Costa Foundation respects your data and your privacy is important to us.
This Privacy Notice explains what personal data we collect and how it is used. This notice also explains what rights you have over your personal data and how you can use those rights.
You have the right to object to some of the processing which Costa Foundation carries out. More information about your rights and how to exercise these is set out in the “Your rights” section of this notice.
Costa Foundation’s registered office is 3 Knaves Beech Business Centre, Davies Way, Loudwater, High Wycombe, Buckinghamshire, HP10 9QR.
1. Summary of how we use your data and your rights
2. Information we collect from you
3. Information we receive from third parties
4. How we use information and the legal basis
5. Data sharing
6. International transfers
7. Cookies and similar technologies
8. Data retention
9. Your rights
10. Contact details
11. Which Costa entity is the controller?
Summary of how we use your data and your rights
We use your data to enable us to keep in touch with our communities and advise you of our events, including for research, feedback and enquiries, and for safety and security purposes.
We will use your data to comply with laws and regulations. We may use your data to prevent and detect crime, such as fraud.
You have the right to object to some of the processing Costa Foundation carries out. More information about your rights and how to exercise these is set out in the “Your rights” section of this notice.
When you give consent, you are able to withdraw that consent at any time, for instance by emailing firstname.lastname@example.org. You can also email email@example.com to exercise any other data rights, such as obtaining a copy of your data, correcting, deleting or restricting how we use your data. Please see “Your rights” for more information.
Costa Foundation is a charity supported by Costa Limited. For details of the group see “Data sharing”.
Information we collect from you
We collect information when you, make enquiries to us or visit our website. This includes using our websites, joining our list of subscribers, or corresponding with us.
- If you post information online about us or provide feedback, we may keep a record.
- If you engage with us online via our website our cookies and similar technologies will capture your IP address, your location, and record how you use the site to help improve it and improve your user experience, where your browser settings or permission allows for this.
- We record and analyse web visits, and details of your E-learning (where applicable).
- We keep information you give us directly such as contact details (including name, email, address and telephone number), comments, date of birth, region, feedback, and opinions.
- If you contact us directly and complain or give feedback, we will record details and all related information such as emails, letters and phone calls.
Information we receive from third parties
We may receive your information from other people. This can happen when:
- We receive your information from Eventbrite UK Limited in relation to a charity event.
- You participate in social media exchanges, such as on Facebook, Twitter and Instagram
How we use information and the legal basis
We are allowed to use your data only if we have a proper reason to do so such as:
- To comply with the law.
- When you consent to it; or
- When it is in our legitimate interest;
A legitimate interest is when we have a business or commercial reason to use your data. This involves us making an assessment of when we can rely on our legitimate interests. For more information on this assessment please contact firstname.lastname@example.org
We have set out below how and why we may use your personal information and the legal basis we rely on. This is also where we tell you what our legitimate interests are.
To run our charitable activities and pursue our legitimate interests, we use your information.
Our legitimate interests include keeping our records up to date, fulfilling our legal, compliance and contractual duties, improving our site developing new initiatives to engage with our supporters, and telling you about them.
Further details of our legitimate interests:
To run and promote our charity, we use your information:
- To understand you better as a supporter by analysing information you provide to us or which we learn through your interactions with us.
- When we monitor our website, social media platforms such as Facebook, Twitter and Instagram and responses to email circulars. If you post comments online or in other media we may capture this information, contact you, and use it to improve our initiatives.
- To provide and improve our charitable endeavours, including fundraising activities, and to respond to you if you contact us.
We may, if you give us consent
- Use data for other purposes where we explain that purpose when we ask for your consent.
- Send you electronic communications, in relation to our charitable endeavours and initiatives and inform you of how we have enhanced the communities we help across the world.
When you give consent, you are able to withdraw that consent at any time by contacting us, for instance by emailing email@example.com. If you do so we can continue to use your data if another legal basis applies, such as when we’re required to do something by law.
When the law requires us to process your data we will do so. This can include
- When you exercise your rights under data protection legislation,
- Legal, compliance, regulatory and investigative purposes, including for government agencies and law enforcement.
Costa Foundation shares data with Costa Limited when Costa Limited provide us with support, IT and other services.
For some activities Costa Foundation uses third party service providers, such as Blueprint Partners Limited for website hosting and management. When these service providers ask for customer data for you we may share information with them,
We use third party providers for the following services:
- Charities Trust for payments’ processing to enable you to provide donations by credit or debit card.
- IT, support, maintenance and hosting, including the provision of website hosting; and
Personal data may be shared with government authorities and/or law enforcement officials for the prevention or detection of crime, if required by law or if required for a legal or contractual claim.
Personal data may be shared with regulators, government authorities and/or law enforcement officials for the prevention or detection of crime, if required by law or if required for a legal or contractual claim or regulatory purposes
We will not send or store your data outside of the European Economic Area (the EU plus Iceland, Lichtenstein and Norway) (‘EEA’).
We keep your data to enable us to fulfil our contract with you or to provide services, whilst you are an active user of our site, where required by law, to respond to a question or complaint or to uphold or protect contractual or legal rights or where it is in your or another party’s vital interests or in our legitimate interests.
We always look to keep your data for the minimum time in line with data protection principles and our processes. For example, we keep:
- Information to maintain records according to rules that apply to us.
- Supporter feedback and correspondence with us, depending on the nature of the interaction and any applicable law, such as health and safety. This enables us to respond to any questions or complaints.
- Records of donation information in line with tax law and audit requirements.
Where we process personal data on the basis of your consent, we will retain it only for as long as required for the specified purpose. We also keep your data in line with any statutory limitation periods and for tax, legal or regulatory purposes. We may keep your data for longer if we cannot delete it for legal, regulatory or technical reasons.
You have rights over your personal data.
- ask for a copy of your information;
- ask for information to be corrected;
- ask for information to be erased or deleted;
- ask for us to limit or restrict processing;
- object to us processing your data, in particular where we use the data for direct promotional purposes in relation to the Foundation. The right to object does not apply if we must process the data to meet a contractual or legal requirement;
- ask us to send you a copy in a structured digital format or ask for us to send it to another party.
Some rights, however, may be limited. We may be obliged by law or regulation to keep information. We must respect other people’s privacy as well, which means we may need to redact or remove information where it includes personal data about someone else, even if it is connected to your data. On occasion there may be a compelling legitimate interest to keep processing data.
If you want a copy of your data, to object to how we use your data, or ask us to delete it or restrict how we use it or, please see ‘Contact details’ below. To process a request from you, we may need to confirm your identity to ensure we’re accessing the right data.
You have a right to complain to an EU data protection authority. This can be where you live, work or where the matter occurred. In the UK, the authority is the Information Commissioner’s Office (the “ICO”).
To exercise any of your rights or to withdraw consent you can email: firstname.lastname@example.org
For any queries relating to data protection please contact email@example.com or by writing to them at Privacy Officer, 3 Knaves Beech Business Centre, Davies Way, Loudwater, High Wycombe, Buckinghamshire, HP10 9QR.
If we make any changes or updates to this notice we will communicate these.
Which Costa entity is the controller?
The controller for your information is Costa Foundation, 3 Knaves Beech Business Centre, Davies Way, Loudwater, High Wycombe, Buckinghamshire, HP10 9QR.