GDPR Data Protection Privacy Notice for Bapio members
Data protection privacy notice for Bapio members
This notice explains what personal data (information) we will hold about you, how we collect it, and how we will use and may share information about you during your membership with Bapio. We are required to notify you of this information, under data protection legislation. Please ensure that you read this notice (sometimes referred to as a ‘privacy notice’) and any other similar notice we may provide to you from time to time when we collect or process personal information about you.
Who collects the information
Bapio Limited trading as Bapio (‘Company’) is a ‘data controller’ and gathers and uses certain information about you.
Data protection principles
We will comply with the data protection principles when gathering and using personal information.
We may collect the following information up to and including the commencement of your membership with Bapio:
- Your name and contact details (i.e. address, home and mobile phone numbers, email address);
- Your nationality
- Details of your qualifications and employment (including job titles), and interests;
- Financial information
How we collect the information
We may collect this information from you and any other relevant professional body.
Why we collect the information and how we use it
We will typically collect and use this information for the following purposes:
- To process your membership with Bapio
- To keep in touch with you in relation to your Bapio membership
- To offer you the benefits of your Bapio membership
- For the purposes of our legitimate interests, but only if these are not overridden by your interests, rights or freedoms.
We seek to ensure that our information collection and processing is always proportionate. We will notify you of any changes to information we collect or to the purposes for which we collect and process it.
How we may share the information
We may also need to share some of the above categories of personal information with other parties, such as Bapio professional advisers, Bapio business and organisational support, any third party instructed on your behalf. Usually, information will be anonymised, but this may not always be possible. The recipient of the information will be bound by confidentiality obligations. We may also be required to share some personal information as required to comply with the law.
Sensitive personal information and criminal records information
Further details on how we handle sensitive personal information and information relating to criminal convictions and offences are set out in our policy, available from the Bapio membership team.
Where information may be held
Information may be held at our offices, and third-party agencies, service providers, representatives and agents as described above.
How long we keep your information
We keep the personal information that we obtain about you during the membership application process for no longer than is necessary for the purposes for which it is processed. How long we keep your information will depend on whether your application is successful, the nature of the information concerned and the purposes for which it is processed.
We will keep membership information for no longer than is reasonable, considering the limitation periods for potential claims such as discrimination (as extended to take account of early conciliation), after which they will be destroyed. If there is a clear business reason for keeping membership records for longer than the membership application period, we may do so but will first consider whether the records can be pseudonymised, and the longer period for which they will be kept.
If your application is successful, we will keep only the membership information that is necessary in relation to your membership for the duration of your membership.
Further details on our approach to information retention and destruction are available from the Bapio membership team.
Your rights to correct and access your information and to ask for it to be erased
Please contact our Data Protection Officer (DPO), who can be contacted via email at firstname.lastname@example.org and on 01234 363272 if (in accordance with applicable law) you would like to correct or request access to information that we hold relating to you or if you have any questions about this notice. You also have the right to ask our Data Protection Officer for some but not all the information we hold and process to be erased (the ‘right to be forgotten’) in certain circumstances. Our Data Protection Officer will provide you with further information about the right to be forgotten, if you ask for it.
Keeping your personal information secure
We have appropriate security measures in place to prevent personal information from being accidentally lost or used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
How to complain
We hope that our Data Protection Officer can resolve any query or concern you raise about our use of your information. If not, contact the Information Commissioner at https://ico.org.uk/concerns/ or telephone: 0303 123 1113 for further information about your rights and how to make a formal complaint.