This privacy notice applies to information we collect about:
• Visitors to our websites;
• Those who sign up to our support services e.g. peer/social, support group and counselling services;
• People who use our online services e.g. who subscribe to our newsletter;
• Supporters, volunteers and donors;
Links to other websites.
This privacy notice does not cover the links within this site linking to other websites. We encourage you to read the privacy statements on the other websites you visit.
Changes to this privacy notice.
We keep our privacy notice under regular review. This privacy notice was last updated on 6th August 2019.
1) Who is The Echo Society Ltd?
The Echo Society Ltd (The Echo Society) is a limited company registered in England & Wales No 10330786 and our registered address is:
71 - 75 Shelton Street, Covent Garden, United Kingdom, WC2H 9JQ.
Data Protection Officer.
The Echo Society Ltd has appointed an internal data protection officer who you can contact if you have any questions or concerns about our personal data policies or practices.
The Echo Society Ltd
71 - 75 Shelton Street
2) Your Rights.
In the UK you have rights as an individual under the Data Protection Bill 2018 which you can exercise in relation to the information we hold about you.
Please see our full Privacy Notice for more details but those rights, in summary are
• A right to information about how we use your data, why and to access a copy of the information we hold about you.
• A right to correct the information we hold about you if it is wrong.
• A right to have the data we hold about you deleted in certain circumstances.
• A right to object to the use of your personal data for direct marketing.
• A right to not be subject to automated decision making.
• A right to data portability i.e. to transfer your data from one service provider to another.
A right to complain.
You have a right to lodge a complaint with the appropriate data protection authority if you have concerns about how we use your personal data.
In the UK this is the Information Commissioner’s Office – www.ico.org.uk/concerns.
3) The reasons we can lawfully use your data.
We only use your personal data when we have a lawful basis to do so.
Data Protection legislation sets out a number of these, but the ones we most commonly use are:
• Consent - In many situations, we collect and use your personal data with your consent. You are able to withdraw or amend this consent at any time.
• Performance of a Contract - There are situations where we need to use your personal data in order to provide the service you have asked us for (or to allow others to do so on our behalf).
• Legal Obligation - If the law requires us to, we may need to collect and process your data – generally under the Health and Social Care Act 2012 or Mental Capacity Act 2005.
We may also use your personal data to pursue our legitimate businesses interests in a way which might reasonably be expected as part of running our organisation as long as it does not materially impact your interests, rights and freedoms.
These legitimate interests can include:
• enhancing, modifying, personalising or otherwise improving our services and communications for the benefit of our users.
You have the right to object to our processing of your personal data for our Legitimate Interests at any time. Please contact us if you wish to do so.
To protect your vital interests or the vital interests of another.
In rare, emergency situations we may use your personal data in order to protect your life or the life of another person.
Please see our full Privacy Notice for more details and examples of the lawful reasons we have to use your data.
4) When do we collect your personal data?
• When you visit our website.
• When you register for our support services e.g. peer/social group, support group and counselling services;
• When you enquire about our sponsorship and other funding opportunities;
• When you engage with us on social media or our campaign work;
• When you contact us by any means with queries, complaints etc;
• When your information is provided to us by someone who is receiving counselling or another service from us.
• When we receive a referral or other information from other healthcare professionals such as GPs, mental health teams, crisis teams etc.
What happens if you don’t give us your data?
We gather only the information we need to provide the services you ask us to. Much of the information on our website is available without giving us your personal data.
However, some personal data is needed so we can supply you with the services and information you have requested.
5) What personal data do we collect, why and how do we use it?
We only collect the personal data we need to provide you with the services you have asked us to.
To begin with, this is normally your name, contact information and high-level details of the abuse you have experienced as well as details of the services you are interested in. This helps us identify a counsellor and services which are suitable to your needs.
We may also gather details of the perpetrator(s) and your relationship(s) with them. We do this to better understand your experience and ensure you receive the support you need.
This is data about your racial or ethnic origin, health data, sex life or sexual orientation, political opinions or affiliations, religious or philosophical beliefs, genetic or biometric data.
We collect and use this data only with your explicit consent and only to provide you with the counselling and support services you have requested from us. This information is never shared for any other purpose although we are required to provide data to our regulator, the Care Quality Commission (CQC), as part of our public interest obligations.
Here’s how we’ll use your personal data and why:
• To process any requests for services you give us.
• To respond to your queries and complaints.
• To develop, test and improve the systems, services and products we provide to you.
• To comply with our contractual or legal obligations to share data with law enforcement.
• To send you survey and feedback requests to help improve our services.
Please see our full Privacy Notice for more information.
The data of children.
We only collect the information we need to provide counselling services to people over the age of 18.
We do not attempt to solicit or knowingly receive information from children under 16.
The use of your data for marketing purposes.
We never use information provided to us as part of our support services for marketing purposes.
With your consent, we collect the information of people who are willing to support our fundraising efforts and community initiatives. In those instances will use your personal data, preferences and details of the events you have attended to keep you informed about funding raising events, initiatives and other ways in which we need your financial support or time as a volunteer.
You can withdraw your consent at any time as described earlier in this notice.
6) How we protect your personal data.
We maintain physical, technical and administrative safeguards to ensure the security and confidentiality of your data.
Examples of some of these are given in our full Privacy Notice but please contact us if you have any questions about the security measures we have in place.
7) How long will we keep your personal data?
We’ll only keep your personal data for as long as is necessary for the purpose for which it was collected and to comply with applicable law or resolve disputes. This means we set retention periods for all the personal data we collect.
When that retention period has passed, your data will either be completely deleted in a secure manner or anonymised e.g. by aggregation with other data in a non-identifiable way for statistical analysis and service planning purposes.
We retain our data in line with the Information Governance Alliance’s guidelines and some examples of personal data retention periods are available in our full Privacy Notice but please contact us if you have any questions about our Data Retention policies.
8) Who do we share your personal data with?
We do not reveal your personal data to third-parties unless:
• You request or authorise it (e.g. when you agree to be referred to one of our external counselling partners);
• The information is provided to comply with the law (for example, to comply with a court order);
• To protect our rights, property or safety, or the rights, property or safety of our employees or others. This includes exchanging information with law enforcement organisations for the purposes of the detection or prevention of crime; or
• The information is provided to protect your health, safety or other vital interests or the health, safety or other vital interests of another; or
• The information is provided to our sub-contractors, agents, vendors or service providers who perform functions on our behalf; or
• To address disputes, claims, or to persons demonstrating legal authority to act on your behalf; or
• Other parts of the health and care system such as local hospitals, the GP, social workers, clinical commissioning groups, and other health and care professionals; or
• The Local Authority; or
• Organisations we have a legal obligation to share information with i.e. for safeguarding purposes or the Care Quality Commission;
Examples of the kind of third parties we work with
IT, software and SaaS companies who support our website and other business systems.
Service providers and specialist counsellors who provide services which suit your needs.
Sharing your data with third parties for their own purposes:
We will only do this in very specific circumstances, for example:
With your consent, given at the time you supply your personal data, we may pass that data to a third party for their direct marketing purposes.
Your privacy and security are our priority. We will not share your information or the information you give us about them with a perpetrator (s) unless we are legally obliged to do under a court order.
9) Where your personal data may be processed.
We always opt to have your data stored in the UK or EU where possible. This includes instances where a vendor offers a choice of storage locations but where the EU option is more expensive.
Sometimes we will need to share your personal data with third parties and suppliers outside the European Economic Area (EEA), such as the United States.
Any transfer of your personal data will follow applicable laws and we will always treat your personal information in line with the principles of this Privacy Notice.
This includes measures such as imposing contractual obligations on the recipient with respect to how they treat your data.
If you would like more information about how we protect your rights and freedoms when transferring your data outside the EEA, please see our full Privacy Notice or contact our Data Protection Officer.
Review of this privacy notice.
We may update this privacy notice from time to time as necessary. The terms that apply to you are those posted here on our website on the day you use our website. We advise you to print a copy for your records.
If you have any question regarding our privacy notice, please contact us by clicking here.