GDPR Policy

Last updated 5th January 2024.

We know that you care how information about you is used and shared and we appreciate your trust in us to do that carefully and sensibly. This Privacy Notice describes how we collect and process your personal information.

Drop the Mask Productions CIC, Voluntary Action Centre, Kingsland Square, St Marys, Southampton, SO14 1NW

• Contact is Gregory White – gregory@dropthemask.co.uk

• We use personal data for customer management, training, marketing and recruitment.

• The categories whose personal data is processed are employees, clients and company contacts by agreement.

• The categories of personal data we process are contact details and information for training purposes.

• The categories of recipients of personal data we have are just for ourselves for our training and employment purposes.

• The retention schedules for personal data is mainly 12 months. Other internal data regarding employees will be kept in-line with legal retention guidance.

• Our technical and organisational security measures and safeguarding for protecting personal data is to have all devices used listed under a policy and registered on systems where software processes personal information. Multi-factor authentication is used for all devices or new hardware. We only use recognised software as Microsoft 365 and HubSpot for processing and storage of personal data and other information.

Our purposes of processing are for training and employment purposes. The legitimate interests for the processing are for employment and training purposes.

The retention periods for the personal data is usually 12 months, unless agreement for a longer retention is agreed or under contract policy.

The rights available to individuals in respect of the processing re available as is the right ­­­to withdraw consent, and the right to lodge a complaint with a supervisory authority.

Provision

We provide individuals with privacy information at the time we collect their personal data from them.

If we obtain personal data from a source other than the individual it relates to, we provide them with privacy information: within a reasonable period of obtaining the personal data and no later than one month; if we plan to communicate with the individual, at the latest, when the first communication takes place; or if we plan to disclose the data to someone else, at the latest, when the data is disclosed.

We provide the information in a way that is: concise, transparent, intelligible, easily accessible; and use clear and plain language.


Changes to the information

We regularly review and, where necessary, update our privacy information.

If we plan to use personal data for a new purpose, we update our privacy information and communicate the changes to individuals before starting any new processing.

We undertake an information audit to find out what personal data we hold and what we do with it.

We put ourselves in the position of the people we’re collecting information about.

We carry out user testing to evaluate how effective our privacy information is.

When providing our privacy information to individuals, we use a combination of a layered approach, to allow the privacy information to be up to date and as relative as possible.