The Good Exchange Limited which is a limited company registered in England and Wales under the Companies Act 2006 (Company Number 09761102) having its registered office at Liberty House, Greenham Business Park, Greenham, Thatcham, Berkshire, England, RG19 6HS (“we”, “our”, “us”) is committed to protecting and respecting your privacy in accordance with the Privacy Laws.
We are the data controller for the purpose of the Privacy Laws (defined below).
The Website is an online platform on which:
- charitable organisations seeking funding can register and promote their project(s);
- visitors can donate to, and show their support for, charitable projects and organisations;
- funders can connect with and fund organisations seeking funding; and
- fundraisers can connect with and support organisations which require assistance to raise funds.
The Website is operated as an online platform on which organisations can make connections and procure and provide funding or services directly from and to each other. For this reason certain Personal Data which you provide on the Website may be publicly available and may be passed to other users of the Website. We are not fundraisers and we do not provide funding. Further information regarding the practicalities of using the Website and its functionality are explained at our support website.
- the basis on which any Personal Data collected from you by us or that you provide to us can be processed by us;
- how we use your Personal Data;
- how and why we store your Personal Data;
- your rights, including how to update and access your Personal Data; and
- the way in which you are authorised to use the Personal Data of other Users which you access on the Website.
Please read the following carefully to understand how we will treat your Personal Data.
Applicant means any user of the Website registered on the Website as an applicant in order to seek Funding from one or more Funder(s) or Donations from one or more Supporter(s);
Donation means a unilateral and freely given cash gift given on the Website by a Supporter to an Applicant without the expectation of receipt of goods, services or otherwise together with any applicable Gift Aid paid by HMRC to the Applicant;
Funder means any user of the Website registered through the Website as a funder in order to offer Funding to one or more Applicant(s);
Funding means cash funding in pounds sterling given on the Website by a Funder(s) to an Applicant as a stand-alone grant, as part of a co-funding arrangement or as part of a match funding arrangement;
Fundraiser means any user of the Website registered on the Website as a fundraiser in order to offer fundraising services and/or opportunities to Applicant(s);
HMRC means HM Revenue and Customs;
Gift Aid means the government scheme enabling eligible charities to reclaim income tax on a Donation made by an eligible UK taxpayer;
Interactive Services means any service made available on the Website by means of which you can input, comment, vote, participate or otherwise interact;
Personal Data has the meaning given in applicable Privacy Laws from time to time;
Privacy Laws means:
- the Data Protection Act 1998, until the effective date if its repeal
- the General Data Protection Regulation ((EU) 2016/679) (GDPR) and any national implementing laws, regulations and secondary legislation, for so long as the GDPR is effective in the UK, and
- any successor legislation to the Data Protection Act 1998 and the GDPR, in particular the Data Protection Bill 2017-2019, once it becomes law
Profile means an electronic profile containing the Personal Data of any Applicant, Funder, Fundraiser or Support that has been supplied for publication on the Website;
Project means any charitable project listed on the Website;
Supporter means any user of the Website, whether or not registered on the Website, who is not an Applicant, Funder or Fundraiser; and
User means any Funder, Applicant, Fundraiser or Supporter.
1.2 A person includes a natural person, corporate or unincorporated body (whether or not having separate legal personality) and that person’s personal representatives, successors and permitted assigns.
1.3 References to the singular shall include the plural and vice versa.
1.4 Reference to any legislation shall be to that legislation as amended from time to time.
3. INFORMATION WHICH MAY BE COLLECTED FROM YOU
We may collect and process the following Personal Data relating to you.
3.1 Personal Data that you give to us
You may give us Personal Data via the Website or by corresponding with us by telephone, e-mail or otherwise. The Personal Data you give us may include (but are not limited to) your name, address, e-mail address, telephone number, financial and credit card information, personal description or photograph.
This includes information you provide when you:
- access or use the Website, such as when you search for profiles for Applicants, Funders, Projects and / or Fundraisers;
- make a donation;
- communicate with other Users on the Website;
- enter into any Funding arrangement on the Website
- register on the Website or create a Profile on the Website for yourself as an individual Fundraiser or Supporter or on behalf of an Applicant, Funder or corporate Fundraiser whether as an Applicant, Funder, Supporter or Fundraiser;
- share Personal Data with another User on the Website;
- link your profile on the Website to a third party website, in which case we will obtain the Personal Data that you have provided on that third party website;
- use the Interactive Services;
- report User misconduct on the Website to us; and
- when you report a technical or other error on the Website to us.
3.2 Personal Data we collect about you
On each of your visits to the Website we may automatically collect the following information:
- technical information, including the Internet protocol (IP) address used to connect your computer to the internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform;
- information about your visit, including the full Uniform Resource Locators (URL) clickstream to, through and from the Website (including date and time); products you viewed or searched for; page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page and any phone number used to call our customer service number.
3.3 Personal Data we receive from other sources
We may receive Personal Data about you if you use any of the other websites we operate or the other services we provide. In this case we will have informed you when we collected the Personal Data that they may be shared internally and combined with data collected on the Website. We are also working closely with third parties (including, for example, business partners, Applicants, Funders, Fundraisers, sub-contractors, advertising networks, and analytics providers) and may receive information about you from them.
4. USE OF YOUR INFORMATION BY US
4.1 Our legal basis for processing your Personal Data varies depending on the information we obtain, however, for the avoidance of doubt the bases we rely on generally are:
- Legitimate interest – to ensure accessibility by the User to our Website and to further the aims of the Website and The Good Exchange (to connect Fundraisers, Applicants, Funders etc). The Personal Data you provide are necessary to meet these purposes. Some Personal Data (such as photographs of the Users) are not necessary for the use of the Website however this type of Personal Data is not required by The Good Exchange and is instead provided by the User’s choice.
- Consent – we obtain your consent in respect of marketing, advertising and sharing data with our business partners and advertisers. Consent is via opt-ins and you are not required to opt-in to use the Website.
- Compliance with legal obligations – where we are required to obtain and retain data as a not-for-profit or in respect of our financial obligations to HMRC and other authorities we do so under a legal or regulatory obligation.
4.2 We use, store and process Personal Data held about you for the general purposes set out in this clause 4. We will only use your Personal Data when the law allows us to.
4.3 Personal Data which you provide to us when registering on the Website or when setting up a Profile, making a Donation, applying for Funding, providing Funding or when communicating with other Users on the Website (including Personal Data you provide to us as an administrator or contact for an incorporated or unincorporated organisation) may be publicly available on the Website. Where a User has an individual profile on the Website they will be given the option to make that profile public (whereby all information you have inputted will be publicly available) or maintain a private profile. If a Funder or Fundraiser seeks information about an Applicant in order to consider whether or not to fund that Applicant, then the Funder or Fundraiser will have access to the profile of the Applicant, which may contain Personal Data. Further details about what information will be publicly available on the Website and your preferences in relation to this can be found at our support website.
4.4 Personal Data you give to us
Legal and Regulatory Requirements – We will use any payment and financial details that you provide to us in order to meet the legal and regulatory requirements imposed on us, including by HMRC in respect of VAT and Gift Aid.
Legitimate Interest – We have a legitimate interest in processing and storing your Personal Data such as your name, email address, address and phone number in that these Personal Data enable you to access, register and use the Website. In addition, these Personal Data permit us to notify you about changes to the Website, allow you to communicate with other Users on the Website and ensure that the content from the Website is presented in the most effective manner for you and your computer.
Marketing – Your Personal Data will only be processed for marketing purposes where we have obtained your consent to that processing. If you give your consent to that processing, then we may provide you, or permit third parties to provide you, with marketing, advertising and promotional information about services we feel may interest you.. If you decide that you do not want us to use your data in this way please let us know by emailing us at email@example.com
Personalisation – You are able to personalise your profile (including by using a photograph or personal description). These are not Personal Data that we require to allow you to use the Website, and we would ask that you think carefully before making this information publicly available. As explained above at Paragraph 4.3 where you have a personal profile you have the option to make this publicly available or to maintain a private profile. By opting to make your profile public you will be allowing all Users of the website to view your preferences and other Personal Data you have made available on that profile. However, by also providing these additional Personal Data you enable us to enhance your experience of the Website by personalising those charitable projects and or fundraising opportunities we believe may be of most interest to you.
4.5 Personal Data we collect about you
We will use these Personal Data:
- to administer the Website and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes;
- to improve the Website to ensure that content is presented in the most effective manner for you and for your computer;
- to allow you to participate in Interactive Services, when you choose to do so;
- as part of our efforts to keep the Website safe and secure;
- to measure or understand the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you;
- to make suggestions and recommendations to you and other Users about goods or services that may interest you or them.
4.6 Personal Data we receive from other sources
We may combine these Personal Data with Personal Data you give to us and Personal Data we collect about you. We may use these Personal Data and the combined Personal Data for the purposes set out above (depending on the types of Personal Data we receive).
5. DISCLOSURE OF YOUR PERSONAL INFORMATION
5.1 We may share your Personal Data with any member of our group, which means our subsidiaries, our ultimate parent company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006.
5.2 We may share your Personal Data with selected third parties including but not limited to:
5.2.1 business partners;
5.2.2 advertisers and advertising networks that require the data to select and serve relevant adverts to you and others; and
5.2.3 analytics and search engine providers that assist us in the improvement and optimisation of the Website.
5.3 Any Personal Data that we have collected about you will be shared with Applicants, Funders and Fundraisers for the following purposes:
5.3.1 your Personal Data will be shared with Applicants in order that each Applicant can be aware of the source of Donations and Funding given to them via the Website where you have opted in to provide such Personal Data (for example, your name) at the point of Donation; so that each Applicant knows who is fundraising on its behalf. The Personal Data which will be provided to the Applicant in such circumstances will only be those Personal Data that you have entered yourself when you have made the Donation, and we will not provide the Applicant with any of the Personal Data that we hold about you. Where you have provided these Personal Data they may be retained by the Applicant for their internal records and for the purpose of progressing funding and fundraising arrangements. You are not required to provide your name and can choose to donate anonymously;
5.3.2 an Applicant’s Personal Data will be shared with Funders so they can make informed decisions about which Applicant or Project to provide Funding to; to provide the Personal Data required for each Funder’s internal records and so the Funder can contact the Applicant for the purpose of progressing funding arrangements; and
5.3.3 your Personal Data will be shared with Fundraisers so that each Fundraiser is aware of the source of Donations and/or Funding raised by them via the Website where you have opted in to provide such Personal Data (for example, your name) at the point of Donation; The Personal Data which will be provided to the Applicant in such circumstances will only be those Personal Data that you have entered yourself when you have made the Donation, and we will not provide the Applicant with any of the Personal Data that we hold about you. Where you have provided these Personal Data they may be retained and processed by the Fundraiser so it can make informed decisions about which Applicant or Project to support; for each Fundraiser’s internal records; and for the purpose of progressing fundraising arrangements. You are not required to provide your name and can choose to donate anonymously;
5.4 We only share your Personal Data with the following third parties where we have your consent:
- marketing companies and other marketing bodies; and
- advertisers and advertising networks.
5.5 We share your Personal Data with the following third parties to pursue a legitimate interest:
- analytics and search engine provides – to assist in the improvement and optimisation of the Website. Please note that where possible data will be anonymised;
- potential purchasers or sellers of assets or business where the personal data is necessary to further the transaction or required to be transferred to that third party as part of that transaction; and
- Applicants, Funders and/or Fundraisers
5.6 We may also disclose your Personal Data to third parties:
5.6.1 in the event that we sell or buy any business or assets, in which case we may disclose your Personal Data to the prospective seller or buyer of such business or assets;
5.6.2 if the Website or if we (or our parent company) or substantially all of our assets (or substantially all of the assets of our parent company) are acquired by a third party, in which case Personal Data held by us or our parent company about the Users will be one of the transferred assets; or
5.6 We may be required to share your Personal Data with our web-developer and server host in order to maintain the Website. Where we do so we require these partners to ensure they have appropriate data protection measures in place in terms of both web security and organisational and other technical measures. Where such data is shared with web-developers and/or server hosts we only provide Personal Data which is necessary to do so on the basis that we have a legitimate interest in sharing those Personal Data, namely to maintain and support the Website thereby furthering the purposes of The Good Exchange.
5.6 When we disclose your Personal Data to Applicants and/or Funders and/or Fundraisers we are not in any way responsible for that Applicant’s, Funder’s or Fundraiser’s use of your Personal Data. Each Applicant, Funder and/or Fundraiser will be responsible for your data under the Privacy Laws and may have their own privacy or data protection policy. You should familiarise yourself with any privacy or data protection policy of that Applicant, Funder and Fundraiser. We do not accept any liability or responsibility for those policies.
5.7 When we disclose your Personal Data to third parties (who are not Applicants, Funders or Fundraisers) we require that they respect the security of your Personal Data and to treat it in accordance with the law.
6. WHERE WE STORE YOUR PERSONAL DATA
6.1 All of the Personal Data that we hold about you will be stored on our secure servers which are situated within England. However the Personal Data that we collect from you may in addition and in some circumstances be transferred to, and stored or processed by a third party situated outside the European Economic Area (“EEA”), including the USA, particularly where any third party platform that we use is situated outside the EEA.
6.3 The third parties referred to in clause 6.1 may be engaged in, among other things, the fulfilment of your donation and/or payment, the processing of your payment details and the provision of support services. By submitting your Personal Data, you agree to this transfer, storing or processing.
6.4 We have implemented appropriate technical and organisational measures to ensure your Personal Data are secure. Where we have given you (or where you have chosen) a password which enables you to access certain parts of the Website, you are responsible for keeping this password confidential. We ask you not to share that password with anyone.
6.5 Unfortunately, the transmission of information via the internet is not completely secure. Although we will use all reasonable endeavours to protect your Personal Data, we cannot guarantee the security of your data transmitted to the Website; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
6.6 We are not responsible for any Personal Data which you give to any other User on the Website. Such Users may have their own privacy or data protection policies and we recommend you familiarise yourself with these where available.
6.7 Any payment transactions will be encrypted by our third party payment provider using SSL technology.
7. YOUR PROFILE
7.1 If you are an individual accessing the Website as a Fundraiser or on behalf of a Funder or Applicant, any public profile on the Website to which you contribute will include some Personal Data such as your fundraising or funding history and experience, how much money you have raised or donated in the past and the types of Projects with which you are usually involved.
7.2 All or part of a Profile (which contains Personal Data) may be displayed in other parts of the Website to other Users.
7.3 The Website may allow part or all of any Profile to be included and accessible via third party search engines. In this case, your Personal Data which is provided publicly on that Profile may be published in search results.
8. YOUR RIGHTS
8.1 You have the right to ask us not to process your Personal Data for marketing purposes. You will be given the option of opting in to the receive marketing materials from us and where we would like to disclose your details to third parties for marketing purposes. Where you do not wish to be contacted for marketing purposes you do not need to opt in to receive those materials to be able to use the Website. You can also exercise the right to not receive marketing materials at any time by contacting us at thegoodexchange.com/contact or at firstname.lastname@example.org.
8.2 You can request that we correct any mistakes in your Personal Data which we hold, require the erasure of Personal Data (in certain situations) and raise any concerns you have about the way we use or store your Personal Data.
8.3 The Privacy Laws also gives you the right to access Personal Data held about you. Your right of access can be exercised in accordance with the Privacy Laws. We will generally not charge a fee for providing you with this information, however, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.
When you make such a request to us we may need to request specific information from you to help us to confirm your identity and to ensure your right to access your Personal Data (or to exercise any other rights) as a security measure.
8.4 The Website may, from time to time, contain links to and from third party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any Personal Data to these websites.
8.5 You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
9. COOKIES AND OTHER TRACKING TECHNOLOGIES
10. COLLECTION AND PROCESSING OF INFORMATION BY APPLICANTS, FUNDERS AND FUNDRAISERS
10.1 This clause 10 will apply to you if you are an Applicant, Funder or Fundraiser. This clause 10 will not apply to you if you are a Supporter.
10.2 When we provide you, as an Applicant, Funder or Fundraiser, with Personal Data that we have collected via the Website or otherwise for the purposes of facilitating a funding or fundraising arrangement or facilitating communication between you and another User, you may become a data controller of such Personal Data for the purposes of the Privacy Laws. You will be solely responsible for your compliance with the Privacy Laws in relation to any Personal Data that we have provided to you for the purposes of facilitating a funding or fundraising arrangement or facilitating communication between you and another User.
10.3 Without prejudice to clause 10.2 above, if you are an Applicant, Funder or Fundraiser and your use of the Website including any Profile that you have registered on the Website results in access to another person’s Personal Data you warrant that you will:
10.3.1 assist us with our responsibilities as a data controller under the Privacy Laws;
10.3.2 not do, cause or permit anything to be done which may result in a breach by us of the Privacy Laws and comply with all requests from us relating to the processing by you of such Personal Data;
10.3.3 comply with the Privacy Laws in respect of your collection, use, disclosure or processing of any Personal Data;
10.3.4 abide by the lawful instructions of all data subjects in respect of their Personal Data and not do anything to compromise the security of such Personal Data;
10.3.5 not sell, or otherwise disclose Personal Data to third parties;
10.3.6 hold the Personal Data securely and not disclose them to anyone other than us, as agreed to by the data subject and/or as permitted by the Privacy Laws;
10.3.7 implement adequate security, technical and organisational measures against all unauthorised, unlawful or accidental access, processing, use, erasure, loss or destruction of, or damage to, Personal Data in accordance with Privacy Laws, and abide by our requirements to ensure the security of the Personal Data as notified to you from time to time;
10.3.9 not retain any Personal Data for longer than is necessary; and
10.3.10 to the extent legally permissible, you will indemnify and hold us harmless, and our successors and assignees, from and against any and all claims, injuries, damages, costs, losses or legal action, arising out of or caused by your breach of this clause.
11. How long we store your Personal Data
11.1 We will only retain your Personal Data for as long as necessary to fulfil the purposes for which we collected them, including for the purposes of satisfying any legal, accounting or reporting requirements.
11.2 To determine the appropriate retention period for your Personal Data, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable requirements.
11.3 By way of example we will keep a record of all donations, which are eligible for and have exercised Gift Aid for a period of 7 years in accordance with HMRC rules and regulations.
11.4 Where you have confirmed to us that you do not wish to be contacted by us it will be necessary for us to retain some basic Personal Data so that we can ensure that materials are not sent to you in the future.
11.4 If you would like further information as to how long we will retain your personal information please contact us using the contact details below.
12. CONTACT DETAILS
The Good Exchange,
Greenham Business Park,