Privacy Policy


1. INTRODUCTION

EPI is committed to protecting your privacy and security. This policy explains how and why we use your personal data, to ensure you remain informed and in control of your information.

You can decide not to receive communications or change how we contact you at any time. If you wish to do so please contact us by emailing info@epi.org.uk, writing to 6th Floor, 27 Queen Anne’s Gate, London SW1H 9BU or telephoning 020 7340 1160 (Lines open 9am – 5pm, Mon – Fri).

We will never sell your personal data, and will only ever share it with organisations we work with where necessary and if its privacy and security are guaranteed.

Questions?

Any questions you have in relation to this policy or how we use your personal data should be sent to info@epi.org.uk for the attention of EPI’s Deputy Head of Research.


2. ABOUT US

Your personal data (i.e. any information which identifies you, or which can be identified as relating to you personally) will be collected and used by the Education Policy Institute (charity no: 1102186,  company registration no: 4579498)


3. THE INFORMATION WE COLLECT

Personal data you provide

We collect data you provide to us. This includes information you give when joining as a member or signing up to our newsletter, placing an order or communicating with us. For example:

·         personal details (name, job title, organisation and email) when you sign up to our newsletter. This also includes address and telephone when you join as a member or supporter;

·         financial information (payment information such as credit/debit card or direct debit details, and whether memberships are gift-aided. Please see section 8 for more information on payment security); and

·         details of EPI events you have attended.

Sensitive personal data

We do not normally collect or store sensitive personal data (such as information relating to health, beliefs or political affiliation) about members and those signed up to EPI’s newsletter. However there are some situations where this will occur (e.g. if you have an accident on one of our events). If this does occur, we’ll take extra care to ensure your privacy rights are protected.

Accidents or incidents

If an accident or incident occurs on our property, at one of our events or involving one of our staff then we’ll keep a record of this (which may include personal data and sensitive personal data).


4. HOW WE USE INFORMATION

We only ever use your personal data with your consent, or where it is necessary in order to:

·         enter into, or perform, a contract with you;

·         comply with a legal duty;

·         protect your vital interests;

·         for our own (or a third party’s) lawful interests, provided your rights don’t override the these.

In any event, we’ll only use your information for the purpose or purposes it was collected for (or else for closely related purposes)

Administration

We use personal data for administrative purposes (i.e. on our research and events programmes). This includes:

·         receiving membership subscriptions (e.g. direct debits or gift-aid instructions);

·         maintaining databases of our members and those signed up to our newsletter;

·         fulfilling orders for goods or services (whether placed online, over the phone or in person);

·         helping us respect your choices and preferences (e.g. if you ask not to receive marketing material, we’ll keep a record of this).


5. DISCLOSING AND SHARING DATA

Your personal data – which include your name, organisation, and email address are held by our mailing list provider. By signing up to our newsletter you are agreeing to the terms and conditions of MailChimp.com (http://mailchimp.com/legal/terms/). This information is not shared with any other organisation. If you wish to unsubscribe from our mailing list at any time, you can do so by clicking the ‘unsubscribe’ link, found at the bottom of any email we send you – or by sending your name and email address to info@epi.org.uk– stating ‘Unsubscribe’ in the email in the subject line or body of the email.

Occasionally, where we partner with other organisations, we may also share information with them (for example, if you register to attend an event being jointly organised by us and another charity). We’ll only share information when necessary and we will never share your contact information (eg. email or telephone).


6. MARKETING

From 9 March 2018, EPI will ask for individuals to “opt-in” for most communications. This includes all our marketing communications (the term marketing is broadly defined and covers information shared in our newsletter.)

We use personal data to communicate with people, to promote EPI and to help with fundraising. This includes keeping you up to date with information from EPI on our research, events, news, job opportunities and other information relating to our work.

You can decide not to receive communications or change how we contact you at any time. If you wish to do so please contact us by emailing info@epi.org.uk, writing to 6th Floor, 27 Queen Anne’s Gate, London SW1H 9BU or telephoning 020 7340 1160 (Lines open 9am – 5pm, Mon – Fri).

What does ‘marketing’ mean?

Marketing does not just mean offering things for sale, but also includes news and information about:

·         our research programme, including details of recent reports or blogs;

·         our events and activities; and

·         job opportunities.

When you receive a communication, we may collect information about you respond to or interact with that communication, and this may affect how we communicate with you in future.


7. HOW WE PROTECT DATA

We employ a variety of physical and technical measures to keep your data safe and to prevent unauthorised access to, or use or disclosure of your personal information. 

Electronic data and databases are stored on secure computer systems and we control who has access to information (using both physical and electronic means). Our staff receive data protection training and we have a set of detailed data protection procedures which personnel are required to follow when handling personal data.

Payment security

All electronic EPI forms that request financial data use pass your details to our payment provider (Stripe Payments Europe: https://stripe.com/gb/privacyhttps://stripe.com/privacy-shield-policy). EPI complies with the payment card industry data security standard (PCI-DSS) published by the PCI Security Standards Council, and will never store card details. If you would rather make a payment through BACS or by cheque please contact us by emailing info@epi.org.uk, writing to 6th Floor, 27 Queen Anne’s Gate, London SW1H 9BU or telephoning 020 7340 1160 (Lines open 9am – 5pm, Mon – Fri).

Of course, we cannot guarantee the security of your home computer or the internet, and any online communications (e.g. information provided by email or our website) are at the user’s own risk.


8. STORAGE

Where we store information

EPI’s operations are based in England and we store our data within the European Union.

How long we store information

We will only use and store information for so long as it is required for the purposes it was collected for. How long information will be stored for depends on the information in question and what it is being used for. For example, if you ask us not to send you marketing emails, we will stop storing your emails for marketing purposes (though we’ll keep a record of your preference not to be emailed).

We continually review what information we hold and delete what is no longer required. We never store payment card information.


9. KEEPING YOU IN CONTROL

We want to ensure you remain in control of your personal data. Part of this is making sure you understand your legal rights, which are as follows:

·         the right to confirmation as to whether or not we have your personal data and, if we do, to obtain a copy of the personal information we hold (this is known as subject access request);

·         the right to have your data erased (though this will not apply where it is necessary for us to continue to use the data for a lawful reason);

·         the right to have inaccurate data rectified;

·         the right to object to your data being used for marketing or profiling; and

·         where technically feasible, you have the right to personal data you have provided to us which we process automatically on the basis of your consent or the performance of a contract. This information will be provided in a common electronic format.

Please keep in mind that there are exceptions to the rights above and, though we will always try to respond to your satisfaction, there may be situations where we are unable to do so.

If you would like further information on your rights or wish to exercise them, please write to EPI’s Deputy Head of Research at to 6th Floor, 27 Queen Anne’s Gate, London SW1H 9BU or email to info@epi.org.uk for the attention of EPI’s Deputy Head of Research.

Complaints

You can complain to EPI directly by contacting our Deputy Head of Research using the details set out above.

If you are not happy with our response, or you believe that your data protection or privacy rights have been infringed, you can complain to the UK Information Commissioner’s Office which regulates and enforces data protection law in the UK. Details of how to do this can be found at www.ico.org.uk


10. COOKIES AND LINKS TO OTHER SITES

Cookies

We use cookies on our website. Cookies files are downloaded to a device when certain websites are accessed by users, allowing the website to identify that user on subsequent visits.

The only cookies in use on our site are for Google Analytics. Google Analytics is tool employed by organisations to help them understand how visitors engage with their website, so improvements can be made. Google Analytics collects information anonymously – and reports overall trends, without disclosing information on individual visitors. By using our site you are consenting to saving and sending us this data. You can opt out of Google Analytics – which will not affect how you visit our site. Further information on this can be found here: https://tools.google.com/dlpage/gaoptout

Our website uses local storage strictly for system administration to provide you with the best possible experience – used in order to create reports relating to web traffic and user preferences. This includes: your IP address; details of which web browser or operating system was used; and information on how you use the site.

Links to other sites

Our website contains hyperlinks to many other websites. We are not responsible for the content or functionality of any of those external websites (but please let us know if a link is not working by using the ‘Contact’ link at the top of the page).

If an external website requests personal information from you (e.g. in connection with an order for goods or services), the information you provide will not be covered by the EPI’s Privacy Policy. We suggest you read the privacy policy of any website before providing any personal information.


11. CHANGES TO THIS PRIVACY POLICY

We’ll amend this Privacy Policy from time to time to ensure it remains up-to-date and accurately reflects how and why we use your personal data. The current version of our Privacy Policy will always be posted on our website.

This Privacy Policy was last updated on 08.03.2018