Dementia UK is committed to protecting your personal data and respecting your privacy.
Whenever you share personal data with us we aim to be clear with you and not to do anything that you would not reasonably expect us to do. We will always endeavour to tell you when we are collecting data from you and in this document we describe what we will and will not do with your personal information.
1. The type of personal information we collect
We receive personal information about you in a number of ways:
(a) Personal information you provide to us
We receive personal information from you when you ask about our activities, order products and services from us (such as publications and email newsletters), use our services, make a donation to us, fundraise on our behalf, share your story with us (where you have given us explicit consent), submit an enquiry, join one of our networks, give us feedback, make a complaint, apply for a job, register as a volunteer, or otherwise give us personal information.
The type of personal information we collect will therefore depend on the reason why you are engaging with us. It may include information such as your name, date of birth, email address, postal address, telephone number and credit/debit card details.
Sometimes it may be appropriate for us to ask for information about your health or personal circumstances (for example, when calling our Admiral Nurse Dementia Helpline, when booking an appointment with one of our Clinics or if you wish to take part in a high risk event). We will only do this when we need to.
Occasionally, it may be useful for us to find out why you are supporting us as this helps us understand the benefits of our work. You do not have to answer this question and we only want you to answer if you are happy doing so.
(b) Personal information provided to us by third parties
Sometimes, we receive personal information about you when you engage with other organisations. Details of this are set out in the section ‘How we collect your information’. When this happens we will treat the information in the same way as if you had shared it directly with us.
(c) Extra personal information we generate – analysis of your personal information
From time to time we may keep your records up-to-date and add information to them by checking against external publicly available information. For example, we might use an external service to find your new address. We may also research information about you, either from publicly available information or from information that we have already collected from you. We do this so we can operate efficiently and to ensure you receive information that is relevant to you and the purposes for which you have shared your personal information.
Additionally, we use Open Tracking functionality in our email marketing campaigns to understand who has opened our marketing emails, how many times and whether any content has been clicked through on. This enables us to better tailor future campaigns to our supporters based on previous activity and interests.
2. How we use your information
We will use your personal information primarily to:
Administer any donation from you or support your fundraising efforts, including the claim of Gift Aid on your donations (as requested by HMRC)
Record your involvement with us
Respond to your request
Let you know about changes to our services or policies
Provide any information you have requested from us, and direct you to any services that may be relevant
Manage your preferences for hearing from us
Send you communications about our work and how you can help us, for example, information about our fundraising activities, volunteering and campaigns
Investigate and respond to complaints, legal claims or other issues
To detect and reduce fraud and credit
2.1 Building profiles
We may also analyse the information we collect about you so that in certain cases we can build a profile and better understand you and target our communications to you appropriately, and with the most relevant information. For example, we may wish to send you invitations to attend special events or to discuss specific fundraising projects. Where we use such profiles it enables us to cost-effectively and efficiently raise funds to support our work.
When building a profile we may analyse geographic, demographic and other information relating to you. In doing this, we may use additional publicly available information about you, for example addresses, listed Directorships or typical earnings in a given area. We may also carry out wealth screening using our trusted third party providers.
Occasionally, we may use your personal information for other purposes consistent with our charitable purposes, but we will notify you about this, and more importantly, obtain your consent.
2.2 Why we build profiles
We believe our collection and use of your personal information is necessary and in the charity’s best interests so that we engage with you in the most effective way, using our resources efficiently, and so that we may raise donations to support the beneficiaries of Dementia UK. In doing so, we do not consider that it will cause undue harm to your privacy.
We believe this because:
the personal information about you has either been provided by you, generated by your engagement with Dementia UK or is personal information that is publicly available from legitimate sources
we have made you aware of how we use your personal information and that we undertake this level of research at the point you first provided your personal information to us
you will expect us to know information about your interests, preferences and the level of potential support you might provide to Dementia UK – in order that we make best use of your time and efforts in engaging with us
3. How we collect your information
Your personal information may be shared with us in the following ways:
you may give us your information when you sign up for one of our events, join our Young Dementia Network, make a donation, register to volunteer or communicate with us any other way
your information may be shared with us via referrals from trustees, volunteers or staff members
your personal details may be available from public sources of personal information. Please see the sections above for more detail
your information may be shared with us from other online accounts. Depending on your settings or the privacy policies for other online services like Facebook or Twitter, you might give us permission to access information from those accounts. The information we get from those online services depends on your personal settings, and therefore it is recommended that you check them regularly.
Your information may also be collected by an affiliated fundraising group, who will store it on password protected excel spreadsheets, accessible only by relevant group members. Dementia UK will only hold your details on our central database and contact you if you have given us permission to do so.
4. Information collected via the Admiral Nurse Clinical Delivery Services
Any data collected via the Admiral Nurse Clinical Delivery Services is stored and managed separately to other data provided to the charity.
Whenever you contact the Admiral Nurse Clinical Delivery services on behalf of another person, you must ensure that you have the right to share personal information with us relating to the individual. This will usually be the case if you are their primary carer and you have their expressed consent or, if they lack capacity to make their own informed decisions and a decision needs to be made for them and you are acting in their best interest in accordance with the Mental Capacity Act.
Our Admiral Nurse Clinical Delivery services are there to assist with the care of vulnerable individuals. As such we treat this sensitive information with the utmost confidence and respect and will not share this information with any third party, except in the specific circumstances detailed in section 4.1 below. The information is stored on a database which can only be accessed by our registered nurses who are governed by the Nursing and Midwifery Council and their Code of Practice and a small number of staff who help to administer the services.
We will be processing your data under the legal basis of Legitimate Interests. We have considered your data privacy rights and the potential impact on you and concluded that the benefits to you of us processing your data in this way, outweigh any negative impacts. For any special category data which we collect, we are relying on an additional legal basis of Health and Social Care.
All calls to the Admiral Nurse Dementia Helpline and some telephone calls booked with our Clinics will be recorded in order that we can monitor and ensure the quality of our service. However, if you do not wish for your call to be recorded, you can alert the Admiral Nurse at the start of the call and we will not record it. Copies of all recorded calls will be retained, but only for as long as required for these purposes.
The information that you give to our Admiral Nurses (dementia specialist nurses) will only be used to:
provide advice in respect of the care of the relevant person (if you are calling about another person) or about your own health;
monitor any advice we have given you;
contact you in relation to any communications between us and any advice we have given you;
contact you to seek your feedback on your experience of the service.
We will also use some of the information to evaluate our services and assess trends, such as who is using them and the types of enquiry that are being made. However, all information used in this way will be anonymised.
We will only hold the information provided via the Admiral Nurse Clinical Delivery services for so long as it is necessary for the intended purposes or as is required by law. We retain this information for 8 years in line with other health and social care records.
4.1 How we share information provided to the Admiral Nurses Clinical Delivery Services
Exceptional circumstances may include:
Where we are legally required to do so by a court order or other law enforcement agencies, professional regulators, and/or safeguarding agencies.
Where you or someone you are telling us about is at risk of serious harm, neglect, death, or other significant threat to self or personal safety and wellbeing and lack capacity under the Mental Capacity Act 2007.
Where you have told us that a child may be experiencing harm or other threats to their personal safety and well-being, either from their own actions or the actions of others.
Where disclosure is deemed necessary to prevent a crime or serious offence being committed.
We may also share any information you provide to us with the relevant GP in circumstances where we are legally required to do so, or if we consider it is in the best interests of the person living with dementia to do so.
Occasionally, our Admiral Nurses will be asked to help you fill out forms for other services (for example a Support Group.) Our nurses will only ever do this when you request this and provide your explicit consent. We cannot be held responsible for the privacy of other websites not managed by us.
5. Legacy information
As part of the process of administering gifts kindly left to us in Wills, we need to collect and process personal data of a number of involved parties – Solicitors, executors, next of kin, family members, other named beneficiaries and employees of other organisations. This processing is necessary in order to comply with our legal obligation to ensure the money is received and used according to the intended charitable purposes.
We receive the personal data involved from a number of sources – from the copy of the will, communication with executors/solicitors/ professional third party, from other charities administering a legacy in respect of the same will and from third parties such as Smee & Ford (a company who advise charities if they have been named in the Will of a deceased person). We only hold onto the data for as long as is necessary. We are legally required to keep a record of information relating to legacies for 7 years.
6. Social media marketing
We may use social media to communicate with you about campaigns, events or news. We do this in a number of different ways, including through posting on our own social media and by marketing on your social media.
One of the tools that we use to do this is provided by Facebook and is called a “custom audience”. We upload your name and email address to Facebook in an encrypted format. Facebook then searches its own data for a match. Where a match is found, our marketing will start to appear on your news feed. We may also use the Facebook “lookalike” tool to help us find profiles of people who are similar to you and who may be interested in supporting our charity. Once identified by Facebook they will also start to see our marketing in their news feed.
We will only share your details with Facebook in this way if you have consented to us sending you marketing via email. You can contact us at any time to let us know that you would prefer us not to use your information in this way. You can also update your preferences within the social media site to stop receiving marketing.
7. How we share your information
We will not sell your details to any third parties, but we may sometimes share your information with our trusted service providers who are authorised to act on our behalf. For example when you indicate that you would like to receive information from us in the post or via email, we may provide your name and address or email address (as applicable) to a third party sub-contractor who will compile and send out the relevant mailings on our behalf. This third party will not use or process the information for any purpose other than compiling and sending out the relevant mailing. The information you receive will be information which you have agreed to receive from us and the third party will not contact you for any other purpose.
In addition, from time to time we may exchange your personal information with other organisations for the purposes of fraud and credit risk reduction. We may also share information with our financial and legal advisers for the purposes of obtaining advice and protecting our legal rights.
8. The Legal Basis for Processing
Data protection laws mean that each use we make of personal information must have a “legal basis”. The relevant legal bases are set out in the General Data Protection Regulation (EU Regulation 2016/679) and in current UK data protection legislation.
Consent is where we ask you if we can use your information in a certain way, and you agree to this (for example when you join our Young Dementia Network or we send you marketing material via post, phone, text or e-mail). Where we use your information for a purpose based on consent, you have the right to withdraw consent for any future use of your information for this purpose at any time.
We have a basis to use your personal information where we need to do so to comply with one of our legal or regulatory obligations. For example, in some cases we may need to share your information with our various regulators such as the Information Commissioner or Fundraising Regulator, or to use information we collect about you for due diligence or ethical screening purposes.
Performance of a contract
We have a basis to use your personal information where we are entering into a contract with you or performing our obligations under that contract. Examples of this would be if you are buying something from us (for instance Christmas cards) or applying for a job with Dementia UK.
We have a basis to use your personal information where it is necessary for us to protect life or health. For instance if there were to a safeguarding issue which required us to share information provided to us via the Admiral Nurses Dementia Helpline (see Section 4.1).
We have a basis to use your personal information if it is reasonably necessary for us (or others) to do so and in our/their “legitimate interests” (provided that what the information is used for is fair and does not unduly impact your rights).
We consider our legitimate interests to include the following activities carried out by Dementia UK
Where you have signed up to fundraise for us at an event, to contact you about the event and support you in your fundraising journey. We may also share your personal information with the third party event organiser so they can administer the event
Where you have registered your interest to volunteer with us or submitted a volunteer application form. We will use your personal data to communicate with you, support you in your role and manage our relationship with you
To update your address using third party sources if you have moved house
To capture details from you when you book and attend one of our Admiral Nurse Clinical Delivery Services so that we can provide you with the support you require
To thank Next of Kin for donations collected in memory of a loved one
To contact prospective company supporters by email, phone and post to: find out information about their giving policies, make them aware of Dementia UK and tell them about opportunities to support us.
To contact prospective Trust funders by email, phone and post to find out more about their giving criteria and to apply for funds.
To contact prospective supporters by post where information in the public domain indicates they may be interesting in supporting Dementia UK.
To contact people who have previously supported the charity where we believe they will be interested in supporting us again.
To track whether you open/forward/click through on our marketing campaigns in order to send you the most relevant marketing materials/campaigns in the future.
To contact people via post or email who have used one of our Admiral Nurse services to seek feedback on their experience so that we can improve our services.
We only rely on legitimate interests where we consider that any potential impact on you (positive and negative), how intrusive it is from a privacy perspective and your rights under data protection laws do not override our (or others’) interests in us using your information in this way.
When we use sensitive personal information, we require an additional legal basis to do so under data protection laws, so will either do so on the basis of your explicit consent or another route available to us at law for using this type of information (for example if you have made the information manifestly public, we need to process it for health and social care reasons, your vital interests, or, in some cases, if it is in the public interest for us to do so).
9. How we keep your data safe and who has access
Dementia UK is responsible for collecting your personal information. We use rigorous procedures and strict security features when we collect your personal information in order to prevent unauthorised access. However, no data transmission over the Internet is 100% secure and although we try to protect your personal information, Dementia UK cannot guarantee the security of any information you transmit to us and you do so at your own risk.
We have appropriate technical controls in place to protect your personal details (for example our online forms are always encrypted and our network is protected and routinely monitored).
Regular reviews are carried out to establish who has access to information that we hold. This ensures that your information is only accessible by appropriately trained staff, volunteers and contractors.
We may, in some limited circumstances, have an obligation to disclose your details to the police, regulatory bodies or legal advisors.
We will only ever share your data in other circumstances if we have your explicit and informed consent.
9.1. Where we store your personal data
We aim to store all information in the UK where possible. However, in some situations, your personal data may be transferred outside the UK either to a country within the EEA, or worldwide. An example of this would be when one of our trusted partners processing information on our behalf has servers located in another country.
If this is the case, we will always seek to ensure that appropriate safeguards are in place to protect your personal data and that they provide an adequate level of protection in accordance with UK data protection law.
9.2. How long we will hold onto your personal data for
We will only hold the information provided to us for so long as it is necessary for the intended purposes or as is required by law. We have specific, defined data retention periods for different data types, which are determined by legal and operational considerations. For instance, if you give us a donation, we are required to keep a record of this for seven years because of legal obligations.
10. External Links
The Dementia UK website may include links to other sites, not owned or managed by us. We cannot be held responsible for the privacy of information collected by websites not managed by us.
Cookies mean that a website will remember you. Cookies are small text files that sites transfer to your computer (or phone or tablet) to make interacting with a website faster and easier.
The information gathered from cookies help us to: review how our website is being used and therefore help us to improve our website and online services; simplify your ability to navigate through the website; personalise and improve the service offered to you by understanding your preferences and establishing which areas of the website are most relevant to you and know if the website is operating effectively.
In addition, the type of device you are using to access our website and the settings on that device may provide us with information about your device, including its type, what specific device you have, what operating system you use, the device settings, and why a crash may have happened. The operating system provider or the manufacturer of the device will have more details about what information your device makes available to us.
If you are aged 16 or under, you must get your parent/guardian’s permission before you provide any personal information on our Website.
13. Your rights
We will use publicly available information to update your details wherever possible. However, it is a great help to us if you are able to let us know if your details have changed.
You can request access to any information we hold about you, free of charge. Please provide us with a description of the information you want and also send proof of your identity. If there are any discrepancies in the information we provide, please let us know and we will correct them.
You can request at any time to for us to delete some or all of your personal information and in certain cases, and subject to certain exceptions, you have the right for this to be done.
If we are processing your personal information based on our legitimate interests or for scientific/historical research or statistics, you have a right to object to our use of your information.
If you are unhappy with how we are using your personal information we would like to hear about it. You also have the right to lodge a complaint about any use of your information with the Information Commissioners Office (link is external), the UK data protection regulator.
If we are processing your personal information for direct marketing purposes, and you wish to object, we will stop processing your information for these purposes as soon as reasonably possible.
For any of the situations mentioned above and throughout this Policy where contacting the charity has been suggested, please contact us at: Supporter Care
Dementia UK 7th Floor, One Aldgate, London, EC3N 1RE
This policy is written in accordance with the General Data Protection Regulation (2018) and describes how Dementia UK collects and uses personal information given directly or indirectly by people who engage with us and or visit our Website.
Dementia UK is registered under the Act as a Data Controller under number Z1250036. If you have any questions about the policy, please contact our Data Protection Officer at Dementia UK, 7th floor, One Aldgate, London, EC3N 1RE or email firstname.lastname@example.org or call 020 8036 5400.
This policy was last updated on 29th September 2022.