Pulmonary Fibrosis Trust Privacy Policy

Policy statement

The Pulmonary Fibrosis Trust (PF Trust) is committed to protecting the privacy and security of your personal information. This Privacy Policy gives you detailed information on when and why we collect your personal information, how we use it and how we keep it secure.

GDPR

The General Data Protection Regulation (GDPR) is a new piece of EU legislation that came into force on 25th May 2018. The core intent of GDPR is to give individuals more control over the use of their personal data and how data is stored. This legislation replaces the Data Protection Act 1998 (DPA), giving more rights to you as an individual and more obligations to organisations holding your personal data.

One of the rights is a right to be informed, which means we have to give you more information than previously about the way in which we use, share and store your personal information.

Data Controller

The Pulmonary Fibrosis Trust is the Data Controller, please see below our full contact details:

Main Office:
Pulmonary Fibrosis Trust
c/o Executive Business Support City Wharf
Davidson Road
Lichfield
Staffordshire
WS14 9DZ

01543 442 191

info@pulmonaryfibrosistrust.org

Registered Charity No: 1149901

How we collect your personal information

Version: May2018EW

We collect your information when you decide to interact with us, make a donation, and receive support services and products. We also collect information about your computer to look at how our audience use our website, so that we can offer the best possible experience. Information collected includes your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths.

Purpose and lawful reasons for processing your data

For all goods and services donated by PF Trust to patients or carers, we will process your data to ensure the correct delivery of those goods and services. The lawful reason for processing data in these cases is contractual and will include:

  • ●  Donated products or services to you by PF Trust
  • ●  Received donationsWe may process your data for emotional support requests and general enquiries. We will only process your data in this regard and contact you if we have obtained your consent to do so. The lawful reason for processing data in this case is consent and will include:
  • ●  Emotional support
  • ●  General enquires – such as donating and fundraising informationWe may process data which falls within the special categories of data. The below list details the data which are processed that falls in that category:

● Health information – for any product or services requests. This information will only be used with your consent and to ensure we are able to deliver any special requirements you may have. The lawful reasons for processing these data are consent and explicit consent as given by you, the data subject.

Data sharing

PF Trust will never share, sell or trade your personal information to any third parties for marketing purposes.

We currently use other organisations to manage our activities: Executive Business Support (EBS) for our administrative support. These organisations have access to your data in order to perform services on our behalf. We make sure anyone who provides a service for us enters into an agreement with us and meets our standards for data security. They will not use your data for anything other than the clearly defined purpose relating to the service that they are providing.

We may share your data with representatives or volunteers of PF Trust for the purposes of providing product or service request approval. The data shared with these individuals is

Version: May2018EW

limited only to individuals that meet our standards for data security. Regular training and auditing is conducted to ensure that these aims are met.

If you have requested a product or service to be donated by PF Trust, your data will be shared with companies that provide such product or service, however, your data will only be shared with your explicit consent. Supply companies frequently used by PF Trust are Pure O2 Ltd and Betterlife (Lloyds Pharmacy group). Please see the website for a complete list. Every third party supplier will have a signed agreement with the PF Trust ensuring their data security is to PF Trust’s security standards.

Types of information we collect

We only collect the information that is necessary to carry out our business and provide a particular service that you have requested, and to keep you informed. This includes:

  • ●  Demographic information (Name, address, contact details, e-mail address)
  • ●  Health information
  • ●  Product or service requests and approvals
  • ●  Fundraising activity
  • ●  Donation activity
  • ●  Support needsHow your information is storedYour information either will be stored on our website, in a restricted secure server environment or on cloud based software that we have verified as suitable and which meets our security requirements. Only individuals that need to will be allowed to access your data and this access is limited to the requirements of the individual’s task. We ensure that all individuals, volunteers and staff members of any third party have been trained to understand their requirements in keeping your data safe. Any hard copy paper records which may be sent to the organisation, such as application forms and health documentation, are stored in a secure environment and where relevant transferred into electronic format.How long is your information kept

    We will only keep your data for as long as it is necessary, the majority of information will be retained for 7 years to coincide with financial requirements. Personal data processed for general enquiries and emotional support will be retained for 3 years. For areas that you have withdrawn your consent or asked for your data to be removed it will be destroyed as soon as possible within 1 month. If we decide not to destroy your data we will inform you as to why we have made this decision.

Version: May2018EW

Your choices

You should find it easy to access and amend the personal information that we hold on you. If you wish to update information or communication preferences please contact us by telephoning 01543 442191 or emailing info@pulmonaryfibrosistrust.org.

Your rights

You have the following rights as an individual:

  • ●  The right to be informed
  • ●  The right of access
  • ●  The right to rectification
  • ●  The right to erasure
  • ●  The right to restrict processing
  • ●  The right to data portability
  • ●  The right to object
  • ●  Rights in relation to automated decision making and profiling.If you have any queries or concerns regarding the use of your data and the above rights, please contact us by telephone on 01543 442191 or by email info@pulmonaryfibrosistrust.org.The supervisory authority is the ICO and comments and concerns can be raised with them Further information on data protection regulations and laws can be found: https://ico.org.uk/for-the-publicAdditional information

    No personal data is transferred outside of the European Economic Area (EEA).