Privacy Policy for COVEY

Introduction 

COVEY is committed to protecting the privacy and security of our beneficiaries, supporters, and partners. This Privacy Policy outlines how we collect, use, store, and protect personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. 

 

Who We Are 

COVEY is a registered charity in Scotland (Charity Number: SC020754) dedicated to supporting children, young people and families to become more resilient, safe and better equipped to reach their full potential. 

Our registered address is Regent House, 9 High Patrick Street, Hamilton, South Lanarkshire, ML3 7JA 

For any data protection queries, please contact us at office@coveybefriending.org.uk 

 

Data We Collect 

We may collect and process the following types of personal data: 

  • Personal Identification Information: Name, date of birth, and contact details (address, email, phone number). 

  • Sensitive Information: Data relating to additional support needs, ways that COVEY can support, the impact of social barriers on everyday life and health, special educational needs, and other relevant data necessary for our services. 

  • Digital Interaction Data: IP addresses, browser type, and pages accessed on our website. This is collected to optimise our website and inform website updates to better meet the needs of our audience. 

 

How We Collect Data 

We collect personal data through various methods, including: 

  • Direct Interactions: Filling out forms on our website, participating in our programs, or contacting us via phone, email, or post. 

  • Third-Party Integrations:  

  • Jotform: Used to create online forms for event registrations, surveys, and feedback. 

  • Salesforce: Employed as our Customer Relationship Management (CRM) system to securely store and manage personal data. 

 

Use of Personal Data 

We use personal data to: 

  • Provide and manage our services. 

  • Process donations and send receipts. 

  • Communicate updates, newsletters, and information about our activities (with consent). 

  • Comply with legal obligations and regulatory requirements. 

 

Legal Basis for Processing 

Our processing of personal data is based on: 

  • Consent: When individuals have provided clear consent for processing their personal data for specific purposes. 

  • Contractual Necessity: Processing necessary for the performance of a contract with the data subject. 

  • Legal Obligation: Compliance with a legal obligation to which we are subject. 

  • Legitimate Interests: Processing necessary for our legitimate interests, provided these do not override the rights and freedoms of the data subjects. 

 

Data Sharing and Third Parties 

We do not sell or rent personal data to third parties. However, we may share data with trusted third-party service providers to facilitate our operations: 

Jotform

  • Jotform collects data through forms created for our services. Jotform complies with GDPR requirements and ensures data protection.

  •  Jotform use a 256-bit SSL connection which is the same level of protection that is used in the online banking industry. 

  • COVEY’s Jotform account has two-factor authentication enabled. 

  • Jotform has built-in Spam protection features. 

Salesforce

  • Salesforce stores and manages personal data securely as our CRM system and is contractually obligated to process data in accordance with our instructions and the UK GDPR.

  • Salesforce is hosted in a secure server environment that uses a firewall and advanced technology to prevent interference or access from outside intruders. 

  • Access to sensitive data within Salesforce is restricted to ensure only staff members, who need the referral data to progress our services, can access it. 

  • Within Salesforce, SSL technology protects information using both server authentication and data encryption.

Squarespace 

  • COVEY’s SSL (Secure Sockets Layer) certificate (HTTPS) is enabled on Squarespace. 

  • Squarespace website traffic is encrypted via SSL providing a secure end to end connection for website hosts and visitors. SSL prevents hackers from impersonating a website or stealing information submitted by visitors to the site. 

  • COVEY is using the most up to date versions of Third-party integrations - Jotform and Salesforce. This is subject to regular review to ensure these are always up to date. 

  • Two-factor authentication is enabled on COVEY’s Squarespace account. 

 

Data Security 

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. This includes secure servers, encryption, and access controls. 

 

Data Retention 

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements. Specific retention periods are determined based on the nature of the data and legal obligations. 

 

Your Rights 

Individuals have the following rights regarding their personal data: 

  • Access: Request access to their personal data. 

  • Rectification: Request correction of inaccurate or incomplete data. 

  • Erasure: Request deletion of their data under certain conditions. 

  • Restriction: Request restriction of processing under certain circumstances. 

  • Data Portability: Receive their data in a structured, commonly used format. 

  • Objection: Object to processing based on legitimate interests or direct marketing. 

If you wish to exercise these rights and retract consent relating to your data, please contact us at office@coveybefriending.org.uk. We will respond within one calendar month and action your request as soon as possible. 

 

Children's Data 

Given our focus on children's services, we ensure that any data collected about children is done with appropriate consent from parents or guardians and is handled with the utmost care and security. 

 

Website Analytics 

This website collects personal data to power our site analytics, including: information about your browser, network and your IP address. 

This information may also include details about your use of this website, including: clicks, internal links, pages visited, scrolling, searches and timestamps. 

We share this information with Squarespace, our website analytics provider, to learn about site traffic and activity. 

 

Cookies 

Our website uses cookies and similar technologies, which are small files or pieces of text that download to a device when a visitor accesses a website or app. For information about viewing the cookies dropped on your device, please visit https://support.squarespace.com/hc/en-us/articles/360001264507-The-cookies-Squarespace-uses#toc-check-your-cookies 

These necessary and required cookies are always used, which allow Squarespace, our hosting platform, to securely serve our website to you. 

These analytics and performance cookies are used on this website only when you acknowledge our cookie banner. This website uses analytics and performance cookies to view site traffic, activity, and other data. 

 

Changes to This Policy 

We may update this Privacy Policy periodically. Any significant changes will be communicated through our website or direct communication channels.