About this policy
We’re committed to processing data lawfully, safely and securely and have stringent data security and data protection practices in place.
This policy gives a broad overview of how our organisation processes personal data but if you would like to find out how the project you are involved in is processing your personal data, please contact firstname.lastname@example.org and someone will be in touch (within 30 days) to answer your questions.
References to ‘we’ or ‘us’ are to the South East Wales Energy Agency, registered charity number 1055753, registered company number, 2898698. Our registered office is at Clarence House, Clarence Place, Newport, NP19 7AA.
Why we process data
There are many reasons why we process personal data, including but not limited to:
- Giving advice on keeping warm at home and energy efficiency improvements.
- Administering grants, and other funding streams.
- Providing mentoring or advice to groups or individuals on topics like community energy, low carbon planning and community development.
- Organising and holding events, workshops and consultations.
- Carrying out energy audits, technical assessments or measuring energy usage.
- Evaluating and improving the services we offer and the work that we do.
- Supporting human resources and administrative functions – like processing payments and recruiting staff.
The lawful basis for processing
The lawful basis for processing your data will depend on how you are interacting with us and what your relationship is with us. Below is a short overview of the different lawful basis we are using to process personal data:
- Consent: In some situations, we will ask for your consent to process your data. It may also apply in some of our other projects or activities.
- Statutory obligation: we are obliged by law to process certain types of personal data, for example, processing salary information for taxation.
- In some extremely limited circumstances, we may rely on vital interests. This would only be in situations where we needed to process data in order to protect someone’s life.
- Our legitimate interests: as detailed below.
Our legitimate interests include:
Providing comprehensive advice through the advice line and in-person advice services
In order to provide comprehensive advice on energy it is necessary for us to collect certain personal information so that we are able to give accurate information and relevant support.
Maintaining relationships with relevant business contacts
This includes people working within our sector or with whom we have a professional relationship. We may process personal information in order to inform people of our work, events and activities, coordinate collaborative work, or to invite people to participate in research or policy work. It also includes processing personal data for the purposes of highlighting the need for and benefits of policy change e.g. to MPs, relevant local authority personnel or other policymakers.
It’s necessary for us to process certain types of personal data in order to manage our relationships with our employees and trustees. We also consider it in our legitimate interests to process personal data for the purposes of recruitment.
General operation and administration
This includes responding to solicited requests and enquiries, complying with internal and external governance procedures, financial reporting and communicating for purposes such as facilities management.
Contacting people to inform them about services of benefit to them
This includes contacting people to let them know about services, specific activities, projects or events which may be of direct benefit to them or where they are likely to have a professional interest e.g. contacting neighbourhood planning groups to inform them about financial support for their activities.
We have balanced our legitimate interests against the rights and freedoms data subjects have enshrined in law through the General Data Protection Regulations and consider that they have a minimal privacy impact. However, you have the right to opt-out or object to our processing of your data on the basis of legitimate interests. You can do so by emailing email@example.com and we’ll respond within 30 days.
Sharing and storing data
In some situations for some projects we will share your information with other organisations. This may include the funder or other project partners (e.g. to obtain a grant or help from them). We will make it clear whether we intend to share your data when we obtain it from you.
We store and process most of the personal data we hold on our secure, internal system which is hosted on servers located in the UK. When we keep paper records, they are stored in locked cupboards accessible only to limited members of staff.
How long we keep your data for will depend on the purposes for which we are using it, which will vary from project to project. Our internal policy and governance procedures describe the maximum amount of time we will keep your data; these are available on request.
When we destroy or delete your data we will do so securely.
Contact us with any questions
We’re happy to answer any questions you have about how we are using your data. You can ask us to:
- Tell you what data we have about you.
- Stop using your data in a certain way.
- Withdraw your consent for us to use your data (if consent is the lawful basis for processing).
- Object to our definition of our legitimate interests or opt-out of us processing your data on this basis.
- Delete your data.
- Correct your data.
You can do any of the above by contacting us at firstname.lastname@example.org or ringing us on 0800 622 6110.