Data Protection & GDPR Policy
We are committed to protecting the privacy, confidentiality and security of personal information, handling all personal data lawfully, fairly, securely and transparently.
Statement of intent
We recognise our responsibilities under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy outlines how we collect, store, use, share and protect personal information relating to children, young people, families, staff, volunteers and partner agencies.
Why we collect data
- To deliver safe and effective provision.
- To safeguard children and vulnerable individuals.
- To communicate with families and professionals.
- To manage referrals and placements, attendance and incident records.
- To complete risk assessments and meet legal and contractual obligations.
Photographs & media
Photographs or videos of participants are only used where appropriate consent has been obtained — for promotional materials, social media, website content, funding reports and community awareness. Parents and carers may withdraw consent at any time.
Your rights
Individuals have rights under UK GDPR including the right to access their information, request corrections, restrict processing, request deletion where appropriate, and complain to the Information Commissioner's Office (ICO). Requests should be made directly to Mending Lines.
Data breaches & retention
Records are retained only for as long as reasonably necessary and then securely deleted or destroyed. Any actual or suspected data breach must be reported immediately to the management team, investigated promptly, and reported to the ICO where necessary.
