1. Your Personal Data – What is it?
Personal data relates to a living individual who can be identified from that data. Identification can be by the information alone or in conjunction with any other information in the data controller’s possession or likely to come into such possession. The processing of personal data is governed by the General Data Protection Regulation (the ‘GDPR’).
2. Who Am I?
Elizabeth White is the data controller. This means Elizabeth White decides how your personal data is processed and for what purposes.
3. How do I process your personal data?
I comply with my obligations under the GDPR by keeping personal data up to date; by storing and destroying data securely using password protection and locked physical storage; by not collecting or retaining excessive amounts of data; by reviewing data I hold regularly; by protecting personal data from loss, misuse, unauthorised access and disclosure and by ensuring that appropriate technical measures are in place to protect personal data. I use your personal data for the following purposes:
• To enable me to reply to your enquiries by phone, email, Skype or Zoom
• To provide you with a service of spiritual direction, supervision, training or group workshops
• To maintain manual records – stored anonymously and securely – for the purposes of best practice in spiritual directees, pastoral supervisees and group/workshop attendees.
• To send you email notice of events, activities and projects which may be of interest to you, if you sign up to receive this
• To maintain my own accounts and records
I use a third party provider, currently MailChimp, to deliver my email news. I gather statistics around email opening and clicks using industry standard technologies to help monitor and improve the email news. Mailchimp’s privacy notice can be found here https://mailchimp.com/legal/privacy You can unsubscribe to mailings at any time by clicking the unsubscribe link at the bottom of any of my emails to you. I don’t rent or trade email lists with other organisations and businesses.
I may use other third party services from time to time such as website maintenance who I engage for the purpose of completing tasks and providing services to you on my behalf. I verify that these third party services are all GDPR compliant (or are working towards GDPR compliance), and are certified under the EU-US Privacy Shield Framework (or are working towards certification) where these organisations are based outside of the EU.
4. What is the legal basis for processing your personal data?
A. Consent – for mailing lists, gathered via online sign-up forms
B. Contract – for providing you with spiritual direction, supervision, workshops and training
With Contract as the lawful basis I also operate a separate condition of explicit consent for processing special categories of data such as race, ethnic origin, politics, religion, health, sex life, sexual orientation etc, for the purpose of providing you with best practice in spiritual direction, pastoral supervision and training whilst protecting your privacy.
5. Sharing your personal data
Your personal data will be treated as strictly confidential. I will only share your data with third parties with your consent – apart from two conditions. Firstly, if you have contracted to receive spiritual direction or supervision and I believe you are at risk of causing immediate harm to yourself or others, I reserve the right to break confidentiality in order to prevent harm; if at all possible, I will discuss this with you first. Secondly, if required by a court of law i.e. in giving evidence in criminal proceedings.
6. How long do I keep your personal data?
If you are on my email list I keep your name and email data for as long as you are signed up; you may unsubscribe at any time. If you are a directee or supervisee your paper and electronic records are held for 7 years after your final appointment and are then securely destroyed. Skype ID is deleted after 2 years.
7. Your rights and your personal data
Unless subject to an exemption under the GDPR, you have the following rights with respect to your personal data:
• The right to request a copy of your personal data which I hold about you, provide within one calendar month
• The right to request that I correct any personal data if it is found to be inaccurate or out of date
• The right to request your personal data is erased where it is no longer necessary for me to retain such data
• The right to withdraw your consent to the processing of data at any time
• The right to request that I provide you with your personal data and where possible, to transmit that data directly to another data controller (known as the right to data portability)
• The right, where there is a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing
• The right to object to the processing of personal data
• The right to lodge a complaint with the Information Commissioners Office
8. Further processing
If I wish to use your personal data for a new purpose, not covered by this Data Privacy Notice, then I will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, I will seek your prior consent to the new processing.
9. Contact Details
To exercise all relevant rights, queries or complaints please in the first instance contact the Elizabeth White at email@example.com
You can contact the Information Commissioners Office on 0303 123 1113 or via email https://ico.org.uk/global/contact-us/email/ or at the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
I am not responsible for the availability or content of external sites that may be linked to, from this site. If you find a broken link or if you have any questions or concerns about a link, please contact me.