Privacy Policy (UK GDPR)

Ensuring your data is protected

Prept. Foundation

Privacy Policy (UK GDPR)

Prept. Foundation (“we”, “us”, “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and in line with our charitable values.

This policy applies to all personal data processed by Prept. Foundation, including data relating to beneficiaries, donors, volunteers, partners, staff, and website users.

 

  1. Who We Are

Organisation name: Prept. Foundation
Legal status: Charity
Registered address: 3 Queen Square, London WC1N 3AR
Website: prept.foundation

 

Prept. Foundation delivers educational food workshops and related charitable activities.

We are the data controller for the personal data we process, unless otherwise stated.

 

Data Protection Lead

The appointed Data Protection Lead for Prept. Foundation is:

Name: Jessica Aggarwal
Role: Co-Founder, Prept. Foundation
Email: [email protected]

 

The Data Protection Lead is responsible for overseeing data protection compliance, safeguarding coordination, and responding to data protection requests.

 

  1. Data Protection Principles

We process personal data in accordance with the UK GDPR principles. Personal data shall be:

  • Processed lawfully, fairly, and transparently
  • Collected for specified, explicit, and legitimate purposes
  • Adequate, relevant, and limited to what is necessary
  • Accurate and kept up to date
  • Kept only as long as necessary
  • Processed securely to protect against unauthorised access, loss, or damage

 

  1. Personal Data We Collect

We may collect and process the following types of personal data through online forms, emails, our website, and in-person interactions:

  1. a) Identity and Contact Data
  • Name
  • Address
  • Email address
  • Telephone number
  1. b) Beneficiary and Programme Data
  • Information required to deliver workshops or services
  • Feedback and attendance records
  • Dietary, allergy, or accessibility requirements (may include special category data)
  1. c) Donor and Supporter Data
  • Donation history
  • Gift Aid declarations
  • Communication preferences
  1. d) Staff and Volunteer Data
  • Application and recruitment information
  • Employment or volunteer agreements
  • References and right-to-work checks
  • Training records and role-related information
  1. e) Technical Data
  • IP address
  • Website usage data (via cookies)

 

  1. Special Category Data and Safeguarding

Where necessary, we may process special category personal data (such as health, dietary, allergy, or accessibility information) to ensure safe, inclusive, and appropriate delivery of our services.

 

This data is processed in line with our Safeguarding Policy and only where:

  • Explicit consent has been provided, or
  • Processing is necessary to protect the vital interests of individuals, or
  • Processing is required for safeguarding children or vulnerable adults

 

Access to safeguarding-related data is strictly limited to authorised staff and volunteers who require it to carry out their role. Such data is handled with enhanced confidentiality and security measures.

 

  1. How We Use Personal Data (Lawful Basis)

We only process personal data where we have a lawful basis, including:

  • Consent – where you have given clear permission
  • Contract – where processing is necessary for an agreement
  • Legal obligation – where required by law (e.g. charity or tax law)
  • Legitimate interests – where necessary for our charitable purposes and not overridden by your rights
  • Vital interests – to protect someone’s life
  • Public task – where processing supports our charitable objectives

 

  1. How We Collect Personal Data

We collect personal data through:

  • Online forms on our website
  • Email correspondence
  • Our website and cookies
  • In-person interactions at workshops, events, and training sessions
  • Donations and fundraising activities
  • Third parties (such as partner organisations or schools, where appropriate and lawful)

 

  1. Data Sharing

We do not sell personal data.

We may share data with:

  • Trusted service providers (e.g. IT systems, payment processors)
  • Partner organisations involved in delivering our charitable activities
  • Regulators or authorities where legally required

 

All third parties are required to respect data security and process data in accordance with the law.

 

  1. International Data Transfers

We do not routinely transfer personal data outside the UK. Where this is necessary, appropriate safeguards (such as UK adequacy regulations or standard contractual clauses) will be in place.

 

  1. Data Security

We have implemented appropriate technical and organisational measures to protect personal data, including:

  • Access controls and password protection for digital systems
  • Secure storage of paper records collected in person
  • Role-based access for staff and volunteers
  • Staff and volunteer training on data protection and confidentiality
  • Procedures for detecting, reporting, and responding to data breaches

 

  1. Data Retention

Prept. Foundation retains personal data in line with its Data Retention Policy, ensuring data is kept only for as long as necessary and proportionate to its purpose.

 

Indicative retention periods include:

  • Beneficiary and programme records: retained for the duration of the programme and up to 3 years afterwards for reporting and safeguarding purposes
  • Donor and financial records: retained for 6 years to comply with charity and tax law
  • Staff and volunteer records: retained for the duration of engagement and up to 6 years after it ends
  • Safeguarding records: retained in line with safeguarding legislation and best practice

 

Data is securely deleted, destroyed, or anonymised once retention periods expire.

 

  1. Volunteers, Staff, and Confidentiality

All staff and volunteers are required to:

  • Follow our Data Protection, Safeguarding, and Confidentiality policies
  • Access personal data only where necessary for their role
  • Complete data protection and safeguarding training
  • Report any data breaches or concerns immediately

 

Failure to comply may result in disciplinary action or termination of involvement with the charity.

 

  1. Your Data Protection Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request erasure of your data
  • Restrict processing
  • Object to processing
  • Request data portability
  • Withdraw consent at any time

 

To exercise your rights, contact us using the details below.

 

  1. Complaints

If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner’s Office (ICO):

Website: ico.org.uk
Telephone: 0303 123 1113

 

We encourage you to contact us first so we can address your concerns.

 

  1. Cookies

Our website may use cookies to improve functionality and user experience. A separate Cookie Policy provides more detail.

 

  1. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be available on our website.

 

  1. Contact Us

For questions about this policy, data protection requests, or safeguarding-related data concerns, please contact:

Data Protection Lead: Jessica Aggarwal
Email: [email protected]
Address: 3 Queen Square, London WC1N 3AR

Team Contacts

We encourage and enable staff, volunteers, and other stakeholders to raise serious concerns within the charity rather than overlooking a problem. Please report those concerns immediately to the Designated Safeguarding Lead or Deputy Safeguarding Lead.

Other contact details:
Charity Commission (www.gov.uk/complain-about-charity)

 

Need more assistance?

Contact Us