Who we are
Tŷ Hafan Children’s Hospice is a registered charity (No: 1047912) and charitable company limited by guarantee (No: 307406), registered in Wales.
In this privacy notice, ‘we’ also includes reference to our two trading subsidiaries:
- Crackerjackpot Ltd., which operates the Tŷ Hafan lottery. It is a company limited by guarantee, registered in Wales (No: 08221671) and licensed with the Gambling Commission.
- Tŷ Hafan Trading Ltd., which manages our retail operation including our shops, warehouse and online trading outlets. It is a company limited by guarantee, registered in Wales (No: 05129825).
The registered address of all three entities is Hayes Road, Sully CF64 5XX
How we collect information about you
We may collect your personal information when you:
- Donate to us
- Sign up to receive our newsletter
- Join our lottery
- Register to take part in one of our events
- Fundraise on our behalf
- Complete a gift aid declaration form
- Contact us via email, phone, SMS, social media, post or our websites
- Apply to work or volunteer for us
We may also collect information about your visit to our website(s). This data is not personal to you and is used to help us better understand how visitors use our site and to analyse the website performance so we can develop the website to be effective and easy to navigate.
We may also receive information about you from third parties, but only if you’ve given them permission to share your information.
Occasionally we may obtain information from publicly available sources such as Companies House or the media to help us determine how you might prefer to engage with us.
What personal information we collect
We collect personal information such as name, address, email, phone number, date of birth (if appropriate) and bank account details. We do not store credit or debit card details.
When can we process your information – the legal basis
We process your information only in situations where: you have expressly given us your consent, to fulfil a contract we have with you, when it is our legal duty, or where we are confident it is in our legitimate interests to do so.
How we use your personal information
We use your personal information to process your donations or regular payment agreements, to claim Gift Aid on your donations (if appropriate), to provide you with any products purchased, to support you with fundraising endeavours, to invite you to participate in surveys, for research and analysis purposes, or for administrative or regulatory reasons.
We may also use your details to keep you updated about how your support is helping Tŷ Hafan, to inform you of forthcoming events and to contact you for fundraising purposes. This could be by email, telephone or text message (if you have given us your consent) or by post (if we believe we have a legitimate reason to do so, and assuming you have not already told us you do not want to be contacted by post).
If you no longer wish to receive these types of communications, or want to change your contact preferences, please follow the “unsubscribe” link on a relevant email or contact us directly: call 029 2053 2255, email email@example.com or write to us at Supporter Care, Tŷ Hafan, Hayes Road, Sully CF64 5XX.
To help us to decide who to send our communications to, and to ensure the communications you receive are relevant to you, we may use profiling techniques and data analysis. This could include analysing the support we receive from different geographic areas and/or from different age groups (if known to us) or by looking at previous donations or types of support.
We may append Experian Mosaic data to the personal information you have given us. This anonymous postcode-based demographic data can help us better understand our supporters and predict how likely they are to be interested in a fundraising campaign or supporter event.
We may also use trusted third-party specialists who collate information about you that is publicly available. This helps us understand more about you and your potential level of engagement and ensures we connect with you in the most appropriate way.
You can “opt out” your data being analysed and used in this way by contacting our Supporter Care team By calling 029 2053 2255, emailing firstname.lastname@example.org or in writing to Supporter Care, Tŷ Hafan, Hayes Road, Sully CF64 5XX.
Sharing your information
We never sell or share any information about you to other organisations for their own marketing purposes.
Your details may need to be shared with third party organisations who are working on our behalf. These organisations act as data processors and in these instances, we ensure a contractual agreement is in place to protect your data and ensure it is only retained for the necessary duration. They may include:
- Printing and mailing companies
- IT service providers
- Specialist payment and direct debit processors
- Event providers
- Insurance and legal firms
Your personal information may also be shared with third party organisations to comply with legal or regulatory obligations. An example of such an organisation is HM Revenue and Customs who require certain information for Gift Aid claim processing.
Social Media and Digital Advertising
We may provide your email address to social media platforms such as Facebook to match it with your social media account. This is known as “Creating Custom Audiences” and means we can share information with you on social media based on your interests and also make sure you are excluded from social media advertising that won’t be relevant to you. We may also provide your email address to create a “Lookalike Audience” of people with similar interests to you.
If we use your email address in this way, it is uploaded securely and encrypted within a portal designed for this specific purpose. It cannot be used for any other purpose. We will only use your email address if you have opted in to receive our marketing.
If you do not want us to use your data for social media advertising, please contact us on 029 2053 2255 or email us at email@example.com
How we protect your information
We are committed to respecting your privacy and protecting your personal information. All our staff receive data protection training and we conduct privacy impact risk assessments before implementing new systems or using personal information in new ways.
We take all reasonable care and precautions to protect your information and use a combination of both physical and technical measures. We hold Cyber Essentials certification and our computer network is protected by Sophos anti-virus software and guarded by robust firewalls which are regularly tested by our IT team. When choosing our computer systems, we prioritise those which enable your information to be stored and processed on servers located within the UK or the European Union. Where we do have to transfer information internationally, we only use reputable suppliers and have contracts in place to ensure your information is protected to the same standard as if it were stored in the UK.
The information you provide via our website forms is safeguarded through SSL encryption while it is transferred to us. Online financial transactions are processed using Stripe which is certified to the highest industry standards including Payment Card Industry Data Security Standards (PCI DSS) compliance.
While we take appropriate steps to protect your information online, we also protect your information offline. If you provide your credit or debit card details over the phone or on a paper form, only staff who are trained to process card payments will see your details. We do not retain your credit or debit card details after processing your donation or payment.
CCTV surveillance is operational in some of our premises for security purposes. The footage is only retained for a maximum of 30 days unless we are required to disclose the images for legal reasons.
Cookies and Third Party websites
Please visit http://www.aboutcookies.org.uk/managing-cookies for information on how to change your preferred browser settings. For more information on Google Analytics cookies, please visit their website.
We may link you to third party websites which have their own privacy policies. We encourage you to look at their policies as we cannot accept any responsibility or liability for the content or security of those websites.
Retaining your data
We will keep your personal information only for as long as the purposes detailed in this policy and in accordance with our retention schedule. Personal information that we no longer need is securely disposed of, or anonymised.
You are in control of how we use your data.
If you think any of the information we hold on you is incomplete or inaccurate, you have the right to have this rectified. Please contact us via our Supporter Care team (details) and we will check its accuracy and correct it.
You have the right to request a copy of your personal information held by us (known as a Subject Access Request).
If you feel we should no longer be using your personal information, you can request that we stop using or erase the information we hold on you. We will confirm that the information has been restricted, anonymised or removed. However, we may not be able to comply with your request if we are required to retain your information for legal or audit purposes. If these circumstances apply, this will be fully explained to you.
To exercise any of your rights under data protection law, please contact Data Protection Officer, Tŷ Hafan, Hayes Road, Sully CF64 5XX or email firstname.lastname@example.org.
How to make a complaint
If you would like to make a complaint about the processing of your data, please contact us at the address above. If you are not satisfied with our response, you can complain to the Information Commissioners Office (ICO) by calling their helpline on 0303 123 1113 or via their website https://ico.org.uk/concerns/
Changes to this Privacy Notice
This Privacy Notice was last updated on 23/08/2023