1. Who we are
In this Privacy Policy, references to the HEADTURNED Foundation or the Foundation mean the organisation responsible for this website and the projects it describes.
The Foundation is the controller of personal information collected through this website and associated public-facing channels, which means we decide how and why that data is used.
2. Scope of this Policy
This Policy explains how we handle personal information when you use this website, contact us, sign up for updates, or make donations through our online channels.
Separate privacy information may apply to other services or platforms operated within the wider HEADTURNED ecosystem, including the HEADTURNED PPV platform when that platform goes live.
3. Information we collect
The information we collect depends on how you interact with us. It may include:
- Contact details, such as your name, email address, and any information you provide when you contact us.
- Donation information, such as the amount given, the method used, and, where relevant, Gift Aid declarations.
- Communication preferences, such as whether you want to hear from us by email or other channels.
- Technical information, such as IP address, browser type, device information, and usage data collected through logs and cookies. See our Cookie Policy for more detail.
4. How we use personal information
We may use personal information for purposes such as:
- responding to enquiries or requests you send us;
- processing donations and related administration, including Gift Aid records where applicable;
- sending updates or information you have asked to receive, and managing your communication preferences;
- operating, maintaining, and improving this website and our digital services; and
- meeting legal, regulatory, governance, and record keeping obligations.
5. Legal bases we rely on
We will only use personal information where we have a lawful basis to do so. The main bases we may rely on include:
- Consent, for example where you actively choose to receive updates or newsletters.
- Legitimate interests, for example to manage our relationship with supporters, operate this website, and communicate about our work where this does not override your rights and interests.
- Legal obligations, for example to maintain certain records for tax, accounting, safeguarding, or reporting purposes.
- Performance of a contract, where we need to process information in order to deliver something you have requested from us.
7. International transfers
Some of our service providers may be based outside the country where you live. Where this involves transferring personal information across borders, we aim to ensure that appropriate safeguards are in place in line with applicable data protection requirements.
8. How long we keep personal information
We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, including to meet legal, accounting, safeguarding, or reporting requirements.
The exact retention period depends on the type of information and the context in which it was collected. For example, donation records may need to be kept for longer than routine enquiry emails.
9. How we keep information secure
We use a combination of technical and organisational measures to help keep personal information secure, including access controls and appropriate security practices for systems, services, and devices.
No system can be guaranteed as completely secure, but we aim to reduce risk in a reasonable and proportionate way and to respond appropriately to suspected data breaches.
11. Your rights
Depending on where you live and the law that applies, you may have rights in relation to your personal information. These may include:
- the right to access a copy of your personal data;
- the right to ask us to correct inaccurate information;
- the right to ask us to delete certain information;
- the right to object to certain processing or ask us to restrict it; and
- the right to withdraw consent where we rely on consent as our legal basis.
To exercise these rights, or to ask a question about them, you can contact us using the details on our website. We may need to request information to confirm your identity before responding.
12. How to contact us about privacy
If you have questions about this Policy or how we handle personal information, you can contact us using the contact details on our website, including our contact form.
You may also have the right to raise concerns with a data protection regulator. If you are unsure which regulator is appropriate, we will try to signpost where we reasonably can.
13. Changes to this Policy
We may update this Privacy Policy from time to time, for example to reflect changes in law, guidance, or how the Foundation operates.
When we do, we will update the version published on this page. Where changes are significant, we may also highlight them on our website or through other appropriate channels.