Privacy
Privacy & cookies policy
The Lily Foundation operates this website. At The Lily Foundation we take your right to privacy very seriously. For that reason, we have set out this privacy & cookies policy so you can make sure you understand how and why we use the information you give us. The terms of this policy may change, so please check it from time to time.
If you have any queries about this policy please contact:
Liz Curtis, Assigned Data Controller – [email protected].
Who are we?
The Lily Foundation is a company limited by guarantee, registered in England and Wales under company number 06400879 and registered as a charity with the Charity Commission for England and Wales under number 1122071 whose registered office is at 31 Warren Park, Warlingham, Surrey CR6 9LD. Our registration number with the Information Commissioners Office is ZA227002.
How we collect information from you
The Lily Foundation is the sole owner of the information submitted by you, to us, in any way. We may use this information gathered during our organisation’s stated role, to further our charitable aims and objectives and to further understand our supporters and how best we can support you. However, we will not ever sell or rent personally identifiable information that you have submitted to this site to third parties.
Collection of your information may be through:
- our online shop
- your registration to an event via our website (we will only contact you about this event unless you have specified otherwise)
- your information passed from a third party you have registered with for a fundraising event (in this instance please always refer to their own privacy policy too)
- via a phone call to us (we will always refer to our marketing preferences and make sure that we have your consent to contact you further)
- via a written consent form you have sent to us.
Information we collect about you
This is the information that you have given us.
Information collected by a third party
Your information may be shared with us by third party organisations, for example fundraising sites like JustGiving and Run for Charity. These sites will do so pursuant to their own policies on data protection and privacy. It’s a good idea to check their privacy policy when you provide your information to understand fully how they will process your data.
Special category or sensitive information
If you are a patient, parent or advocate of someone with mitochondrial disease, some health information that you may tell us falls under what is deemed as sensitive information, such as your genetic data, medical data or health information. As with all the personal information you provide us, you can be assured that any sensitive information you choose to supply will be kept confidential and only shared with your consent.
What are we collecting?
Through our contact form we will collect the following data:
- your name/name of affected child or individual you advocate for
- date of birth
- date of death (where relevant)
- ethnic background
- first language
- address/postcode
- specialist mitochondrial disease centre
- medical diagnosis, if you have one, and when this was given.
Why do we collect this sensitive information?
As a charity we like to ensure that we are providing the best possible service for our patients. By understanding demographics and the disease spread it will help to ensure that our services are targeted in the right areas.
How do we store your sensitive information?
Any personal data, such as names and email addresses – the “contact record” – is stored on the central Lily Foundation database.
Who do we share your data with?
None of your data will be shared with third parties without your knowledge and consent.
None of your data will be used for marketing purposes unless you have opted in.
Retention of data
We will retain your information for as long as we feel it necessary to do so for the purpose upon which it was obtained and/or retained and/or processed. If at any stage you would like us to delete your information you should make this request in writing by contacting [email protected].
What do you do with the data?
We use your data:
- to provide you with the services, products or information you have asked for (for example when you purchase an item from our shop or sign up to an event via our website)
- for specific sporting events we will share your email with third parties to process registration (e.g. London Marathon event)
- to administer your donation or support your fundraising, including processing Gift Aid
- to add you to our database
- to keep a record of your relationship with us
- to comply with financial regulations and the law
- to contact you for marketing purposes by email if you have opted in to receive these.
If you have provided us with your postal address or telephone number, we may send you direct mail for marketing purposes unless you have told us that you would prefer not to receive such information.
You may opt out of marketing emails at any time by clicking the ‘unsubscribe’ link in our marketing emails.
You can also change your contact preferences at any time, including telling us to no longer send you marketing by post, by contacting [email protected] or calling 0300 400 1234.
If you request to receive no further contact from us, we will keep some basic information in order to avoid sending you unwanted materials in the future, and to ensure that we do not accidentally store details for the same person multiple times. This will be the only reason your data is retained and/or processed in such a scenario.
How long do we keep your personal data?
We keep personal data only for as long as it’s necessary. When it comes to financial donations and Gift Aid, we’re required to keep information such as the supporter’s name, address, Gift Aid declaration form(s) and financial information for seven years for HMRC auditing purposes. We’ll retain basic information (such as a supporter’s postcode and transactional history). We believe it’s important to keep basic information of this kind in case someone leaves a gift in their will to us and we are required to evidence the nature of their support if it’s contested.
How do we protect personal information?
We use a secure server when you make a donation or payment via our website. We take appropriate measures to ensure that the personal information disclosed to us is kept secure, accurate and up to date and kept only for so long as is necessary for the purposes for which it is used. All personal information is stored in a central database which has stringent measures in place for restricting access and preventing external data breaches.
We undertake regular reviews of who has access to information that we hold to ensure that your information is only accessible by appropriately trained staff and third-party organisations who have been contracted by us to process data. Our approach to personal information involves restricting access to sensitive personal information, for example health information and financial contributions, to only those departments that need this data in order to carry out their functions.
We use external companies to collect or process personal data on our behalf. We make sure we only work with companies that comply with the Payment Card Industry Data Security Standard (PCI DSS) and we do annual reviews of their data processes to be certain that they meet our GDPR expectations and requirements. The data we collect from you may be transferred to, and stored at, a destination outside the European Economic Area (EEA) e.g. USA. It may also be processed by persons operating outside the EEA.
We use the following systems for processing and storing your data:
Donorfy – please click here to read their privacy policy.
Dropbox for Business – please click here to read their privacy policy.
Mailchimp – please click here to read their privacy policy.
Free Online Surveys – please click here to read their privacy policy.
Microsoft – please click here to read their privacy policy.
Google Workspace – please click here to read their privacy policy.
Facebook – please click here to read their privacy policy.
Acuity Unified Communications – please click here to view their privacy policy.
JustGiving – please click here to view their privacy policy.
Stripe – please click here to view their privacy policy.
WeTransfer – please click here to view their privacy policy.
Unfortunately, no data transmission over the internet can be completely secure. Whilst we do our best to protect your personal data, we cannot guarantee the security of any information which you transmit to us online and you must understand that you do so at your own risk.
Your consent
By providing us with your personal data, including sensitive personal data such as your state of health, you consent to the collection and use of this information in accordance with the purposes described above and this privacy statement.
You also consent to us transferring your information to countries or jurisdictions outside the UK if necessary for the above purposes. These countries may not provide the same level of data protection as the UK.
Your rights under the GDPR
The General Data Protection Regulation (GDPR) gives you more control over what happens to your personal information. Under this legislation you have the right to:
- be given clear, transparent and free information about how your data will be used
- access your personal data so that you can see how your personal information is being used by us
- have your personal information updated and corrected
- obtain and reuse the personal data you have given to us for your own purposes
- request that we permanently delete or remove your information where there is no “compelling” reason for us to keep it; and request that we don’t use your personal data for specific purposes and, unless we are under a legal or contractual obligation, we must respect your wishes
- the GDPR also prohibits us from using solely automated technologies to build profiles and make decisions about people who support us which will have “legal or similarly significant effects”, unless: it’s necessary to fulfil a contract; it’s been authorised by a Union or Member state law; or you’ve given your explicit consent for your information to be used in this way.
How to access and update your personal information
We want to make sure that your personal information is accurate and up to date. You may ask us to correct or remove information you think is inaccurate by contacting us using the contact details below. You may also withdraw your consent for us to keep your personal data for some of the above purposes by writing to the address below. You have a right to access the personal information we hold about you and in certain circumstances to be provided with a copy of that information. You can request this free of charge by email to [email protected] or by writing to The Lily Foundation, 31 Warren Park, Warlingham, Surrey CR6 9LD.
If you are unhappy with the way in which your personal data has been handled you are entitled to make a complaint to the Information Commissioner’s Office.
Cookies and how we use them
What is a cookie?
A cookie is a small piece of information that we place on your computer or mobile device when you visit our website. They help us to recognise you and your device and store some information about your preferences or past use of our website, to ensure the website is as user-friendly and relevant as possible.
How we use cookies
We’ll ask for your permission to place optional cookies on your device when you visit our website. Some cookies are essential for our website to work properly and can’t be turned off. When you visit our site a cookie banner will ask for your consent to place cookies on your device. You can allow all or click the link in the banner to decline the optional cookies. Your choices will be saved for a year, but you can update your preferences by clicking on the ‘Cookie preferences’ link at the bottom of the page at any time.
- Strictly necessary cookies: These cookies are absolutely necessary for core functions such as navigating the page or accessing secure areas. The website cannot function properly without these cookies.
- Optional analytics cookies: These serve to improve the performance and functionality of this website by collecting and reporting information anonymously.
- Optional marketing cookies: These ones are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
Cookies do not provide us with access to your computer or any information about you, other than that which you choose to share with us.
To learn more about cookies and how they are used, visit www.aboutcookies.org.uk.
Changes to this privacy policy
We may change the terms of this privacy policy from time to time. If we do so, we will post the changes here for you to see. By continuing to use our website you will be deemed to have accepted such changes.