Privacy and Data Protection is at the heart of our organisation and business culture. Here at OnePlusOne, we have a number of policies which refer to how we collect and process your data.
Our Policies
Last update: October 2024
OnePlusOne ("we," "us," or"our") is a registered charity that operates a business websitewithin the UK/EU area. We are committed to protecting and respecting yourprivacy. This Privacy Policy sets out how we collect, use, disclose, andprotect any personal information you provide to us when using our website andrelated services. We comply with the General Data Protection Regulation (GDPR)and other applicable data protection laws.
OnePlusOne are the designated data controller for thepurposes of the General Data Protection Regulations. Certain third partyservices we use will be designated as a data processor on our behalf.
We have appointed a Data Protection Officer (DPO) to oversee data privacy compliance. You can contact our DPO for any data-related queries:
Data Protection Officer: privacy@oneplusone.org.uk
We may collect and process the following types of personal information:
We use your personal information for the following purposes:
We process your personal information on the following legal bases:
We may share your personal information with third-party service providers who assist us in operating our website and providing services to you. These service providers are contractually obligated to handle your data securely and only process it on our behalf. We do not sell, rent, or trade your personal information to third parties for marketing purposes.
We ensure all third parties comply with UK GDPR by signing data processing agreements, outlining their responsibilities for data security.
We may also share your personal information with collaborative researchers for legitimate research purposes, as described in our Research Privacy Policy. We ensure all third parties comply with UK GDPR by signing data processing agreements, outlining their responsibilities for data security.
OnePlusOne provides some training and support programs through online learning platforms. When you register for a OnePlusOne online course or training program, we may collect personal information such as your name, email address, organisation (if applicable), and information about your learning activity, including course enrolment, progress and completion.
We use this information to provide access to training, support learners using the platform, and monitor how our programs are being used and evaluated.
Where a course has been commissioned or funded by a Local Authority or partner organisation, authorised staff from that organisation may have access to learner reports within the learning platform. These reports may include your name, email address and course progress so they can monitor the program they have commissioned. Local Authorities and partner organisations accessing this information are expected to use it only for program monitoring and evaluation purposes and to handle personal data in accordance with applicable data protection legislation.
Our learning platform providers process personal data on our behalf as data processors and are contractually required to protect personal data in accordance with UK data protection law.
We do not transfer your personal data outside of the UK/EU area. If we transfer your data outside the UK or EU, we will ensure appropriate safeguards, such as Standard Contractual Clauses (SCCs), are in place to protect your rights in accordance with the UK GDPR.
We implement reasonable technical and organisational measures to protect your personal information from unauthorised access, alteration, disclosure, or destruction. We use encryption for data storage and data transfer using SSL. Access to certain data is controlled through access management controls.
We conduct regular vulnerability assessments, penetration testing, and provide staff training on data security as per ICO guidance
We conduct regular vulnerability assessments, penetration testing, and provide staff training on data security as per ICO guidance
Under the GDPR, you have the following rights regarding your personal information:
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. Any changes will be posted on this page, and the updated Privacy Policy will be effective from the date of posting.
If you have any questions, concerns, or requests related to this Privacy Policy or how we handle your personal information, please contact us at:
Email: privacy@oneplusone.org.uk