The Third Age Trust Information Security Management System | |
Doc Third Age Trust Privacy Policy | Date 05/05/20 |
Ref U3A-ISMS-DOC-023 | Review 00/00/00 |
2.1. In this Privacy Policy:
2.1.1 references to we, us or our means The Third Age Trust, charity number 288007. a company limited by guarantee registered in England and Wales (company number: 01759471), whose registered office is The Third Age Trust,156 Blackfriars Road, London, SE1 8EN. You can contact us by post at the above address, by email at
2.1.2 references to you or your means the person accessing and using the Website (as defined below) or to whom we supply products or services, or contacts;
2.1.3 references to the Website means the websites found on the .u3a.org.uk domain.
2.2. Scope
Relevant to all data subjects.
2.3. Related documentation
U3A-ISMS-DOC-029 Third Age Trust Trading Limited Privacy Policy
This Privacy Policy and any other documents referred to in it sets out the basis on which we collect and use personal data about you through your use of the Website and when we supply products and services to you.
3.1 This Policy describes:
3.1.1 who is responsible for the personal data that we collect about you;
3.1.2 the personal data we collect about you;
3.1.3 how we will use it;
3.1.4 who we may disclose it to; and
3.1.5 your rights and choices in relation to your personal data.
This is to make sure you have a full picture of how we collect and use your personal data.
3.2 Personal data
In this Privacy Policy where we use the words personal data we use these words to describe information that is about you and which identifies you.
We are the data controller for the purposes of data protection law, in respect of your personal data collected and used by us.
5.1 Collection and use
We collect and use personal data about you for the purpose of communicating with you as representative of your U3A. The personal data we hold includes:
5.1.1 Information that you provide to us / we collect from you:
Type of Personal Data | Examples |
General | |
Contact information | Name, title, address, email address, social media name and telephone number |
U3A membership | Name of your U3A |
U3A role |
Whether you perform one of the following roles for your U3A for example: Chairman Secretary Treasurer Membership contact Direct Mail contact Website editor Newsletter editor Accessibility contact |
Trust Volunteer Role | Details of role(s) performed |
Marketing | |
Marketing preferences (including subscriptions to our national newsletter and magazine) | Details of any marketing preferences that you express including any opt outs you provide. |
Other | |
Online activity information (to the extent that it constitutes personal data) |
|
Project activity | Information about U3A activity or personal activity that you contribute as part of a U3A learning or communications event |
This information may be provided:
(a) in the course of communications between you and us (including by phone, email or otherwise);
(b) when you provide personal data via our Websites or using other systems which we provide to you;
(c) via our social media pages, other social media content, tools and applications;
5.1.2 Information we receive from other sources
(a) Third Age Trust Trading Limited
(b) Our service providers and business partners
(c) Information we receive from public websites and social media accounts belonging to U3As
6.1 Third parties
In the course of us communicating with you, you may provide us with personal data relating to third parties.
6.2 Consent and third parties
We will use this personal data in accordance with this Privacy Policy. If you are providing personal data to us relating to a third party, you confirm that you have the consent of the third party to share such personal data with us and that you have made the information in this Privacy Policy available to the third party.
7.1 Purposes
We use your personal data for a variety of different purposes during the course of us providing services to you. The purposes for which we use your personal data are set out below. Under data protection law, we can only use your personal data if we have a legal basis to do so. Examples of where we have a legal basis to process your personal data, includes when:
7.1.1 we have your consent;
7.1.2 it is necessary to enter into or perform a contract we have with you (or to take steps at your request prior to entering into that contract);
7.1.3 it is necessary to comply with a legal obligation; or
7.1.4 it is in our legitimate interests to process your personal data.
7.2 Legal Basis
We have set out our reasons for using your personal data in the table below under the heading Legal Basis. Where we rely on our legitimate interests, we have set out those interests in the table below.
Purpose | Legal Basis |
Setting up and managing the information we hold about you |
Contract Legitimate interests |
Assisting Third Age Trust Trading Limited with the management, development and making improvements to the Beacon system |
Contract Legal obligations Legitimate interests |
Communicating with you about our products, services and events |
Contract Legitimate interests |
Providing our newsletter | Legitimate interests |
Use of our library | Legitimate interests |
Participation In Third Age Trust learning programmes |
Contract Legitimate interests |
Providing our magazine "Third Age Matters" |
Contract Legitimate interests |
Survey participation |
Consent Legitimate interests |
Registering on our U3A Support Forum |
Consent Legitimate interests |
Publicity |
Consent Legitimate interests |
To comply with any legal or regulatory obligations (including in connection with a court order | Legal obligation |
To enforce or apply the agreements concerning you (including agreements between you and us). |
Contract Legitimate interests |
To manage any service or quality related issues, complaints, feedback and queries in relation to the supply of products and services. |
Consent Contract Legitimate interests |
We do not use your personal data to make any automated decisions that might affect you.
9.1 We may share your personal data with:
9.1.1 the Third Age Trust Trading Limited and
9.1.2 our service providers and business partners.
For more information please refer to Schedules 1 and 2.
9.2 We may also disclose your personal data to other third parties, for example:
9.2.1 if we or substantially all of our assets are acquired by a third party, personal data held by us will be one of the transferred assets; and
9.2.2 if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our the agreements concerning you (including agreements between you and us).
If we transfer personal data outside the UK or the European Economic Area (EEA), we will implement appropriate and suitable safeguards to ensure that such personal data will be protected as required by applicable data protection law.
11.1 Retention periods
We will keep your personal data for different periods depending on the nature of the information, the purpose for which it was collected, any legal obligation and/or business reason to retain.
11.2 Extensions
Please note that the above retention period may be extended where we need to preserve and use personal data for the purposes of bringing or defending a legal claim. In such cases, we will continue to hold and process your personal data for as long as is necessary to deal with the legal proceedings.
You have certain rights with respect to your personal data. The rights will only apply in certain circumstances and are subject to certain exemptions. Please see the table below for a summary of your rights. Details of who to contact to exercise these rights can be found in paragraph 16.
Summary of your rights | |
Right of access to your personal data | You have the right to receive a copy of your personal data that we hold about you and information about how we use it, subject to certain exemptions. |
Right to rectify your personal data | You have the right to ask us to correct your personal data that we hold where it is incorrect or incomplete. |
Right to erasure of your personal data |
You have the right to ask that your personal data be deleted in certain circumstances. For example:
|
Right to restrict the use of your personal data |
You have the right to suspend our use of your personal data in certain circumstances. For example:
|
Right to data portability |
You have the right to obtain your personal data in a structured, commonly used and machine-readable format and for it to be transferred to another organisation, where it is technically feasible. The right only applies:
|
Right to object to the use of your personal data |
You have the right to object to the use of your personal data in certain circumstances and subject to certain exemptions. For example:
|
Right to withdraw consent | You have the right to withdraw your consent at any time where we rely on consent to use your personal data. |
Right to complain to the relevant data protection authority |
You have the right to complain to the relevant data protection authority, which is in the case of us, the Information Commissioner's Office (ICO), where you think we have not used your personal data in accordance with data protection law. The ICO's contact details are: Information Commissioner's Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF |
Our Website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for how they handle your personal data. When you leave our Website, we encourage you to read the privacy notice of every website you visit.
Any changes we make to this Privacy Policy in the future will be posted on this page and, where appropriate, notified to you by email. The updated Privacy Policy will take effect as soon as it has been updated or otherwise communicated to you.
16.1 Queries regarding this policy or use of data
If you have any questions regarding this Privacy Policy or the way we use your personal data, please contact us by:
16.1.1 telephone on 020 8466 6139
16.1.2 email at
16.1.3 post at 156 Blackfriars Road, London, SE1 8EN.
Name of third party | Purpose |
Atlassian | Beacon administration |
Attend2IT | Technical and event support (specifically for the AGM) |
Banks e.g. Barclays Bank plc | Banking services |
Barclaycard | Payment processing |
Castelli (Diaries) Ltd | Fulfil bulk diary orders |
Cloudflare, Inc | Web application firewall |
Delivery companies e.g. Mailing & Marketing Solutions Ltd and Royal Mail Group Ltd |
Deliver ordered items |
DigitalOcean, Inc | Data storage |
D M Print Ltd | Print our magazine |
Fasthosts Internet Ltd | Web hosting |
GoDaddy Media Temple, Inc. d/b/a Sucuri | Web application firewall |
Goodman Jones LLP | Audit |
Google LLC | Website analytics |
HMRC | Regulatory filing |
Microsoft Corporation |
Data storage and management Communications handling |
N2 (Brand IQ) | Brand management and asset delivery |
Paragon Internet Group t/a tsoHost |
Web hosting SSL certification |
Parliament Hill | Member benefit services |
PayPal | Process payments |
Pen Test Partners LLP | Audit |
Rackspace, Inc | Web hosting |
Relevant U3As | Member charities |
The Rocket Science Group LLC d/b/a Mailchimp | Marketing platform |
Sarah Hayes |
Web development Web hosting |
Siftware Ltd | Development and maintenance of the legacy Beacon system |
SolarWinds, Inc | Log management |
SurveyMonkey Inc., SurveyMonkey Europe UC | Survey and form response collection and analysis |
Terias Consultancy Ltd | Database support |
Third Age Trust Trading Limited | Shared operations |
Transpeed (Europe) Ltd | IT support |
Trustwave Holdings, Inc |
SSL certification PCI compliance |
Twilio, Inc | Email delivery |
William Gibbons | Printers |
Zendesk Inc | Customer support |
Zoom Video Communications | Video conferencing |