Data Protection Policy
Data Protection Policy
UK Customer Privacy Notice
We take your privacy very seriously. Please read this privacy notice carefully as it contains important information about who we are and how and why we collect, store, use and share your personal data. It also explains your rights in relation to your personal data and how to contact us or the Information Commissioner’s Office (“ICO”) if you have a question or a complaint.
Our use of your personal data is governed by the UK General Data Protection Regulation (“UK GDPR”) and the UK Data Protection Act 2018 and other privacy laws which apply in the United Kingdom (the “Data Protection Laws”). Where we decide how and why your personal data is processed, we are the “Controller” of that personal data and are responsible for complying with the Data Protection Laws.
Key terms
Here are some of the key terms used in this notice:
| We, us, our | Legal name: Branch Baby Loss Network CIC. Other trading or known name: Branch. |
| Personal data | Any data relating to an identified or identifiable individual. |
| Special category personal data |
Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership. Genetic or biometric data processed to uniquely identify an individual. Data concerning health, sex life or sexual orientation. |
| Processing | Any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, restriction, erasure or destruction. |
Personal data we process about you
We may process personal data about you which we have grouped together as follows:
Identity Data: including your first and last name, any previous names, username or similar identifier, marital status, title, date of birth, location (if you choose to give that to us) and gender (if you choose to give that to us);
Contact Data: including email address, billing address, delivery address and telephone number and company details;
Financial Data includes bank account and payment card details;
Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us;
Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device ID and other technology on the devices you use to access this website;
Profile Data includes your username and password, purchases or orders made by you, your personal and professional interests, your professional online presence (e.g. LinkedIn), information from accounts you link to us (e.g., Facebook, Instagram), preferences, feedback and responses to surveys, competitions and promotions;
Usage Data includes information about how you interact with and use our Instagram, WhatsApp community, website, products and services; and
Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
Some of this personal data is required to provide our products and services to you. If you do not provide personal data we ask for, it may delay or prevent us from providing our products and services to you.
How and why we use your data
The Data Protection Laws require us to have a legal basis for collecting and using your personal data. We rely on one or more of the following legal bases:
To comply with our legal and regulatory obligations: We may use your personal data where it is necessary for compliance with a legal obligation that we are subject to;
For the performance of our contract with you or to take steps at your request before entering into a contract: Where we need to perform the contract we are about to enter into or have entered into with you.
For our legitimate interests: If individuals have signed up to be a member of Branch Baby Loss Network CIC and have signed up to participate in Branch’s activities including meet ups and events, then it is in Branch’s legitimate interests to obtain, for example, names and contact details to inform our members and event participants about upcoming meetings, walks and events, as well as details for events they have signed up for, such as Zoom links to online meetings and events. Branch will assess what information is needed in order to safely, securely and effectively carry out its activities.
Where you have given explicit consent: Branch can use personal data if it has explicit consent. In order for consent to be valid, it must be freely given, specific, informed and unambiguous. Consent is only valid for the particular purpose it was gained for (e.g. if we gain consent to use someone’s address to send them newsletters, it does not mean we have consent to use this information for other purposes). Examples of when we might ask for consent are asking visitors to tick to agree to cookies on our website, asking meet up participants to give consent to their photos being used in our marketing materials or their personal data being shared with us for safety (such as their age or an emergency contact), or asking someone to give consent to signing up to our email newsletters. Consent can be given explicitly via WhatsApp, in writing or orally, and can be withdrawn at any point by letting Branch know in writing at branchbabyloss@gmail.com.
To protect someone’s life: Branch can use a member’s personal data in order to protect their life or someone else’s life. Branch can use a member’s personal data in order to protect an individual from harm or protect the physical, mental or emotional well-being of an individual. If a Branch employee or volunteer suspects a member may be at risk of harm, they will act in accordance with Branch’s Safeguarding Adults Policy and Procedure, which means personal data may be shared with other Branch employees or volunteers or with relevant safeguarding and health and safety bodies, including the Samaritans, local safeguarding boards, and, if someone’s life is at risk, 999.
The table below explains what we process your data for and our reasons for doing so:
| What we use your data for | Type of data | Legal basis |
|---|---|---|
| To provide our products and services to you |
Identity Contact Financial Transaction Marketing and Communications |
For the performance of our contract with you, services for you, or to take steps at your request before entering into a contract. |
| To prevent and detect fraud for the safety of our community |
Identity Contact Technical |
For our legitimate interests or those of a third party, i.e. to minimise fraud that could be damaging for us and for you. |
|
Personal data on application forms for conducting checks to identify our staff and volunteers and verify their identity for recruitment. This will be done by references and DBS checks via external agencies. Data related to staff and volunteer training. Other processing necessary to comply with professional, legal and regulatory obligations that apply to our business, e.g. under health and safety regulations or rules issued by our professional regulator. |
Identity Contact Financial Profile |
To comply with our legal and regulatory obligations and to ensure suitability for the role and the safeguarding of the community. |
| Participants’ ages to ensure they are adults |
Identity Contact |
For our legitimate interests, for safeguarding purposes. |
| Personal data may be collected ahead of Zoom meet-ups, including names and email addresses |
Identity Contact |
For our legitimate interests, to ensure meeting safety and privacy. |
| Data that the community platform requires users to provide to join the community, including WhatsApp name and number, email address and location on our website and app |
Identity Contact Profile |
For our legitimate interests, to ensure the community is supported and for safeguarding purposes. |
| Gathering and providing information required by or relating to audits, enquiries or investigations by regulatory bodies |
Identity Contact Transaction Technical Profile Usage Marketing and Communications |
To comply with our legal and regulatory obligations. |
| Ensuring our policies and procedures are adhered to, e.g. policies covering security and internet use |
Identity Contact Technical Profile Usage Marketing and Communications |
For our legitimate interests or those of a third party, i.e. to make sure we are following our own internal procedures so we can deliver the best service to you. |
| Operational reasons, such as improving efficiency, training and quality control |
Technical Usage |
For our legitimate interests or those of a third party, i.e. to take steps to improve our processes and service delivery at a competitive price. |
| Preventing unauthorised access and modifications to systems |
Identity Contact Technical Usage Marketing and Communications |
For our legitimate interests or those of a third party, i.e. to prevent and detect criminal activity that could be damaging for us and for you. To comply with our legal and regulatory obligations. |
| Updating customer records |
Identity Contact Transaction Technical Profile Usage Marketing and Communications |
For the performance of our contract with you or to take steps at your request before entering into a contract. To comply with our legal and regulatory obligations. For our legitimate interests or those of a third party, e.g. making sure that we can keep in touch with our customers about existing orders and new products. |
| Statutory returns |
Identity Contact Transaction Profile |
To comply with our legal and regulatory obligations. |
| Ensuring safe working practices, staff administration and assessments |
Identity Contact Technical Usage |
To comply with our legal and regulatory obligations. For our legitimate interests or those of a third party, e.g. to make sure we are following our own internal procedures and working efficiently so we can deliver the best service to you. |
| Marketing our services and those of selected third parties where we have consent to existing and former customers |
Identity Contact Technical Usage Profile Marketing and Communications |
For our legitimate interests, i.e. to promote our business to existing and former customers. |
| External audits and quality checks, e.g. for ISO or Investors in People accreditation and the audit of our accounts |
Transaction Technical Usage |
For our legitimate interests or those of a third party, i.e. to maintain our accreditations so we can demonstrate that we operate at the highest standards. To comply with our legal and regulatory obligations. |
We have determined, acting reasonably and considering the circumstances, that we are able to rely on legitimate interests as the lawful basis on which to process your data in certain circumstances. Where we rely on this lawful basis, we have stated this in the table above and set out the legitimate interest being pursued.
We have reached this decision by carrying out a balancing exercise to make sure our legitimate interest does not override your privacy rights as an individual. We consider that it is reasonable for us to process your data for the purposes of our legitimate interests outlined above as: (a) we process your information only so far as is necessary for such purpose; and (b) it can be reasonably expected for us to process your information in this way.
Promotional communications – Direct Marketing
During the registration process on our WhatsApp community, Instagram, website and / or community app when your data is collected, you may be asked to indicate your preferences for receiving direct marketing communications from us via email, WhatsApp messaging or SMS. If you consent to receiving the marketing, we may use your data to send you updates about our services and products, including upcoming events, meet ups, and fundraisers, exclusive offers and promotions, or new products and services.
We have a legitimate interest in processing your data for promotional purposes (see above ‘How and why we use your data’). However, where consent is needed (e.g. for third party marketing), we will ask for this consent separately and clearly.
We will always treat your data with the utmost respect and never sell it to other organisations for their marketing purposes.
You have the right to opt out of receiving promotional communications at any time by:
contacting us at branchbabyloss@gmail.com
using the ‘unsubscribe’ link in emails
using the ‘STOP’ number in texts when provided
We may ask you to confirm or update your marketing preferences if you instruct us to provide further products or services in the future, or if there are changes in the law, regulation, or the structure of our business.
Who we share your data with
We may share data where necessary with the parties set out below in accordance with the legal basis table above:
companies within our group;
our professional advisors and auditors (including without limitation tax, legal or other corporate advisors who provide professional services to us);
other third party suppliers, business partners and sub-contractors for business administration, support, processing, services, or IT purposes;
other third party suppliers for marketing purposes (including without limitation providers of customer relationship management systems;
third parties that you approve (including without limitation, social media sites, membership and community hosting platforms and apps such as Heartbeat, and third party payment providers);
if we are part of a merger or acquisition or joint venture, the purchasers of our business or assets or our joint venture partner;
credit bureaus and other financial institutions;
credit reference agencies;
identification verification agencies, such as agencies that conduct DBS checks;
our regulators, law enforcement or fraud prevention agencies, as well as our legal advisers, courts, the police, law enforcement agencies and any other authorised bodies, for the purposes of investigating any actual or suspected criminal activity or other regulatory or legal matters;
HMRC or other tax bodies or agencies to comply with our legal and regulatory obligations;
Safeguarding or emergency health and safety teams, including 999, local safeguarding boards, and the Samaritans;
Educational and research institutions, and other charities, including university researchers, and Tommy’s and Sands staff, where consent is given to participate in research projects relating to pregnancy loss, baby loss and infertility; and
Contacts you provide for the purpose of conducting reference checks.
We only allow our service providers to handle your data if we are satisfied they take appropriate measures to protect your data. We also impose contractual obligations on service providers.
We may also need to share some personal data with other parties, such as potential buyers of some or all of our business or during a re-structuring. Usually, information will be anonymised but this may not always be possible. The recipient of the information will be bound by confidentiality obligations.
Keeping your data secure
We have appropriate security measures to prevent personal data from being accidentally lost, or used or accessed unlawfully. We limit access to your personal data to those who have a genuine business need to access it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality. We only use trusted, secure third party sites to host our community/membership, including WhatsApp and Heartbeat. Our documents and volunteer forms are secure in restricted Google Drive folders, so that only those who require access can access these documents.
Where Your data Is Held
We store your personal data using a range of secure systems and platforms, including:
Emails, Instagram and WhatsApp: Your personal data may be included in our email communications, Instagram activity and WhatsApp messages.
Cloud-Based Solutions: We use cloud-based services, such as Google Drive, to securely store your personal data. Due to the global nature of these services, our providers may access your information from locations outside the UK or EEA for IT support and maintenance.
Community and Membership Platforms: We maintain your personal data on our community and membership platforms.
As a result of using these services, your personal data may be transferred to and accessed from jurisdictions outside the UK or EEA. We ensure that all such transfers comply with applicable data protection laws and that appropriate security measures are in place.
We may also transfer your personal data to third parties based outside the United Kingdom. When doing so, we may rely on:
(a) a lawful exception to the rules relating to overseas data transfers (for example, your explicit consent or a necessity to fulfill our contract with you);
(b) a decision from the Secretary of State (or another mechanism permitted under the Data Protection Laws) determining that the destination country provides an adequate level of protection; or
(c) appropriate safeguards, such as requiring the recipient to agree to standard contractual clauses or an approved international data transfer agreement.
How long your data will be kept
We will keep your personal data only for as long as is necessary:
to provide goods and services to you;
to respond to any questions, complaints or claims made by you or on your behalf;
to keep records required by law.
We will not retain your data for longer than necessary for the purposes set out in this privacy notice below. Different retention periods apply for different types of personal data.
When it is no longer necessary to retain your personal data, we will delete or anonymise it.
Your rights
You have the following rights, which you can exercise free of charge:
| Access | The right to be provided with a copy of your personal data (the right of access). |
| Rectification | The right to require us to correct any mistakes in your personal data. |
| To be forgotten | The right to require us to delete your personal data in certain situations. |
| Restriction of processing | The right to require us to restrict the processing of your personal data in certain circumstances, for example if you contest the accuracy of the personal data. |
| Data portability | The right to receive the personal data you provided to us in a structured, commonly used and machine-readable format and/or transmit that personal data to a third party in certain situations. |
| To object |
The right to object:
|
| Not to be subject to automated individual decision-making | The right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you. |
| Withdraw consent | You can withdraw your consent, although this does not affect the processing carried out up to the point of withdrawal. |
For further information on each of those rights, including the circumstances in which they apply, please contact us.
How to complain
We hope that we can resolve any query or concern you may raise about our use of your data. If you do have any concerns about how we use your data, please get in touch.
You have the right to lodge a complaint with the UK’s supervisory authority the Information Commissioner who may be contacted at: First Contact Team, Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF, https://ico.org.uk/concerns or telephone: 0303 123 1113.
How to contact us
If you have any questions about this privacy notice or the data we hold about you, please contact us by email using the details below.
Our Contact Details
Email address: