1. Overview

This Privacy Statement sets out the data processing practices carried out by East Sussex Community Voice [including Healthwatch East Sussex].

We retain and use personal data (information that relates to and identifies living people) to help us carry out our role in delivering our various projects and programmes.

Our commitment to your personal information We will always make sure that personal information is only captured where necessary, that we communicate when and why information is sought from you,
and that any we do collect is protected and treated securely.

Any information that you give will be held in accordance with:
The Data Protection Act 2018
The UK General Data Protection Regulation (UK GDPR).

We maintain a Register of Processing Activity (ROPA) and a data record and retention schedule which identify the lawful basis for capturing, storing and retaining personal data.


2.Information we collect and use personal data and information

We collect personal information from visitors to our website(s) through the use of online forms and every time you email us or contact us with your details. We also collect feedback and views from people about the services that they access.

In addition, we receive information about our own staff, board members, volunteers and people who apply to work or volunteer for us.

Personal information about you may be used for the following purposes:
• in our day-to-day work, such as research, engagement and information and signposting;
• to send you our newsletter(s), bulletins, news and event updates or other relevant information where you have requested it;
• to respond to any queries you may have;
• to improve the quality and safety of services;
• to train staff and volunteers.
This may include any personal information that you choose to share with us, but we will treat this as confidential and protect it accordingly.

We will never include your personal information in our reports or other outputs unless we have obtained your consent to do so.

We have included much more detail about each of the above and other various types of information we process under each of the headings listed within this statement. They are:

• Information about people who use our website(s);
• Information about people who share their experiences with us by other means;
• Information about people who contact our services, including our Healthwatch East Sussex Information and Signposting service;
• Information about our own staff, board members, volunteers and anybody applying to work or volunteer for us.


Information about people who use our website(s)
Please note that this statement does not cover links within this website to other websites.
When you browse through the information on our websites, it does not store or capture your personal information.

We do log your IP address (as it is automatically recognised by the web server) but this is only so you can download this website onto your device rather than for any tracking purpose; it is not used for any other purpose.

User provided information
When you use our websites, as a user or as a visitor, you may provide, and we may collect Personal Data. Examples of Personal Data include your name and email address or other contact details.

Personal Data also includes other information, such as geographic area or your preferences, when any such information is linked to information that identifies a specific individual. We will only collect personal information provided by you.
We will only collect personal information provided by you, such as:
• feedback from surveys and online forms
• names, email addresses and telephone number (if provided)
• preferred means of communication

We will tell you why we need your personal information and how we’ll use it.

Measuring website usage (Google Analytics)
We use Google Analytics to collect information about how people use our websites. We do this to make sure it is meeting our users’ needs and to understand how we could do it better.

Google Analytics stores information about what pages you visit, how long you are on the site, how you got here and what you click on. We do not collect or store your personal information (e.g. your name or address) so this information cannot be used to identify who you are.

We also collect information on the number of times particular search terms are used and the number of failed searches. We use this information to improve access to the site and to identify gaps in the information content so we can plan appropriate expansion of the system.

Unless the law allows us to, we do not:
• share any of the information we collect about you with others
• use this information to identify individuals

Signing up to our mailing lists for bulletins and information about our services and activities
We use third-party suppliers to provide our newsletter services. By subscribing to these services you will be agreeing to them handling your data.

Third-party suppliers handle the data purely to provide these services on our behalf. These suppliers follows the requirements of the Data Protection Act 2018 and UK GDPR in how they obtain, handle and process your information and will not make your data available to anyone other than East Sussex Community Voice.

Information about people who share their experiences with us by other means
There are a number of ways that we collect feedback from people about their experiences of using statutory, voluntary and community services day to day.

This includes:
• When people submit information in response to one of our research or engagement projects
• Face to face engagement activity
• When people share their experience with us by email, post or verbally
• We also receive phone calls with enquiries or requests for information directly from members of the public, such as part via our Healthwatch Information and Signposting service (see below).
• Direct observations and engagement through ‘Enter and View’ activity
• Personal data received from other sources e.g. referrals

Where personally identifiable information is collected, we will ensure that we identify a valid lawful basis. Usually, we process it where we have your consent to keep it and we will be clear on how we intend to use your information. We will aim to anonymise information where we can but there may be instances where this is not possible in order to make change happen on your behalf.

There may be circumstances where we can and will keep the data without consent but we must have a lawful basis for doing so, such legal obligation or public task, including for safeguarding purposes.

We ensure that where consent is required it will be freely given, used only for agreed specific and unambiguous purposes and that you are well informed about how the information will be kept. This includes where it will be stored, details on security and for how long it will be kept. We will comply with current data protection legislation at all times.

Where we are processing your personal data with your consent, you have the right to withdraw that consent. If you change your mind, or you are unhappy with our use of your personal data, please let us know by contacting us using our contact details (see below).

For any other services we use to handle data via a commercial company or partner, there is always an Memorandum of Understanding (MOU), data sharing agreement or contract in place.

Personal data received from other sources
On occasion we will receive information from the families, friends and carers of people who access statutory, commercial and voluntary services. We use this data to inform providers and commissioners to help them deliver services that work for you.

Where it is practically possible, we will make sure that we have your consent to use information that is about you. We will only process your personal data where there is a lawful basis to do so under current data protection legislation.

Publishing information
In most cases we anonymise our data to ensure that a person cannot be identified, unless this has been otherwise agreed and consent has been sought and given.

Information about people who contact our Healthwatch Information and Signposting Service
In delivering Healthwatch East Sussex, we also provide an Information and Signposting Service to help people access, understand, and navigate health and care services in East Sussex. Our trained staff can help people to find out about:
• Health and care services near them
• How to access support and advice
• What to do if they have a concern or complaint
• How to share feedback about services

You do not have to tell the helpline worker anything you don’t want to, and you do not have to give your name or location. Any personal information you do give to the helpline will not be shared with any other organisations without your consent.

We record the details of all enquiries securely and use this information to capture trends and help improve people’s experiences of health and care in East Sussex. The records of all enquiries are retained and destroyed in line with our data retention policy.

If contact with our service is made, people will be asked to indicate their consent for us to store information about them and a record of this consent will be maintained on our database.

Safeguarding
It is recognised that there may be times when it is appropriate to breach confidentiality for legitimate reasons without permission. The law does not allow us to share your information without your permission, unless there is proof that someone is at risk. This risk must be identified as being serious before we can go against your right to confidentiality.

In instances where East Sussex Community Voice staff, board members or volunteers are worried about your physical safety or we feel that we need to take action to protect you from being harmed in other ways, we will discuss this with you and, if possible, get your permission to tell others about your situation.

We may still share your information if we believe the risk to others is serious enough to do so. There may also be rare occasions when the risk to others is so great that we need to share the information straight away. If this is the case, we will make sure that we record the information we share and our reasons for doing so. We will let you know what we have done and why as soon as or if we think it is safe to do so.

Sharing your data with Healthwatch England
In delivering Healthwatch East Sussex, East Sussex Community Voice is required to share information with Healthwatch England to ensure that your views are considered at a national level. This enables them to analyse service provision across the country and supply the Department of Health & Social Care and national health and care commissioners with the information you provide.

Find out more about Healthwatch England’s purpose and what they do.

The information we provide to Healthwatch England contains no personally identifiable data. Any information that is used for national publications is anonymised and will only be used with the consent of a local Healthwatch.

Our Healthwatch data systems
Healthwatch England provides a secure digital system for local Healthwatch to manage their data. Other organisations process the data contained within it on behalf of local Healthwatch and a Data Processing Agreement is in place to ensure that this is held securely and according to current data protection legislation.

Healthwatch England is a committee of the Care Quality Commission (CQC) but acts independently. These organisations must comply with all legal requirements and do not reuse any data for any other reason or make it available to others.

Information about our own staff and people applying to work with us
We need to process personal data about our own staff (and people applying to work for us) so that we can carry out our role and meet our legal and contractual responsibilities as an employer.

The personal data that we process includes information about racial or ethnic origin, religion/belief, disability, gender and sexuality. We use this information to check we are promoting and ensuring diversity in our workforce and to make sure we are complying with equalities legislation.

Our employees decide whether or not to share this monitoring data with us, and can choose to withdraw their consent for this at any time. Employees who wish to withdraw their consent for us to process this data can let us know.

Other personal data that we are required to process includes information on qualifications and experience, pay and performance, contact details and bank details.

We check that people who work for us are fit and suitable for their roles. This may include asking people to undertake Disclosure and Barring Service (DBS) checks.

Staff joining East Sussex Community Voice will be asked to complete a ‘declaration of interests’ form to identify any services with which they have close links (for example, because they have previously worked there or because the service is run by a close relative) or any other issues which could cause a perceived conflict of interest. Staff are regularly asked to update these forms.

We have a legal obligation to comply with the Freedom of Information Act 2000 and this may include the requirement to disclose some information about our employees – especially those in senior or public facing roles. We also publish some information about our staff, including the names, images and work contact details of people in some roles.


Information about people who volunteer for us
We need to process personal data about our volunteers (including our Board of Directors) so that we can carry out our role and meet our legal and contractual responsibilities.

The personal data that we process includes information about racial or ethnic origin, religion/belief, disability, gender and sexuality. We use this information to check we are promoting and ensuring diversity in our workforce and to make sure we are complying with equalities legislation.

Our volunteers and Board Directors decide whether or not to share this monitoring data with us and can choose to withdraw their consent for this at any time. Volunteers and Board Directors who wish to withdraw their consent for us to process this data can let us know.

Other details that we may process includes information on qualifications and experiences, contact details and bank details (for the payment of expenses).

We check that people who work for us are fit and suitable for their roles. This may include asking people to undertake Disclosure and Barring Service (DBS) checks.

Volunteers and Board Directors joining East Sussex Community Voice will be asked to complete a ‘declaration of interests’ form to identify any services with which they have close links (for example, because they have previously worked there or because the service is run by a close relative) or any other issues which could cause a perceived conflict of interest. Volunteers and Board Directors are regularly
asked to update these forms.

We have a legal obligation to comply with the Freedom of Information Act 2000 and this may include the requirement to disclose some information about our Board Directors and Enter and View volunteers.

3.Cookies

A cookie is a small file, typically of letters and numbers, downloaded on to a device when the user accesses certain websites.

Please be aware that some systems on our websites require the use of cookies, but we will always state if this is the case. We will never collect and store information about you without your permission.

Our websites use cookies to help to identify and track visitors and their website access preferences. We use traffic log cookies to identify which pages are being used. This helps us analyse data about webpage traffic and improve our website in order to tailor it to our users needs. We only use this information for statistical analysis purposes.

Overall, cookies help us provide you with a better website by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.

We will never collect and store information about you without your permission.
Find out more about our use of Cookies https://www.gov.uk/help/cookies


Third party cookies
We use videos from YouTube and feeds from other websites such as Facebook and Twitter on our websites. These third-party platforms place cookies on your device when watching or viewing these pages.

Below are links to their cookie policies:
Google and YouTube
Facebook
Twitter


Disabling cookies

You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer, however, this may prevent you from taking full advantage of the website or platform you are seeking to access.

Website visitors who do not wish to have cookies placed on their computers should set their browsers to refuse cookies before using the East Sussex Community Voice/Healthwatch East Sussex website.

There is more information about how to delete or stop using cookies on www.aboutcookies.org. If you wish, you can also opt out of being tracked by Google Analytics.

4. Sharing and publishing your information (including safeguarding)

How we share information with other organisations

We only share personal information with other organisations where it is lawful to do so and in accordance with our Data Protection Policy. Information is shared in order to fulfil our statutory, contractual and public interest obligations.

We work with various public, private and voluntary organisations. We can also engage external suppliers to process personal information on our behalf.

We will only disclose your personal information where we have your consent to do so, or where there is another very good reason (lawful basis) to make the disclosure – for example, we may disclose information to the Care Quality Commission (CQC) or a local authority (East Sussex County Council) where we think it is necessary to do so in order to protect a vulnerable person from abuse or harm. Any such disclosure will be made in accordance with the requirements of the current data protection legislation.

Wherever possible, we will ensure that any information that we share or disclose is anonymised, so as to ensure that you cannot be identified from it.

We sometimes use other organisations to process personal data on our behalf. Where we do this, those companies are required to follow the same rules and information security requirements as us. They are not permitted to use or reuse the data for other purposes.

We do not share or sell personal information to any other organisation for the purposes of direct marketing.

5.Security (including data systems)

Security – keeping information safe and secure
We are strongly committed to data security and we take reasonable and appropriate steps to protect your personal information from unauthorised access, loss, misuse, alteration or corruption.

We have put in place physical, electronic, and managerial procedures to safeguard and secure the information you provide to us.

Only authorised employees and contractors under strict controls will have access to your personal information. Our security includes:

• Encryption
• Access controls on systems and platforms
• GDPR training for staff
• Information security training for staff
• GDPR and Information Security training for Board members and volunteers who may or will have access to personal data.

6. Retention

Retention and disposal of personal data
We use a retention and disposal schedule to guide how long we keep different types of records and documents for, including records and documents containing personal data.

Personal data is deleted or securely destroyed at the end of its retention period. For more information on this please contact us.

7. Individuals Rights

Your right to access information about you
If you think we may hold personal data relating to you and you want to see it please write to info@escv.org.uk

When we receive a request from you in writing, we must normally give you access to everything we have recorded about you. However, we will not let you see any parts of your record if:
• It contains confidential information about other people; or
• It includes information a care professional thinks will cause serious harm to your or someone else’s physical or mental wellbeing; or
• We think that a crime may be prevented or found out by disclosing information to you.

This applies to paper and electronic records. If you cannot ask for your records in writing, we will make sure there are other ways you can apply.

Your other rights
Under data protection legislation, you also have the right to:
• ask for your information to be corrected if it is inaccurate or incomplete
• ask for your information to be deleted or removed where there is no need for us to continue processing it
• ask us to restrict the use of your information
• object to how your information is used ask us to copy or transfer your information from one IT system to another in a safe and secure way, without impacting the quality of the information
• challenge any decisions made without human intervention (automated decision making)

Please make your request using our contact details below.

8. Contact details and how to complain

Our contact details and key roles
East Sussex Community Voice is the data controller for all of the personal data that you provide us with.

Any issues relating to the processing of personal data by or on behalf of East Sussex Community Voice may be addressed to:

East Sussex Community Voice
Barbican Suite
Greencoat House
32 St Leonards Road
Eastbourne
East Sussex
BN21 3UT

Telephone: 01323 403590
Email: info@escv.org.uk

Data Protection Officer

East Sussex Community Voice’s Data Protection Officer under Article 37 GDPR is Peter Questier (East Sussex County Council, Information Governance Team, Children’s Services).

However, please contact us in the first instance if you have a query regarding this privacy policy or how your information is used.

If you feel that we have not met our responsibilities under data protection legislation, you have a right to request an independent assessment from the Information Commissioner’s Office (ICO). You can find details on their website.

Sign up to our mailing listKeep up-to-date with Healthwatch East Sussex and receive regular information on our activities and how you can have your say on local health and social care services

For detail on how we use your data please view our privacy policy here.