Privacy Policy (UK GDPR)
Ensuring your data is protected
Prept. Foundation
Privacy Policy (UK GDPR)
Prept. Foundation (“we”, “us”, “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and in line with our charitable values.
This policy applies to all personal data processed by Prept. Foundation, including data relating to beneficiaries, donors, volunteers, partners, staff, and website users.
-
Who We Are
| Organisation name: | Prept. Foundation |
| Legal status: | Charity |
| Registered address: | 3 Queen Square, London WC1N 3AR |
| Website: | prept.foundation |
Prept. Foundation delivers educational food workshops and related charitable activities.
We are the data controller for the personal data we process, unless otherwise stated.
Data Protection Lead
The appointed Data Protection Lead for Prept. Foundation is:
| Name: | Jessica Aggarwal |
| Role: | Co-Founder, Prept. Foundation |
| Email: | [email protected] |
The Data Protection Lead is responsible for overseeing data protection compliance, safeguarding coordination, and responding to data protection requests.
-
Data Protection Principles
We process personal data in accordance with the UK GDPR principles. Personal data shall be:
- Processed lawfully, fairly, and transparently
- Collected for specified, explicit, and legitimate purposes
- Adequate, relevant, and limited to what is necessary
- Accurate and kept up to date
- Kept only as long as necessary
- Processed securely to protect against unauthorised access, loss, or damage
-
Personal Data We Collect
We may collect and process the following types of personal data through online forms, emails, our website, and in-person interactions:
- a) Identity and Contact Data
- Name
- Address
- Email address
- Telephone number
- b) Beneficiary and Programme Data
- Information required to deliver workshops or services
- Feedback and attendance records
- Dietary, allergy, or accessibility requirements (may include special category data)
- c) Donor and Supporter Data
- Donation history
- Gift Aid declarations
- Communication preferences
- d) Staff and Volunteer Data
- Application and recruitment information
- Employment or volunteer agreements
- References and right-to-work checks
- Training records and role-related information
- e) Technical Data
- IP address
- Website usage data (via cookies)
-
Special Category Data and Safeguarding
Where necessary, we may process special category personal data (such as health, dietary, allergy, or accessibility information) to ensure safe, inclusive, and appropriate delivery of our services.
This data is processed in line with our Safeguarding Policy and only where:
- Explicit consent has been provided, or
- Processing is necessary to protect the vital interests of individuals, or
- Processing is required for safeguarding children or vulnerable adults
Access to safeguarding-related data is strictly limited to authorised staff and volunteers who require it to carry out their role. Such data is handled with enhanced confidentiality and security measures.
-
How We Use Personal Data (Lawful Basis)
We only process personal data where we have a lawful basis, including:
- Consent – where you have given clear permission
- Contract – where processing is necessary for an agreement
- Legal obligation – where required by law (e.g. charity or tax law)
- Legitimate interests – where necessary for our charitable purposes and not overridden by your rights
- Vital interests – to protect someone’s life
- Public task – where processing supports our charitable objectives
-
How We Collect Personal Data
We collect personal data through:
- Online forms on our website
- Email correspondence
- Our website and cookies
- In-person interactions at workshops, events, and training sessions
- Donations and fundraising activities
- Third parties (such as partner organisations or schools, where appropriate and lawful)
-
Data Sharing
We do not sell personal data.
We may share data with:
- Trusted service providers (e.g. IT systems, payment processors)
- Partner organisations involved in delivering our charitable activities
- Regulators or authorities where legally required
All third parties are required to respect data security and process data in accordance with the law.
-
International Data Transfers
We do not routinely transfer personal data outside the UK. Where this is necessary, appropriate safeguards (such as UK adequacy regulations or standard contractual clauses) will be in place.
-
Data Security
We have implemented appropriate technical and organisational measures to protect personal data, including:
- Access controls and password protection for digital systems
- Secure storage of paper records collected in person
- Role-based access for staff and volunteers
- Staff and volunteer training on data protection and confidentiality
- Procedures for detecting, reporting, and responding to data breaches
-
Data Retention
Prept. Foundation retains personal data in line with its Data Retention Policy, ensuring data is kept only for as long as necessary and proportionate to its purpose.
Indicative retention periods include:
- Beneficiary and programme records: retained for the duration of the programme and up to 3 years afterwards for reporting and safeguarding purposes
- Donor and financial records: retained for 6 years to comply with charity and tax law
- Staff and volunteer records: retained for the duration of engagement and up to 6 years after it ends
- Safeguarding records: retained in line with safeguarding legislation and best practice
Data is securely deleted, destroyed, or anonymised once retention periods expire.
-
Volunteers, Staff, and Confidentiality
All staff and volunteers are required to:
- Follow our Data Protection, Safeguarding, and Confidentiality policies
- Access personal data only where necessary for their role
- Complete data protection and safeguarding training
- Report any data breaches or concerns immediately
Failure to comply may result in disciplinary action or termination of involvement with the charity.
-
Your Data Protection Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request erasure of your data
- Restrict processing
- Object to processing
- Request data portability
- Withdraw consent at any time
To exercise your rights, contact us using the details below.
-
Complaints
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner’s Office (ICO):
| Website: | ico.org.uk |
| Telephone: | 0303 123 1113 |
We encourage you to contact us first so we can address your concerns.
-
Cookies
Our website may use cookies to improve functionality and user experience. A separate Cookie Policy provides more detail.
-
Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be available on our website.
-
Contact Us
For questions about this policy, data protection requests, or safeguarding-related data concerns, please contact:
| Data Protection Lead: | Jessica Aggarwal |
| Email: | [email protected] |
| Address: | 3 Queen Square, London WC1N 3AR |
Team Contacts
We encourage and enable staff, volunteers, and other stakeholders to raise serious concerns within the charity rather than overlooking a problem. Please report those concerns immediately to the Designated Safeguarding Lead or Deputy Safeguarding Lead.
Other contact details:
Charity Commission (www.gov.uk/complain-about-charity)