Data Privacy Notice

PRIVACY NOTICE FOR OUR MEMBERS

We are committed to respecting your privacy. This notice is to explain how we may use personal information we collect before, during and after your membership with us. This notice applies to you if you have registered to become or are a member of our Association. This notice explains how we comply with the law on data protection, what your rights are and for the purposes of data protection we will be the controller of any of your personal information.

References to we, our or us in this privacy notice are to the National Association of Civic Officers.

We have not appointed a Data Protection Officer to oversee our compliance with data protection laws as we are not required to do so, but our Data Protection Compliance Secretary has overall responsibility for data protection compliance in our organisation.  Contact details are set out in the "Contacting us" section at the end of this privacy notice.

1. PERSONAL INFORMATION WE COLLECT FROM YOU

As part of your membership with us, you may initially provide us with, or we may obtain personal information about you, such as information regarding your:

  • personal contact details that allows us to contact you directly such as name, title, email addresses and telephone numbers;
  • date of birth;
  • gender;
  • membership start date;
  • any credit/debit card and other payment details you provide so that we can receive payments from you and details of the financial transactions with you;
  • records of your attendance at any events hosted by us;
  • images in video and/or photographic form and voice recordings;
  • your marketing preferences so that we know whether and how we should contact you.

2. WHERE WE COLLECT YOUR INFORMATION

We typically collect personal information about our members when you apply to become a member of the Association, when you make a query and/or complaint or when you correspond with us by phone, e-mail or in some other way.

3. USES MADE OF THE INFORMATION

The table below describes the main purposes for which we process your personal information, the categories of your information involved and our lawful basis for being able to do this.

To administer any membership, you have with us and managing our relationship with you, including dealing with payments and any enquiries made by you.

  • All contact and membership details, transaction and payment information, records of your interactions with us, and marketing preferences.
  • This is necessary to enable us to properly manage and administer your membership contract with us.

Retention of records

  • All the personal information we collect.
  • We have a legitimate interest in retaining records whilst they may be required in relation to membership. We need to retain records in order to properly administer and manage your membership and run our Association and in some cases, we may have legal or regulatory obligations to retain records.

The security of our IT systems

  • Your usage of our IT systems and online portals.
  • We have a legitimate interest to ensure that our IT systems are secure.

To conduct data analytics studies to better understand event attendance and trends within the Association

  • Records of your attendance at any events hosted by us.
  • We have a legitimate interest in doing so to ensure that our membership is targeted and relevant.

For the purposes of promoting the Association and our events.

  • Images in video and/or photographic form.
  • Where you have given us your explicit consent to do so. [Note:  Best practice would be to obtain consents where you intend to use any images or footage of members in any promotional or information campaigns.

Where you have given us your consent to use your personal information in a particular manner, you have the right to withdraw this consent at any time, which you may do by contacting us as described in the "Contacting us" section below.

Please note however that the withdrawal of your consent will not affect any use of the data made before you withdrew your consent and we may still be entitled to hold and process the relevant personal information to the extent that we are entitled to do so on bases other than your consent.  Withdrawing consent may also have the same effects as not providing the information in the first place, for example, we may no longer be able to provide certain member benefits to you.

4. DISCLOSURE OF YOUR PERSONAL INFORMATION

We share personal information with the following parties:

  • Any party approved by you.
  • The Government: where we are required to do so by law or to assist with their investigations or initiatives.
  • Police, law enforcement and security services: to assist with the investigation and prevention of crime and the protection of national security.

5. TRANSFERRING YOUR PERSONAL INFORMATION INTERNATIONALLY

The personal information we collect is not transferred to and stored in countries outside of the UK and the European Union.

6. HOW LONG DO WE KEEP PERSONAL INFORMATION FOR?

The duration for which we retain your personal information will differ depending on the type of information and the reason why we collected it from you. However, in some cases personal information may be retained on a long-term basis: for example, personal information that we need to retain for legal purposes will normally be retained in accordance with usual commercial practice and regulatory requirements.  Generally, where there is no legal requirement we retain all physical and electronic records for a period of 6 years after your last contact with us or the end of your membership.  Exceptions to this rule are:

Details regarding unsuccessful membership applicants where we hold records for a period of not more than 12 months;

It is important to ensure that the personal information we hold about you is accurate and up-to-date, and you should let us know if anything changes, for example if you change your phone number or email address. You may be able to update some of the personal information we hold about you. You can contact us by using the details set out in the "Contacting us" section below.

7. YOUR RIGHTS IN RELATION TO PERSONAL INFORMATION

You have the following rights in relation to your personal information:

  • the right to be informed about how your personal information is being used;
  • the right to access the personal information we hold about you;
  • the right to request the correction of inaccurate personal information we hold about you;
  • the right to request the erasure of your personal information in certain limited circumstances;
  • the right to restrict processing of your personal information where certain requirements are met;
  • the right to object to the processing of your personal information;
  • the right to request that we transfer elements of your data either to you or another service provider; and
  • the right to object to certain automated decision-making processes using your personal information.

You should note that some of these rights, for example the right to require us to transfer your data to another service provider or the right to object to automated decision making, may not apply as they have specific requirements and exemptions which apply to them and they may not apply to personal information recorded and stored by us.  For example, we do not use automated decision making in relation to your personal data.  However, some have no conditions attached, so your right to withdraw consent or object to processing for direct marketing are absolute rights.

Whilst this privacy notice sets out a general summary of your legal rights in respect of personal information, this is a very complex area of law. More information about your legal rights can be found on the Information Commissioner’s website at https://ico.org.uk/for-the-public/.

To exercise any of the above rights, or if you have any questions relating to your rights, please contact us by using the details set out in the "Contacting us" section below.

If you are unhappy with the way we are using your personal information you can also complain to the UK Information Commissioner’s Office or your local data protection regulator. We are here to help and encourage you to contact us to resolve your complaint first.

8. CHANGES TO THIS NOTICE

We may update this privacy notice from time to time. When we change this notice in a material way, we will update the version date at the bottom of this page. For significant changes to this notice we will try to give you reasonable notice unless we are prevented from doing so. Where required by law we will seek your consent to changes in the way we use your personal information.

9. CONTACTING US

In the event of any query or complaint in connection with the information we hold about you, please email our Data Protection Compliance Secretary – paul.millward@nottinghamcity.gov.uk or write to him at National Association of Civic Officers c/o Paul Millward, LH31, Loxley House, Station, Street, Nottingham, NG2 3NG.

Dated June 2018