Privacy Policy

Oakleaf Privacy Policy

How to use this policy (quick guide)

  • If you work for or volunteer with Oakleaf: this tells you what personal data we use and why.
  • If you are a client, donor, supporter, partner or supplier: this tells you what we do with your information and your rights.
  • If you run a project: use the ‘Lawful basis’ and ‘Sharing’ sections to check your activity is covered.
  1. About this policy.
  2. The policy applies to: Oakleaf (the charity) and its services, websites, fundraising and communications.
  3. The policy explains how Oakleaf (“we”, “us” or “our”) collects, uses, stores, shares and protects personal data. It is written to be readable for day-to-day operations while remaining legally robust.
  4. The policy supports our compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended from time to time, including changes introduced by the Data (Use and Access) Act 2025 (DUAA). It also covers relevant e-privacy rules under the Privacy and Electronic Communications Regulations (PECR).
  5. We also adopt appropriate elements of the Charity Commission’s expectations around good governance, accountability and transparency, and we apply suitable operational resilience practices where relevant to our use of technology, informed by principles in the EU Digital Operational Resilience Act (DORA) (recognising that DORA is a sector-specific EU framework primarily for financial entities).
  • Who we are and how to contact us.

Oakleaf is a charity registered in England and Wales (Charity Number:1064524) We are the ‘data controller’ for the personal data we process, unless stated otherwise.

Controller Oakleaf 
Registered address Oakleaf Enterprise
101 Walnut Tree Close
Guildford
GU1 4UQ
General contact mikeallcock@oakleaf-enterprise.org 01483303649
Data protection contact Mike Allcock 
ICO registration (if applicable) Name: Oakleaf Enterprise Reference: Z4965160  

If you have questions, want to exercise your rights, or want a copy of this policy in an accessible format, contact us using the details above.

  • Key definitions
  • Personal data is information that identifies you or could identify you.
  • Special category data is more sensitive data such as health information.
  • Processing is anything we do with personal data (collect, store, use, share, delete).
  • Controller – the organisation that decides why and how personal data is processed.
  • Processor – an organisation that processes personal data on a controller’s behalf (e.g., an IT service provider).
  • What information we collect.

We may collect the following categories of personal data, depending on your relationship with us:

  1. Identity and contact details: name, postal address, email address, telephone number, role and organisation.
  2. Service and support information: information you share when you contact us or use our services (including queries, feedback and correspondence).
  3. Beneficiary and safeguarding-related information (where relevant): information needed to deliver our charitable services; this may include special category data such as health information.
  4. Donations and fundraising: donation amount, payment method details (usually handled securely by our payment providers), Gift Aid declarations, and fundraising preferences.
  5. Employment, volunteer and recruitment: CVs, references, right-to-work checks, training and onboarding records.
  6. Website and device data: IP address, device and browser information, cookies and similar technologies (see section 12).
  7. Event participation: attendance lists, accessibility needs, dietary requirements (may be special category data).
  8. Photos, audio and video: images or recordings where you have consented or where justified for our legitimate interests (e.g., documenting events).
  • Where we get your information.

We collect personal data from:

  1. You directly (forms, email, phone calls, events, surveys).
  2. Your organisation (where you are a partner contact or referral).
  3. Public sources (e.g., professional directories), where appropriate.
  4. Our service providers (e.g., donation platforms) who share information back to us to administer donations and supporter relationships.
  5. Cookies and analytics tools on our websites (subject to PECR/consent where required).
  • Why we use your information.

We use personal data for the following purposes:

  1. To deliver our charitable services and support beneficiaries.
  2. To manage relationships with supporters, donors, volunteers, staff, trustees and partners.
  3. To run fundraising and communicate about our work.
  4. To administer events and training.
  5. To manage recruitment, volunteering and HR processes.
  6. To meet legal, regulatory and governance obligations (e.g., safeguarding, accounting, tax, reporting).
  7. To keep our systems secure and prevent fraud.
  8. To improve our services, including using aggregate analytics and feedback.
  • Lawful basis for processing (UK GDPR).

We only process personal data where we have a lawful basis under UK GDPR. Common lawful bases we rely on include:

Lawful basis When we use it Examples at Oakleaf 
ConsentWhen you have a genuine choice and can withdraw easily.Email marketing sign-up; optional event photos; non-essential cookies.
ContractTo fulfil a contract or take steps you ask us to take before a contract.Providing services you request; supplier contracts; employment contracts.
Legal obligationTo comply with law (excluding contracts).Tax and accounting; safeguarding duties; responding to regulator requests.
Vital interestsTo protect someone’s life.Emergency medical information at events where needed.
Public taskFor tasks carried out in the public interest (usually public bodies).Unlikely to apply to Oakleaf; we will rely on this basis only where clearly applicable to a specific activity.
Legitimate interestsWhere necessary for our legitimate interests and not overridden by your rights.Service improvement; fraud prevention; limited supporter stewardship (with opt-out).

Where we rely on legitimate interests, we assess necessity and balance our interests against your rights and expectations (a Legitimate Interests Assessment).

  • Special category data and criminal offence data.

If we process special category data (for example health information), we do so only where we have both:

  1. a UK GDPR lawful basis; and
  2. a specific condition under UK GDPR / Data Protection Act 2018 for processing special category data.

Examples of conditions we may rely on include:

  • Explicit consent (e.g., where you choose to share health information and we need it).
  • Substantial public interest (e.g., safeguarding where applicable).
  • Provision of health or social care or support services (where applicable).
  • Employment and social protection law (for staff/volunteers).

We do not routinely process criminal offence data. If we must (e.g., DBS checks for certain roles), we will apply additional safeguards and strict access controls.

  • How we share your information.

We may share personal data with:

  1. Service providers (processors) who support our operations (e.g., IT hosting, email distribution, CRM, fundraising platforms, payment processors).
  2. Professional advisers (e.g., auditors, legal advisers) where necessary.
  3. Regulators and authorities where required (e.g., the Charity Commission, HMRC, law enforcement).
  4. Partners and delivery organisations where needed to deliver services, with appropriate safeguards and transparency.
  5. Others with your consent or where permitted by law.

We require appropriate contractual protections (including confidentiality and data protection clauses). Where a supplier acts as our processor, we ensure they only process data on our instructions.

  1. How long we keep your information (retention).

We keep personal data only as long as necessary for the purposes described in this policy, and in line with our retention schedule. Key retention factors include legal requirements (e.g., tax/accounting), safeguarding considerations, limitation periods for claims, and operational need.

Typical examples (illustrative):

Record typeTypical retentionReason
Donation and Gift Aid records6 years (minimum) from end of financial yearHMRC/accounting requirements
Supporter contact preferencesUntil updated or you opt out + audit trail (limited)Compliance and accountability
Recruitment (unsuccessful applicants)6-12 monthsFairness; defence of claims
Safeguarding recordsAs required by safeguarding policy and risk assessment (often longer)Protecting individuals; legal obligations
Website analyticsAs configured in our analytics tools; minimise and review regularlyService improvement; data minimisation

If you would like details of the retention period for a specific category of information, contact us.

  1. Cookies, website analytics and PECR.

We use cookies and similar technologies on our websites. Under PECR, we must obtain consent for non-essential cookies (for example, analytics and marketing cookies) unless a cookie is strictly necessary to provide a service you requested.

We provide a cookie banner and preference centre (where implemented) so you can accept or reject non-essential cookies. You can also control cookies through your browser settings; however, blocking strictly necessary cookies may impact website functionality.

Email and SMS marketing: where PECR applies, we will only send electronic marketing where we have valid consent or another permitted route under PECR, and we will always provide a clear unsubscribe or opt-out mechanism.

  1. Fundraising and supporter communications.

We may contact supporters about our work, fundraising, and ways to help. We respect your communication preferences and comply with UK GDPR and PECR.

We may use the following channels, subject to the rules that apply:

  1. email/SMS: generally requires consent under PECR (unless a specific soft opt-in applies and conditions are met).
  2. Phone: we screen against preference services where required and respect opt-outs.
  3. Post: may be sent based on legitimate interests, subject to your right to object.
  4. Social media: we may use platforms that act as independent controllers for their own purposes; review their privacy notices.

You can update your preferences or opt out at any time by contacting us or using the unsubscribe link in our emails.

  1. Automated decision making.

We do not normally make decisions about individuals using solely automated processing that produces legal or similarly significant effects. If we do, we will provide clear information about the logic involved, the significance and the likely consequences, and we will implement appropriate safeguards as required by UK GDPR and DUAA amendments.

  1. Keeping your information secure.

We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration, or disclosure. Controls may include access management, multi-factor authentication, encryption where appropriate, secure configuration, staff training, and supplier due diligence.

If we use third-party IT services, we assess security controls and require appropriate contractual commitments. We have an incident management process to investigate and respond to suspected personal data breaches.

Where a personal data breach is likely to result in a risk to people’s rights and freedoms, we will report it to the ICO without undue delay and, where required, inform affected individuals.

  1. Operational resilience and technology risk (DORA-informed practices)

DORA is an EU regulation focused on digital operational resilience for financial entities and critical ICT service providers. Oakleaf is not generally a DORA-regulated entity unless it carries out regulated financial activities in scope or provides critical ICT services to such entities. However, as good practice we adopt proportionate measures aligned to the DORA principles where appropriate, including:

  1. ICT risk management: maintaining an inventory of key systems and suppliers; applying security baselines.
  2. Incident response: documented procedures, triage, and lessons learned.
  3. Backup and recovery: regular backups and recovery testing for critical systems.
  4. Third-party risk: due diligence and contractual controls for critical suppliers (e.g., cloud and SaaS providers).
  5. Resilience testing: periodic testing of business continuity and disaster recovery for key processes.

If Oakleaf becomes subject to a comparable operational resilience framework, we will update this policy and the associated controls accordingly.

  1. Your rights.

Under UK GDPR you have rights over your personal data, subject to some legal limits. These include the right to:

  1. Access your personal data (subject access).
  2. Rectify inaccurate personal data.
  3. Erase personal data (in certain situations).
  4. Restrict processing (in certain situations).
  5. Object to processing based on legitimate interests or for direct marketing (absolute right for direct marketing).
  6. Data portability (for data you provided to us where processing is based on consent or contract and carried out by automated means).
  7. Withdraw consent at any time (where we rely on consent).
  8. Raise a complaint with the Information Commissioner’s Office (ICO).

To exercise your rights, contact us using the details in section 2. We may need to verify your identity before responding.

  1. Children’s data.

If we provide services to children or collect children’s data, we apply additional safeguards and ensure that information is presented in a way that is appropriate to the age group. Where consent is required, we take steps to ensure it is valid (including parental responsibility checks where appropriate).

  1. Links to other websites and social media.

Our websites may link to third-party sites. Those sites have their own privacy notices and we are not responsible for their practices. If you use social media features or interact with us on social media platforms, those platforms may collect information about you as separate controllers.

  1. Changes to this policy.

We keep this policy under review and may update it to reflect changes in law, our services or our practices. We will publish the current version on our website and, where appropriate, notify supporters of material changes.

21. Legal and regulatory context (for reference).

This policy is intended to align with, among other sources, the following high-level frameworks and guidance:

  1. UK GDPR and Data Protection Act 2018.
  2. Data (Use and Access) Act 2025 (DUAA) – amendments to UK data protection and PECR.
  3. Privacy and Electronic Communications Regulations (PECR).
  4. Charity Commission expectations on transparency and handling of personal information.
  5. Digital Operational Resilience Act (DORA) – EU operational resilience framework (applied as good practice where relevant).

Legacy note: the Data Protection Act 1998 has been superseded (principally by the Data Protection Act 2018 and UK GDPR). Where historic records or contracts refer to the Data Protection Act 1998, we interpret and manage those obligations in line with current UK law.

This policy was approved by the Oakleaf Board on 3rd June 2026

There is ONE (1) Annex to this policy

Annex A – Oakleaf Privacy Policy

Contact details for complaints.

If you are unhappy with how we handle your personal data, please contact us first so we can try to resolve your concerns.

You also have the right to complain to the Information Commissioner’s Office (ICO). For current contact details, see the ICO website