Data Protection
George
Last Update a month ago
1. Introduction
Take Back Your Mind UK (TBYM) is committed to protecting the personal data of all individuals accessing our mental-health and wellbeing services. This policy sets out how we comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and ICO guidance.
All personal data is processed lawfully, stored securely, and managed with transparency.
2. Purpose and ScopeThis policy explains how TBYM processes personal data relating to:
Individuals accessing our support service.
Individuals booking appointments, or contacting us by email, or phone.
Volunteers and staff supporting service users.
It includes all types of personal data collected:
Names, contact details, and enquiry information.
Conversation notes, interaction summaries, advice provided, referrals made.
Safeguarding notes and health-related information (special category data).
Personal Data: Any information relating to an identifiable individual.
Special Category Data: Sensitive information such as health or wellbeing details.
Processing: Any operation applied to personal data, including collection, storage, retrieval, and deletion.
Data Subject: The individual to whom the data relates.
Data Controller: TBYM.
Data Processor: Third parties processing data on behalf of TBYM.
Data Breach: Unauthorised or accidental access, disclosure, loss, or alteration of personal data.
Individuals may contact the support service without providing identifying information.
If a person voluntarily shares their name or contact details for follow-up, lawful basis: Consent.
A record of the interaction is kept under Legitimate Interests to provide safe, effective support and meet safeguarding duties.
Name, email, and relevant details are required for arranging and delivering appointments.
Lawful basis: Performance of a Contract or Legitimate Interests (service delivery and duty of care).
Where life or wellbeing may be at risk: Vital Interests.
Where required by law or statutory safeguarding frameworks: Legal Obligation.
Processed only where required and under the appropriate lawful condition, such as:
Explicit Consent,
Substantial Public Interest (safeguarding), or
Vital Interests.
TBYM ensures all personal data is processed in accordance with GDPR principles:
Lawful, fair, transparent processing
Purpose limitation – used only for support, safeguarding, and administration
Data minimisation – only what is necessary is collected
Accuracy – records kept up to date
Storage limitation – normally retained for 7 years after last contact
Integrity and confidentiality – securely stored and access-restricted
Accountability – DPO oversight, audits, and training
Personal data may be collected through:
Appointment booking systems
Email, phone, or online contact
Support interactions recorded by staff or volunteers
Accessing the support service:
Individuals may choose not to provide personal details.
Where they do provide identifiable information for follow-up, consent is obtained.
A record of the interaction itself is maintained under legitimate interests for safe service provision and safeguarding.
Special category data is collected only where necessary and under a valid lawful condition.
7. Data Storage and AccessData is stored in secure TBYM UK systems (including Google Workspace).
Access is strictly role-based:
Volunteers: Access only data required for communication and support.
Staff: Access full records needed for service delivery and safeguarding.
DPO: Access for compliance and breach investigation.
Data is encrypted and protected by internal security measures.
Only authorised personnel can upload, modify, or access records.
Data is retained for 7 years after the last contact unless legal or safeguarding requirements specify otherwise.
Individuals may request deletion or correction by emailing [email protected].
Data is securely deleted, with minimal audit logs retained.
Service users have the right to:
Access their personal data
Request corrections
Request deletion where applicable
Restrict or object to processing
Request a copy of their data
Requests are completed within GDPR timeframes following identity verification where required.
10. Data Breach ManagementAny suspected data breach must be reported to the DPO immediately.
The DPO will assess risk, notify the ICO where required, and inform affected individuals when appropriate.
All breaches are documented and reviewed, with improvements implemented.
Data is only shared externally when:
Required by safeguarding or vital interests
Required by law
The individual has given explicit consent
Any data processors must sign a Data Processing Agreement (DPA) and comply with GDPR.
12. Training and AwarenessAll staff and volunteers handling personal data must complete annual:
GDPR and data protection training
Safeguarding training
The DPO maintains training records.
13. Monitoring and ReviewThe DPO monitors compliance, performs audits, and reports findings to the Directors.
This policy is reviewed annually or following major changes in law, systems, or service structure.
Data Protection Officer:
George Griffiths – 📧 [email protected]
Service enquiries:
📧 [email protected]
