Data Protection Policy

 

Adopted: 5 June 2023
Last reviewed: 2 September 2026
Next review due: 2 September 2027

Purpose

 

ADHD Pirates CIC is committed to handling personal information lawfully, fairly, securely and transparently.

This policy explains how we manage personal data across our activities and services.

We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and relevant changes introduced by the Data (Use and Access) Act 2025.

Our public Privacy Policy explains in more detail how we use personal information. Our Website Cookie Policy explains how we use cookies and website analytics.

Scope

 

This policy applies to personal data processed by ADHD Pirates CIC.

This may include information collected through:

  • our website, contact forms and email;
  • resource downloads;
  • peer groups and other activities;
  • the Executive Function Support Programme;
  • safeguarding concerns;
  • feedback and service delivery; and
  • website cookies and analytics where consent has been given.

Anonymous evaluation and reporting information is not personal data where individuals cannot be identified from it, but it will still be handled responsibly.

Data Protection Principles

 

ADHD Pirates CIC will:

  • process personal data lawfully, fairly and transparently;
  • collect information only for clear and legitimate purposes;
  • collect only the information that is necessary;
  • keep information accurate where appropriate;
  • keep personal data only for as long as it is needed;
  • protect personal data from unauthorised access, loss or misuse; and
  • respect individuals’ rights over their personal information.

Responsibilities

 

Data Protection Officer

 

Robert Walmsley, Director, is responsible for overseeing data protection within ADHD Pirates CIC.

This includes:

  • ensuring appropriate data protection arrangements are in place;
  • responding to data protection requests and complaints;
  • managing data breaches;
  • reviewing how personal information is collected, stored and shared; and
  • reviewing this policy as the organisation develops.

Other Directors

 

ADHD Pirates CIC currently has one additional director who is not involved in day-to-day operations and does not routinely handle personal data.

If their role changes, the relevant requirements of this policy will apply.

Future Staff and Volunteers

 

ADHD Pirates CIC does not currently have paid staff or formal volunteers.

Anyone who handles personal data on behalf of the organisation in the future will be expected to follow this policy and receive appropriate information or training before doing so.

Collecting and Using Personal Data

 

We will only collect personal information where there is a clear reason for doing so.

Information collected will be limited to what is reasonably necessary for the activity or service concerned.

This may include:

  • names and contact details;
  • information provided through enquiries or messages;
  • communication preferences;
  • accessibility or support information;
  • limited information required to organise and deliver services;
  • safeguarding information where a concern is raised; and
  • website information collected through cookies or analytics where appropriate.

Programme evaluation questionnaires that are designed to be anonymous will not intentionally collect identifying information.

Individuals are provided with information about how their personal data is used through our Privacy Policy and, where relevant, other information provided when data is collected.

Lawful Use of Personal Data

 

We will identify an appropriate lawful basis when processing personal information.

Depending on the circumstances, this may include:

  • consent;
  • legitimate interests;
  • legal obligations; or
  • vital interests.

Some information, including information about health or ADHD, may be classed as special category data.

Where special category data is processed, ADHD Pirates CIC will ensure that an appropriate additional legal condition applies.

We will not collect sensitive information simply because a person uses one of our services. It will only be collected where it is necessary and appropriate.

Data Storage and Security

 

Personal data will be stored securely and access will be limited to people who need the information for an appropriate organisational purpose.

Measures may include:

  • password-protected devices and accounts;
  • secure cloud platforms;
  • appropriate access controls;
  • secure storage of paper records; and
  • separate or restricted storage of safeguarding and other sensitive information where appropriate.

Physical records are currently stored securely at the Director’s home.

We will take reasonable steps to protect personal information against loss, unauthorised access, alteration or disclosure.

Sharing Personal Data

 

We will only share personal information where there is an appropriate reason and lawful basis for doing so.

This may include sharing information with:

  • service providers used to operate our website or services;
  • legal or regulatory bodies where required;
  • safeguarding services, local authorities or the police where necessary to respond to a safeguarding concern; and
  • other organisations where sharing is necessary and lawful.

Funders and partners will normally receive anonymous information where information is used to demonstrate impact or effectiveness.

ADHD Pirates CIC does not sell personal information.

Data Retention and Disposal

 

Personal information will normally be retained for one year after the person’s last interaction with ADHD Pirates CIC unless there is a reason to keep it for a different period.

Some information, such as safeguarding records, may need to be retained differently depending on the circumstances.

Genuinely anonymous information may be retained for evaluation, reporting and service improvement.

When personal information is no longer required, it will be securely deleted or destroyed.

This may include:

  • secure deletion of digital records; and
  • shredding of paper documents.

Individual Rights

 

People have rights over their personal information under data protection law.

Depending on the circumstances, these may include the right to:

  • access personal information we hold about them;
  • correct inaccurate or incomplete information;
  • ask for information to be deleted;
  • restrict how information is used;
  • object to certain uses of their information;
  • receive information in a portable format where the right applies; and
  • withdraw consent where processing relies on consent.

Requests can be sent to:

hello@adhdpirates.co.uk

We may need to confirm the person’s identity before responding.

Requests will be dealt with without undue delay and normally within one month.

More detailed information about these rights is available in our Privacy Policy.

Data Breaches

 

A personal data breach may include loss, unauthorised access, accidental disclosure or other inappropriate handling of personal information.

If a breach occurs, ADHD Pirates CIC will:

  1. identify and contain the breach where possible;
  2. assess the potential risk to individuals;
  3. take appropriate steps to reduce further risk;
  4. report the breach to the Information Commissioner’s Office where required;
  5. inform affected individuals where required; and
  6. record the breach and any action taken.

Where reporting to the Information Commissioner’s Office is required, this will normally be done within 72 hours of becoming aware of the breach.

Cookies and Website Analytics

 

ADHD Pirates CIC uses CookieYes to manage cookie choices on our website.

Necessary cookies remain active because they support essential website and cookie-consent functions.

Google Analytics and other non-essential cookies are only activated where the visitor has given permission.

ADHD Pirates CIC does not currently use advertising cookies for personalised advertising.

Full information about cookies, cookie categories and how visitors can manage their choices is available in our Website Cookie Policy.

International Data Transfers

 

Some organisations that provide services to ADHD Pirates CIC, including Google, may process personal information outside the UK.

Where personal information is transferred internationally, we will ensure that an appropriate safeguard recognised under UK data protection law is in place.

Further information is provided in our Privacy Policy.

Training and Awareness

 

Directors, staff or volunteers who handle personal data will receive information, induction or training appropriate to their responsibilities.

This will include, where relevant:

  • secure handling of personal information;
  • sensitive and safeguarding information;
  • recognising and responding to data breaches; and
  • understanding when information may or may not be shared.

Training requirements will be proportionate to the person’s role and responsibilities.

Complaints

 

Anyone who is concerned about how ADHD Pirates CIC has handled their personal information can contact:

Robert Walmsley
Director and Data Protection Officer
Email: hello@adhdpirates.co.uk

Data protection complaints will be recorded, investigated and responded to without undue delay.

People also have the right to complain to the Information Commissioner’s Office.

Further information about making a complaint is available in our Privacy Policy.

Monitoring and Review

 

This policy will normally be reviewed annually, or sooner where there is a significant change in:

  • legislation or regulatory guidance;
  • ADHD Pirates CIC’s activities or services;
  • the personal information we collect or use;
  • the systems or service providers we use; or
  • identified data protection risks.

The Privacy Policy, Website Cookie Policy and Data Protection Policy will be reviewed together where a change affects more than one of them.

Shares