Title: GDPR Policy
Version:
1.0
Replaces / Date:
January 2024
Lead with responsibility :
Hunrosa Data Protection Lead
Ratified Date:
January 2025
Date for Review:
Twelve months from ratification
In adherence to the General Data Protection Regulation (GDPR), Hunrosa’s GDPR Policy underscores our commitment to data privacy, protection, and the rights of individuals. Respecting the personal information of our clients, staff, and partners is fundamental to our operations. Our GDPR Policy ensures that we remain compliant with European legislation, outlining how we process personal data, ensuring transparency, and upholding the rights of data subjects. This is not just a legal obligation but also a testament to our dedication to maintaining the trust and confidence of those we serve.
1. GDPR Overview
Hunrosa (referred to as “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data. This policy outlines our compliance with the General Data Protection Regulation (GDPR), which ensures the lawful and transparent processing of personal data and the protection of data subjects’ rights. By using our services, you acknowledge and consent to the processing of your personal data as outlined in this policy.
2. Data Controller and Data Processor
We may act as both a Data Controller and a Data Processor, depending on the specific circumstances of data processing activities. When acting as a Data Controller, we determine the purposes and means of processing personal data. When acting as a Data Processor, we process personal data on behalf of Data Controllers, strictly following their instructions.
3. Lawful Basis for Data Processing
We will only process personal data when we have a lawful basis under GDPR. This includes instances where processing is necessary for:
The performance of a contract.
Compliance with a legal obligation.
Protection of vital interests.
Consent.
The performance of a task carried out in the public interest or in the exercise of official authority.
Legitimate interests pursued by us or a third party.
4. Rights of Data Subjects
Under GDPR, you have the following rights regarding your personal data:
Access: Request access to your personal data.
Rectification: Request correction of inaccurate or incomplete data.
Erasure: Request deletion of your personal data under specific conditions.
Restrict Processing: Request limits on how your data is processed.
Data Portability: Request transfer of your data to another organisation or yourself.
Object: Object to certain types of data processing.
Automated Decision-Making: Not to be subject to decisions made solely based on automated processing.
You may exercise these rights by contacting us using the information provided in Section 10.
5. Personal Data Protection
We implement appropriate technical and organisational measures to ensure the security and protection of personal data against unauthorised or unlawful processing and accidental loss, destruction, or damage. These measures include:
Encryption of sensitive data.
Secure email systems for transmitting personal information.
Regular staff training on data protection practices.
Ensuring any third-party processors provide adequate protection measures.
6. Secure Communication Policy
Sensitive data must only be transmitted using organisationally approved systems that meet GDPR standards for security. Personal email accounts or unapproved platforms must not be used to send or receive sensitive information. Staff are required to:
Verify recipient email addresses before sending.
Use encryption or password protection for highly sensitive data.
Avoid using autocomplete features when addressing emails with sensitive data.
7. Data Breach Notification
In the event of a data breach that poses a risk to the rights and freedoms of individuals, we will:
Notify the relevant supervisory authority without undue delay and within 72 hours of becoming aware of the breach, where feasible.
Inform affected data subjects without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
Take immediate steps to contain and mitigate the impact of the breach.
All breaches must be reported internally to our Data Protection Officer (DPO) immediately upon discovery.
8. Data Transfers
If personal data is transferred outside the European Economic Area (EEA), we will ensure that appropriate safeguards, such as Standard Contractual Clauses or Binding Corporate Rules, are in place to protect the rights and freedoms of data subjects.
9. Staff Responsibilities
All employees are responsible for adhering to this GDPR policy. Key responsibilities include:
Completing mandatory GDPR training and attending refresher courses.
Verifying email recipients when sending sensitive data.
Reporting any suspected or actual data breaches immediately to the DPO.
Non-compliance with this policy may result in disciplinary action.
10. Incident Management and Reporting
If a data breach or incident occurs:
Report the incident to the DPO immediately.
Follow containment measures, such as requesting the recipient delete the data and ceasing further transmission.
Document the incident thoroughly, including:
Date and time of the breach.
Description of the data involved.
Actions taken to mitigate the risk.
The DPO will assess whether the incident requires reporting to the Information Commissioner’s Office (ICO) and/or affected individuals.
11. Contact Information
For any inquiries or concerns related to the processing of personal data and our GDPR compliance, please contact our Data Protection Officer (DPO):
Jan Jenner.
12. Policy Enforcement
We are committed to enforcing this GDPR policy through regular audits, training sessions, and reviews. Failure to comply with this policy may lead to corrective actions, including but not limited to disciplinary measures for staff or contract termination for third-party processors.
13. Consent
By using our services, you consent to the processing of your personal data in accordance with the terms outlined in this policy. Staff and partners are bound by this policy and must adhere to the outlined guidelines to ensure GDPR compliance.
The Hunrosa website uses cookies to store device information. Consenting to these technologies allows us to process data such as browsing behaviour and analytics data to improve site experience.
Sign up to Hunrosa to access practical, trauma informed guidance designed to help foster carers support better sleep, reduce overnight stress and create calmer nights at home.
Hunrosa will use your information to contact you about our services, updates, and relevant news. You can unsubscribe at any time. For details on how we handle personal data, please see our Privacy Policy.
Automated page speed optimizations for fast site performance