Privacy Policy
Heart Research UK is dedicated to protecting your personal data and being honest and transparent about what information we hold about you and how we process this data.
About this policy
This policy describes how we use your personal data when you use our website heartresearch.org.uk or when buy goods on our shop shop.heartresearch.org.uk, when you apply for a grant from us or when we provide services to you. We have provided this policy to ensure that you understand what personal data we may collect and hold about you, what we may use it for and how we keep it safe. You have legal rights to access the personal data that we hold about you and to control how we use it which are also explained.
We are Heart Research UK, a Company limited by guarantee (No 3026813) and charity registered in England (our charity number is 1044821). Our registered office address is Suite 12D, Joseph’s Well, Leeds, LS3 1AB.
You can contact us in writing at the address above or by emailing info@heartresearch.org.uk. If you would like to speak to us, please call us on 0113 234 7474.
Personal data you share with us:
This comes in many forms, for example when you engage with our social media, make a donation to us, register for an event, apply for a grant, take part in our Healthy Heart at Work programme or contact us in connection with goods or services that we provide.
The personal data that you provide to us may include your name, address, e-mail address and phone number, date of birth, financial information you use to make a payment or donation, place of work and job title as well as any other information you choose to share with us such as information related to your personal experience with heart diseases.
Personal data that we receive from third parties:
If we work with other businesses or use sub-contractors these parties may collect personal data about you which they will share with us. For example, we may have your name and contact details passed to us by a fundraising platform that you have used to fundraise with or event organisers that you have registered with. You should check their Privacy Policy when you provide your information to understand fully how they will process your data and when they may share data with us.
Personal data about your use of our websites:
This is technical information and includes details such as your IP address, browser type and version, time zone setting, operating system and platform, as well as details of how you navigated to our website and where you went when you left, what pages you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs).
Information available publicly:
We may use information available in the public domain such as Companies House, LinkedIn or other available records such as publications and articles.
In the course of our interactions with you or in order to provide some of our services (such as our Patient and Public Involvement group or our Healthy Hearts at Work program) we may collect ‘Special Category data’. This is personal information which is regarded by the law as more sensitive than others and covers things like information about your health, ethnic origin, religious beliefs, political opinions or any genetic or biometric data that is used to identify you.
We may also collect sensitive personal data if you make the information public or if you tell us about your experiences relating to heart diseases (for example, if you act as a case study for us).
We will always make it clear to you when we collect this information, what sensitive personal data we are collecting and why and the legal basis we use to do so.
We use your personal data in the following ways:
- personal data that you provide to us is used to:
- provide you with the information and services that you request from us
- provide you with marketing information in accordance with your marketing preferences (see the how we use your personal data for marketing)
- fundraise in accordance with this policy and in a way that you might reasonably expect
- manage and administer our organisation (for example we may contact you regarding your donation or fundraising)
- review and improve our service
- analyse information you provide to us alongside other publicly available information to create a profile of supporter interest so that we can personalise our communications and provide you with the most relevant information
- personal data that we receive from third parties is combined with the personal data that you provide to us and used for the purposes described above
- personal data about your use of our website is used to:
- administer our website and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes
- to improve our website to ensure that content is presented in the most effective manner for you and for your computer or mobile device
as part of our efforts to keep our site safe and secure - to measure or understand the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you
- to make suggestions and recommendations to you and other users of our site about goods or services that may interest you or them
We use data analysis to understand the data we hold about you and predict how likely you are to support us. If we have identified that you have capacity to support us at a higher level, we may collect additional information about you and combine this with information you may have provided us to create a profile. This is used by us to engage with you in a more personalised way.
We use information available in the public domain such as Companies House, the Electoral Register and data you choose to make public (for example on social media platforms) and combine this with any information you might share with us directly. We may also use your geographical information to measure affluence. Where we do this, we work with specialist agencies that collect information from public registers and use statistical methodologies to create socio-economic profiles. For example, we used Experian to better understand existing and potential supporters. (https://www.experian.co.uk/business/platforms/mosaic)
You may opt-out of this type of processing at any point by contacting us using the details provided in this policy.
When seeking or accepting large donations, we are required to carry out some due diligence to comply with our regulatory obligations and our own risk management policies and procedures. This means that even if you opt-out of your data being analysed in the ways described above we may still carry out some analysis in order to accept a donation from you.
Whilst we always want you to be aware of how we are using your personal data, this does not necessarily mean that we are required to ask for your consent before we can use it. In the day to day running of our business we may use your personal data for a number of purposes as described in this policy. Depending on the purposes for which we use your data, we may use one or more legal basis:
- Contract: when we are entering into and carrying out our obligations under a contract with you or to provide you with good or services you have requested
- Legitimate Interest: we rely on Legitimate Interest when collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. For example:
-
- the administration and management of our business and the improvement of our services
- sending direct marketing material to supporters by post for fundraising purposes
- taking and using photos and/or films of event participants and attendees
sending relevant marketing and fundraising information to your work email address
- Legal Obligation: we may need to collect, process and disclose personal information to comply with a legal obligation.
In exceptional circumstances we may wish to use your personal data for a different purpose which does require your consent. In these circumstances we will contact you to explain how we wish to use your data and to ask for your consent. You are not required to give consent just because we ask for it. If you do give consent, you can change your mind and withdraw it at a later date.
Please refer to the section on How we use your personal data for marketing to read about marketing consents.
You are not under a legal obligation to provide us with any of your personal data but please note that if you elect not to provide us with your personal data, we may be unable to provide our services to you.
You have a legal right to know what personal data we hold about you – this is called the right of subject access. You can exercise this right by sending us a written request at any time. Please mark your letter “Subject Access Request” and send it to us at Suite 12D Joseph’s Well, Leeds, LS3 1AB or by email to info@heartresearch.org.uk
You also have rights to:
- prevent your personal data being used for marketing purposes (see How we use your personal data for marketing for further details)
- have inaccurate personal data corrected, blocked or erased
- object to decisions being made about you by automated means or to your personal data being used for profiling purposes
- object to our using your personal data in ways that are likely to cause you damage or distress
- restrict our use of your personal data
- require that we delete your personal data
You can find full details of your personal data rights on the Information Commissioner’s Office website at www.ico.org.uk.
Whilst we do not make use of automated decision making, we use an Artificial Intelligence profiling software when asking for donations on our website. This is used to help us decide the most appropriate amount to ask for and helps us improve the performance of our donation forms.
We share your data with the following people in the day to day running our business:
- any subsidiaries, business partners, suppliers and sub-contractors we work with to provide you with goods or services that you have requested from us. For example, we store most personal information in our database, Beacon CRM (https://www.beaconcrm.org/)
- analytics and search engine providers that assist us in the improvement and optimisation of our sites
- payment providers that we use to take payments on our sites
- social media companies and advertising networks to help us identify audiences with interest similar to yours
We may also share your personal information with third parties on a one-off basis, for example, if:
- we sell or buy any business or assets (including our own), in which case we will disclose your personal data to the prospective seller or buyer of such business or assets
- we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our website terms of use and other agreements; or to protect the rights, property, or safety of our customers, ourselves or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection.
We take every care to ensure that your personal data is kept secure. The security measures we take include:
- only storing your personal data on secure servers
- encrypting any payment transactions and data transfers made through our websites using SSL technology
- ensuring that our staff receive regular data security awareness training
- keeping paper records to a minimum and ensuring that those we do have are stored in locked filing cabinets on our office premises
- maintaining up to date firewalls and anti-virus software to minimise the risk of unauthorised access to our systems
Please remember that you are responsible for keeping your passwords secure. If we have given you (or you have chosen) a password which enables you to access certain parts of our website you are responsible for keeping this password confidential. Please do not to share your passwords with anyone.
Unfortunately, sending information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of personal data sent to our website; you send us personal data at your own risk. Once we have received your personal data, we will use strict procedures and security features (some of which are described above) to try to prevent unauthorised access.
We may send you marketing communications by email, telephone, text message and post.
You can ask us to only send you marketing communications by particular methods (for example, you may be happy to receive emails from us but not telephone calls), about specific subjects (for example to hear about our grant rounds) or you may ask us not to send you any marketing communications at all.
We may ask you to indicate your marketing preferences when you first register an account on our websites. You can check and update your current marketing preferences at any time by emailing us using the details set out in the Who we are and how you can contact us section above.
We sell or rent your personal data with third parties for marketing purposes.
Your personal data may be transferred to, and stored at, a destination outside the UK by us or by our sub-contractors.
Where we, or our sub-contractors, use IT systems or software that is provided by non-UK companies, your personal data may be stored on the servers of these non-UK companies.
We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy.
We only keep your personal data for as long as we actually need it and we have adopted a data retention policy which sets out the different periods we retain personal information for depending on their purposes. In deciding on this policy we consider the legal requirement, the purpose(s) for which we hold the data and whether we have a legitimate reason to keep storing it (such as our ability to deal with any future potential legal dispute).
Please note that we may anonymise your personal data or use it for statistical purposes. We keep anonymised and statistical data indefinitely, but we take care to ensure that such data can no longer identify or be connected to any individual.
If you are unhappy with the way we have used your personal data please contact us to discuss this using the contact details provided in this policy or by visiting our website.
You are also entitled to make a complaint to the Information Commissioner’s Office which you can do by visiting www.ico.org.uk.
Whilst you are not required to do so, we encourage you to contact us directly to discuss any concerns that you may have and to allow us an opportunity to address these before you contact the Information Commissioner’s Office.
We will review and update this policy from time to time. This may be to reflect a change in the goods or services we offer or to our internal procedures or it may be to reflect a change in the law.
The easiest way to check for updates is by looking for the latest version of this policy on our websites or you can contact us (see Who we are and how to contact us) to ask us to send you the latest version of our policy.
This is policy was last updated on 16/11/2024.