Data Protection

George

Last Update a month ago

1. Introduction

Take Back Your Mind UK (TBYM) is committed to protecting the personal data of all individuals accessing our mental-health and wellbeing services. This policy sets out how we comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and ICO guidance.

All personal data is processed lawfully, stored securely, and managed with transparency.

2. Purpose and Scope

This policy explains how TBYM processes personal data relating to:

  • Individuals accessing our support service.


  • Individuals booking appointments, or contacting us by email, or phone.

  • Volunteers and staff supporting service users.

It includes all types of personal data collected:

  • Names, contact details, and enquiry information.

  • Conversation notes, interaction summaries, advice provided, referrals made.

  • Safeguarding notes and health-related information (special category data).

3. Definitions

Personal Data: Any information relating to an identifiable individual.
Special Category Data: Sensitive information such as health or wellbeing details.
Processing: Any operation applied to personal data, including collection, storage, retrieval, and deletion.
Data Subject: The individual to whom the data relates.
Data Controller: TBYM.
Data Processor: Third parties processing data on behalf of TBYM.
Data Breach: Unauthorised or accidental access, disclosure, loss, or alteration of personal data.

4. Lawful Bases for Processing 4.1 Accessing Our Support Service (initial contact)
  • Individuals may contact the support service without providing identifying information.

  • If a person voluntarily shares their name or contact details for follow-up, lawful basis: Consent.

  • A record of the interaction is kept under Legitimate Interests to provide safe, effective support and meet safeguarding duties.

4.2 Appointment Bookings
  • Name, email, and relevant details are required for arranging and delivering appointments.

  • Lawful basis: Performance of a Contract or Legitimate Interests (service delivery and duty of care).

4.3 Safeguarding
  • Where life or wellbeing may be at risk: Vital Interests.

  • Where required by law or statutory safeguarding frameworks: Legal Obligation.

4.4 Special Category (Sensitive) Data

Processed only where required and under the appropriate lawful condition, such as:

  • Explicit Consent,

  • Substantial Public Interest (safeguarding), or

  • Vital Interests.

5. Data Protection Principles

TBYM ensures all personal data is processed in accordance with GDPR principles:

  • Lawful, fair, transparent processing

  • Purpose limitation – used only for support, safeguarding, and administration

  • Data minimisation – only what is necessary is collected

  • Accuracy – records kept up to date

  • Storage limitation – normally retained for 7 years after last contact

  • Integrity and confidentiality – securely stored and access-restricted

  • Accountability – DPO oversight, audits, and training

6. Data Collection and Consent

Personal data may be collected through:

  • Appointment booking systems

  • Email, phone, or online contact

  • Support interactions recorded by staff or volunteers

Accessing the support service:

  • Individuals may choose not to provide personal details.

  • Where they do provide identifiable information for follow-up, consent is obtained.

  • A record of the interaction itself is maintained under legitimate interests for safe service provision and safeguarding.

Special category data is collected only where necessary and under a valid lawful condition.

7. Data Storage and Access
  • Data is stored in secure TBYM UK systems (including Google Workspace).

  • Access is strictly role-based:

    • Volunteers: Access only data required for communication and support.

    • Staff: Access full records needed for service delivery and safeguarding.

    • DPO: Access for compliance and breach investigation.

  • Data is encrypted and protected by internal security measures.

  • Only authorised personnel can upload, modify, or access records.

8. Retention and Deletion
  • Data is retained for 7 years after the last contact unless legal or safeguarding requirements specify otherwise.

  • Individuals may request deletion or correction by emailing [email protected].

  • Data is securely deleted, with minimal audit logs retained.

9. Rights of Service Users

Service users have the right to:

  • Access their personal data

  • Request corrections

  • Request deletion where applicable

  • Restrict or object to processing

  • Request a copy of their data

Requests are completed within GDPR timeframes following identity verification where required.

10. Data Breach Management
  • Any suspected data breach must be reported to the DPO immediately.

  • The DPO will assess risk, notify the ICO where required, and inform affected individuals when appropriate.

  • All breaches are documented and reviewed, with improvements implemented.

11. External Sharing and Third Parties

Data is only shared externally when:

  • Required by safeguarding or vital interests

  • Required by law

  • The individual has given explicit consent

Any data processors must sign a Data Processing Agreement (DPA) and comply with GDPR.

12. Training and Awareness

All staff and volunteers handling personal data must complete annual:

  • GDPR and data protection training

  • Safeguarding training

The DPO maintains training records.

13. Monitoring and Review

The DPO monitors compliance, performs audits, and reports findings to the Directors.
This policy is reviewed annually or following major changes in law, systems, or service structure.

14. Contact Information

Data Protection Officer:
George Griffiths – 📧 [email protected]

Service enquiries:
📧 [email protected]

Was this article helpful?

2 out of 2 liked this article

Still need help? Message Us