POLICY

Privacy / Cookies

Privacy Notice

This notice applies to all websites & applications developed and delivered by Her Story Scotland

Her Story Scotland is a Community Interest Company incorporated in Scotland under company number SC805930 and has a registered office at 11 Braeheid, St Vigeans, Arbroath, Angus, DD11 4PA. All significant decisions about data processing and policy implementation will be made using UK GDPR (General Data Protection Regulation). This notice is set out to help you understand the types of data that we collect from you, and/or your business, and how that data is used and managed.

Commitment

Her Story Scotland are committed to protecting the privacy and security of your personal data. We continually monitor compliance through implementing policies & procedures to safeguard data and by setting regular reviews to manage these policies and procedures.

Data Controller

In accordance with ICO (Information Commissioners Office) requirements of Data Controllers (the main decision maker when it comes to how people’s personal information is managed), Her Story Scotland is registered with the Information Commissioners Office (ZC029281). When you are using Her Story Scotland website, Her Story Scotland is the Data Controller.

Who we collect data from

We collect and process personal data from a range of individuals in the course of delivering our wellbeing, educational and support services. This includes:

  • Service users – Girls, young women and adult women who participate in our group programmes, one-to-one support, wellbeing sessions or educational activities.
  • Parents and carers – Where relevant, we collect information from parents or carers of children and young people engaging with our services, including contact details and consent information.
  • Children and young people – Where appropriate, we collect personal data to provide age-appropriate guidance, support and safeguarding for younger participants.
  • Employees – Staff members who deliver our programmes or support the running of the organisation.
  • Volunteers – Individuals who assist with sessions, events or organisational support.
  • Referral partners – We receive personal data from organisations such as local authorities, schools, health services or community partners when an individual is referred to our services.
  • Website users and individuals who contact us – Anyone who gets in touch through our website, email or social media to request information, register interest or provide feedback.

We only collect and use personal data where it is necessary to deliver our services, meet our safeguarding responsibilities, manage our organisation, or comply with our legal and contractual obligations.

What data we collect

Personal data is information about you and from which you can be identified. We will collect and process personal data about you depending on our relationship with you. Most of the personal information we process is provided to us directly by you. Data collection can be through a variety of channels, including by telephone, email, via our website or on site and via third parties.

Service Users (Women, Girls, Young People)

  • Identification: Name, date of birth, gender, address, contact details (phone/email)
  • Demographics: Age, school or workplace, background information relevant to support
  • Support needs: Health information, wellbeing concerns, learning needs, social or emotional circumstances
  • Programme participation: Attendance records, progress notes, session notes, assessments
  • Safeguarding information: Risks, disclosures, concerns, referrals
  • Consent information: Consent forms, permissions for participation, photography/video (if applicable)


Parents and Carers (Where Relevant)

  • Name, contact details, relationship to the child or young person
  • Consent for participation or data processing
  • Emergency contact information
  • Relevant background information to support child or young person (e.g., health, educational needs)


Children and Young People

  • Name, date of birth, age
  • Contact details (or parent/carer contact)
  • Health or additional support needs relevant to their participation
  • Programme progress, attendance, and outcomes
  • Safeguarding or welfare information


Employees

  • Identification: Name, date of birth, gender, address, phone/email
  • Employment details: Job title, contracts, payroll and tax information
  • HR records: Qualifications, training, performance appraisals, absence records
  • Health information: Where relevant for employment, adjustments, or occupational health


Volunteers

  • Identification: Name, date of birth, contact details
  • References and background checks (e.g., PVG / DBS)
  • Availability, preferences, and roles undertaken
  • Records of training, inductions, and supervision
  • Emergency contact information


Referral Partners

  • Name, job role, and organisation of the referrer
  • Contact information (phone/email)
  • Details of the referral (information about the participant, consent status, relevant health or social circumstances)


Website Users / Individuals Contacting Her Story Scotland

  • Name, email address, phone number
  • Enquiries or messages submitted via contact forms
  • Newsletter sign-ups or event registrations (if applicable)
  • Website usage data (cookies or analytics, if used)

 

 

How and why we use your data

Service Users

  • Purpose: To provide support, assess individual needs, and ensure safety and wellbeing.
  • How we use it: To deliver tailored group and one-to-one programmes, complete risk and needs assessments, communicate about sessions or appointments, monitor participation and progress, and meet safeguarding or legal obligations.


Children and Young People (Accessing Support)

  • Purpose: To provide age-appropriate support and ensure safety.
  • How we use it: To deliver programmes suitable for their age and development, communicate appropriately, assess their needs, monitor engagement and progress, and implement safeguarding procedures.


Parents and Carers

  • Purpose: To support children and young people and ensure their safety.
  • How we use it: For communication about services, obtaining consent for participation, sharing relevant programme information, and following safeguarding procedures where necessary.


Employees

  • Purpose: To manage employment and comply with legal obligations.
  • How we use it: For payroll, HR management, training, performance appraisals, occupational health or safeguarding checks, and general workforce administration.


Volunteers

  • Purpose: To recruit, manage, and support volunteers.
  • How we use it: To assess suitability, conduct safeguarding checks, provide training and supervision, schedule activities, and manage their involvement in delivering programmes.


Referral Partners (Local Authority, Schools, Health Services, Other Agencies)

  • Purpose: To manage referrals and coordinate support for service users.
  • How we use it: To receive referral information, confirm consent where required, plan and deliver appropriate services, and report on service engagement or outcomes to the referrer.


Website Users and Individuals Contacting Us

  • Purpose: To respond to enquiries, manage registrations, and provide information about services.
  • How we use it: To respond to messages or requests, send newsletters or updates (if opted in), process event sign-ups, and monitor website usage where cookies or analytics are used.

 

Lawful Basis for processing data

Her Story Scotland will only process personal data where we have a lawful basis for doing so. The legal grounds for processing data will depend on the purpose of the data collected and its processing requirements. Under UK GDPR, there are six available lawful basis, namely: Consent, Contract, Legal Obligation, Vital Interests, Public Task, and Legitimate Interests.

We rely on the following lawful bases for processing data: –

  • Legitimate Interests – Used when processing is necessary for the effective delivery of our services, managing employees and volunteers, and maintaining donor relationships.
  • Legal Obligation – Applied when complying with safeguarding laws, employment regulations, financial record-keeping, and statutory reporting.
  • Contract – Used for employees to fulfil payroll, HR, and contractual obligations.
  • Consent – Required when sharing information externally (unless legally required), for certain types of support, and for donor communications.
  • Vital Interests – Relied on in emergencies where processing is necessary to protect someone’s life or prevent serious harm.
  • Public Task – Applied when fulfilling statutory duties, such as working with social services.

For special category data (e.g., health, safeguarding), we process this under:

  • Article 9(2)(b) (employment/social protection) – For safeguarding, service provision, and employee welfare.
  • Article 9(2)(g) (substantial public interest) – Where necessary to protect vulnerable individuals.

 

How we protect your personal data

We know how much data security matters to all our clients. With this in mind we will treat your data with the utmost care and take all appropriate steps to protect it. We secure access to all transactional areas of our website using ‘https’ technology. Access to your personal data (such as email and phone number) is password-protected, and sensitive data is secured and encrypted to ensure it is protected. All significant decisions about data processing and policy implementation will be made using UK GDPR. we take steps to ensure that appropriate security measures are taken with the aim of ensuring that your privacy rights continue to be protected as outlined in this notice.

Retention

We only keep your personal data for as long as necessary to fulfil the purposes we collected it for, including to meet any legal, accounting, or reporting requirements. Retentions will vary depending on the type of data and our legal obligations. When we no longer need your information, we will securely delete or anonymise it. If you would like more detail about how we long we keep specific types of information please contact us any time.

3rd Parties

Statutory and Safeguarding Agencies

  • Local authorities
  • Schools and education services
  • Health professionals (e.g., GPs, nurses, mental health teams)
  • Social work and child protection services
  • Police (where required for safeguarding or legal reasons)


Partner and Support Organisations

  • Community organisations involved in wellbeing, mentoring or educational support
  • Referral partners and agencies who signpost individuals to our services
  • Counselling or therapeutic services (with consent)


Operational and Administrative Providers

  • Secure IT, case management and communication platforms
  • Professional service providers such as payroll, HR, and accountancy services
  • Disclosure Scotland for staff and volunteer safeguarding checks
  • Funders (anonymised reporting unless consent is provided)


Website

Her Story Scotland collects personal data from web forms submitted by individuals requesting information in the form of general enquiries or to register for the events and services provided by Her Story Scotland. This comprises the name, phone number, email address, mailing address, company name, subject & message of the person making the enquiry.

Our websites & information we share around services & involving stakeholders may contain links to other websites run by other organisations. This privacy policy applies only to our website‚ so we encourage you to read the privacy statements on the other websites you visit. We cannot be responsible for the privacy policies and practices of other sites even if you access them using links from our website. In addition, if you linked to our website from a third-party site, we cannot be responsible for the privacy policies and practices of the owners and operators of that third party site and recommend that you check the policy of that third party site.

Social Media

Her Story Scotland can be found on social media platforms such as Facebook and Instagram. Social Media is an important part of our awareness effort, so you may be presented with retargeting ads & emails in future following a visit to our website. We may target ads at audiences that we believe match the profile of our target audience and would therefore be interested in our services. We will also regularly tag or mention you where we are carrying out business promotion on your behalf or to raise your professional profile. 

These platforms are run by commercial companies and Her Story Scotland is not the Data Controller or Data Processor of your social media profile. You should contact these social media platforms directly if you have concerns over how your personal data is being used and stored by them.

Payment data

We collect payments directly from customers who sign up for services. We also collect payments from organisations who have commissioned us to carry out services. Information collected for these purposes will be personal and financial data such as name, billing address, e-mail address, bank/debit/credit card or account information and transaction references.

Some of our commissioned services may involve collecting 3rd party donations through fundraising portals such as Just Giving. Personal and financial information will be collected. This includes but is not limited to your name, billing address, email address, credit/debit card information, or other payment details. This information is securely processed by the funding portal, and we do not store or have access to your full payment details.       

The processing of payment information is governed by the funding portals own Privacy Policy, which you can review on their website It is important to familiarise yourself with their privacy practices to understand how they will handle your data.

Website visitor behaviour analytic software

We use software to collect analytic information on how website visitors engage with our website pages and content. We do this to understand how our website visitors use a website in order to provide an efficient user experience along with relevant information. This information is only processed in a way which does not identify individuals.

Google Analytics

We use Google Analytics to collect standard internet log information on visitor behaviour patterns. We do this to understand how our website visitors use a website in order to provide an efficient user experience along with relevant information. This information is only processed in a way which does not identify individuals. For more information about Google Analytics terms and conditions, visit https://www.google.com/analytics/terms/.

To opt out of being tracked by Google Analytics across all websites visit http://tools.google.com/dlpage/gaoptout.

We may also collect personal data from the website using Google Analytics to anonymously track how users interact with our site. This involves installing Google Analytics code on our website in the form of a ‘cookie.’ Cookies contain an ID number which is assigned to a user and provides us with the following information:

  • Your IP address (An IP address does not provide identifiable personal information)
  • Your visits to our website
  • The time of your visits and the length of time you spent on our website.
  • The pages that you visited.
  • Your location (although this might be influenced by the location of your server)
  • The browser you are using.
  • Type of operating system
  • The device you are using (e.g., desktop, tablet or mobile)
  • Referral source (how you arrived on our site, e.g. search engine, direct URL, social media, or third-party website).


The Principles

Whether we are acting as a data controller or processor we continue to apply the UK GDPR principles to all personal & Sensitive data that we hold, or process and these principles lie at the heart of our approach to processing personal data.

1) Processed lawfully, fairly and in a transparent manner in relation to individuals.

2) Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be incompatible with the initial purposes.

3) Adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.

4) Accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased, or rectified without delay.

5) Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the UK GDPR in order to safeguard the rights and freedoms of individuals.

6) Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures.

Sharing Information

We use third parties who provide elements of our services for us. We have contracts in place with these 3rd parties who are data processors (the people who process personal information on our behalf). This means they cannot do anything with your personal information unless we have instructed them to do it. We will apply the following considerations at all times: –

 

  • They will not share your personal information with any organisation apart from us.
  • They will hold it securely and retain it for the period we instruct them to.
  • We provide only the information they need to perform their specific services.
  • They may only use your data for the exact purposes we specify in our contract with them.
  • If we stop using their services, any of your data held by them will either be deleted or rendered anonymous.
  • We will not sell or rent your information to third parties.
  • We will not share your information with any third parties for the purposes of direct marketing.
  • We will not transfer any personal data out with the UK or European Economic Area or to any third party without your knowledge.

 

We may be required to transfer your information to a third party as part of a division/merger/sale of some or all of our business assets as part of any restructuring or reorganisation of the business.

We may also be required to disclose or share your personal data to comply with any legal obligation or to enforce or apply our terms of use or to protect the rights, property or safety of our trustees, members, volunteers, supporters, contractors, and customers. However, we will take steps with the aim of ensuring that your privacy rights continue to be protected.

Examples of the kind of third parties we work with are: –

 

  • IT companies who support our website and other business systems
  • Third-party suppliers
  • Third-party credit checks
  • Photographers or independent consultants

 

We may share names, email addresses, pictures, job roles and organisational information as part of business-to-business networking events & with organisations & contractors commissioned to assist & co-ordinate these events.

Pre & post event/webinar management may include grouped online communications such as meeting invites in meeting chats and document sharing. Others attending may see your name and email address and may see conversation responses and questions you may ask.

Where we have been commissioned by an organisation to host a webinar or event, your registration & attendance information & any feedback you provide will be shared with this organisation.

We work closely with organisations to ensure that your privacy is respected and protected at all times.

We will not transfer any personal data out with the UK or European Economic Area or to any third party without your knowledge.

Protecting your personal information

We will continue to look for new ways to protect data. We have effective processes and procedures in place to be able to detect, investigate, risk assess and record incidents and breaches. However, in the event of a data breach we will notify the ICO (Information Commissioners Office) within 72 hours of becoming aware of the breach as well as take steps to inform any individuals affected. Where we do not yet have all the relevant details we will notify the ICO, if required, when we expect to have the results of the investigation. We use the ICO guidance framework on managing a security breach to guide us.

International

All significant decisions about data processing and policy implementation will be made using UK GDPR.  As part of the services offered to you the information which you provide to us will not be transferred to countries outside the UK. Our servers are located inside the UK. If we have a requirement to transfer your information outside of the UK in any way, we will take steps to ensure that appropriate security measures are taken with the aim of ensuring that your privacy rights continue to be protected as outlined in this Policy.

If you use our services while you are outside the UK, your information may be transferred outside the UK in order to provide you with those services.

Your data protection rights.

Under data protection law, you have rights we need to make you aware of. The rights available to you depend on our reason for processing your information.  

Your right of access – You have the right to ask us for copies of your personal information.

Your right to rectification – You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.

Your right to erasure – You have the right to ask us to erase your personal information in certain circumstances.

Your right to restriction of processing – You have the right to ask us to restrict the processing of your personal information in certain circumstances.

Your right to object to processing – You have the the right to object to the processing of your personal information in certain circumstances.

Your right to data portability – You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.

Right to complain (Data Use and Access Act 2025) – you have the right to complain if you believe your data is being misused or if your rights under UK data protection law or the Data Use and Access Act 2025 have been infringed.

You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.

Communications & Direct Marketing

The Privacy and Electronic Communication Regulations (PECR) sits alongside the Data Protection Act and the UK GDPR and gives individuals specific rights around electronic communication. This means if we send electronic marketing or use cookies or similar technologies, we must comply with both PECR and UK GDPR

Although PECR covers a number of areas which provide public electronic communication network or services, PECR applies to Her Story Scotland for

  • Direct Marketing by phone, email, text, or fax
  • Website cookies

 

Direct Marketing

You have the right to stop the use of your personal data for direct marketing activity through all channels, or selected channels. We must always comply with your request unless an exemption applies. There are various ways you can stop direct marketing communications from us.

  • Click the “unsubscribe” link in any direct marketing email communication that we send you. We will then stop any further direct marketing emails.
  • You can also email, call, or write to us to ask us to add you to our suppression list.

 

Exemptions

If you unsubscribe from our marketing mailing lists, you will still receive service and support communications from us where you are an existing customer, supplier or have a relationship with us that requires us to process your information as part of a contract or where the law requires us to do so.

Website Cookies

Cookies are small pieces of information sent by an organisation to your computer and stored on your hard drive to allow that website to recognise you when you visit. They collect statistical data about your browsing actions and patterns and do not identify you as an individual. For example, we use cookies to store your country preference. This helps us to improve our website and deliver a better more personalised service. It is possible to switch off cookies by setting your browser preferences. Turning cookies off may result in a loss of functionality when using our website.

Artificial Intelligence (AI)

We may use artificial intelligence (AI) to support our work and improve how we deliver services, always with care and oversight.

AI refers to computer systems that can carry out tasks the normally require human thinking – such as helping staff organise information, draft documents, or respond more efficiently.

There are 2 types of AI we may use:

  • Non-generative AI:- This type of AI helps with analysing and sorting data, such as identifying trends in anonymised service information. It does not create new content and does not make decisions on its own.
  • Generative AI:- This type of AI can produce content such as draft letters, summaries or reports based on information it is given. When used, it supports staff and is never a replacement for human judgement.

We do not use AI to make decisions about individuals without meaningful human involvement. If any AI tools are used in a way that involves personal data, we carry out a risk assessment beforehand to make sure the use is safe, fair, and lawful. These assessments help us check for risks such as bias, inaccuracy, or misuse, and ensure that any AI use is in line with our safeguarding responsibilities and data protection obligations.

Contact Us

Email:  hello@herstoryscotland.co.uk

 

Regulatory Information

Further information around your rights can be found at  https://ico.org.uk/your-data-matters

The ICO’s address:           

Information Commissioner’s Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF