How to use this policy (quick guide)
Oakleaf is a charity registered in England and Wales (Charity Number:1064524) We are the ‘data controller’ for the personal data we process, unless stated otherwise.
| Controller | Oakleaf |
| Registered address | Oakleaf Enterprise 101 Walnut Tree Close Guildford GU1 4UQ |
| General contact | mikeallcock@oakleaf-enterprise.org 01483303649 |
| Data protection contact | Mike Allcock |
| ICO registration (if applicable) | Name: Oakleaf Enterprise Reference: Z4965160 |
If you have questions, want to exercise your rights, or want a copy of this policy in an accessible format, contact us using the details above.
We may collect the following categories of personal data, depending on your relationship with us:
We collect personal data from:
We use personal data for the following purposes:
We only process personal data where we have a lawful basis under UK GDPR. Common lawful bases we rely on include:
| Lawful basis | When we use it | Examples at Oakleaf |
| Consent | When you have a genuine choice and can withdraw easily. | Email marketing sign-up; optional event photos; non-essential cookies. |
| Contract | To fulfil a contract or take steps you ask us to take before a contract. | Providing services you request; supplier contracts; employment contracts. |
| Legal obligation | To comply with law (excluding contracts). | Tax and accounting; safeguarding duties; responding to regulator requests. |
| Vital interests | To protect someone’s life. | Emergency medical information at events where needed. |
| Public task | For tasks carried out in the public interest (usually public bodies). | Unlikely to apply to Oakleaf; we will rely on this basis only where clearly applicable to a specific activity. |
| Legitimate interests | Where necessary for our legitimate interests and not overridden by your rights. | Service improvement; fraud prevention; limited supporter stewardship (with opt-out). |
Where we rely on legitimate interests, we assess necessity and balance our interests against your rights and expectations (a Legitimate Interests Assessment).
If we process special category data (for example health information), we do so only where we have both:
Examples of conditions we may rely on include:
We do not routinely process criminal offence data. If we must (e.g., DBS checks for certain roles), we will apply additional safeguards and strict access controls.
We may share personal data with:
We require appropriate contractual protections (including confidentiality and data protection clauses). Where a supplier acts as our processor, we ensure they only process data on our instructions.
We keep personal data only as long as necessary for the purposes described in this policy, and in line with our retention schedule. Key retention factors include legal requirements (e.g., tax/accounting), safeguarding considerations, limitation periods for claims, and operational need.
Typical examples (illustrative):
| Record type | Typical retention | Reason |
| Donation and Gift Aid records | 6 years (minimum) from end of financial year | HMRC/accounting requirements |
| Supporter contact preferences | Until updated or you opt out + audit trail (limited) | Compliance and accountability |
| Recruitment (unsuccessful applicants) | 6-12 months | Fairness; defence of claims |
| Safeguarding records | As required by safeguarding policy and risk assessment (often longer) | Protecting individuals; legal obligations |
| Website analytics | As configured in our analytics tools; minimise and review regularly | Service improvement; data minimisation |
If you would like details of the retention period for a specific category of information, contact us.
We use cookies and similar technologies on our websites. Under PECR, we must obtain consent for non-essential cookies (for example, analytics and marketing cookies) unless a cookie is strictly necessary to provide a service you requested.
We provide a cookie banner and preference centre (where implemented) so you can accept or reject non-essential cookies. You can also control cookies through your browser settings; however, blocking strictly necessary cookies may impact website functionality.
Email and SMS marketing: where PECR applies, we will only send electronic marketing where we have valid consent or another permitted route under PECR, and we will always provide a clear unsubscribe or opt-out mechanism.
We may contact supporters about our work, fundraising, and ways to help. We respect your communication preferences and comply with UK GDPR and PECR.
We may use the following channels, subject to the rules that apply:
You can update your preferences or opt out at any time by contacting us or using the unsubscribe link in our emails.
We do not normally make decisions about individuals using solely automated processing that produces legal or similarly significant effects. If we do, we will provide clear information about the logic involved, the significance and the likely consequences, and we will implement appropriate safeguards as required by UK GDPR and DUAA amendments.
We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration, or disclosure. Controls may include access management, multi-factor authentication, encryption where appropriate, secure configuration, staff training, and supplier due diligence.
If we use third-party IT services, we assess security controls and require appropriate contractual commitments. We have an incident management process to investigate and respond to suspected personal data breaches.
Where a personal data breach is likely to result in a risk to people’s rights and freedoms, we will report it to the ICO without undue delay and, where required, inform affected individuals.
DORA is an EU regulation focused on digital operational resilience for financial entities and critical ICT service providers. Oakleaf is not generally a DORA-regulated entity unless it carries out regulated financial activities in scope or provides critical ICT services to such entities. However, as good practice we adopt proportionate measures aligned to the DORA principles where appropriate, including:
If Oakleaf becomes subject to a comparable operational resilience framework, we will update this policy and the associated controls accordingly.
Under UK GDPR you have rights over your personal data, subject to some legal limits. These include the right to:
To exercise your rights, contact us using the details in section 2. We may need to verify your identity before responding.
If we provide services to children or collect children’s data, we apply additional safeguards and ensure that information is presented in a way that is appropriate to the age group. Where consent is required, we take steps to ensure it is valid (including parental responsibility checks where appropriate).
Our websites may link to third-party sites. Those sites have their own privacy notices and we are not responsible for their practices. If you use social media features or interact with us on social media platforms, those platforms may collect information about you as separate controllers.
We keep this policy under review and may update it to reflect changes in law, our services or our practices. We will publish the current version on our website and, where appropriate, notify supporters of material changes.
21. Legal and regulatory context (for reference).
This policy is intended to align with, among other sources, the following high-level frameworks and guidance:
Legacy note: the Data Protection Act 1998 has been superseded (principally by the Data Protection Act 2018 and UK GDPR). Where historic records or contracts refer to the Data Protection Act 1998, we interpret and manage those obligations in line with current UK law.
This policy was approved by the Oakleaf Board on 3rd June 2026
There is ONE (1) Annex to this policy
Annex A – Oakleaf Privacy Policy
Contact details for complaints.
If you are unhappy with how we handle your personal data, please contact us first so we can try to resolve your concerns.
You also have the right to complain to the Information Commissioner’s Office (ICO). For current contact details, see the ICO website