The PCC of the Parish of Basingstoke Down is the data controller (contact details below). This means it decides how your personal data is processed and for what purposes.
Our website address is: https://www.parishofbasingstokedown.org.uk
Personal data relates to a living individual who can be identified from that data and includes recordings of your image and/or voice. Identification can be by the information alone or in conjunction with any other information in the data controller’s possession or likely to come into such possession. The processing of personal data is governed by the General Data Protection Regulation (the “GDPR”).
The PCC of the Parish of Basingstoke Down complies with its obligations under the “GDPR” by keeping personal data up to date; by storing and destroying it securely; by not collecting or retaining excessive amounts of data; by protecting personal data from loss, misuse, unauthorised access and disclosure and by ensuring that the minimum and appropriate technical measures (see Appendix 1 – Definition of Secure) are in place to protect personal data.
We use your personal data for the following purposes:
When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
Only the data requested in the contact form will be used. The form is submitted via email to the parish office and no records are stored within the website database.
If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
We use third party applications for statistics and analytics of our website to better understand how we can improve it for you. These providers may leave cookies to track your session to give us anonymized data about your visit.
Your personal data will be treated as strictly confidential and will only be shared with other members of the Parish in order to carry out a service to other Parish members or for purposes connected with the Parish. We will only share your data with third parties outside of the parish with your consent, unless required to do so by law or court order.
Your personal data may be included in the Parish directory, if you have previously agreed to this, and managed in accordance set out within the privacy notice and Appendix 2 – Deletion Policy.
Comments by visitors to our website may be checked through an automated spam detection service.
We keep data in accordance with the guidance set out in the guide “Keep or Bin: Care of Your Parish Records” which is available from the Church of England website.
Specifically, we retain electoral roll data while it is still current; gift aid declarations and associated paperwork for up to 6 years after the calendar year to which they relate; and parish registers (baptisms, marriages, funerals) permanently.
Recordings of services which have been live-streamed will be stored indefinitely on YouTube.
On our website:
Unless subject to an exemption under the GDPR, you have the following rights with respect to your personal data:
If we wish to use your personal data for a new purpose, not covered by this Data Protection Notice, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, we will seek your prior consent to the new processing.
To exercise all relevant rights, raise queries or make complaints please in the first instance contact the data controller’s representatives. Using the below details:
The Churchwardens,
Parish of Basingstoke Down
Parish Office
Saint Mark’s Church
Kempshott
Basingstoke
Hampshire
RG22 5LQ
Should you have any disputes and/or concerns with how your personal data has been used in the first instance you should contact the parish data protection officer using the below details.
You also have the right to complain to the Information Commissioner’s Office, the supervisory authority, about our collection and use of your personal data. They can be contacted at
Information Commissioner’s Office,
Wycliffe House,
Water Lane,
Wilmslow,
Cheshire,
SK9 5AF
www.ico.org.uk
Below are the minimum requirements that the Parish of Basingstoke Down will adhere to when storing all personal data without exception.
Hard data is personal data that is stored with physical copies, e.g. paper.
Wherever practical, Parish of Basingstoke Down will keep all hard data in locked cabinets when not in use.
Where access is shared (e.g. a key lent), wherever practical there will be written consent from the Data Protection Officer before access is granted. Should the need for immediate access arise, the Data Protection Officer will be informed of the access and reason behind the immediate nature.
If you have agreed to allow your data to be contained within the Parish directory distributed to the worshipping community, this form of personal data will be out of scope of the control of this definition.
Soft data is personal data stored on computers of any nature including desktops, laptops, tablets, phones and cloud services (devices).
All soft data stored on Parish owned devices will be encrypted, and soft data held on other devices not owned by the Parish should have a minimum of password protection.
All users of Parish owned devices containing personal data will have access controls (user accounts) in place to allow audit of access.
All users of Parish owned devices will ensure that such equipment is not left unattended or in an unsecured state.
All distributed personal data (eg membership lists) will have access limited to those with legitimate needs to access, and this list of people will be available on request.
Recordings of services which have been live-streamed and stored on YouTube are in the Public Domain and outside the scope of Parish of Basingstoke Down to keep secure.
All personal data held by Saint Mark’s will be deleted within 21 days of receipt of a formal request, made to the Data Controller through the appropriate representative.
Exceptions are made for any data required to be held by the parish by law.
[1] Details about retention periods can currently be found in the Record Management Guides located on the Church of England website at: – https://www.churchofengland.org/more/libraries-and-archives/records-management-guides
[2] Please see also the Data Privacy Notice displayed on our website for all definitions