UK Data Protection & GDPR Policy: CiviCode Ltd.

1. Introduction

CiviCode Ltd. ("CiviCode") is committed to protecting the privacy and security of personal data. This policy outlines our practices to ensure compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).

2. Scope and Definitions

  • Scope: This policy applies to all personal data processed by CiviCode, including data relating to clients, employees, and third parties.
  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Processing: Any operation performed on personal data, such as collection, storage, or extraction.
  • Data Subject: The individual to whom the personal data refers.

3. Principles of Data Processing

CiviCode adheres to the following principles:

  • Lawfulness, Fairness, and Transparency: Processing is conducted legally and transparently.
  • Purpose Limitation: Data is collected for specified, explicit, and legitimate purposes.
  • Data Minimisation: Only data necessary for the intended purpose is collected.
  • Accuracy: Personal data must be accurate and kept up to date.
  • Storage Limitation: Data is kept in an identifiable form for no longer than is necessary.
  • Integrity and Confidentiality: Data is processed securely to protect against unauthorised access or accidental loss.

4. Rights of the Data Subject

CiviCode facilitates the following rights under the UK GDPR:

  • Right of Access: Confirmation of whether data is being processed.
  • Right to Rectification: Correction of inaccurate data.
  • Right to Erasure: Deletion of data under specific conditions.
  • Right to Restrict/Object: The right to limit or stop certain processing activities.
  • Right to Data Portability: Receiving data in a structured, commonly used format.

5. Data Protection Roles

  • CiviCode as Data Controller: For internal data (e.g., employee records), CiviCode determines the purpose and means of processing.
  • CiviCode as Data Processor: When delivering digital transformation support, CiviCode processes data solely on the written instructions of the Client (the Data Controller).

6. Data Security and Transfers

  • Security Measures: CiviCode implements technical and organisational measures, including encryption, "Zero Trust" access controls, and regular security assessments.
  • International Transfers: Data is not transferred outside the United Kingdom unless adequate protections are in place, such as the UK International Data Transfer Agreement (IDTA).

7. Data Breach Management

  • Controller Breach: If CiviCode is the Data Controller, we will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to individuals.
  • Processor Breach: If CiviCode is the Data Processor, we will notify the Client without undue delay to allow them to fulfil their own regulatory obligations.

8. Accountability and Governance

  • Data Protection Officer (DPO): CiviCode has appointed a DPO to oversee compliance. Contact: [email protected].
  • Impact Assessments: We conduct Data Protection Impact Assessments (DPIAs) for processing likely to result in high risks to individuals.
  • Record-keeping: CiviCode maintains records of processing activities, including purposes and categories of data subjects.