Our commitment to data protection and privacy
The Croydon Bach Choir ("the Choir") takes the protection of personal data very seriously. This sets out how we manage personal data. To make this document easy to find, we make it available via the page footer on every page of our website.
Personal data: what this means
Personal data is information relating to an individual who can be identified from that data. Identification can be from the information alone or in conjunction with any other information already in the data controller's possession or likely to come into such possession. The processing of personal data (from 25th May 2018) is governed by the General Data Protection Regulations 2016/679 ("GDPR").
Who we are
The Choir is the data controller. This means it decides how your personal data are processed and for what purposes.
How we process your personal data
The Choir complies with its obligations under the GDPR by keeping personal data up to date; by storing and destroying it securely; by not collecting or retaining excessive amounts of data; by protecting personal data from loss, misuse, unauthorised access and disclosure; and by ensuring that appropriate technical measures are in place to protect personal data. We do not source personal data from third parties, other than as may be publicly available. We use your personal data to be able to keep records of consents given for the processing of such data, and for the following purposes:
• For new membership applicants
We exercise a probationary period so that we can check you can sing to the required standard. During this period, we need to have a means to send you information regarding setting you up as a prospective new member, and ultimately to inform you of the Choir's decision at the end of your probationary period.
• For current Choir members
We will contact you in order to administer your membership of the Choir (including the claiming of Gift Aid), to give you information about Choir rehearsals and Choir events, as well as to send you information about the activities of other choirs in which the Committee feels its members may be interested, in accordance with any specific consents or requests you may have given.
• For Choir members taking a temporary break
We will send you information about Choir rehearsals and Choir events in time for your return.
• For Come and Sing day registrants
We will send you information about the day, particularly in case there are any changes to the timings or venue. We also contact participants to ask for feedback after the event.
• For suppliers of services, goods and funding
We need to be able to administer your relationship with the Choir.
• For past suppliers
We will contact you regarding the provision of further services or goods to the Choir.
• For supporters, past supporters, previous members and previous Come and Sing day participants
We would also like to contact you regarding Choir events in accordance with any specific consents or requests you have given.
The legal basis for processing your personal data
We process data under one or more of the following bases, as set out in Article 6 of the GDPR:
• consent of the data subject;
• necessity for the performance of a contract with the data subject or for taking steps to enter into a contract, as in the case of supply services to the Choir;
• compliance with legal obligations, for example those of the Companies Act, Charities Act and HMRC;
• necessity for the legitimate interests of the data controller, except where such interests are overridden by the interests, rights or freedoms of the data subject, (In this context our legitimate interests are to promote the objectives of the Choir as set out in our Articles of Association and to carry out our legal and contractual obligations efficiently).
With whom we share your personal data
Your personal data will be shared only with the Choir's Management Committee. Personal data from Choir members may also be shared with individual members of the choir (excluding any contact information). In all cases personal data is shared only to the extent reasonably necessary for the purposes described above. We will share your data with third parties only with your consent, unless we are required to do so by law.
Length of time we keep your personal data
We keep your personal data for no longer than is reasonably necessary. In deciding how long we should keep your data, we take into account:
• the nature of your relationship with the Choir, e.g. member, past member, supporter or past supporter, supplier or past supplier of services or goods (whether or not under direct contract);
• the legitimate reasons we may have for continuing to contact you deriving from our Choir objectives (see above);
• our legal obligations as a charity to retain company, financial and other records (typically for a minimum of six years);
• any specific consents or requests you have made regarding the duration of processing of your personal data.
Your rights and your personal data
Unless subject to an exemption under the GDPR, you have the right to:
• request a copy of your personal data which the Choir holds about you.
• request that the Choir correct any personal data if it is found to be inaccurate or out of date.
• request your personal data be erased where it is no longer necessary for the Choir to retain such data.
• withdraw your consent to the processing of your personal data at any time.
• request a restriction placed on further processing, where there is a dispute in relation to the accuracy or processing of your personal data,
• lodge a complaint with the Information Commissioner's Office (ICO).
Changes to how we process personal data
The Choir's processing of personal data is kept under review by the Choir's Management Committee and this Privacy Notice may be revised from time to time. Where our processing of your personal data relies on your consent, we will provide you with a new notice explaining any new purposes and processing conditions and seek your prior consent prior to commencing such processing.
How to contact us
Should you have any question or concerns about these privacy policies, to exercise all relevant rights, or to raise queries or complaints, please in the first instance contact:
Data Protection Manager
Croydon Bach Choir
41 Bredon Road
Surrey CR0 6JH