PRIVACY POLICY

C3 London Data Protection and Privacy Policy 

C3 London uses personal data about living individuals for the purpose of general church  administration and communication. 

C3 London is fully committed to compliance with the requirements of the Data Protection Act  2018 and all other data protection legislation currently in force. The Regulation applies to  anyone processing personal data and sets out principles which should be followed and gives  rights to those whose data is being processed. 

To this end, C3 London endorses fully and adheres to the Data Protection Principles listed  below. When processing data we will ensure that it is: 

  • processed lawfully, fairly and in a transparent way (‘lawfulness, fairness and  transparency’); 

  • processed no further than the legitimate purposes for which that data was collected  (‘purpose limitation’); 

  • limited to what is necessary in relation to the purpose (‘data minimisation’);

  • accurate and kept up to date (‘accuracy’); 

  • kept in a form which permits identification of the data subject for no longer than is  necessary (‘storage limitation’); 

  • processed in a manner that ensures security of that personal data (‘integrity and  confidentiality’); 

  • processed by a controller who can demonstrate compliance with the principles  (‘accountability’). 

These rights must be observed at all times when processing or using personal information. 

Therefore, through appropriate management and strict application of criteria and controls,  C3 London will: 

  • observe fully the conditions regarding having a lawful basis to process personal  information; 

  • meet its legal obligations to specify the purposes for which information is used;

  • collect and process appropriate information only to the extent that it is necessary to  fulfil operational needs or to comply with any legal requirements; 

  • ensure the information held is accurate and up to date; 

  • ensure that the information is held for no longer than is necessary;

  • ensure that the rights of people about whom information is held can be fully exercised  under the Data Protection Act 2018 (i.e. the right to be informed that processing is  being undertaken, to access personal information on request; to prevent processing  in certain circumstances, and to correct, rectify, block or erase information that is  regarded as wrong information); 

  • take appropriate technical and organisational security measures to safeguard  personal information; 

  • ensure that personal information is not transferred outside the EU, to other countries  or international organisations without an adequate level of protection.

Introduction 

C3 London – the church – has adopted this Privacy Policy as we recognise and take seriously  the right of people to keep their personal information private. This Policy covers the church’s  use of personal information that you provide, and that we collect and hold, including the use  of the website: www.c3london.com

By continuing to use this website you are agreeing to comply with the following terms and  conditions of use that govern the church’s relationship with you. Should you disagree with  any part of the Policy please desist from providing any personal information and/or using the  website. 

Data Protection 

The Policy explains how C3 London complies with the General Data Protection Regulation  (GDPR) that comes into effect on May 25th, 2018.  

By providing your personal details/information you are agreeing to allow C3 London to  contact you by telephone, email, mail, or SMS text in connection with its charitable purposes.  

1. Maintaining Confidentiality 

C3 London will treat all your personal information as private and confidential and not disclose  any data about you to anyone other than the leadership and ministry overseers of the church  in order to facilitate the administration and day-to-day ministry of the church. 

All C3 London staff and volunteers who have access to Personal Data will be required to agree  to sign a Confidentiality Policy and a Data Protection Policy. 

There are four exceptional circumstances to the above permitted by law:

1. Where we are legally compelled to do so. 

2. Where there is a duty to the public to disclose. 

3. Where disclosure is required to protect your interest. 

4. Where disclosure is made at your request or with your consent. 

2. Use of Personal Information 

C3 London will use the personal information we collect for the purpose disclosed at the time  of collection, or otherwise as set out in this Privacy Policy. 

Generally, we use and disclose your personal information as follows: 

1. The day-to-day administration of the church; e.g. pastoral care and oversight including  calls and visits, preparation of ministry rotas, maintaining financial records of giving  for audit and tax purposes. (This is not an exhaustive list) 

2. To establish and maintain your involvement in the church and contacting you to keep  you informed of church services, activities and events. 

3. Statistical analysis; gaining a better understanding of church demographics. 

N.B. although collated church data may be passed to a third party, such as number of small  groups or small groups attendance, no personal data will be disclosed.

3. Collection of Information 

Data is collected or passed through to C3 London in a variety of ways including when you:

  • Complete a ‘Welcome’ or ‘Membership’ Cards at Church events. 

  • Visit the website; 

  • Register your details and/or your families, at https://c3london.churchsuite.co.uk/ or  via an embedded form on our website 

  • Make a donation, by completion of giving cards or by electronic means

  • Provide personal details, written or oral, to church staff and volunteers;

  • When you communicate with the church by means such as email, letter, and  telephone; 

  • Access social media platforms the church uses such as Facebook, WhatsApp,  Instagram and X. 

For all of these methods of data collection, the method of collection, storage and sharing will  be subject to GDPR regulations. 

The church doesn’t hold Debit or Credit card details for donations or registrations made via  the C3 London website. Card payments made via the website, and other electronic means,  are handled by service providers who encrypt card information. Currently (as of May 2018)  the church uses World Pay, Go Cardless and Stripe.  

4. The C3 London Database 

Information contained on the database will not be used for any other purposes than set out  in this section. The database is accessed through the cloud and therefore, can be accessed  through any computer or smart device with internet access. 

C3 London has selected Churchsuite (www.churchsuite.com) to host the pastoral database of  C3 London. Churchsuite are a Data Processor of our data and they have extensive policies,  Q&As and support on their website to give information on how they store and control data.  The server for Churchsuite is based in the UK. 

1. Access to the database is strictly controlled through the use of name specific  passwords, which are selected by the individual. 

2. Those authorised to use the database only have access to their specific area of use  within the database. This is controlled by specified administrators. These are the only  people who can access and set these security parameters. This list is regularly checked  and maintained. 

3. People who will have secure and authorised access to the database include C3 London  Trustees, Staff, Administration Team, Team Leaders and Table Leaders. 4. Each user will only be given access to the appropriate part of the Churchsuite  database. 

5. The database will NOT be accessed by any authorised users outside of the EEA, in  accordance with the Data Protection Act, unless prior consent has been obtained from  the individual whose data is to be viewed. 

6. All access and activity on the database is logged and can be viewed by the Database  Administration.

7. Subject Access - all individuals who are the subject of personal data held by C3 London  are entitled to: 

  • Ask what information the church holds about them and why. 

  • Ask how to gain access to it. 

  • Be informed how to keep it up to date. 

  • Be informed what C3 London is doing to comply with its obligations under the  General Data Protection Regulation 2017 

8. We do not sell or pass any of your personal information to any other organisations  and/or individuals without your express consent, with the following exceptions: 

By providing us with your details you are giving C3 London your express permission to  transfer your data to service providers including mailing houses, such as MailChimp,  to enable fulfilment of the purpose for collection. 

9. Sensitive Personal Information: The Church may collect and store sensitive personal  information such as health information, religious information (church attendance)  when you and/or your family attend, register for church events and conferences.Your  personal information will be kept strictly confidential. It is never sold, given away, or  otherwise shared with anyone, unless required, by law. 

Please let us know as soon as any of your contact details change so that we can keep our  records up to date. 

You can request access to the personal information that the church holds about you by  contacting the church via hello@c3london.com We will provide you with access to your  personal information unless we are legally authorised to refuse your request. 

Please bear in mind that the Internet is not a totally secure method of transmitting  information. Accordingly, the church cannot accept responsibility for the security of  information you send to or receive from us over the Internet or for any unauthorised access  or use of that information. We take measures to protect your information from access by  unauthorised persons and against unlawful processing, accidental loss, destruction and  damage. 

COOKIES POLICY 

Cookies are small amounts of information that we store on your computer. Unless you have  indicated your objection when disclosing your details to us, our system will issue cookies to  your computer when you log on to the site. 

You may set up your computer to reject cookies although, in that case, you may not be able  to use certain features on our site. 

SOCIAL MEDIA 

The church uses social media such as Facebook, Instagram and YouTube. Users should verify  authenticity of sites before posting or providing personal information on such sites.

Our website may provide social media buttons, permitting sharing our web content directly  to a social media platform. Use of such buttons is at your own risk. 

Unless it is material supplied or officially posted by the church we do not endorse social media  website(s) and have no responsibility for the content nor for the cookies they may contain. 

POLICY CHANGES 

The church may amend this Privacy Policy from time to time to ensure compliance with  changes or amendments to the law of the UK and/or in relation to changes due to a final  Brexit. Any amended version will be available on our website at www.c3london.com

Data Protection (Employees)  

Employees’ Personal Information 

Throughout employment and for as long as is necessary after the termination of employment,  C3 London will need to process data about you. The kind of data that C3 London will process  includes: 

  • any references obtained during recruitment; 

  • details of terms of employment; 

  • payroll details; 

  • tax and national insurance information; 

  • details of job duties; 

  • details of health and sickness absence records; 

  • details of holiday records; 

  • information about performance; 

  • details of any disciplinary and grievance investigations and proceedings; ● training records; 

  • contact names and addresses; 

  • correspondence with C3 London and other information that you have given C3  London. 

C3 London believes that those records used are consistent with the employment relationship  between C3 London and yourself and with the data protection principles. The data C3 London  holds will be for management and administrative use only but C3 London may, from time to  time, need to disclose some data it holds about you to relevant third parties, for example  where legally obliged to do so by HM Revenue & Customs, where requested to do so by  yourself for the purpose of giving a reference or in relation to maintenance support, and/or  the hosting of data in relation to the provision of insurance. 

In some cases C3 London may hold sensitive data, which is defined by the legislation as special  categories of personal data, about you. For example, this could be information about health,  racial or ethnic origin, criminal convictions, trade union membership, or religious beliefs. This  information may be processed not only to meet C3 London's legal responsibilities but, for  example, for purposes of personnel management and administration, suitability for  employment, and to comply with equal opportunity legislation. Since this information is  considered sensitive, the processing of which may cause concern or distress, you will be asked to give express consent for this information to be processed, unless C3 London has a specific  legal requirement to process such data. 

Access to Data 

You may, within a period of one month of a written request, inspect and/or have a copy,  subject to the requirements of the legislation, of information in your own personnel file and/or other specified personal data and, if necessary, require corrections should such  records be faulty. If you wish to do so you must make a written request to your Manager. C3  London is entitled to change the above provisions at any time at its discretion. 

Data Security 

You are responsible for ensuring that any personal data that you hold and process as part of  your job role is stored securely. 

You must ensure that personal information is not disclosed orally, in writing, via web pages,  or by any other means, accidentally or otherwise, to any unauthorised third party. 

You should note that unauthorised disclosure may result in a disciplinary action or dismissal  for gross misconduct, depending on the circumstances. Personal information should be kept  in a locked filing cabinet, drawer, or safe. Electronic data should be coded, encrypted, or  password protected both on a local hard drive and on a network drive that is regularly backed  up. If a copy is kept on removable storage media, that media must itself be kept in a locked  filing cabinet, drawer, or safe. 

When travelling with a device containing personal data, you must ensure both the device and  data is password protected. The device should be kept secure and, where possible, it should  be locked away out of sight, for example in the boot of a car. You should avoid travelling with  hard copies of personal data where there is secure electronic storage available. When it is  essential to travel with hard copies of personal data this should be kept securely in a bag and  where possible locked away out of sight, for example in the boot of a car. 

Notifying Breaches 

A personal data breach is a breach of security leading to the accidental or unlawful  destruction, loss, alteration, unauthorised disclosure of, or access to, personal data  transmitted, stored or processed. 

The following are examples of data breaches 

  • access by an unauthorised third party; 

  • deliberate or accidental action (or inaction) by a data controller or data processor; ● sending personal data to an incorrect recipient; 

  • computing devices containing personal data being lost or stolen; 

  • alteration of personal data without permission; 

  • loss of availability of personal data. 

Investigation and Notification

In the event that we become aware of a breach, or a potential breach, an investigation will  be carried out. This investigation will be carried out by the Trustees. 

We will undertake to notify the Information Commissioner of a breach which is likely to pose  a risk to people’s rights and freedoms without undue delay and at the latest within 72 hours  of discovery. If we are unable to report in full within this timescale, we will make an initial  report to the Information Commissioner, and then provide a full report in more than one  instalment if so required. 

We will undertake to notify the individual whose data is the subject of a breach if there is a high risk to people’s rights and freedoms without undue delay and may, dependent on the circumstances, be made before the supervisory authority is notified. 

Record of Breaches 

C3 London records all personal data breaches regardless of whether they are notifiable or not  as part of its general accountability requirement under the Data Protection Act 2018. It records the facts relating to the breach, its effects and the remedial action taken. 

Adoption of the policy 

This policy has been agreed by the C3 London Trustees and is reviewed on an annual basis. Signed by:  

Position: Trustee 

Policy renewal date: June 2027 

C3 London Details: 

Venue: 18-19 Lettice St, London, SW6 4EH 

Church Office Address: Flat 1, 19 Hartington Road, Chiswick, London, W4 3TL

Charity Number: 1182833 

C3 London is a Registered Charity and is part of C3 Church Global group of churches.