In this section Policies

Privacy policy

The Well is committed to protecting your data and your privacy. We aim to ensure that any information you give us is held securely and safely.

Please read this policy carefully, along with our Terms and conditions and any other documents referred to in this policy, to understand how we collect, use and store your personal information.

The website referred to in this statement is wellhealing.org.

The Well holds and processes personal details in accordance with the Data Protection Act 1998 and is registered with the Information Commissioner.

If you have any questions about this policy or how your data is handled, please contact our Data Protection Officer, Mark Askew.

Who we are

The Well is a Christian charity that offers healing prayer to people of all faiths and none. We are a charity registered in England and Wales (number 1097443) and Registered Company Number 04664030. Our registered office is 20 Augusta Place, Royal Leamington Spa CV32 5EL.

For the purposes of this policy, ‘us’, ‘we’ and ‘our’ refer to The Well.

Data protection

The Well takes data protection very seriously.

As you use our website, get in touch with us, or take part in our campaigns and activities, we collect information. This deepens our understanding of what you are interested in and helps us to improve the quality and relevance of all of our communications with supporters.

The Well will never share your information with another organisation for their own marketing purposes and we will never sell your information for any reason whatsoever. We know that this is important and want to reassure you that you are always in control of how we use your personal information in regard to marketing and fundraising activities.

We do however need to collect and use your personal information for carefully considered and legitimate business purposes, which will help to ensure that we can run The Well efficiently, raise funds effectively and deliver our charitable programmes.

This policy will set out what data we collect, how we will use it, what the legal basis for this is, and outline what your rights are in respect of your personal data.

Purposes

The main reason we will use your personal information will be to help us effectively carry out our charitable activities, through your involvement in our campaigns and events or to help us raise funds to carry out our work.

We will always endeavour to be clear, honest and transparent with you whenever we collect and use your personal data. The overview below summarises the different reasons why we may collect and use your data. We may not use your personal information for all of these purposes, it will depend on the nature of your relationship with us, and how you interact with The Well as an organisation:

Fundraising, campaigning and marketing:

Like all charities, we have a range of fundraising and marketing activities that are designed to raise income or promote the aims and objectives of the charity. We use a range of marketing activities and channels such as direct marketing, events, advertising (print, broadcast and digital) and public relations for marketing, fundraising, and income generation. This may include talking to you about specific appeals, commercial trading activities, sponsorships, events or volunteering opportunities. We may also ask if you are able and prepared to Gift Aid any of your donations.

Delivery of core charitable services:

Delivery of our core charitable activities may require the recording of our beneficiaries’ contact details, records of financial transactions and communications. We may also need to use your personal information for the prevention of fraud and to identify any misuse or abuse of our services.

Management of volunteers:

If you are one of our valued volunteers we may need to use your personal information to manage your volunteering activities, deliver training, involve and update you on our projects and campaigns and to ensure your safety. This may include sending you newsletters or information about our fundraising appeals so that you are best equipped to perform your role and advise the public about our work.

Retail trading:

Through its event programme The Well offers individuals the chance to purchase a range of merchandise. If you interact with this service, we may use your personal information for the marketing of similar products to you in future.

Analysis, targeting and segmentation:

In order to fund our healing prayer ministry, we have to communicate our aims and objectives and ask people for financial support. Efficiency is very important to us, as we value every single donation. Therefore, we only want to send communications that are genuinely interesting and relevant to you. We will make use of information you have given us and your interactions with our services, to help us predict your interests and tailor and personalise our communications in the future.

Research:

We may collect data in order to carry out research on our supporter base. This is in order to improve our communications and ensure that we understand how best to interact with our valued supporters. Information we gather from individuals as part of this process is kept separately from our marketing database and is only used for research purposes.

Profiling:

In some limited circumstances we may combine the personal information you have given us with information available in the public domain to create a profile of your interests and preferences where they are relevant to your potential engagement with The Well. Information collected for these purposes may include information about your corporate directorships, shareholdings, published biographical information, employment, philanthropic interests and networks, charitable giving and relevant media coverage. We do this to help us understand the ways in which our supporters can support our work sooner, and more cost effectively. The use of publicly available sources helps us determine what support we should ask you for and helps us engage you in activities that are relevant to your areas of interest and influence. We may gather information about you from publicly available sources such as Companies House, the electoral register and the media to help us understand more about you as an individual and your ability to support The Well. You can opt-out of your personal information being used for profiling or analysis by contacting us.

Due diligence research:

The Well’s trustees have a duty to ensure that there is no reputational or financial risk to accepting a donation or other kind of support. We may therefore use publicly available sources to carry out due diligence on you to ensure that we are fundraising within the law.  For more information on the circumstances this may apply in and the type of information required please visit the Charity Commission.

Staff administration:

The Well employs a number of staff in the UK who are crucial to both delivering our programmes and raising the funds to provide our charitable services as well as providing a range of professional and technical support. We process the personal information of our employees for recruitment, staff administration, remuneration, pensions and performance management purposes.

Lawful processing

The Well, like all organisations in the UK, needs a lawful basis to collect and use your personal data. The law allows for six legitimate purposes which organisations can rely on to legally process people’s personal data. Of these, only three are relevant to charities for the type of activities listed above:

  • Information is processed on the basis of an individual’s consent.
  • Information is processed in line with a contractual relationship.
  • Information is processed on it being a legitimate interest for The Well to do so.

We may also share your personal information when we are compelled to do so by a legal authority acting in compliance with the law.

Consent

From May 2018 The Well will always ask new contacts for your consent to send you marketing by email and SMS. We will also ask you for your consent before contacting you by telephone for the purpose of marketing.

Should we ever ask you to provide any sensitive personal data about yourself, for example any health condition that may be relevant if you are taking part in The Well Ministry session, we will always seek your explicit consent to process this data.

Where you give us consent to process your data we will always keep a clear record of how and when this consent was obtained, and you can withdraw this consent for all channels and activities at any time by contacting our supporter care team.

Contractual relationships

Most of relationships with our supporters and beneficiaries are voluntary and not contractual. This purpose primarily relates to how we process the data that we hold in relation to our staff, and in some circumstances, our volunteers.

Legitimate interests

The law allows personal data to be legally collected and used by an organisation if it is necessary for a legitimate business interest of the organisation – as long as its use is fair and balanced and does not unduly impact the rights of the individual concerned.

There are times when it is just not practical to ask a person for consent. In many situations, the best approach for The Well and our supporters, beneficiaries, and volunteers is to process personal data because of our legitimate interests, rather than consent.

If you want to change our use of your personal data for marketing and fundraising activities, you can do so at any time by contacting our supporter care team.

What are The Well’s legitimate interests?

Governance:

  • Delivery of our charitable purposes as set out in our charitable objects.
  • Reporting criminal acts and compliance with the legal instructions of law enforcement agencies.
  • Internal and external audit for financial or regulatory compliance purpose.
  • Statutory reporting.

Publicity and income generation:

  • Conventional direct marketing by direct mail and other forms or marketing, publicity or advertisement.
  • Unsolicited commercial or non-commercial messages, including campaigns, income generation or charitable fundraising.
  • Unsolicited communications to Churches and other organisations, for example schools, with whom we work closely in order to publicise our appeals and campaigns.
  • Personalisation to tailor and enhance the supporter experience in our digital and postal communications.
  • Exercise of the right to freedom of expression or information, including in media and the arts.
  • Analysis, targeting and segmentation to develop fundraising strategy and improve communication efficiency.
  • Processing for research purposes.
  • Profiling, including the use of publicly available information.

Operational management:

  • Employee and volunteer recording and monitoring for recruitment, safety, performance management or workforce planning purposes.
  • Provision and administration of staff benefits such as pensions.
  • Physical security, IT and network security.
  • Maintenance of suppression lists.
  • Processing for historical, research or statistical purposes.

Financial management and control

  • Processing of financial transactions and maintaining financial controls.
  • Prevention of fraud, misuse of services, or money laundering.
  • Enforcement of legal claims.

Purely administrative purposes

  • Responding to any solicited enquiry from any of our stakeholders.
  • Delivery of requested products, resources or information packs.
  • Administration of direct debits and other existing financial transactions.
  • Administration of Gift Aid.
  • Providing ‘thank you’ communications and receipts.
  • Maintaining ‘do not contact’ lists

When we use your personal information, we will always consider if it is fair and balanced to do so and whether it would be within your reasonable expectations that we would use your data in this way.

We will balance your rights and our legitimate interests to ensure that the way in which we use your data never goes beyond what you would expect and is not unduly intrusive or unfair.

What information we collect

We collect and use personal information such as names and address details, as well as other contact information such as email addresses and telephone numbers. We also collect information about the services you use on our website, any purchases or financial transactions you make and any marketing preferences you give.

We maintain a record of communications that we send to you, and will also log any communications that you send to us. In some limited cases we may collect some publicly available information about you, including company directorships, and your interests. If you attend a The Well event it is possible that your photograph may be taken.

If you have made a donation to The Well and kindly agreed to Gift Aid that donation we must record the fact that you are a UK tax payer and we have to maintain a record of the amount of Gift Aid we have collected.

Sensitive personal information

Under data protection law, certain categories of personal information are recognised as sensitive, including health information, race, religious beliefs, and political opinions (‘sensitive personal data’). In limited cases, we may collect sensitive personal data about you.

We would only collect sensitive personal data if there is a clear reason for doing so, as outlined earlier in this policy, such as where we need this information to ensure that we provide appropriate facilities or support.

We will only use sensitive information provided to us for the purpose it is provided.

Credit and debit card information

If you use your credit or debit card to donate to us, or buy something online, we may pass your card details securely to our payment-processing partner as part of the payment process. We do this in accordance with the Payment Card Industry Security Standard and don’t store the details on our website or databases.

Where does this information come from?

The vast majority of personal data we hold is given to us directly by our supporters, customers, beneficiaries and volunteers in the course of them interacting with our services, websites, or fundraising activities. We may also receive your personal information when you donate to The Well through third party services such as Just Giving, Virgin Money Giving, or Stewardship.

We may occasionally use third party organisations to provide us with further details of individuals who have expressed an interest in The Well and have agreed to receive communications from The Well.

In some situations we may update our supporters, clients and volunteers personal information using other agencies; for example, to check we have a valid and deliverable postal address, or to check if you are on the telephone preference service or fundraising preference service.

Data retention

The Well removes personal data from our systems in line with our data retention policy. The length of time each category of data will be retained will vary on how long we need to process it, the reason it is collected, and in line with any statutory requirements.

After this point the data will either be deleted or rendered anonymous. In certain specific situations, for example where a supporter has kindly pledged a legacy to The Well in their will, we will maintain their details up to the time when we need to carry out the legacy administration and communicate effectively with their family.

Data sharing

As mentioned above, The Well will never sell your personal information and will never share it with another organisation for their own marketing purposes. However, there are a number of legitimate situations where we may share your information with third parties whom we have contracted to fulfil specific services for us.

This will include organisations such as mail fulfilment houses and email broadcasters who will send out our marketing materials on our behalf. In all of these situations we ensure that we always have a written contractual agreement in place that will ensure that those organisations can only use the data provided for the specific purposes we direct them to do, and that they have in place strict security requirements in order to protect your personal information. Any such data will also be deleted following the completion of the third parties work for us.

Your data protection rights

Where The Well is using your personal information on the basis of your consent, you have the right to withdraw that consent at any time. You also have the right to ask The Well to stop using your personal information for direct marketing purposes. Simply contact our supporter care team and they will amend your contact preferences.

The law also gives you a number of other rights in relation to your personal data:

Right to be Informed:

You have the right to be told how your personal information will be used. This policy document, and shorter summary statements used on our communications, are intended to be a clear and transparent description of how your data may be used.

Right of Access:

You can write to the Data Protection Officer asking what information we hold on you and to request a copy of that information. Currently the Data Protection Act 1998 gives us 40 days to respond. From May 2018 we will have 30 days to comply once we are satisfied you have rights to see the requested records and we have successfully confirmed your identity.

Right of erasure:

From May 2018, you have the right to be forgotten (i.e. to have your personally identifiable data deleted). In many cases we would recommend that we suppress you from future communications, rather than data deletion.

Right of rectification:

If you believe our records are inaccurate you have the right to ask for those records concerning you to be updated.

Right to restrict processing:

In certain situations you have the right to ask for processing of your personal data to be restricted because there is some disagreement about its accuracy or legitimate usage.

Right to data portability:

Where we are processing your personal data under your consent the law allows you to request data portability from one service provider to another. This right is largely seen as a way for people to transfer their personal data from one service provider to a competitor and is unlikely to be relevant to your relationship with The Well.

Right to object:

You have an absolute right to stop the processing of your personal data for direct marketing purposes.

Right to object to automated decisions:

In a situation where a data controller is using your personal data in a computerised model or algorithm to make decisions ‘that have a legal effect on you’, you have the right to object. This right is more applicable to mortgage or finance situations. The Well does not undertake complex computerised decision making that produces legal effects.

Data security

We maintain a high level of physical and electronic security in relation to the collection, storage and disclosure of your information. We take reasonable steps to ensure that any information we hold about you is protected. We use Secure Socket Layer (SSL) software, which encrypts information given over the internet to protect all personal data as soon as it is possible.

The software scrambles data transmitted between your computer and our server, where it is unscrambled securely. While we make every reasonable effort to ensure that information sent to us is done so securely, we cannot warrant the security of information transmitted to us through the internet. When you transmit information to us via the internet, you do so at your own risk.

Cookies

The Well uses cookies.

Every time you visit our website, it sends us a cookie – a text file that tells us about your visit. The information is all anonymous, so we’re told about your computer, not you. And when the data comes to us it’s bulked together with information from all the other visitors to our site. Cookies tell us, for example, about traffic data, location data, device information, the date and time people visit and the pages they visit.

Most major websites use cookies.

How we use cookies on our website:

To make the most of our website you should leave cookies turned on, otherwise you might not be able to see all of our site.

Cookies help us:

  • customise what you see when you visit our site, and help us understand what would interest you
  • process any requests, applications or transactions
  • do our internal administration and analysis

Managing cookies

You can turn off cookies on most browsers. To find out how, use the help function.

Third party cookies

There are a few external companies that The Well works with who set cookies on our website. These cookies are mainly used for reporting and advertising so we can improve the way we communicate.

We use websites like Youtube and Vimeo to embed videos, and they may send you cookies too. We don’t control the setting of these cookies, so check those websites for more information.

The Well also uses companies like Facebook and Google Analytics, which may use cookies. They may also use tracking pixels, which tell us how effective our adverts are.

You can opt out of Google’s tracking cookies any time you want. Google uses cookies to match adverts with your preferences so they’re more relevant to you. If you don’t want to see adverts from us based on that information, you can use Google’s Ad Personalisation Tool.

All information we get through Google’s cookies is anonymous, it just helps us understand how people use our website and which pages are more popular. If you don’t want Google to include you in this information, you can install the Google Analytics Opt Out Tool.

You can also visit the Digital Advertising Alliance website to personalise your advertising preferences.

As some of these services may be based outside of the UK and the European Union, they might not fall under the jurisdiction of UK courts. If you’re worried about that, you can change your cookie settings (see above). Or for more information, visit https://ico.org.uk/

Use of IP addresses

We collect IP addresses to obtain aggregate information on the use of this website. An IP address is a number assigned to your computer by a web server when you’re on the web. When you are on our site, we have a server that logs your computer’s IP address. We only use the information we find out from tracking IP addresses in the aggregate, such as how many users entered a specific area of our site, and not to track a specific IP address to identify an individual user.

Changes to The Well’s privacy statement

From time to time, we will make changes to this statement to keep it up to date and relevant. Please make sure you check regularly to see what’s changed. This statement was last updated on 20 March 2019.

What to do if you are not happy?

In the first instance, please talk to us directly so we can help resolve any problem or query. You can also register with the fundraising preference service (FPS). This service is run by the Fundraising Regulator and allows you to stop email, telephone, addressed post, and/or text messages from a selected charity or charities by using the online service at fundraisingpreference.org.uk or by calling 0300 303 3517. Once you have made a request through the FPS, we will ensure that your new preferences take effect within 28 days.

You can also contact the Fundraising Regulator directly to complain by using the online complaints form on their website. You also have the right to contact the Information Commissioners Office (ICO) if you have any concerns about Data Protection using their help line 0303 123 1113 or at ico.org.uk.