Our privacy notice

Download this privacy notice as a PDF here. 

What this privacy notice covers

Head to Toe Charity is committed to protecting your personal information and being transparent about what information we hold, whether you are a donor, volunteer, fundraiser or supporter.

The purpose of this notice is to give you a clear explanation about how Head to Toe Charity uses the personal information you provide to us and that we collect, whether online, via phone, email, in letters or in any other correspondence.

We ensure that we use your information in accordance with all applicable laws concerning the protection of personal data and information. This notice explains:

  • What information Head to Toe Charity may collect about you;
  • How we will use that information;
  • Whether we disclose your details to anyone else;
  • Your choices regarding the information your provide to us; and
  • How we use cookies to provide services to you or to improve your use of our websites.

This notice is written in accordance with the General Data Protection Regulation 2018 and the Data Protection Act 2018. The Charity is registered with the Information Commissioner’s Office (ICO) as a Data Controller via Cambridgeshire and Peterborough NHS Foundation Trust under reference number Z6521629.

If you have any queries about this notice please contact the Charity Manager at: Head to Toe Charity, Elizabeth House, Fulbourn Hospital, Cambridge Road, Cambridge CB21 5EF. Alternatively, you can call 01223 219 708 or email charity@cpft.nhs.uk.

By using our website or any of our services, or providing us with any personal data, you agree to your personal data being used and disclosed in the manner set out in the notice.

Who we are

Head to Toe Charity is the official NHS charity for Cambridgeshire and Peterborough NHS Foundation Trust (CPFT) and we support NHS services delivered by CPFT across Cambridgeshire and Peterborough. We are registered with the Charity Commission and our registered charity number is 1099485.

Head to Toe Charity is also legally part of CPFT, although it operates as an entity in its own right. Head to Toe Charity staff are employees of CPFT.

General Data Protection Regulation (GDPR)

In carrying out our day to day activities we process and store personal information relating to our supporters and we are therefore required to adhere to the requirements of the General Data Protection Regulation 2016/679 and the Data Protection Act 2018.

We take our responsibilities under these regulations very seriously and we ensure the personal information we obtain is held, used, transferred and otherwise processed in accordance with the GDPR and all other applicable data protection laws and regulations.

Collecting personal information

Personal information is information that can be used to identify you. It can include your name, data of birth, email address, postal address, telephone number, mobile number, fax number, bank account details, debit/credit card details and whether you are a UK tax payer so that we can claim Gift Aid (please rest assured we do not collect information about your actual tax payments, just whether you are a tax payer).

We collect this information when you donate money, undertake fundraising activities on our behalf, or otherwise give us personal information online, in paper or electronic form, over the phone or face to face.

We will use your personal information for administrative purposes and to enable you to make your donation and for us to acknowledge its receipt and reassure you about the use of your gift.

We collect information in the following ways:

  • Information you give us directly. For example, when you make a donation to us, fundraise for us, register for an event, engage with us on social media or otherwise provide us with personal information. When you register for fundraising or make a donation, we’ll ask for personal information – like your name, address, email and telephone number to store with your account.
  • When you give it to us indirectly. Your information may be shared with us by independent organisations such as online fundraising services, fundraisers taking part in events, funeral directors, solicitors and other similar intermediate organisations. Those people will only provide us with information when you have indicated that you want to support Head to Toe Charity, and with your consent. If you have any concerns about the use and transfer of such information you should check their privacy policies when you provide your information to understand how they will process the information you give them.
  • When you give permission to other organisations to share it. Depending on the privacy and settings you may apply to social media and messaging apps such as Facebook and Twitter, you might provide permission for us to access information from your accounts with those services. You may also provide information for third party organisations to share your information with us where you require us to contact you when you are interested in making a donation.
  • From other publicly available information sources. In some cases, for example to verify your address or post code when we have a legitimate reason to contact you (for example the information on a donation form is illegible), we reserve the right to use publicly available sources of information such as Google and other search engines to ensure the accuracy of the information we hold about you.
  • Information we get from your use of our website. We collect information about your website and social media usage and engagement using cookies, page-tagging techniques and data analytics available through each social media platform (where applicable).

Data Protection law recognises that certain categories of personal information are more sensitive. This is known as ‘sensitive personal data’ and covers health information, race, religious beliefs and political opinions. We do not usually collect sensitive personal data about our supporters unless there is a clear reason for doing so, such as participation in a marathon or similar fundraising event or where we need this information to ensure that we provide appropriate facilities or support to enable you to participate in an event.

We may also collect sensitive personal data if you make the information public or if you tell us about your experiences relating to a personal health condition, the NHS or CPFT. This will enable us to provide you with information about a particular healthcare area that may be relevant and of interest to you. However we will always make it clear to you when we collect this information from you, what sensitive personal data we are collecting and why.

Our staff members are trained to handle your information correctly and to protect your confidentiality and privacy.

Our website

All Head to Toe Charity websites are subject to CPFT's online Privacy Notice that is available on their website. By using any Head to Toe Charity website, you consent to the data practices described in CPFT's online Privacy Notice.

For all areas of our websites which collect personal information then the following will also apply:

  • Head to Toe Charity websites collect personal information when you register, supply feedback or complete any form with us.
  • The website you sign up to will collect information such as your name, email and post code. Once you registered with that website you will no longer be anonymous to us when you submit that form.
  • Although we cannot 100 per cent guarantee the security of any information you transmit to us, we enforce strict procedures and security features to protect your information and prevent unauthorized access.
  • As part of the registration process and continued use of Head to Toe Charity services, you agree that any information you submit to the Charity will always be accurate, correct and up to date.
  • We collect and retain information about your transactions with us so that we can process your transactions and deal with future queries efficiently and effectively.
  • We collect and retain information about your interactions with us so that we can process your interactions and deal with future queries.
  • We use cookies to provide you with a good experience when browsing our website and to improve the functionality of our site. For further information about the use of cookies, please refer to the CPFT's online Privacy Notice.
  • We use Google Analytics for our web analytics.
  • All Head to Toe Charity websites are managed by the Charity and the CPFT Communications Team.
  • If you post or send any content that we believe to be inappropriate, offensive or in breach of any laws, such as defamatory content on our forums or social media pages, we may use your personal information to inform relevant third parties such as your internet provider or law enforcement agencies.

Your debit and credit card information

If you use your credit or debit card to donate to us, buy something or pay for a registration online or over the phone, we will ensure that this is done securely and in accordance with the Payment Card Industry Data Security Standard. You can find our more information about PCI DSS here - www.pcisecuritystandards.org

 All donations to us by debit or credit card are made via trusted third party processors. Your debit or credit card details are never received or stored by the Charity. Those companies who take donations on our behalf are: PayPal, JustGiving and Virgin Money Giving. These companies ensure your data is processed safely and securely. For further information about how they process and store your data when making a donation please visit their websites.

If we receive an email containing any credit or debit card details, it will be immediately deleted, no payment will be taken and you will be notified about this.

Job applicants

If you apply to work at Head to Toe Charity via Cambridgeshire and Peterborough NHS Foundation Trust then the information you provide at the time of application is subject to the Trust’s online Privacy Notice, which is available via their website.

The Charity will only use the information it receives during recruitment to process your application and to monitor recruitment statistics. If we want to disclose that information to someone outside the Charity or the Trust – for example, if we need a reference – we will makes sure we tell you beforehand, unless we are required to disclose this information by law.

If you commence employment at Head to Toe, your data will be processed in accordance with your employment contract and other applicable policies.

Grant applicants

 If you apply to Head to Toe Charity for charitable funding then the information you provide at the time of application and during the application process will be processed in accordance with this privacy notice.

How might we use your data?

We may use your information for a number of purposes including the following:

  • To process donations we may receive from you;
  • To process a grant application we may have received from you;
  • To create an account for you on our database if you register with or donate to us;
  • For administration purposes (for example, we may contact you regarding a donation you have made or an event you have registered for);
  • For internal record keeping, including the management of any feedback or complaints;
  • To provide you with services, products or information you have requested or which we feel may interest you where you have consented to being contacted;
  • To fundraise in accordance with our internal policies and procedures;
  • To provide you with information about our work or our activities that you have agreed to receive;
  • To invite you to participate in surveys or research (although this is entirely voluntary);
  • To analyse and improve the services we offer;
  • We may supplement the personal information we collect from you with publicly available information to create a profile of your interests, preferences and level of potential donations so that we can contact you in the most appropriate way and with the most relevant information if you have agreed to being contacted;
  • We may assess your personal information for the purposes of credit risk reduction or fraud prevention (unfortunately this is because some people target charities for illegal purposes such as money laundering and, quite rightly, we are required to monitor financial activity and report suspected fraud to the appropriate authorities).

To comply with our obligations as a charity, we must take reasonable and appropriate steps to know who our donors are, particularly where significant sums are being donated. This means we may conduct research, including accessing information which is already publicly available, on prospective donors, partners or volunteers to ensure it would be right for us to accept support, whether that is from an individual or an organisation. This will help to give assurance that the donation is not from an inappropriate source and to safeguard our reputation. This does not mean that we will question every donation, nor that we will research lots of personal and other details about every donor. Any information we do collect for this purpose will only consist of what is necessary for us to meet these requirements and will be processed in line with your rights – see the section ‘Your rights’ below for more information about your rights.

Legal basis

If you give us your information whilst making a donation, registering for fundraising, applying for grant funding or any other charitable purpose we are required to store and process that data for administration and auditing purposes and we will keep your information for as long as is required to enable us to operate our services but will not keep your information for any longer than necessary.

This does not include using your personal information for marketing purposes unless you have given agreed we can do so.

Therefore, we rely on obtaining your consent to our use of your personal information for marketing purposes. This is the case, for example, where we seek to obtain your consent to receive email marketing about the Head to Toe Charity. For more information on marketing communications, please see the ‘Marketing materials’ section of this notice.

Marketing materials

When you contact us and provide us with your information – for example, when making a donation, registering for fundraising or applying for a grant – we may contact you by post, email, telephone or text for administration purposes relating to the reason you have contacted us.

We also like to contact you to tell you how your support has made a difference through the Charity, give you updates and details about our work, let you know about our fundraising and how you can get involved. We do this by post and email. These are known as marketing materials. We will only do this with your consent. 

It is your choice as to whether you want to receive marketing materials from us; how you want to receive them and the types of material you want to receive. You will only ever get marketing materials from us if you have consented to receive them and only ever by the method(s) you tell us. We will not use your information for marketing purposes if you have indicated to us that you do not wish to be contacted for such purposes.

At the point at which we collect your data – for example, when making a donation, registration forms, Gift Aid declarations – we will ask you what for these contact preferences. This can be digitally, verbally and/or in paper format. If you do not want us to use your personal information for marketing purposes please indicate your preferences at this point.

Two years after your most recent contact or donation – unless you tell us otherwise when we contact you – we will archive/suppress your personal information and you will no longer receive marketing materials from us.

You can also change your contact preferences at any time by contacting us on 01223 219708 or emailing charity@cpft.nhs.uk or by updating your contact preferences using the form on our website. You can also opt-out of our marketing emails by clicking on the ‘unsubscribe’ link at the end of the email.

Keeping your records

We store your personal information as an account on our Charity’s database and on a financial ledger and, in certain circumstances, in a paper format.

We will retain certain information in respect of donations and financial transactions securely for as long as the law requires to for tax and accounting purposes (generally seven (7) years). When your information is no longer required, we will ensure it is deleted and/or disposed of in a secure manner at the appropriate time.

Where we may store your information

Any information we collect is stored securely and processed in the UK or European Economic Area except for our Charity Customer Relationship Management database service eTapestry, which is provided by Blackbaud Europe, which is based in the US. The latter is covered by the international Privacy Shield Framework. (The EU-US Privacy Shield Framework is designed by the US Department of Commerce and the European Commission to provide companies on both sides of the Atlantic with a mechanism to comply with data protection requirements when transferring personal data from the European Union to the United States in support of transatlantic commerce).

For financial and technical reasons we may, on occasion, need to use the services of a supplier outside the European Economic Area (EEA), however we will ensure that your information is held in compliance with European data protection regulations.

By submitting your personal information you agree to this transfer, storing or processing at a location outside the EEA. We will take all steps reasonably necessary to ensure that your data is kept secure and in accordance with this privacy notice.

Information sharing and disclosure

We do not, and will never, sell or swap your personal information with any third parties.

We may share your information with parties who provide a service to us and are our data processors and with Cambridgeshire and Peterborough NHS Foundation Trust. These are trusted partner organisations that work with us in connection with our charitable purposes, and other entities that act as fundraisers for the Charity, sell Head to Toe Charity products or provide Charity information and marketing (subject to your communication preferences and our internal policies and procedures). Our trusted partners are required to comply strictly with our instructions and data protection laws and we will make sure that appropriate controls are in place. We enter into contracts with all of our data processors and regularly monitor their activities to ensure they are complying with Head to Toe Charity policies and procedures.

We may disclose your information to third parties where we are under a duty to do so in order to comply with any legal obligation (for example to government bodies and law enforcement agencies), or in order to enforce or apply our rights (including in relation to our website or other applicable terms and conditions) or to protect the Charity, for example in cases of suspected fraud or defamation.

Under 16s

If you are under 16 and would like to get involved, please ensure that you have consent from a parent or guardian before giving us your personal information. When we collect information about a child or young person aged under 16 we will make it very clear as to the reasons for collecting this information and how it will be used.

When you register to fundraise for us we will specifically ask for information about your age, usually your date of birth, and will ask for confirmation of consent from a parent or guardian.

Patient information

We do not have access to patient information.

In cases where information about your care/treatment, or the care/treatment of a family member, is relevant to the purpose and aims of your donation, and where you wish to share that information with us, we will only receive that information with your express and documented permission.

Vulnerable supporters

We recognise the importance of protecting our vulnerable supporters and follow the guidance issued by the Institute of Fundraising on treating donors fairly. We believe this helps to support our staff and fundraisers who come into contact with supporters in providing high quality customer care, ensuring anyone donating to the Charity is in a position to make a free and informed decision.

The accuracy of your information

We aim to ensure that all information we hold about you is accurate and, where necessary, kept up-to-date. If any of the information we hold about you is inaccurate or incomplete and either your advise us or we become otherwise aware, we will ensure it is amended and updated as soon as possible.

Your ability to edit and delete your information

You can edit your Head to Toe Charity account information and/or communication preferences, including your address and contact details, at any time by contacting us on 01223 219708 or emailing charity@cpft.nhs.uk or by updating your contact preferences using the form on our website.

Your rights to your personal information

You have the following rights with regard to your personal information:

  • The right to be informed
  • The right of access
  • The right to rectification
  • The right to erasure
  • The right to restrict processing
  • The right to data portability
  • The right to object
  • Rights in relation to automated decision making and profiling.

These include the right to request a copy of the personal information we hold about you, the right to have your personal information deleted from our records, the right to object to how we are processing your personal information and the right to obtain and reuse your personal information for your own purposes.

Should you wish to exercise these rights we require you to prove your identity with two pieces of approved identification. Please address requests to: Charity Manager, Head to Toe Charity, Elizabeth House, Fulbourn Hospital, Cambridge Road, Cambridge CB21 5EF and we will respond within 30 days. Please provide as much information as possible about the nature of your contact with us to help us locate your records.

Where you have provided your consent for our use of your personal information, you always have a right to withdraw your consent at any time.

Changes to this privacy notice

This notice is correct as of May 2018.

We may update the terms of this notice at any time, so please do check it from time to time. We will notify you about significant changes in the way we treat personal information by sending a notice to the primary email address you have provided to us or by placing a prominent notice on our website(s). By continuing to use our website and any of our services and/or the continued provision of personal information after we have posted the changes to this notice will be taken to mean you are in agreement with those changes.

Complaints, compliments or comments

If you are unhappy with our work or something that we have done or failed to do, we want to know about it. We also welcome your views on what we do well. Your comments enable us as an organisation to learn and continuously improve our services.

Please get in touch wit h us on 01223 219718 or email charity@cpft.nhs.uk.

Download this privacy notice as a PDF here. 

The page was last updated on 25 May 2018 by cjones.

Head to Toe Charity

Elizabeth House, Fulbourn Hospital
Cambridge, CB21 5EF
T 01223 219708
E charity@cpft.nhs.uk

Registered Charity No. 1099485

Facebook Logo
Facebook Logo
Facebook Logo Twitter Logo