Privacy Notice

At Disability Initiative (DI), we are committed to protecting the privacy of our staff, volunteers, and the people we support. It is our responsibility to look after your personal data in a way that respects your rights and follows the latest UK data protection laws.

Looking after the information you share with us is hugely important. We want you to feel confident that your data is safe and secure when you are with us.

What this notice tells you

This Privacy Notice explains what you can expect us to do with your personal information when you contact us or use any of our services. It will help you understand:

  • What personal data we collect
  • Our legal reasons (lawful basis) for using your information
  • Why we need to process it
  • What we use your data for
  • The reasons we might share it with others
  • Your legal rights regarding your data
  • How to apply for an Access Request
  • How to raise a complaint

Who is responsible for your data?

Disability Initiative Services Ltd is the Data Controller (the organisation responsible for your information).

Please take a moment to read through our practices. If you have any questions or if anything is unclear, we would appreciate hearing from you. You can get in touch using the contact details at the end of this notice.

Who we are

DI is a registered charity based in Camberley, Surrey. For over 50 years, we have been dedicated to providing highly individualised care and slow stream rehabilitation for adults with physical disabilities and/or acquired brain injuries.

Our mission is to create an environment where every individual can thrive, grow in confidence, and live as independently as possible. To do this safely and effectively, we need to collect and use certain personal information.

Our Legal Identity

When we use your data, DI acts as the Data Controller. This means we are the organisation responsible for deciding how your information is used and for keeping it safe.

  • Registered Charity Number: 1049002
  • Company Number: 3029077
  • Registered Office: Resource Centre, Knoll Road, Camberley, Surrey, GU15 3SY

We are also registered with the Information Commissioner’s Office (ICO), the UK’s independent body set up to uphold information rights. Our registration number is Z481174X.

How do we collect information about you?

We collect personal information when you enquire about our services, are employed by us, attend DI as a client, volunteer, or donate. We also receive information from external sources; this includes fundraising sites like JustGiving, professional health agencies, or a friend or relative who gets in touch to ask about our services for you.

What personal data do we collect?

The information we collect depends on your relationship with DI. We only collect what is necessary to provide our services safely and legally.

  1. For our Clients (Service Users)

To provide high-quality care and support, we collect:

  • Identity Details: Your name, date of birth, and photographs for your care profile.
  • Health & Care Needs: Information about your disability, diagnosis, medications, and dietary requirements.
  • Support & Funding: Details of your Social Worker or GP, and information regarding your funding (e.g., NHS or Local Authority).
  • Daily Records: Notes on the support we provide you each day, including any incident or accident reports.
  • Financial Information: Bank details or Direct Debit info if you pay for your services directly.
  1. For our Staff and Volunteers

To manage your role safely and meet our legal obligations as an employer, we collect:

  • Recruitment & Identity: Your CV, references, and “Right to Work” documents (like your passport).
  • Criminal Record Checks: Results of your Disclosure and Barring Service (DBS) checks.
  • Employment & Payroll: Your National Insurance (NI) number, tax code, and bank details for salary or expense payments.
  • Health at Work: Records of sick leave and any “reasonable adjustments” we have made to support you in the workplace.
  1. For Carers, Family, and Next of Kin

To ensure we can communicate effectively, especially in an emergency, we collect:

  • Contact Details: Your name, phone number, email, and home address.
  • Legal Relationship: Your relationship to the client and whether you hold “Power of Attorney” to make decisions on their behalf.
  • Updates & Events: We use your contact details to invite you to Carers’ evenings and social events (you can opt out of these at any time).
  1. For Everyone (General & Technical Data)

This applies to anyone who interacts with DI via our website, phone, or in person:

  • Communication Records: Copies of emails or letters you send us.

Please Note: All telephone calls to DI are recorded for training and quality purposes.

  • Website Data (Cookies): Your IP address and information about how you use our website. You can easily manage or opt out of these via our cookie banner.
  • Equality Monitoring: Information you choose to share regarding your background (such as ethnicity or religion). This is voluntary and helps us ensure DI remains a fair and inclusive environment.

Why we collect and use information?

At DI, we use your personal data to ensure you receive the best possible support and to keep our charity running safely. We are guided by three key principles:

  • Data Minimisation: We only collect and transfer the minimum amount of data necessary for a specific, lawful purpose.
  • Accuracy: We take reasonable steps to ensure data is accurate and up to date. If your details change (like a new phone number or address), please let us know so we can update our records.
  • Storage Limitation: We do not keep your data forever. We only hold onto it for as long as our Data Retention & Disposal Schedule allows, or as required by law.

Why we need your data

We use the information we collect for the following reasons:

  1. To support you personally
  • To provide services and programmes tailored to your specific needs and goals.
  • To keep an accurate record of your relationship with DI (administrative purposes).
  • To contact your next of kin, social workers, or other third-party agencies.
  1. To manage DI safely and legally
  • To comply with UK law and our regulatory obligations (such as safeguarding and health and safety).
  • To process donations, gift aid, or other payments and verify financial transactions.
  • To ensure our staff and volunteers are suitable for their roles (DBS checks).
  1. To improve and grow our charity
  • To analyse how people use our website and services so we can make them better.
  • To ask for your feedback, case studies, surveys or research (this is always optional).
  • To share updates on DI’s work and tell you about fundraising activities, only where you have told us you are happy to hear from us.

Important Information about your Data

  • It is your choice: Providing your personal data is voluntary. However, please be aware that if you choose not to share certain information (such as medical needs or contact details), we may be unable to provide you with the services you require.
  • Your Contact Preferences: We may contact you by post, telephone, email, or SMS if you have given us your permission.
  • Fundraising & Marketing (Charitable Soft Opt-in): From January 2026, DI may utilise the “Charitable Purpose Soft Opt-in” for electronic communications. This allows us to contact individuals who have previously expressed interest in or supported our charitable goals, provided they were given a clear opportunity to opt out at the point of collection and in every subsequent message.

Note: This does not apply to individuals on our database prior to January 2026 without explicit prior consent.

You are in control: You can change your mind or “opt out” of hearing from us at any time. Simply contact our Data Protection Lead (DPL) using the details provided in the ‘Contact Us’ section below.

Our legal basis for processing your data

Data protection law says we must have a “lawful basis” (a valid legal reason) for every way we use your personal data. At DI, we mainly rely on the following reasons:

  1. To Fulfil Our Agreement with You (Contractual)

When you join DI as a client, staff member, or volunteer, we enter into an agreement with you. We use your data to provide the services, or employment benefits you have signed up for.

  1. To Keep You Safe (Vital Interests & Safeguarding)

In an emergency, such as a medical incident, we may share your health information with the emergency services. We also process data to protect vulnerable individuals from harm, as required by UK safeguarding laws.

  1. To Follow the Law (Legal Obligation)

As a registered charity and employer, we have a legal duty to keep certain records. This includes tax information for HMRC, health and safety records, and performing DBS checks.

  1. To Run DI Effectively (Legitimate Interests)

Under the Data (Use and Access) Act 2025, we use “Legitimate Interests” for activities that help our charity function, provided they don’t unfairly affect your rights. This includes:

  • Security & Crime Prevention: Ensuring the security of DI’s network and information systems. Preventing, detecting or investigating crimes (including fraud).
  • Emergency Response: Responding or dealing with an emergency event or situation.
  • Safeguarding: Safeguarding adults at risk.
  • Direct Marketing: Sending you updates about our work (where you have a relationship with us and haven’t opted out).
  • Service Improvements: Analysing how our services are used so we can make them better.
  1. Specific Events (Consent)

Where you have given us clear, affirmative consent to process your data for a specific purpose (e.g., signing up for a fundraising event).

  1. Sensitive Health Information (Special Category)

To provide our core services and to ensure we are an inclusive organisation, we process “Special Category Data.” This is personal data that is more sensitive and requires higher levels of protection under the UK GDPR and the Data Protection Act 2018.

What Sensitive Data Do We Collect?

The sensitive information we typically hold includes:

  • Health and Care Information: Details about your physical or mental health, disability, medical history, and specific support or equipment needs.
  • Equality, Diversity, and Inclusion (EDI) Information: Information about your racial or ethnic origin, religious beliefs, and sexual orientation.

Why We Need This Information

We process this data for two distinct reasons:

  • To Provide Your Care and Support: We use health-related information to assess your needs, provide safe and effective social care, and ensure our staff can support you appropriately during your time with us.
  • To Promote Equality and Diversity: We collect demographic information to ensure our services are reaching everyone in our community. This helps us identify if any groups are facing barriers to accessing our support and helps us remain an anti-discriminatory organisation.

How We Protect Your Privacy

Because this data is sensitive, we apply extra safeguards:

  • Strict Confidentiality: Only staff who directly support you or manage our equality monitoring have access to this information.
  • Anonymity in Reporting: When we look at EDI data to improve our services, we “anonymise” it. This means we look at the numbers and trends as a whole, and no individual can be identified in our final reports.
  • Your Choice: Providing health information is usually necessary for us to support you safely. However, providing EDI information (like your ethnicity or religion) is entirely voluntary. Choosing not to share this will never affect the care or support you receive.

Our Legal Conditions

For a full breakdown of the specific legal gateways we use under the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018 to process this data, please refer to the Appendix A Legal Processing Conditions at the end of this policy.

Who do we share this information with?

At DI, we value your privacy. We will never sell, distribute, or lease your personal information to third parties for their own marketing purposes.

However, to provide you with the best care and to run our charity safely, we do need to share your information with certain trusted partners and organisations.

  1. For Your Care and Wellbeing

We share relevant health and support information with professional bodies to ensure you receive joined-up care. This includes:

  • Health Professionals: Such as your GP, NHS specialists, and therapists.
  • Local Authorities: Including Social Services and funding bodies who oversee your care package.
  • Safeguarding Bodies: We have a legal duty to share information with local safeguarding teams or the police if we believe someone is at risk of harm.
  1. Our Trusted Service Providers (Data Processors)

We use modern technology to keep your data organised and secure. These companies (known as “Data Processors”) only use your information under our strict instructions:

  • IT and Cloud Services: This includes Microsoft 365 for our daily communications and secure document storage.
  • Relationship Management: We use NetSuite (Oracle) as our secure database to manage your records.
  • Technical Support: Our external IT Provider has access to our systems to keep them running smoothly and securely.
  1. Financial and Legal Requirements
  • Regulatory Bodies: For our Employees: We share information with the HMRC to meet our legal and auditing duties.
  • Payment Processing: If you donate or pay for services, your financial details are processed through secure banking systems.
  • Emergency Services: In an urgent medical situation, we will share vital health data with paramedics or hospital staff.
  1. Third-Party Promotions

We will only send you information about other organisations or services we think might interest you if you have given us your explicit permission to do so. You can withdraw this permission at any time.

How we keep your information secure?

We take the security of your personal data extremely seriously. We use a “Defence in Depth” strategy, combining industry-leading technical controls with robust organisational procedures to protect your information from unauthorised access, loss, or disclosure.

  1. Technical Security & Encryption

We have implemented technology to ensure your data remains protected at all times:

  • Endpoint Management: All DI-owned devices are managed through Microsoft 365 Intune. This allows us to enforce strict security policies, ensure software is updated automatically, and remotely wipe data if a device is lost or compromised.
  • Full-Disk Encryption: We use BitLocker to encrypt all DI devices. This ensures that even if hardware is physically stolen, the data stored on it remains unreadable.
  • Real-time Threat Protection: Our network and devices are monitored 24/7 by Microsoft Defender, providing an active shield against malware, phishing, and evolving cyber threats.
  • Multi-Factor Authentication (MFA): Access to our systems requires more than just a password. We enforce MFA across our organisation to ensure that only verified personnel can access your information.
  1. Data Residency & International Transfers

We are committed to transparency regarding where your data lives.

  • UK & EEA Storage: Most of your data is stored on secure servers located within the UK or the European Economic Area (EEA).
  • International Transfers (NetSuite Oracle): Where we use global providers such as NetSuite Oracle, data may be processed in the United States. We ensure these transfers are lawful by only working with organisations that adhere to the UK-US Data Bridge (the UK Extension to the EU-U.S. Data Privacy Framework). This confirms they provide an “adequate” level of protection that is equivalent to UK data protection standards.
  1. AI Transparency & Ethical Use

We embrace modern technology responsibly. While we may use Artificial Intelligence (AI) to improve our internal efficiencies, we do so under a strict AI Safety Policy:

  • No PII in AI: We have a strict prohibition against inputting Personally Identifiable Information (PII) into any third-party or generative AI tools.
  • Human Intervention: We do not use AI for automated decision-making that has a legal or significant effect on you. Our policy ensures a “Human in the Loop” approach, meaning all AI-assisted outputs are reviewed and verified by a DI staff member.
  1. Organisational Safeguards

Technology is only effective when supported by a culture of security:

  • Access Control: We operate on the principle of “Least Privilege.” Access to your data is strictly limited to employees who require it to perform their specific roles.
  • Mandatory Training: Every member of our staff undergoes regular, mandatory data protection and cybersecurity training.
  • Incident Response: In the event of a data breach, we have formalised handling and reporting procedures in place. We will notify you and the Information Commissioner’s Office (ICO) if we are legally required to do so.
  1. Internet Risks & Your Responsibility

While we make every effort to ensure the security of our systems, the transmission of information over the internet is never 100% secure. You transmit data to us at your own risk. However, once received, it is guarded by the measures outlined above.

How long will DI keep your information?

We will only retain your personal data for as long as is strictly necessary to fulfil the purposes for which it was collected. This includes satisfying any legal, accounting, or regulatory reporting requirements.

  1. Our Retention Criteria

To determine the appropriate retention period for personal data, we consider:

  • The volume, nature, and sensitivity of the data
  • The potential risk of harm from unauthorised use or disclosure
  • The purposes for which we process your data and whether we can achieve those purposes through other means
  • Applicable legal and statutory requirements
  1. The DI Data Retention Schedule

All personal information is managed in accordance with our Data Retention Schedule. This internal policy sets out specific lifespans for different categories of data. For example:

  • Financial & Transactional Data: By law (for HMRC and tax purposes), we are required to keep basic information about our customers and donors (including Contact, Identity, Financial, and Transaction Data) for six years after they cease being a customer.
  • Enquiries: General enquiries that do not result in a transaction or ongoing relationship are typically deleted after a maximum 12 months in line with our schedule.
  1. Secure Destruction

Once the retention period for your data expires, we ensure it is disposed of permanently and securely.

  • Digital Data: We use industry-standard secure digital wiping (leveraging our Microsoft Intune management tools) to ensure data is unrecoverable.
  • Physical Data: Any paper-based records are destroyed using high-security cross-cut shredding.
  1. Anonymisation

In some circumstances, we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes. Unlike pseudonymised data, truly anonymous data does not fall under data protection law, and we may use this information indefinitely without further notice to you.

Your Data Protection Rights

Under UK data protection law, you have specific rights to control how we use your information. Disability Initiative (DI) is committed to helping you exercise these rights easily and transparently.

The Right of Access (Subject Access Request)

You have the right to ask us for copies of the personal information we hold about you. This is known as a Subject Access Request (SAR).

  • Our Search Standard: We will conduct “reasonable and proportionate” searches to find the data you have requested. We are not required to search every single possible location if it would be an excessive burden, but we will always aim to be as thorough as possible.
  • How Long Will it Take? We must respond to your request within one calendar month.
    • Example: If we receive your request on 3rd September, our deadline is 3rd October.
  • “Pausing the Clock”: If your request is broad or unclear, we may contact you to ask for clarification so we can find exactly what you need. Under the Data (Use and Access) Act 2025, we are permitted to “pause” our response countdown from the day we ask for this clarification. The clock starts again the day after you provide the information we need.
  • Extensions: If your request is particularly complex or you have made multiple requests, we may extend the deadline by a further two months. We will always notify you within the first month if an extension is necessary.

The Right to Rectification

If you believe the information we hold about you is inaccurate or incomplete, you have the right to ask us to correct it. We will respond to these requests within one month.

The Right to Erasure (‘Right to be Forgotten’)

You can ask us to delete your personal information in certain circumstances—for example, if we no longer need it for the reason we originally collected it, or if you withdraw your consent.

The Right to Restriction of Processing

You can ask us to “pause” the use of your data (without deleting it). This is common if you are disputing the accuracy of the data and want us to stop using it until it is corrected.

The Right to Object (Including AI & Marketing)

  • Direct Marketing: You have an absolute right to stop us from using your data for marketing. If you object, we must stop immediately.
  • AI & Automated Decisions: We follow a “human intervention” rule. If a significant decision is made about you using an automated system (AI), you have the right to object and request that a member of the DI team reviews the decision personally.

The Right to Data Portability

You have the right to ask us to transfer the information you gave us to another organisation, or directly to you, in a digital, machine-readable format. This applies only to information you provided to us with your consent or for a contract.

The Right to Withdraw Consent

If we are using your data because you gave us your explicit permission (consent), you can change your mind and withdraw that consent at any time.

How to exercise your rights or make a complaint

We are committed to working with you to settle any concern or query you may have regarding your privacy.

Step 1: Contact our Data Protection Lead (DPL)

If you wish to exercise any of your rights or have a concern about how your data is handled, please contact our DPL first at: [email protected]

Telephone: 01276 673205

Post: Disability Initiative, Resource Centre, Knoll Road, Camberley, Surrey,       GU15 3SY

We will acknowledge your formal request or complaint within 30 days. We aim to resolve all matters internally through a fair and transparent process.

Step 2: Contact the Regulator

If you remain dissatisfied after we have had the opportunity to resolve your concern, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection.

The ICO usually expects you to have raised your concerns with us first before they will investigate.

Appendix A

Legal Processing Conditions

Purpose of ProcessingType of DataLawful Basis (Article 6)Special Category / Criminal Condition (Article 9 & DPA 2018)
Direct CareHealth, Disability, Support NeedsContractHealth & Social Care: Necessary for the provision of health or social care (Sch 1, Part 1, Para 2).
Support & Service DeliveryHealth/SensitiveLegitimate Interests: To fulfill our service agreement and provide safe care.Health & Social Care: Necessary for the provision of health or social care (Sch 1, Part 1, Para 2).
SafeguardingSensitive Health & Risk DataRecognised Legitimate Interest: Protecting the well-being of individuals at risk.Substantial Public Interest: Safeguarding of individuals at risk (Sch 1, Part 2, Para 18).
EDI MonitoringEthnicity, Religion, OrientationLegitimate Interests: To ensure our services are inclusive and accessible.Substantial Public Interest: Equality of opportunity or treatment (Sch 1, Part 2, Para 8).
Staff & Volunteer ManagementEmployment history, Health, NI NumberContract / Legal Obligation: To manage your role and meet employer duties.Employment & Social Security: Necessary for carrying out obligations in the field of employment law (Sch 1, Part 1, Para 1).
Recruitment (DBS Checks)Criminal Offence DataLegal Obligation / Lawful basis: Statutory requirement for roles working with vulnerable adults.Criminal Convictions: Statutory requirements (DPA 2018, Section 10(5) & Sch 1, Part 1, Para 1).
Donations & PaymentsFinancial & IdentityContract: To process your donation or payment for services.N/A
HMRC / Tax ComplianceFinancial & IdentityLegal Obligation: To meet UK tax and Gift Aid reporting laws.N/A
Internal IT SecurityTechnical (IP address, device ID)Legitimate Interests: To protect our systems and data from cyber threats.N/A
Fundraising & MarketingContact details, PreferencesConsent / Legitimate Interests: To keep you updated (using “soft opt-in” where applicable).N/A
Photography & Case StudiesVisual Images & Personal StoriesConsent: Your clear permission to use your image/story. 

Explicit Consent: You have given clear, written permission (Article 9(2)(a)).

Donations & PaymentsFinancial & IdentityContractual ObligationN/A
HMRC/Tax ComplianceFinancial & IdentityLegal ObligationN/A
Staff/Volunteer ManagementPersonal & SensitiveContractual/LegalEmployment, Social Security (DPA Sch 1, Part 1)
Internal Security (Defender/Intune)Technical/DeviceLegitimate InterestsN/A
Equality & Diversity MonitoringSensitiveLegitimate InterestsSubstantial Public Interest (DPA Sch 1, Part 2, Para 8)

Updated April 2026
Doc Ref: DI009A