Skip to main content

Processing of (personal) data by the entity in charge of the online application process

Privacy Policy

At Harmless CIC, we’re committed to protecting and respecting your privacy. This privacy policy sets out the basis on which any personal information we collect from you, or that you provide to us, will be processed by Harmless CIC or its associated projects (The Tomorrow Project, The Hope Project & Let’s Talk Training). It covers how we use this information, the conditions under which we may disclose it to others and how we keep it secure.

 

Please read the following carefully to understand our policy and procedures regarding your personal data.

 

For the purpose of the Data Protection Act 1998 and General Data Protection Regulation (EU) 2016/679 (GDPR) and any subsequent UK data protection legislation the data controller for the data we collect from you is Harmless CIC, 1 Beech Avenue, Nottingham, NG7 7LJ.

 

Who we are?

We are Harmless CIC and we provide support, information, training and consultancy to those who self harm and/or experience suicidal thoughts, their friends, family and professionals. Harmless CIC is a registered company limited by guarantee (no. 7150904). Our registered address can be found at the bottom of this policy. Harmless CIC also manage our other associated projects i.e. The Tomorrow Project, The Hope Project and Let’s Talk Training.

 

What information might we collect about you?

The information we collect about you depends on the service you access from us, for example, we will collect more information about you if you access our therapy services than if you access our training services. The information we collect is appropriate and proportionate to the service you are accessing and we will only collect information for the purposes for which they are used.

We may collect and process the following data about you:

  • Information that you have submitted on a referral form (or have authorised a third party to submit on your behalf);
  • Information that you have provided by completing one of our internal forms e.g. a training booking form;
  • Information that you have provided in order for us to offer services appropriate to you;
  • Information that you disclose to us when accessing our support services;
  • If you contact us about our services, we may keep a record of that correspondence and the information enclosed. This includes information received verbally or by email, text, our website, our shop, social media messaging, social media posting and physical letters;
  • Details of transaction you carry out through our website and online shop;
  • Details of your visits to our websites including, but not limited to, your IP address, your log in data, details about your browser, length of visit to pages on our website, page views and navigation paths, details about the number of times you use our website, time zone settings and other technology on the devices you use to access our website;
  • Information about your marketing preferences and communication preferences.

 

In some circumstances, we may collect and process data (without your consent) where there is a risk, or a potential risk, to your life. This information may be received from external parties or by actively seeking the information ourselves. This is fundamental aspect of our service and the information collected will only be used to ensure that you are safe and in order to provide information to you about our support services. The Harmless website uses Cookies. Cookies are small pieces of information sent by an organisation to your computer and stored on your hard drive to allow that website to recognise you when you visit. They collect statistical data about your browsing actions and patterns and do not identify you as an individual. It is possible to switch off cookies by setting your browser preferences.

 

 

We may also collect sensitive data.

Sensitive Data refers to data that includes details about your physical or mental health, race or ethnicity, religious or philosophical beliefs, sexual orientation, trade union membership and armed forced background. We may collect and process the following sensitive data about you:

  • Sensitive Information you given to our team as part of a clinical assessment. This will be recorded on our clinical assessment forms.
  • Sensitive Information you verbally disclose to our team when accessing our support services. These will in the form clinical notes written by our team.
  • Sensitive Information that you have freely disclosed to us when contacting us for support
  • Sensitive Information that you have provided to us on training monitoring reports. We collect information in this way to uphold equal opportunity requirements of external funders; however, you have the right to withhold this information.

 

When we collect and process sensitive data, we will clearly explain this to you.

 

How will we use the information about you?

Personal information which you supply to us may be used in a number of ways, including:

 

  • Internal record keeping
  • To carry out our contractual obligations arising from any contracts or service agreements entered in to between you and us;
  • To provide a quote or information about the services we can offer you;
  • To keep you safe when there are concerns over your wellbeing or there is a risk to life;
  • To seek your views or comments on the services we provide;
  • To send you communications (including direct marketing) that may be of interest to you;
  • To uphold contractual obligations and reporting obligations with external funders;
  • To process purchases of goods or services;
  • To help us improve our services;
  • For internal audit purposes;
  • For research purposes;
  • To inform you about any changes in our services.

 

Who has access to your information?

We will not sell or rent your personal information to any third parties. We use external online systems such as Eventbrite, Survey Monkey and Mail Chimp to collect some of your personal data. The personal data we collect on these systems are limited and only include basic information such as name, email address, organisation and job title. When purchasing good or services, your card information is not held by us, it is collected by our third-party payment processors, who specialise in the secure online capture and processing of credit / debit card transactions. We may disclose your personal information to third parties, if:

  • We have a legal obligation to do so
  • We have concerns over your safety, or there is a risk to life, and have to involve external agencies to ensure you are safe.
  • You have given consent for us to disclose your personal information to a third party.

 

We disclose anonymised information to third parties, if:

  • We have a contractual obligation to do so
  • We want to enhance the business case of Harmless CIC in order to secure future funding
  • For research purposes

 

How do we ensure that your data is secure?

We have put in place security measures to prevent your personal data from being accidentally lost, used, altered, disclosed or accessed without authorisation. All information you provide to us is stored on our secure systems or locked away in secure files. Only employees who have the authority to collect and process your personal information will be able to access it for the purpose it is intended. We will do our best to protect your personal data; however, the transmission of information via the internet is not completely secure. As such, we cannot guarantee the security of your data transmitted over the internet and is done at your own risk. Once we receive your information, we will use our secure internal procedures and systems to prevent unauthorised access.

 

What are your rights?

You have the right to request a copy of the information that we hold about you. If you would like a copy of some or all of your personal information, please email us using the details at the bottom of this document. You have a number of rights in relation to your personal data, including the right to:

  • Find out about how we collect and use your data;
  • Obtain a copy of your person data process concerning you (and supplementary information)
  • Request that any incorrect or inaccurate personal data is rectified
  • Request to have your personal data deleted
  • Request the restriction on our processing of your personal data
  • Object to the processing of your personal data
  • Where we rely on legitimate interest for direct marketing, you can object to receiving communication of this nature
  • Where we rely on consent, you can withdraw your consent to us processing your personal data (which includes any direct marketing).

 

To exercise any of your rights, you should contact Harmless using the details at the bottom of this privacy policy.

 

Data Retention – How long do we keep your personal information?

We retain personal data for no more than seven years after last contact with you. We keep information for this timeframe to fulfil the purposes we collected it for, including the purposes of satisfying any legal, accounting, clinical governance or reporting requirements or claims.

 

Legal basis for processing your data

We may process your data because:

  • The process is necessary to protect your life; or
  • The process is necessary to uphold our contract with you to provide services; or
  • You have asked us to take specific steps before entering into a contract; or
  • It is in our legitimate interest to do so.

 

We may also rely on your consent to process personal data and where we do this, it will be clearly explained to you at the time.

 

Link to other websites

Our website may contain links to other websites run by other organisations. This privacy policy applies only to our website, so we encourage you to read the privacy policies on the other websites you visit. We cannot be responsible for the privacy policies and practices of other sites even if you access them using links from our website.

 

Changes to our privacy policy

We regularly review this privacy policy and any changes will be posted on our blog and, where appropriate, notified to you by email or in person when you access our services. By using our services and corresponding with us, you are agreeing to be bound by this policy.

 

How to contact us

If you have any questions, comments or requests about this privacy policy, you can contact us by:

  • Email: admin@harmless.org.uk
  • Phone: 0115 880 0280
  • Post: Harmless CIC, 1 Beech Avenue, Nottingham, NG7 7LJ

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.