Introduction
Somebody Cares Scotland (“we”, “our”, or “us”) is committed to protecting your personal information and respecting your privacy rights. This Privacy Policy describes how and why we collect, store, use, share & protect personal data—whether you are a service user, supporter, volunteer, employee, or visitor to our website, during and after your relationship with us.
We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and any other relevant UK data protection legislation.
Who We Are
We are a Data Controller for the personal data we hold. This means we determine the purposes and means of processing personal data and the responsibility for ensuring it is handled lawfully.
- Charity Name: Somebody Cares SCIO (known as Somebody Cares Scotland)
- Registered Address: Royfold House, Hill of Rubislaw, Aberdeen, AB15 6GZ
- Charity Number: SC034820
- ICO Registration Number: ZC135353
What personal data do we collect
You may give your personal data to us directly, or we may collect it from other sources such as external agencies, partners, and government bodies, that we use as part of our service offering. We may sometimes collect additional data from third parties including former employers, educational establishments, training and medical providers or other background check agencies.
We may, where necessary, collect additional personal data during the period in which we continue to provide support services to you.
We may collect the following types of personal data:
- Contact details (including name, title, address, email, phone number/s)
- Date of birth, age, gender
- Nationality/citizenship/place of birth
- Identification for right to work purposes
- Employment or volunteering information
- Marital status, dependents, next of kin/emergency contact details
- Payroll and tax information (including bank details, national insurance number)
- A copy of your passport/driving licence/birth certificate/concession card
- Proof of residential address
- Previous employment history/qualifications, referee details, details about your current remuneration package, other information contained in a CV or cover letter.
- Training and competency records
- Photographs
- Donation and payment details (including Gift Aid preferences)
- Communication preferences
- Details about your relationship with us
- Information provided when using our services
- Special category data (health, safeguarding, ethnicity, etc.) where necessary
- Any other information which is voluntarily disclosed during the service provision
If you choose not to provide personal data
If you choose not to provide certain information when requested, we may not be able to provide or perform the services you require (such as paying you or providing a benefit), or we may be prevented from complying with our legal obligations.
Change of purpose
We will only use your personal data for the purposes for which we have collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for any unrelated purpose, we will notify you and explain the legal basis which allows us to do so.
Sensitive (Special Category) Data
We may also collect, store and use the following “special categories” of more sensitive personal data:
- Diversity information including racial or ethnic origin, religious or similar belief.
- Information about your health, including any medical conditions, including disability related information
- Information about criminal convictions and offences
- “Special categories” or particularly sensitive personal data require a higher level of protection. We need to have further justification for collecting, storing, and using this type of personal data.
In limited circumstances, with your explicit written consent
- Where we need to carry our legal obligations and in line with our Data Protection Procedure
- Where it is needed in the public interest, and in line with our Data Protection Procedure
- Where is it needed to assess our working capacity on health grounds, subject to the appropriate confidentiality safeguards
- Where you have already made the information public
Do we need your consent
We do not need your consent if we use special categories of your personal data in accordance with our Data Protection Procedure to carry out legal obligations or exercise specific rights in the field of employment law. In limited circumstances, we may approach you for your written consent to allow us to process certain particularly sensitive data.
Referees and Emergency Contacts
It may be necessary to obtain references on prospective employees & volunteers. To ask for a reference, we will need the referees' contact details (such as name, email address, and telephone numbers). Emergency contact details give us somebody to call in an emergency, we will need emergency contact details (such as name, email address and telephone numbers).
Why do we collect your personal data
Purpose
We will collect and process your personal data for the purposes of providing you with support and essential services in doing so, we act as a “Data Controller”.
Legal bases for processing
We must have a legal basis for processing your personal data. Most commonly, this will be one of the following:
- Legitimate interests – to pursue our charitable aims responsibly and effectively, while respecting your rights.
- Contractual necessity – to carry out agreements with you
- Compliance with a legal obligation – where we need to comply with a legal obligation. For example, verify your identity and right to work and comply with HMRC reporting requirements.
- Consent – where required due to the sensitive nature of the personal data and, in the absence of any legal obligation upon us, we may seek your explicit consent to undertake certain activities.
- Public Task – where we carry out activities in the public interest consistent without charitable objectives
- Vital Interest – in exceptional circumstances where processing is necessary to protect someone’s life.
Communication on WhatsApp
We use WhatsApp groups with volunteers and trustees for quick, informal communication such as shift reminders, rota changes, meeting logistics, and notifying members that further information has been shared by email. We do not use WhatsApp to share personal information about staff, volunteers, beneficiaries, or service users, or any confidential charity business; such information is only shared through our secure email and SharePoint systems. Please note that WhatsApp is provided by a third party (Meta), and using it means your phone number is visible to other group members, and limited technical information about your use of the service is processed by Meta in accordance with its own privacy policy.
How we collect your personal data
We collect data directly or indirectly
Directly
- When you contact us by phone, email, post or online
- When you donate, fundraise, or subscribe to updates
- When you register for an event or engage with our services
- When you apply for a role as staff or volunteer
Indirectly:
- Via third-party fundraising platforms (e.g. JustGiving), with your consent
- From referrals bodies, agencies or collaborative service providers
- Through publicly available sources
- From CCTV footage at our premises
- Via cookies when using our website
In addition to the above, we typically collect personal information from you because we observe or infer that information about you from the way you interact with us. For example, we may use cookies and web beacons on our Website so as to automatically collect information about your visit. This information will help to improve your experience when you use this Website and ensure that it is functioning correctly. Please see our Cookies Notice for more details.
If you visit our website, we gather limited information about how it is used, including which pages are visited most often and how visitors arrive at our site (for example, via a search engine, social media, or a referral link). We use this information to improve our website and communications, and to understand which of our activities are most effective. Wherever possible, we use this information in an aggregated or anonymous form that does not identify individuals. Further detail on the specific cookies used for this purpose is set out in our Cookie Notice. Where you receive electronic communications from us such as emails, we also typically gather information about your use of that communication. This includes information on when you open the communication and what links you click on within it. If you unsubscribe to a communication from us, we will also adjust your preferences and retain a record of this so that we don't contact you inappropriately.
How We Use Your Information
We may use your information to:
- Provide you with services and support
- Manage staff and instruct volunteers
- Process donations and fundraising
- Communicate updates and appeals (where consented)
- Respond to enquiries and feedback
- Improve our services, website and engagement through research and analytics
- Comply with legal and regulatory obligations
- Ensure safeguarding and wellbeing
Sharing Your Information
- We will never sell your data. We may share your information only when:
- Required to do so by law, regulators, or safeguarding obligations
- You have provided explicit consent (e.g. sharing your story)
- Working with trusted third-party providers (e.g. IT services, payment processors, scheduling and fundraising platforms like Calendly or JustGiving) under strict data processing agreements
- Required for contractual service delivery
- There is a risk to life, safety or welfare (e.g. safeguarding, self-harm risk, or vulnerable adults)
- All third-party processors are vetted and contractually bound to keep your data secure and confidential.
Keeping Your Data Secure
Somebody Cares Scotland – have implemented operational controls and internal policies to ensure that your data is not lost, accidentally destroyed, misused or disclosed, and in not accessed except by our employees in the performance of their duties. We use secure systems, role-based access, locked storage for paper forms, password-protected files, and regular staff training to safeguard data.
Data Retention & Disposal
Different laws require us to keep different dates for different periods of time. We will retain your personal data only for as long as necessary, in line with legal and contractual obligations. Please note our retention of records policy below.
Your Rights
You have the right to access, rectify, erase, restrict, object to processing, and request data portability. You can withdraw consent at any time.
Data Breach Management
In the event of a data breach, we will act promptly to contain and investigate, notify the ICO within 72 hours if required, and inform affected individuals where there is a high risk.
Contact Us
For all data protection queries, please contact:
- Email: dpo@somebodycaresscotland.org
- Post: DPO, Somebody Cares Scotland, Royfold House, Hill of Rubislaw, Aberdeen, AB15 6GZ
- Phone: 01224 460700 option 1
TRANSFER OF DATA
Somebody Cares Scotland is based in the UK and takes care to ensure personal data remains within the UK and European Economic Area (EEA) wherever possible. In limited circumstances, a small number of individuals, including certain trustees, may need to access personal data from outside the UK/EEA to carry out their governance responsibilities. Where this is necessary, access is granted only through an official @[somebodycares] email account and is provided via our secure SharePoint system. Personal data is not downloaded, exported, or stored locally by these individuals; it may only be viewed within SharePoint's secure environment. This approach ensures that we retain control over where personal data is stored and how it is accessed. We assess the safeguards in place for any such access in line with our obligations under UK GDPR.
RETENTION OF RECORDS
This schedule sets out how long Somebody Cares Scotland retains different categories of records. Records are disposed of once the retention period ends, eitjher by confidential shredding for paper records or secure deletion for digital versions, including backups. This approach supports compliance with the UK GDPR storage limitation principle (personal data should not be kept longer than necessary) and with our statutory and funder obligations.
Retention periods below are recommendations based on standard UK limitation periods, HMRC requirements, and sector good practice. Where a specific funder, insurer, or regulator sets a longer requirement, that longer period will be followed instead.
Record Type | Retention Period |
|---|---|
Employee HR Records | 7 Years |
Recruitment | 2 Years |
Financial Records / Accounts | 7 Years (HMRC Requirnment) |
Volunteers | 2 Years |
Client Records | 2 Years |
Van Logistics | 2 Years |
Health & Safety | 7 Years |
Donators | 7 Years |
Gift Aid | 7 Years |
Supplier / Contractor Records | 7 Years |
Buildings | 12 Years |
Funding | 7 Years |
Trustee Documents | 10 Years |
Office Furniture | 7 Years |
Retail | 7 Years |
Special things / work experience records for young people aged 16-17 | 9 Years |
IT & Systems Log | 2 Years |
Legal / Contractual Documents | 7 Years |