Privacy Policy

Last updated: 14/04/2024

At The Happy Mums Foundation, we believe that privacy is a foundation of trust. When you share your story, your contact details, or your time with us, we promise to look after that information with the same care we provide in our support groups.

This policy explains what information we collect, why we need it, and, most importantly, how we keep it safe.

 

1. Information We Collect

Depending on how you interact with us, we may collect:

  • Contact Details: Your name, email, and phone number so we can stay in touch.

  • Support Data: Information about your wellbeing (such as the Warwick Edinburgh Wellbeing scale) to help us provide the right support and measure our impact.

  • Safeguarding Information: If we are concerned about your safety or the safety of a child, we record these details as part of our duty of care.

  • Volunteer & Training Data: Your training progress, quiz results, and group attendance.

  • Financial Data: Our payment processor (Stripe) handles your card details for donations or training. We never see or store your card number.

  • Digital Data: Information about how you use our website (via the google analytics, tag manager and Facebook Pixel).

2. How We Communicate With You

We use various tools to make sure we are accessible while keeping everyone’s data secure:

  • Facebook Messenger: We only communicate via the official Happy Mums Foundation business account. Our staff and volunteers never use their personal Facebook accounts to contact you about Foundation work.

  • WhatsApp: We use a Business WhatsApp Channel. This allows us to send updates and information to members safely without sharing your personal phone number with other members of the group.

  • Professional Telephony: When we call you, we use an app called FlowUC. This means our team calls from our office number, even if they are working flexibly, ensuring their personal numbers and your contact logs stay private.

  • Newsletters: We use Mailchimp for bulk updates. You can “unsubscribe” at any time with one click.

3. Our “System Family” (Where Your Data Lives)

We use a carefully chosen “family” of secure systems. We use Two-Factor Authentication (2FA) on all these systems—which is like having a second, secret lock on the door that only we have the key to.

  • Beacon CRM: Our main “digital filing cabinet” for contact details and support history.

  • Volunteero: Used to coordinate our volunteers. To protect you, safeguarding notes here use initials only, keeping your identity separate from the sensitive details of the report.

  • Microsoft 365: Our internal emails and documents, secured by our IT partners, Castle Computers.

  • Stripe & QuickBooks: These handle our payments and accounting with world-class security.

  • Our Website: Stores training progress and utilizes the Facebook Pixel. This “pixel” helps us understand how people use our site and ensures our Facebook adverts reach the people who might need our support most.

.

4. Privacy by Design: Our “Silo” Approach

We take an extra step to protect your most sensitive information. By keeping your name in Beacon and any safeguarding notes in Volunteero (using only your initials), we ensure that even if one system were ever compromised, your full identity and your private wellbeing notes stay disconnected.

5. DBS Data & Recruitment

We handle criminal record checks with the highest confidentiality. We physically inspect certificates, log the check, and return the certificate to you. We only keep a record of that inspection for one year after you stop working or volunteering with us.

6. Sharing Your Data

We will never sell your data. We only share it when:

  • You give us explicit permission.

  • We are legally required to (for example, in a safeguarding emergency).

  • We share “anonymised” impact data (like average mood scores) with funders. This never includes your name or identifying details.

7. Your Rights

You are in charge of your data. You have the right to:

  • Ask for a copy of the information we hold about you.

  • Ask us to correct anything that is wrong.

  • Ask us to delete your information (unless we have a legal duty to keep it).

8. Contact Us

If you have any questions or would like to exercise your rights, please contact our Data Protection Officer, Katie Bruce, at info@happymums.org.uk.

We review this policy every year to make sure we are always using the best and safest ways to look after you.

 

The Happy Mums Foundation Record of Processing Activities

Mums, Mums-to-be & Birth-Givers (Service Users)

What do we collect:

Name, phone number, email address, emergency contact name and phone number, dates attended groups, mood survey scores, photos and quotations

ANONYMISED: ethnicity, age, pregnancy status, postcode, sexual orientation, gender, disability status

How do we collect it:
Online registration form, Group Registers, Group Debrief Form
Emails, Telephone calls recorded manually, Meta messenger
Questionnaires. Images taken at events usually via smart phones. All Electronic Unless Specified otherwise.

Storage:
Manual: If initially collected on paper, this is transferred to electronic format within a maximum of 2 weeks and paper version securely destroyed.
Electronic: Microsoft 365 – Password protected system. Images taken via smart phones are transfered to M365 as soon as possible then removed from Mobile Device
Facebook Messenger
Canva (images for promotional use)

Why do we need this data:
To provide project services
To report safeguarding concerns
To inform of new services
To analyse impact and report to funders

Source of Data:
Service User, Group Facilitators

Permission / Legal Basis for storing and using data:
Legitimate Interests
Consent (explicitly for newsletter, photos, quotations and all special category data)

Who is this data shared with:

Police / Safeguarding Hub (with or without consent in instances of Immediate risk of harm)

To healthcare providers in health emergency (with consent where possible)

To Emergency contact (with Consent where possible)

Is any of this data shared oversees:
No

Security Arrangements:
Password protected systems with 2-step -verifcation where possible

Any Further Processing: 
Anonymised statistical analysis for reporting to funders; CIC Regulator and HMRC

Retention and Disposal:
All data held for 6 years from last contact EXCEPT:
If safeguarding procedures retain for 10 years from last contact
Suspicious death of a service user kept for 75 years
Aggregated statistical returns including non-identifiable personal data kept indefinitely
Enquiries which do not lead to services being received kept for 2 years (aggregated statistical returns including non-identifiable personal data kept indefinitely)

Volunteers

What do we collect:
Name, address, phone numbers, personal email address, volunteer role title, DBS Certificate number, bank details, date of birth, driving licence number, passport number, medical conditions, declarations of interests, training records and certificates. Next of Kin name and phone number (for emergecy use only)

How do we collect it:
Application form, Volunteer Details Form, DBS supporting evidence , Medical Info form, letters
ALL ELECTRONIC unless specified otherwise

Storage:
Manual: If initially collected on paper, this is transferred to electronic format within a maximum of 2 weeks and paper version securely destroyed.
Electronic: Microsoft 365 – Password protected system. DBS information restricted to need-to-know users.

Why do we need this data:
To provide volunteer role
To pay expenses
To ensure safety of service users

Source of Data:
Volunteer, Line Manager

Permission / Legal Basis for storing and using data:
Contract – Volunteer Agreement

Who is this data shared with:
In response to requests for references
To/ from DBS check provider
To/ from HMRC as required by law
To healthcare providers in health emergency (with consent where possible)
To/ from accountant

Is any of this data shared oversees:
No

Security Arrangements:
Password protected systems with 2-step -verifcation where possible

Any Further Processing: 
Anonymised statistical analysis for reporting to funders; CIC Regulator and HMRC

Retention and Disposal:
Application and recruitment data for unsuccessful candidates held for 6 months from interview date
Volunteer details and training records up to 6 years after volunteering ends
Bank details & DBS info no longer than necessary
Expenses payments 6 years from financial year end

Supporters (via Supporterships)

What do we collect:

Name, email address

Collected via Stripe for Payment processing: Name, Address, email address and Payment Information. This information is not held by Happy Mums.

How do we collect it:
Online sign up page

Storage:
Electronic: WordPress Database and Microsoft 365 – Password protected system. 

Why do we need this data:
To provide services described in each supportership package

Source of Data:
Supporter

Permission / Legal Basis for storing and using data:
Legitimate Interests
Consent 

Who is this data shared with:

To / From Payment Provider
To / From Accountant

Is any of this data shared oversees:
No

Security Arrangements:
Password protected systems with 2-step -verifcation where possible

Any Further Processing: 
Anonymised statistical analysis for reporting to funders; CIC Regulator and HMRC

Retention and Disposal:
All data held for 6 years from last contact 

Third Parties: Next of Kin, Emergency Contacts and Children of Service Users

What do we collect:
Name, address, phone number, email address, job title, organisation

How do we collect it:
Application forms, Registration Forms, Group Register, Group Debrief Form, Emails, Telephone calls. 
ALL ELECTRONIC unless specified otherwise

Storage:
Manual: If initially collected on paper, this is transfered to electronic format within a maximum of 2 weeks and paper version securely destroyed.
Electronic: Microsoft 365 – Password protected system.

Why do we need this data:
To comply with Recruitment Policy
To keep employees, volunteers and beneficiaries safe
To report safeguarding concerns

Source of Data:
Service User, Volunteer, Employee

Permission / Legal Basis for storing and using data:
Legitimate Interest

Who is this data shared with:
Police / Safeguarding Hub (with consent where possible)
To healthcare providers in health emergency (with consent where possible)

Is any of this data shared oversees:
No

Security Arrangements:
Password protected systems with 2-step -verifcation where possible

Any Further Processing: 
Anonymised statistical analysis for reporting to funders; CIC Regulator and HMRC

Retention and Disposal:
All data held for 6 years from last contact EXCEPT:
If safeguarding procedures retain for 10 years from last contact
Suspicious death in relation to services provided of a service user kept for 75 years
Aggregated statistical returns including non-identifiable personal data kept indefinitely
Enquries which do not lead to services being received kept for 2 years (aggregated statitstical returns including non-identificable personal data kept indefinitely)
Records of accidents/incidents and If safeguarding procedures used until child reaches 24 years
Suspicious death in relation to services provided of a child kept for 75 years
Shredded on disposal

Employees

What do we collect: 
Name, address, phone numbers, personal email address, job title, bank details, salary, NI Number and Tax Code, date of birth, DBS certificate number, passport number, driving licence number, medical conditions, travel expenses claims, personalised risk assessments, training records and certificates, sickness absence records, contracts and letters, Right to Work ID check form

How do we collect it:
Application form, Employee Details Form, DBS and Right to Work checklists, HMRC forms, Medical Info form, training records form, travel expenses form, sickness absence recording forms, letters, contracts. ALL ELECTRONIC unless specified otherwise

Storage:
Manual: If initially collected on paper, this is transferred to electronic format within a maximum of 2 weeks and paper version securely destroyed.
Electronic: Microsoft 365 – Password protected system. DBS information restricted to need-to-know users.

Why do we need this data:
To provide employment
To pay wages
To ensure safety of service users
To ensure health and wellbeing of employee

Source of Data:
Employee, Line Manager

Permission / Legal Basis for storing and using data:
Contract – Terms and Conditions of employment

Who is this data shared with:

To/ from payroll provider
To / from pensions provider
In response to requests for references
To/ from DBS check provider
To/ from HMRC as required by law
To healthcare providers in health emergency (with consent where possible)
To/ from accountant

Is any of this data shared oversees:
No

Security Arrangements:
Password protected systems with 2-step -verifcation where possible

Any Further Processing: 
Anonymised statistical analysis for reporting to funders; CIC Regulator and HMRC

Retention and Disposal:
Application and recruitment data for unsuccessful candidates held for 6 months from interview date
Personal details and training records up to 6 years after employment ends
Bank details & DBS info no longer than necessary
HMRC/Pension/Payroll payments 6 years from financial year end

Suppliers

What do we collect:
Name, business address, business phone number, email address, company name, job title, bank details (if BACs payment required)

How do we collect it:
Phonecalls, emails, websites, invoices.

Storage:
Manual: If initially collected on paper, this is transferred to electronic format within a maximum of 2 weeks and paper version securely destroyed.
Electronic: Microsoft 365 – Password protected system. DBS information restricted to need-to-know users.

Why do we need this data:
To request products/services,
To pay invoices

Source of Data:
Supplier

Permission / Legal Basis for storing and using data:
Contract 
Legitimate Interests

Who is this data shared with:
To / from accountant
To / from payment provider

Is any of this data shared oversees:
No

Security Arrangements:
Password protected systems with 2-step -verifcation where possible

Any Further Processing: 
None

Retention and Disposal:
All data held for 6 years from last contact.

Associated Privacy Policies

Microsoft 365 Cloud Overview of privacy controls for Microsoft 365 Apps for enterprise – Deploy Office | Microsoft Learn
WordPress.org Website Web  https://wordpress.org/about/privacy/
Divi – Elemental Themes Web  https://www.elegantthemes.com/policy/privacy/
Stripe Web  https://stripe.com/gb/privacy
Facebook Web  https://www.facebook.com/security/
Twitter / X Web  https://help.twitter.com/en/rules-and-policies/x-rules
Instagram Web  https://help.instagram.com/155833707900388
LinkedIn Web  https://www.linkedin.com/legal/privacy-policy
Canva Web  https://www.canva.com/policies/privacy-policy/
Online Banking Web  Available on Request
Pension Portal Web  Available on Request