to have any inaccuracies in this data corrected, have the data removed or object to your data being used for marketing. If you wish to exercise this right please contact us using the details at the end of this policy.
Direct and marketing communications
We aim to communicate with you about the work we do in ways you find relevant, timely and respectful. To do this, we use data we have stored about you, such as courses or events you have booked on in the past, as well as any preferences you may have told us about.
We use our legitimate organisational interest as the basis for communications by post and email. You may object to receiving these at any time using the contact details at the end of this policy.
We may also contact you about our work by telephone, however we will always get explicit consent from you before doing this. Please bear in mind that this does not apply to telephone calls we may need to make to you relating to the running of a course or event. For example, as to not cause you any inconvenience, we will let you know in advance if any course or event scheduling has been changed.
Photography
We occasionally take photographs of individuals participating in our courses and events to be used for marketing purposes.
We ask for explicit consent before taking and using photographs.
Explicit consent will be collected in procedures adhering to our privacy policy.
Complaints
In the event you feel we have not acted within the law in relation to your personal data, please contact us with the details and the complaint will be acknowledged within 30 days and respond to in a timely manner: contact@digitalvoice.org.uk
Changes
Our Privacy Policy may change from time to time. We will not reduce your rights under this Privacy Policy without your explicit consent. We will post any Privacy Policy changed on our website.
Policy Review Dates
This policy will be reviewed annually or after any changes in legislation or near misses.
GDPR Policy (CIO)
Digital Voice for Communities CIO Policy 107
Reviewed annually or in case of changes in law or near misses.
Last Updated: January 2026
Next Update: January 2027
Supervisory body: Information Commissioner's Office (ICO)
Who this policy applies to:
All staff, including but not limited to the CEO, the board of trustees, paid staff, volunteers, freelance associates and anyone working for or on behalf of Digital Voice for Communities.
Individuals who engage with Digital Voice for Communities: those that attend and help coordinate our courses and events or contact us via email, post, telephone or social media platforms (including but not limited to our website, facebook, instagram, LinkedIn and TikTok).
The purpose of this policy:
● To provide genuine control for the individual and transparency about processing of data.
● To provide staff and volunteers with the overarching principles that guide our approach to general data protection regulation.
● To provide explicit purpose and use of any data collected.
● Ensure collected data is relevant and has storage limitations
● Ensure appropriate security and safeguarding methods have been established.
Digital Voice for Communities identifies that general data protection regulation is not limited to how the data is collected but also how it is used, retained and monitored. We are committed to protecting your personal information and being transparent about what information we hold for you.
Information collection
Information you give us
“Personal data meaning any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier.” - ICO
For example, whenever you sign onto a course we will store the personal data you give us such as your name, email address, postal address and telephone number, any paper copies are disposed of immediately after the information is recorded
Information about your interactions with us
For example when you like a post or contact us on our Facebook page there will be a record of our interaction. Equally, when we send you a mailing via post we store a record of this, and in the case of emails we keep record of any interaction within our emailing platforms: Outlook and Google Mail.
Information about third parties
We may occasionally receive information about you from third parties.
For example, we may be given your personal data by a local authority, who has specific consent from you, to allow us to contact you about a course or event.
We do not sell or intentionally share data but some data may still be processed by third party services that we use.
Sensitive personal data
Data Protection law recognises that certain categories of personal information are more sensitive such as health information, race, religious beliefs and political opinions. We do not normally collect this type of information unless there is a clear reason for doing so.
For example, we may collect health information about participants on our courses if it were going to ensure their safety.
Maintaining your personal information
We store your personal information for up to ten years so that any subsequent contact can be fulfilled in a relevant, timely and respectful manner.
If there are any aspects of your record that are inaccurate or you would like to be removed from our records you can do this by contacting us using the contact details at the end of this policy.
Any objections you make regarding the processing of your data will be stored or your records will subsequently be deleted from our files.
Security of your personal data
We will put into place appropriate physical and digital measures (both in terms of our procedures and technology we use) to keep your personal data as secure as possible.
Our files are in both physical and digital format. Physical files are protected in a secure location monitored by CCTV. Electronic data and databases are store on secure computer systems within Google Drive and we control who has access to the information.
The way we use your information
We use the information you provide about yourself strictly to contact you directly.
We use return email addresses to answer the email we receive. Such addresses are not used for any other purpose and are not shared with outside parties.
Finally, we never use or share the personal data provided to us via our website.
Your rights to your personal information
You have a right to request a copy of the personal information we hold about you and to have any inaccuracies in this data corrected, have the data removed or object to your data being used for marketing. If you wish to exercise this right please contact us using the details at the end of this policy.
Direct and marketing communications
We aim to communicate with you about the work we do in ways you find relevant, timely and respectful. To do this, we use data we have stored about you, such as courses or events you have booked on in the past, as well as any preferences you may have told us about.
We use our legitimate organisational interest as the basis for communications by post and email. You may object to receiving these at any time using the contact details at the end of this policy.
We may also contact you about our work by telephone, however we will always get explicit consent from you before doing this. Please bear in mind that this does not apply to telephone calls we may need to make to you relating to the running of a course or event. For example, as to not cause you any inconvenience, we will let you know in advance if any course or event scheduling has been changed.
Complaints
In the event you feel we have not acted within the law in relation to your personal data, please contact us with the details and the complaint will be acknowledged within 30 days and respond to in a timely manner: contact@digitalvoice.org.uk
Photography
We occasionally take photographs of individuals participating in our courses and events to be used for marketing purposes.
We ask for explicit consent before taking and using photographs.
Explicit consent will be collected in procedures adhering to our privacy policy.
Changes
Our Privacy Policy may change from time to time. We will not reduce your rights under this Privacy Policy without your explicit consent. We will post any Privacy Policy changed on our website.
Policy Review Dates
This policy will be reviewed annually or after any changes in legislation or near misses.