How We Handle Personal Data, End to End
- Data Protection & Storage Policy
1. Purpose
Spring Together CIC is committed to protecting the personal data of its participants, staff, volunteers, directors, and partners. This policy sets out how Spring Together CIC collects, uses, stores, and disposes of personal data in compliance with UK data protection law.
2. Scope
This policy applies to all directors, staff, volunteers, contractors, and any third party processing personal data on behalf of Spring Together CIC.
3. Legal Framework
Spring Together CIC complies with:
- The UK General Data Protection Regulation (UK GDPR)
- The Data Protection Act 2018
- The Privacy and Electronic Communications Regulations (PECR)
4. Data Protection Principles
Spring Together CIC processes personal data in accordance with the following principles:
Lawfulness, fairness and transparency — data is processed on a lawful basis and individuals are informed of how their data is used
Purpose limitation — data is collected for specified, explicit purposes and not further processed in a manner incompatible with those purposes
Data minimisation — only data that is necessary for the stated purpose is collected
Accuracy — data is kept accurate and up to date
Storage limitation — data is retained only for as long as necessary
Integrity and confidentiality — data is kept secure against unauthorised access or loss
5. Lawful Basis for Processing
Spring Together CIC will identify and document a lawful basis for each type of personal data processing. Lawful bases may include consent, contract, legal obligation, legitimate interests, or vital interests.
6. Data Collection
Spring Together CIC will collect only the personal data it genuinely needs. Individuals will be informed at the point of collection of the purpose for which their data is being collected and their rights under UK GDPR.
7. Data Storage
Personal data held by Spring Together CIC will be:
- Stored securely using password-protected systems or locked physical storage
- Accessible only to those who need it for their role
- Protected using appropriate technical and organisational security measures
- Not transferred outside the UK without appropriate safeguards in place
8. Retention and Disposal
Personal data will be retained only for as long as necessary for the purpose for which it was collected, or as required by law. Spring Together CIC will maintain a data retention schedule. Data that is no longer required will be securely deleted or destroyed.
9. Data Subject Rights
Individuals have the following rights under UK GDPR:
- The right to be informed about how their data is used
- The right of access to their personal data
- The right to rectification of inaccurate data
- The right to erasure ('right to be forgotten') in certain circumstances
- The right to restrict processing
- The right to data portability
- The right to object to processing
Requests to exercise any of these rights should be submitted in writing to a director of Spring Together CIC. Requests will be responded to within one calendar month.
10. Data Breaches
Any suspected or confirmed data breach must be reported to a director immediately. Where a breach is likely to result in a risk to individuals' rights and freedoms, it will be reported to the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it.
11. Data Protection Officer
Spring Together CIC has designated Sodeeq Olalekan as Data Protection Officer (DPO) and lead for data protection matters. Contact details for the designated lead will be made available to all staff and participants.
12. Review
This policy will be reviewed annually or following any significant change in legislation or organisational practice.
Authorised by Sodeeq Olalekan, Director / Head of Digital Trust, Policy and Compliance, Spring Together CIC — 18 May 2026.