Skip to content

Privacy Policy

Hope Church Merthyr 

Data Protection & Privacy Policy 

YOUR PERSONAL INFORMATION  

This statement sets out how Hope Church Merthyr will deal with any personal information we collect from you or that you provide to us.  All personal data, whether it is held on paper, on computer or other media, will be subject to the appropriate legal safeguards as specified in the Data Protection Act 2018.  For the purpose of the Act, we are the data controller of personal data we hold about you. 

THE PRINCIPLES 

The principles of the regulation require that personal data shall: 

  1. Be processed fairly and lawfully and shall not be processed unless certain conditions are met. 
  1. Be obtained for a specified and lawful purpose and shall not be processed in any manner incompatible with that purpose. 
  1. Be adequate, relevant and not excessive for those purposes. 
  1. Be accurate and where necessary, kept up to date. 
  1. Not be kept for longer than is necessary for that purpose. 
  1. Be processed in accordance with the data subject’s rights. 
  1. Be kept secure from unauthorised or unlawful processing and protected against accidental loss, destruction or damage by using the appropriate technical and organisational measures. 
  1. Not be transferred to a country or territory outside the European Economic Area, unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data. 

We are committed to conducting our business in accordance with these principles in order to ensure that the confidentiality of personal information is protected and maintained 

1. DATA COLLECTION 

We collect personal information when you are in contact with Hope Church Merthyr.  For example when you: 

  • Register details via paper registration forms, digital consent forms, embedded forms on our website or social media 
  • Make a financial donation using our gift box or electronic means 
  • Provide your contact details in writing or orally to Church staff and volunteers 
  • Communicate with the Church through means such as email, letter, telephone. 
  • Information contained in checks provided by the Disclosure & Barring Service 
  • Information that you share with us for the purposes of pastoral care, encouragement, training and prayer. 
  • Information relevant to your employment by the church 
  • Medical information where necessary to ensure that the care and hospitality that we provide for you is appropriate to your needs. 
  • Details of your visits to our website (including, but not limited to, traffic data, location data, weblogs and other communication data, whether this is required for our own purposes or otherwise) and the resources that you access. 

2. CONFIDENTIALITY 

Hope Church Merthyr will treat all of your personal information as private and confidential, not to be disclosed with anyone other than the relevant  church leadership and ministry overseers/co-coordinators within the church, in order to facilitate the administration and day-to-day ministry of the church. 

There are four exceptions to the above permitted by law: 

  1. Where we are legally compelled to do so. 
  1. Where there is a duty to the public to disclose. 
  1. Where disclosure is required to protect your interest. 
  1. Where disclosure is made at your request or with your consent. 

3. USE OF DATA 

Hope Church Merthyr will use your personal information for three main purposes: 

  1. The day-to-day administration of the church e.g. pastoral care, including calls and visits, coordinating team rotas, keeping financial records for audit and tax purposes. 
  1. Making contact with you to keep you informed of church activities and resources. 
  1. Statistical analysis, as and when requested by external funders.  

STORAGE OF DATA  

Stored data will not be used for any other purposes than the above in section 3. All data is held in the UK, we use the following methods to store information: MailChimp, Sharepoint, YLP Pantry Portal.  Any relevant hard copies of information are stored in locked cabinets.  

1. Access to Sharepoint is strictly controlled through the use of name specific passwords, which are selected by the individual. 

2. Those authorised to use the database only have access to their specific area of use within the database. This is controlled by the Data Controller and other specified administrators. These are the only people who can access and set these security parameters. 

3. People who will have secure and authorised access to the database include Church staff, elders and deacons, data in-putters, ministry team leaders.  

4. All access and activity on the database is logged and can be viewed by the Database Controller. 

5. Subject Access – all individuals who are the subject of personal data held by Hope Church are entitled to: 

  • Ask what information the church holds about them and why. 
  • Ask how to gain access to it. 
  • Be informed how to keep it up to date. 
  • Be informed what Hope Church is doing to comply with its obligations under the General Data Protection Regulations 

6. Personal information will not be passed onto any third parties without your consent eg: Disclosure & Barring Service.  We do not sell or pass any of your personal information to any other organisations and/or individuals without your express consent, with the following exception: by providing us with your details you are giving the Church your express permission to transfer your data to service providers including mailing houses, such as MailChimp.  

7. Sensitive Personal Information: The Church may collect and store sensitive personal information such as health information where. Your personal information will be kept strictly confidential. It is never sold, given away, or otherwise shared with anyone, unless required, by law. 

YOUR RIGHTS 

You have the right to ask us not to process your personal data for the purposes of informing you of events and other opportunities. We will usually inform you (before collecting your data) if we intend to use your data for such purposes. You can exercise your right to prevent such processing at any time by contacting us. 

The Act gives you the right to access information held about you. Your right of access can be exercised in accordance with the Act.  

You may request that personal information is corrected where it is not correct or that the information is deleted.  You may also object to the church processing information about you.  Where you have consented to us handling your information, you have the right to withdraw that consent at any time. 

Our website may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites. 

OUR DATA PROTECTION CONTACT 

Our nominated representative for the purpose of the Act is Dylan Pritchard Finance & Compliance Manager.   For further information about how your personal information is used, how we store your information securely and your rights to access the information that we hold about you, please contact Dylan via: office@hopemerthyr.org.uk 

If you are unhappy with how we have handled your information, you may complain to the Information Commissioner Office Wales (ICO).                     2nd Floor Churchill House, Cardiff, CF10 2HH. Tel: 0330 4146421.            Email: wales@ico.org.uk

Website Specific:

Our website address is: hopemerthyr.org.uk

What personal data we collect and why we collect it

Comments

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Contact forms

Cookies

If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Analytics

Who we share your data with

How long we retain your data

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where we send your data

Visitor comments may be checked through an automated spam detection service.

Your contact information

See above under general privacy policy for Hope Church Merthyr