Policies

Privacy policy

How we collect, use and protect your personal information.

1. About This Document

This Privacy Notice explains how Kisharon Langdon collects, uses, stores and discloses personal data for all non-employees. Employees have a separate Employee Data Protection Notice.

2. Definitions

  • Personal Data: any information relating to an identified or identifiable living individual.
  • Special Category Data: a defined set of personal data that requires a higher level of protection under UK GDPR because of its sensitivity. This includes information about health, disability, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, biometric data, political opinions and data concerning sex life.
  • Processing: any operation or set of operations performed on personal data, including collection, recording, organisation, structuring, storage, retrieval, use, disclosure, alteration, restriction, erasure or destruction.
  • Data Controller: the organisation that determines the purposes and means of processing personal data. Kisharon Langdon is the Data Controller. Contact details in section 11.
  • Data Processor: an organisation or individual that processes personal data on behalf of a Data Controller.
  • Data Subject: the identified or identifiable living individual to whom personal data relates.
  • Consent: a freely given, specific, informed and unambiguous indication of agreement to the processing of personal data.
  • Lawful Basis: the legal justification under UK GDPR that permits processing.

3. Categories of Personal Data We Collect

  • Members / People We Support & Families: Identity; contact; health and social care information; care plans; incident/safeguarding information; tenancy/funding; emergency contacts; communications records; audio and video recordings of meetings and assessments (including AI-assisted transcription); CCTV.
  • Students & Families: Identity; contact; emergency contacts; attendance; learning/assessment progress; EHCP; SEN information; timetabling; course enrolment and qualifications; bursary/funding eligibility; communications records; video conferencing recordings; incident and safeguarding information; post-college transition plans; CCTV.
  • Donors & Supporters: Identity; contact; donation/payment information; Gift Aid status; event attendance; communication preferences; CCTV.
  • Contractors & Service Providers: Identity; contact; bank/payment details; due diligence; identification photographs; CCTV.
  • Volunteers: Identity; contact; application details; interview notes; references; DBS outcome/date; role-based health/fitness information; training/induction completion; supervision notes; incident/safeguarding information; video conferencing recordings; CCTV.
  • Website Users & Visitors: Cookie/analytics data; IP addresses; device identifiers; visitor logs; CCTV if accessing monitored areas.

4. Lawful Bases & Purposes of Processing

4.1 Purposes of Processing

  • Delivering social care and support and meeting CQC regulatory obligations.
  • Using AI-assisted tools to transcribe and summarise meetings with people we support (all outputs reviewed by staff before use; no AI decisions about individuals).
  • Delivering further education and meeting Ofsted/ESFA obligations.
  • Monitoring student attendance, progress and learning needs, administering EHCPs.
  • Enabling assessments/qualifications and recording achievements.
  • Supporting post-college transition planning and providing references.
  • Administering student bursaries, funding and Local Authority placements.
  • Administering donations, payments and Gift Aid.
  • Volunteer recruitment, onboarding, training, supervision and placement matching.
  • Managing contractors/suppliers including access control and payments.
  • Safeguarding, incident management, accident reporting and H&S compliance.
  • Site and system security including access logs and CCTV.
  • Event management, communications, service improvement, enquiries and complaints handling.

4.2 Lawful Bases (Article 6)

  • Legal Obligation — safeguarding, health & safety, social care duties, tax/Gift Aid.
  • Legitimate Interests — service communications, volunteer administration, donor management, security.
  • Public Task — delivering further education under statutory duties (ESFA/Ofsted).
  • Contract — supplier agreements, certain donor transactions.
  • Consent — images, testimonials, certain marketing/fundraising communications.

4.3 Special Category & Criminal Conviction Data Conditions

  • Article 9(2)(b) — employment/social protection including safeguarding & H&S.
  • Article 9(2)(g) — substantial public interest under DPA 2018 Schedule 1.
  • Article 9(2)(h) — health/social care processing (members/people we support); also applies to students' EHCPs.
  • Article 10 — criminal convictions (DBS), processed under DPA 2018 Schedule 1 safeguarding.

4.4 Marketing & Supporter Communications

We may send marketing or fundraising emails, texts or social media messages to individuals who have previously donated, purchased event tickets, expressed an interest in or otherwise engaged with our charitable purposes without requiring explicit consent. We do this in accordance with the charitable soft opt-in introduced by Section 114 of the Data (Use and Access) Act 2025. Lawful basis: Legitimate Interests. Opt-out available via unsubscribe link or info@kisharonlangdon.org.uk.

4.5 Use of Artificial Intelligence Tools

We use Microsoft Copilot (within Microsoft 365) for drafting and summarising. All outputs reviewed by staff; no decisions about individuals made by AI. We also use AI-assisted tools to record, transcribe and summarise meetings with people we support. You will always be told before recording begins and can ask us to stop at any time without it affecting the support you receive.

5. How We Collect Personal Data

  • Directly from you (forms, email, phone).
  • From your representatives, carers or referees.
  • From DBS provider for eligible roles.
  • From health/social care partners and regulators.
  • From Local Authorities, education partners and awarding bodies.
  • Automatically via CCTV, access logs, website cookies.

5.1 Our Website & Cookies

We use two types of cookies: Essential cookies (necessary for the website to work, no consent required) and Analytics cookies (only placed with your consent). You can accept or decline cookies using the banner displayed on first visit. Further information at www.allaboutcookies.org.

6. Disclosure & Sharing of Personal Data

We share personal data only where necessary and lawful, with: local authorities; CQC and regulators; NHS/health/social care partners; DBS provider; occupational health; insurers; legal advisers; auditors; IT, security and systems providers; AI transcription/summarisation platforms (operating on our instruction only, no data used for model training); Microsoft Corporation as processor of Microsoft 365/Copilot (Data Protection Addendum, no data used for model training); Ofsted; ESFA; awarding and qualifications bodies; other schools and colleges; careers and employment support services; DWP or benefits agencies; police/safeguarding bodies.

A full list of third-party processors is available on request from the DPO.

6.1 National Data Opt-Out

We do not currently share any data for planning or research purposes for which the national data opt-out would apply. This is reviewed annually.

7. Security

We use technical and organisational measures including encryption, MFA, secure hosting, access controls, training, breach procedures and supplier due diligence. Most systems are hosted on secure, encrypted UK servers. CCTV operates with restricted access and signage at monitored locations.

8. International Transfers

Where data is processed outside the UK, we use adequacy regulations, Standard Contractual Clauses (SCCs) with the UK Addendum and Transfer Risk Assessments. Microsoft Copilot interaction data may be processed outside the UK by Microsoft, safeguarded by the IDTA under Microsoft's Data Protection Addendum.

9. Retention

Most personal data is retained for 7–10 years unless a longer period is required by law (e.g. certain health, safeguarding and social care records). Shorter periods apply for website analytics and visitor logs. At the end of the retention period, data is securely deleted or anonymised. A full retention schedule is available on request.

10. Your Rights

To exercise any of the rights below, contact the DPO at dpo@kisharonlangdon.org.uk. We will respond within one month (extendable by two months in complex cases).

  • Access — request a copy of personal data held about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete data where no compelling reason to continue processing exists (not absolute; balanced against legal obligations).
  • Restriction — ask us to restrict processing in certain circumstances.
  • Objection — object to processing based on legitimate interests or direct marketing. Direct marketing objections are always complied with.
  • Portability — receive data in a structured, machine-readable format where processing is consent/contract-based and automated.
  • Withdrawal of consent — withdraw consent at any time; this does not affect prior lawful processing.
  • Automated decision-making — we do not carry out automated decision-making with legal or similarly significant effects.

11. Queries & Complaints

Data Protection Officer: dpo@kisharonlangdon.org.uk

Complaints can be lodged with the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint — please contact us first so we have the opportunity to address your concern. You can also raise compliments, concerns or complaints via our contact page.