Owner: Neil Barrett · Approved by: Phil Taylor-Guck · Version: 0.1 (draft) · Date: 29/07/2026 · Next review: 29/07/2027
1. Purpose & scope
This policy sets out how Elect Social Value Exchange Ltd ("the Company") meets its obligations under the UK GDPR and the Data Protection Act 2018. It applies to all directors, employees, contractors and volunteers who process personal data on the Company's behalf, and to all personal data processed through the ELECT Social Value Exchange platform.
The platform processes data about partner organisations (councils, contractors, delivery partners, venues) and their staff, business enquiries, and the aggregate outcomes of delivered programmes. It does not process personal data about individual programme participants, and it does not process special category or children's data.
2. Roles & responsibilities
- The Company is the data controller for the organisation, account and business data it holds.
- Neil Barrett is responsible for overseeing compliance, handling data subject requests and breaches, and maintaining this policy and the Record of Processing Activities (ROPA).
- All staff must follow this policy, complete data protection training, and report any suspected breach immediately to the Data Protection Lead.
3. Data protection principles
We process personal data in line with the seven principles:
- Lawfulness, fairness & transparency — a lawful basis for every processing activity; the Privacy Policy explains processing to individuals.
- Purpose limitation — data used only for the purposes it was collected for.
- Data minimisation — collect only what is necessary.
- Accuracy — keep data accurate and up to date; correct errors promptly.
- Storage limitation — retain only as long as necessary (see §9).
- Integrity & confidentiality (security) — protect data with appropriate measures (see §6).
- Accountability — demonstrate compliance through records and this policy.
4. Lawful basis & Record of Processing Activities (ROPA)
The Company maintains a ROPA documenting each processing activity, its purpose, lawful basis, data categories, recipients, transfers and retention. Lawful bases relied on include contract, legitimate interests and legal obligation. Legitimate interests assessments (LIAs) are documented and reviewed.
5. Data subject rights
We handle requests to access, rectify, erase, restrict, port, or object to processing, and to withdraw consent, in line with the UK GDPR:
- Requests are logged and acknowledged, and answered within one calendar month (extendable by two months for complex requests, with notice).
- Identity is verified before disclosure.
- Where a request relates to data shared with a partner organisation, we coordinate with that organisation.
6. Security — technical & organisational measures
- Encrypted connections (HTTPS/TLS); passwords stored hashed; role‑based access control by user role (admin, ops, client, delivery partner, network partner, council, trainer).
- Access limited to those who need it; access reviewed periodically.
- Data hosted on Microsoft Azure (UK South); database access restricted.
- Secrets (API keys, webhook URLs, connection strings) kept out of source control and in secure configuration (user secrets / App Service settings / Key Vault).
- Logging and monitoring for security events.
7. Processors & sub‑processors
- We only use processors that provide sufficient guarantees, under a written data processing agreement (DPA).
- Current/expected sub‑processors: Microsoft Azure (hosting/DB), Stripe (payments), Anthropic (AI matching), Google (Workspace, Google Chat notifications), Resend (transactional email), and third‑party CDNs (Google Fonts, jsDelivr) that receive IP addresses when pages load.
- New sub‑processors are assessed before use.
8. International transfers
Where personal data is transferred outside the UK (e.g., to US‑based providers), we ensure an appropriate transfer mechanism — UK adequacy, the IDTA, or the UK Addendum to the EU SCCs — plus a transfer risk assessment where required.
9. Retention & disposal
Personal data is retained per the schedule in the Privacy Policy §8 and the ROPA, then securely deleted or anonymised. Retention periods are set by business need and legal obligations (e.g., financial records 6 years), and are reviewed regularly.
10. Personal data breach procedure
- Report — anyone who suspects a breach notifies the Data Protection Lead immediately.
- Contain & assess — the Lead contains the breach and assesses risk to individuals.
- Notify the ICO without undue delay and, where feasible, within 72 hours, if the breach is likely to result in a risk to individuals' rights and freedoms.
- Notify affected individuals without undue delay if the risk is high.
- Record — all breaches are logged (facts, effects, remedial action), whether or not reported.
11. DPIA screening
The Company has screened its processing against the ICO's criteria and concluded that a Data Protection Impact Assessment (DPIA) is not required, because the platform processes only organisation, account and business‑contact data and aggregate outcomes — it does not process special category data or children's data, or carry out large‑scale profiling of individuals. This screening is reviewed whenever processing materially changes.
12. Training & awareness
All staff receive data protection training on induction and periodically thereafter. This policy is made available to all staff.
13. Review
This policy is reviewed at least annually, and after any significant change to processing, technology, sub‑processors or the law.