Privacy

Privacy Notice
St Michael’s Hospice (May 2018)

At St Michael’s Hospice, we are committed to protecting your personal information and privacy. This Privacy Notice describes how we collect and use personal information.  We aim to be clear when we collect your data and not to do anything you wouldn’t reasonably expect.

We may make changes to this Privacy Notice from time to time so please check back periodically. We will notify you of significant changes by placing a notice on our website.

By visiting our website, using our services or participating in our activities, you agree to your personal information being collected and used in the manner set out in this Privacy Notice as updated from time to time.

This Privacy Notice is not exhaustive and we are always happy to provide any additional information or explanations where needed. Please contact our Data Protection Lead either by email, telephone or in writing using these contact details:

Data Protection Lead, St Michael’s Hospice, Bartestree, Hereford, HR1 4HA.  Telephone: 01432 851000.  Email info@smhospicehereford.org

This Privacy Notice applies to all information held by St Michael’s Hospice relating to individuals, whether you are a patient, service user, member of staff, volunteer, supporter or contractor.

St Michael’s Hospice
In this Privacy Notice, “St Michael’s Hospice” means St Michael’s Hospice (registered charity no 511179 and company limited by guarantee (registered company 1634942) and/or St Michael’s Hospice Trading Company Limited (registered company 06545386), whose registered offices are at Bartestree, Hereford, HR1 4HA.

How do we collect personal information?
We collect personal information about you when you interact with us (e.g. by phone, letter or online), register with us, enquire about our activities, make a donation to us, fundraise on our behalf, participate in an event, buy from our shops or order a product, enter our Lottery, tell us your story, apply to work or volunteer with us, visit our website or otherwise provide us with your personal information.

We may also receive information about you from third parties that we work with, for example JustGiving or eBay, where you have consented to them sending us your information.  You should check their Privacy Policy when you provide your information to understand fully how they will process your information.

What is Personal Data?
Personal information is any information that can be used to identify you.  For example, it can include information such as your name, date of birth, photo or video image or voice recording, email address, postal address, telephone number and credit/debit card details, as well as information relating to your health or personal circumstances.

Data Protection law recognises that certain categories of personal information are more sensitive. This is known as sensitive personal information and covers health information, racial or ethnic origin, religious beliefs or other beliefs of a similar nature, political opinion and trade union membership.

What personal information do we collect?
Personal information we collect about you may include your name, postal address, email address, phone numbers, photo or video image or voice recording, date of birth, credit or debit card details, and whether you are a taxpayer so that we can claim Gift Aid.

We do not collect “sensitive personal data” about our supporters unless there is a legitimate reason for this (e.g. if you participate in an event for which we may need to provide support, to ascertain what services are relevant to you or to cater other services and support to you).  Before collecting any sensitive personal information about you we will make it clear to you what information we are collecting and the purposes for collecting it.

The Hospice processes several different types of information:
Identifiable – containing details that identify an individual. This may include but is not limited to such information as name, address, NHS number, full postcode, date of birth.
Pseudonymised – information where individuals can be identified by using a coded reference which does not show their ‘real world’ identity.
Anonymised – information about individuals with identifying details removed.
Aggregated – statistical information about a group of individuals that has been combined to show general trends or used for benchmarking purposes.

Our records may be held on paper or in electronic computer systems.

We also collect information about how our website is used and track which pages users visit when they follow links in St Michael’s Hospice emails. We use this information to monitor and improve our website, services and activities e.g. to personalise website presentation or to see which services or events are of most interest. Where possible we use anonymous or aggregated data that does not identify individuals. See further information about cookies below.

CCTV – Crime Prevention and/or Staff Monitoring
CCTV is used for maintaining the security of property and premises and for preventing and investigating crime, it may also be used to monitor staff when carrying out work duties. For these reasons the information processed may include visual images, personal appearance and behaviours. This information may be about staff, customers and clients, offenders and suspected offenders, members of the public and those inside, entering or in the immediate vicinity of the area under surveillance. Where necessary or required this information is shared with the data subjects themselves, employees and agents, services providers, police forces, security organisations and persons making an enquiry.

Legal Obligations to Collect and Use Information
In the circumstances where we are required to use personal identifiable data we will only do this if:
The information is necessary for your direct healthcare.
We have received written consent from you to use your information for a specific purpose e.g. employment, volunteering, fundraising, lottery membership etc.
There is an overriding public interest in using the information e.g. in order to safeguard an individual or to prevent a serious crime.
There is a legal requirement that will allow us to use or provide information e.g. a formal Court order or subpoena.
We have permission to do so from the Secretary of State for Health to use certain confidential patient identifiable information when it is necessary for our work.
Emergency Planning reasons such as protecting the health and safety of others. Typically, these relate to severe weather, outbreaks of diseases e.g. seasonal flu, and major transport incidents.

How do we use personal information?
How we use your information will largely depend on why you are providing it.
We use the personal information collected from users for a number of purposes, including:
To give you the information, support, services or products you have requested.
To gain a full understanding of your situation so we can develop and offer you the best possible personalised care.
To provide further information about our work, services, activities or products.
To process donations or payments we have received from you.
To further our charitable aims, including for fundraising activities.
To fulfil sales made online or through our shops.
To claim Gift Aid on your donations.
To keep a record of your relationship with us and for internal administrative purposes (such as accounting and records), and to let you know about changes to our services or policies.
To look into, and respond to complaints, legal claims or other issues.
To invite voluntary participation in research or surveys.
To register, administer and personalise online accounts.
To register and administer your participation in events for which you have signed up.
To analyse and improve our work, services, activities, products or information (including our website) or for our internal records;
To use IP addresses and monitor website use to identify locations, block disruptive use, record website traffic or personalise the way information is presented to you.
To process your Lottery membership and ensure compliance.
To process your application for a job or volunteer role with us.
For fraud prevention, credit risk reduction or otherwise as required by law or regulation.
We may also use your personal information for other purposes which we specifically notify you about and, where appropriate, obtain your consent.
We may analyse your data for research purposes to improve our services, or to try to understand your preferences in order to contact you in the most appropriate and relevant way.

When you use our secure online donation or payment pages you will be directed to a specialist supplier company, who will receive your credit card number and contact information to process the transaction. We do not retain your credit or debit card details.

Direct Marketing
With your consent, we may use your information to send you communications about our work and how you can help us to help you, for example, information about our developments, volunteering and fundraising activities and how you can donate to us.  You can let us know if you would prefer not to receive these communications at any time by emailing fundraising@smhospicehereford.org, calling us on 01432 851000, or writing to our Data Protection Lead at the address above.

Care and support services
If you, a relative, or a friend are cared for or supported by St Michael’s Hospice, the personal and/or sensitive personal information you provide to us will be used only for the purposes of providing you with health and social care services, or training, or monitoring the quality of our services.  St Michael’s Hospice will not disclose your personal information to any third party without your consent, except in the following circumstances:
To healthcare professionals and organisations involved in the provision of care.
Exceptionally, to professional bodies or otherwise as required by law, regulation or codes of practice.
Even though St Michael’s Hospice is a registered charity, we are also an NHS Business Partner since we provide a healthcare service to the people of Herefordshire and surrounding Counties.  St Michael’s is a Secondary Care setting.
St Michael’s Hospice uses the Health and Social Care Network (HSCN), a data network for health and care organisations to access and share information.  The HSCN is provided by the Health and Social Care Information Centre (also known as NHS Digital).  NHS Digital is the national provider of information, data and IT systems for commissioners, analysts and clinicians in health and social care. NHS Digital provides information based on identifiable information passed securely to them by Primary and Secondary Care Providers who are legally obliged to provide this information.
St Michael’s Hospice may share your personal data with NHS Digital, or a third party contractor acting on its behalf, for NHS Digital to process personal data on St Michael’s’ behalf and/or to share your personal data with NHS Digital in its capacity as a data controller.  Further information on how NHS Digital may use your information, can be found here: http://content.digital.nhs.uk/patientconf.

Our Commitment to Data Privacy and Confidentiality Issues
We are committed to protecting your privacy and will only process personal confidential data in accordance with the Data Protection Act 1998, the General Data Protection Regulation (2018), the Common Law Duty of Confidentiality and the Human Rights Act 1998.  The various laws and rules about using and sharing confidential information, with which St Michael’s Hospice will comply, are available in “A guide to confidentiality in health and social care” which is published on the NHS Digital website.

St Michael’s Hospice is a Data Controller and under the terms of the Data Protection Act 1998 and the General Data Protection Regulation (2018) we are legally responsible for ensuring that all personal confidential data that we collect and use i.e. hold, obtain, record, use or share about you is done in compliance with this legislation.

All data controllers must notify the Information Commissioner’s Office (ICO) of all personal information processing activities. Our ICO Data Protection Register number is Z5391512 and our entry can be found in the Data Protection Register on the Information Commissioner’s Office website (https://ico.org.uk/).

Everyone working for St Michael’s Hospice has a legal duty to keep information about you confidential. The NHS Care Record Guarantee and NHS Constitution provide a commitment that all NHS organisations and those providing care on behalf of the NHS will use records about you in ways that respect your rights and promote your health and wellbeing.

All identifiable information that we hold about you will be held securely and confidentially. We use administrative and technical controls to do this. We use strict controls to ensure that only authorised staff are able to see information that identifies you. Only a limited number of authorised staff have access to information that identifies you where it is appropriate to their role and is strictly on a need-to-know basis.

All of our staff, volunteers and Senior Management Team receive appropriate and on-going training to ensure they are aware of their personal responsibilities and have contractual obligations to uphold confidentiality, enforceable through disciplinary procedures. All staff are trained to ensure they understand how to recognise and report an incident ensuring that the organisation’s procedure for investigating, managing and learning lessons from incidents.

We will only retain information in accordance with the schedules set out in the Records Management Code of Practice for Health and Social Care 2016. The Hospice’s Records Management Policy includes guidance around the secure destruction of information in line with the Code of Practice.

It may sometimes be necessary to transfer personal information overseas. When this is needed information is only shared within the European Economic Area (EEA). Any transfers made will be in full compliance with all aspects of the data protection act. We will never sell any information about you.

Confidentiality Advice and Support
St Michael’s Hospice has a Caldicott Guardian who is a member of the Senior Management Team responsible for protecting the confidentiality of service user and service user information and enabling appropriate and lawful information-sharing. Further information about the role of the Caldicott Guardian is available on request.

We will not use your information for other purposes without your permission. If you tell us about your own experience with terminal illness or the experience of someone else, we will explain how we will use that information. If you don’t want to use such information for other purposes or change your mind at any time, it will not affect any services we provide.

Privacy and our social media sites
Our social media sites are moderated and we do not display the full names of individuals (without their express permission) nor addresses.

When you post personal information on one of our social media sites or other messaging board on our websites, your information is publicly accessible. Such information can be viewed online and collected by third parties. We are not responsible for the use of information by such third parties.

When contributing to a social media site we strongly recommend you avoid sharing any personal information that can be used to identify you (such as your name, age, address, name of employer etc). We are not responsible for the privacy of any identifiable information that you post on our social media sites or other public pages of our websites.

Using our website
What information we may collect via our website:
Form submissions, for example registering interest for events, feedback forms and information requests.
Subscribing to receive communications from St Michael’s Hospice such as fundraising, education or other event updates.
Details of your visits to our site, including which pages you visit and what you do.
Shop, Tickets, Donations and Tribute microsites:

Personal information, such as but not limited to name, email address, billing and shipping address, when making a purchase or donation.
Details of transactions you carry out through our site and of the fulfilment of your orders.
Ticket registration details.

Third party software
Our third parties who receive data – directly or indirectly – from our website include:
The Raiser’s Edge – Customer Relationship Management (CRM) platform for our fundraising department. You can find their Privacy Shield Certification Notice here: https://www.blackbaud.com/privacy-shield
Online Express – event management software for our events
ComBase for our Lottery administration. You can find their Data Hosting and Processing Policy here. (Insert).
E-productive for the processing of our Retail Gift Aid. You can find their Data Hosting and Processing Policy here. (Insert)

What information is collected directly via third parties on our behalf:
Personal information such as name, registration details, billing and shipping address, when purchasing an events place (Online Express)
Personal information such as name, address and interests when registering to receive events updates (Online Express).
Personal information such as name, address, tax information when registering for Retail Gift Aid. (E-Productive).

Links and third parties
This policy only applies to St Michael’s Hospice and its subsidiary company, so when you go through to our partner companies (e.g. to donate or pay in the shop) please read their own privacy policies.

When you make a donation through Text to Donate, your donation will be managed by your network provider in accordance with their terms and conditions and Privacy Policy.

If you’re 16 or under
If you’re aged 16 or under, you must get your parent/guardian’s permission before you provide any personal information on our websites.

Your Rights
The Data Protection Act gives you certain rights over your data and how we use it.  These include:
The right to have inaccurate personal data rectified.
The right in certain circumstances to have personal data blocked, erased or destroyed.
The right to prevent your data being used for direct marketing.
The right of access to a copy of the information we hold about you (known as a subject access request).
You have the right to privacy and to expect St Michael’s Hospice to keep your information confidential and secure.

You also have a right to request that your confidential information is not used beyond your own care and treatment and to have your objections considered.

If you wish to exercise any of these rights please contact the Data Protection Lead in writing using the details below:

St Michael’s Hospice, Bartestree, Hereford HR1 4HA. Or email: info@smhospicehereford.org

For more information about your rights under the Data Protection Act go to the website of the Information Commissioner’s Office at https://ico.org.uk

Complaints
St Michael’s Hospice aims to meet the highest standards when collecting and using personal information. For this reason, we take any complaints we receive about this very seriously. We encourage people to bring concerns to our attention if they think that our collection or use of information is unfair, misleading or inappropriate. We would also welcome any suggestions for improving our procedures. Contact details for complaints regarding the processing of information should be directed to the Data Protection Lead, St Michael’s Hospice, Bartestree, Hereford HR1 4HA. Telephone: 01432 851 000 Email: info@smhospicehereford.org.  For more information on how to make a suggestion or complaint, please see our guidance leaflet (Insert)

Registering with the free Telephone Preference Service gives you the opportunity to opt out of receiving unsolicited calls. The Mailing Preference Service will enable you to register to have your name taken off direct mailing lists.

Cookies
How do we use Cookies?

St Michael’s Hospice uses cookies to give you a more personalised web service.  To see how we use cookies, what they are, and which ones we use please go to our ‘How we use cookies’ page.  This page also includes instructions on how to disable cookies if you don’t want them to be used.

What is a cookie?
A cookie is a simple text file of letters and numbers that is stored on to your computer or mobile device by a website’s server when you access certain websites. Only that server will be able to retrieve or read the contents of that cookie.

Each cookie is unique to your web browser. It will contain some anonymous information such as a unique identifier and the site name and some digits and numbers

What does a cookie do?
A cookie is like a door key – cookies unlock a computer’s memory and allow websites to recognise users when they return to that particular site.

Most websites you visit will use cookies in order to improve your user experience by enabling that website to ‘remember’ you. Cookies may be set by the website you are visiting or they may be set by other websites who run content on the page you are viewing.

Cookies do many different jobs, like letting you navigate between pages efficiently, storing your preferences and generally improving your experience of a website. Cookies make the interaction between you and the website faster and easier.

Cookies have limited functionality and cannot browse or scan your computer or dig for information. Users always have the option of accepting or denying cookies.

How does St Michael’s use cookies?
Information received via web cookies is used to enhance your experience of our site and microsites, ascertain whether the website is functioning correctly and for logged-in members to ensure access to entitled resources.

Analytical cookies
The cookies we use are predominantly ‘analytical’ cookies. They allow us to recognise and count the number of visitors and to see how visitors move around our web site when they’re using it.  This helps us to improve the way our website works, for example by making sure users are finding what they need easily.

This website uses Google Analytics* cookies.  Unless you have adjusted your browser setting to refuse cookies, our website will deliver the cookie as soon as you visit the website.

Google Analytics is collected via a JavaScript tag in the pages of our site.  Google Analytics uses a Persistent Cookies (remains on your computer unless it expires or your cookie cache is cleared) and some session cookies (used to calculate visit information such as visit length and where a visitor arrived from).

We have enabled Google Analytics Demographics and Interest Reporting so we better understand our demographics and our website users’ interests.

More information on Google Analytics can be found on Google’s support website https://support.google.com/analytics/answer/6004245

Functional cookies
St Michael’s Hospice uses cookies for the checkout process when making a purchase in our shop, registering for an event or donation.

We also use cookies to remember login details and information you supply, for example for registering for an event or making a donation.

What to do if you don’t want Cookies to be set
Some people find the idea of a website storing information on their computer or mobile device a bit intrusive, particularly when this information is stored and used by a third party without them knowing.

The cookies St Michael’s Hospice use are harmless and we do not use them for advertising that has been targeted to your interests.

However, if you prefer, it is possible to block some or all cookies, or even to delete cookies that have already been set; but you need to be aware that you might lose some functions of the St Michael’s Hospice website.

You can control which types of cookies you allow by turning cookies on or off in your web browser’s settings. You can also delete cookies by clearing your browser’s cookie cache (history).

To find out how to turn cookies on and off in your browser, click on the relevant browser link below.

If you have any questions or concerns about the cookies we use, please email: info@st-michaels-hospice.org.uk.