Privacy policy

1. About this policy

This privacy policy explains how SharpFutures Manchester CIC collects, uses, shares, and protects personal data. It applies to:

•  Visitors to our website www.sharpfutures.org.uk;

•  Clients and prospective clients who commission services from us;

•  Members of our POD programme and other programme participants;

•   Business contacts at organisations we work with, market to, or partner with;

•   Suppliers and contractors;

•   Individuals whose personal data we process on behalf of our clients in the course of delivering projects.

This policy does not cover the processing of personal data relating to our employees and workers, which is dealt with in the staff privacy notice issued under our Staff Handbook.

We use the terms “UK GDPR” to mean the United Kingdom General Data Protection Regulation, “DPA 2018” to mean the Data Protection Act 2018, and “PECR” to mean the Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended. References to “we”, “us”, and “our” are to SharpFutures Manchester CIC.

2. Who we are and how to contact us

SharpFutures Manchester CIC is the data controller for the personal data described in this policy.

Our details

• Registered name: SharpFutures Manchester CIC

• Company number: 08153185

• Registered office: The Sharp Project, Thorp Road, Manchester, M40 5BJ

• ICO registration number: ZB456650

Data protection contact

Questions about this policy, requests to exercise your data protection rights, and any other data protection matters should be directed to:

• Email: dataprotection@sharpfutures.org.uk

• Post: Data Protection Contact, SharpFutures Manchester CIC, The Sharp Project, Thorp Road, Manchester, M40 5BJ

We are not required under Article 37 of the UK GDPR to appoint a Data Protection Officer. We have nominated a senior member of the management team to act as our data protection contact and to oversee compliance with data protection law across the organisation.

3. Personal data we collect, and why

We collect different categories of personal data depending on your relationship with us. This section describes each category, the data we collect, where we get it from, what we use it for, and our lawful basis for doing so.

3.1 Website visitors

When you visit our website, we may collect:

• Technical information from your device and browser (including IP address, device type, browser type, operating system, and pages visited);

• Information about how you interact with the website (pages viewed, time spent, referral source, broad geographic region);

• Any information you choose to provide through online forms, enquiries, or newsletter sign-ups.

We use this data to operate, secure, and improve our website, to respond to enquiries, and, where you have consented, to send you our newsletter and other communications. Further information on cookies and analytics is set out in section 9.

Lawful basis: legitimate interests (operating, securing and improving our website, and responding to enquiries); consent for non-essential cookies and electronic marketing under PECR.

3.2 Clients and prospective clients

When you commission services from us, or engage with us about commissioning services, we collect:

• Name, job title, organisation, business address, business email address, and business telephone number;

• Information about the project or services you have engaged us to deliver, including any briefing or background materials you provide;

• Contractual and financial information needed to administer the engagement, including purchase orders, invoices, and payment details;

• Correspondence and notes of meetings, calls, and other interactions.

We use this data to deliver the services we have agreed with you, to manage our relationship with your organisation, to comply with our legal and accounting obligations, and, where appropriate, to keep you informed about other services we offer.

Lawful basis: performance of a contract (or to take steps prior to entering into a contract); legitimate interests (managing client relationships and informing clients about related services); legal obligation (tax, accounting, and other statutory record-keeping).

3.3 POD members and programme participants

Our core mission involves working with adult learners through the POD and our other programmes. Participation in the POD programme and our other programmes is open only to adults aged 18 or over.

The personal data we process about programme participants varies according to the programme and the participant’s circumstances, but may include:

• Name, date of birth, contact details, and emergency contact details;

• Information needed to verify eligibility for a programme, including residency, education status, and employment status;

•  Application materials, portfolios, and work produced during participation;

• Attendance records, training records, and progress reports;

• Equality and diversity monitoring information provided voluntarily on an anonymised basis;

• Information about accessibility requirements, health conditions, or learning needs where the participant chooses to share these in order to receive appropriate support;

• Safeguarding records where a concern is raised or disclosed in relation to an adult at risk;

• Photographs, video, and audio recordings of activities, where the participant has agreed.

We use this data to deliver our programmes, to support participants effectively, to meet our safeguarding responsibilities, to monitor and evaluate the impact of our work for our funders and stakeholders, and to comply with the contractual and reporting obligations that apply to publicly funded programmes.

Lawful basis: performance of a contract or steps prior to entering a contract; legitimate interests in delivering and evaluating our programmes; legal obligation (including safeguarding); public task where we are delivering a publicly funded programme. Where we rely on consent (for example, for photography or for sharing case studies), you can withdraw consent at any time.

Special category data: where we process special category data (including data about health, disability, racial or ethnic origin, religion, or sexual orientation), we rely on Article 9(2)(g) UK GDPR (reasons of substantial public interest, in particular equality of opportunity or treatment, and safeguarding of individuals at risk, under Schedule 1 Part 2 of the DPA 2018), Article 9(2)(b) (employment, social security and social protection law) where relevant to programme delivery, or your explicit consent under Article 9(2)(a).

3.4 Business contacts and prospects

We identify and contact organisations that may be interested in our services. The data we hold typically includes business contact details (name, job title, organisation, business email, business telephone) and notes of our interactions. This data is generally obtained from publicly available business sources, business directories, networking events, referrals, or directly from the individual concerned.

Lawful basis: legitimate interests (developing our business and informing organisations about services that are likely to be relevant to them). We carry out a documented legitimate interests assessment for our business development activity.

Direct marketing (PECR): we send electronic marketing communications to corporate subscribers (companies, limited liability partnerships, public bodies) on the basis of legitimate interests, with a clear and free opt-out in every communication. To individual subscribers (including sole traders and non-LLP partnerships in most cases), and to personal email addresses, we send electronic marketing only with prior consent or where the soft opt-in conditions under PECR are met.

3.5 Third-party data subjects (data we process for clients)

In the course of delivering projects for our clients, we sometimes process personal data about individuals on the client’s behalf (for example, where a client provides us with a contact list or supplies information about its own customers or staff so that we can deliver a project). In that situation, our client is the data controller and we act as a data processor, processing personal data only on the documented instructions of our client and under a written processing agreement that meets the requirements of Article 28 UK GDPR.

If you are a third party whose data has been provided to us by one of our clients, your data protection rights are exercised in the first instance against that client. We will, however, assist our client to respond to any request you make. You can also contact us using the details in section 2.

3.6 Suppliers and contractors

We process contact and contractual information about our suppliers and contractors, including the names, business contact details, and (where applicable) bank details of individuals through whom we deal with supplier organisations. We use this data to manage our supply chain, place and receive deliveries of goods and services, pay invoices, and meet our legal obligations.

Lawful basis: performance of a contract (or steps prior to a contract); legitimate interests (operating our supply chain); legal obligation (tax, accounting, anti-money laundering, and other statutory obligations).

4. Special category data

Some of the personal data we process is “special category data” under Article 9 of the UK GDPR. This includes data revealing racial or ethnic origin, religion or philosophical beliefs, trade union membership, data concerning health, and data concerning a person’s sex life or sexual orientation. We process special category data only where we have both a lawful basis under Article 6 and a separate condition under Article 9. The conditions we rely on are:

• Article 9(2)(a) – explicit consent. Where appropriate (for example, in connection with case studies, accessibility support, or voluntary disclosures of equality information), we rely on explicit consent and you can withdraw that consent at any time.

• Article 9(2)(g) – substantial public interest. We rely on this condition, together with the relevant conditions in Schedule 1 Part 2 of the DPA 2018, for equality of opportunity or treatment monitoring (paragraph 8) and for safeguarding of individuals at risk (paragraph 18).

•  Article 9(2)(b) – employment, social security and social protection law. We rely on this condition where we process special category data in connection with publicly funded programmes that operate under a statutory or quasi-statutory framework.

We maintain an Appropriate Policy Document, as required by Schedule 1 Part 4 of the DPA 2018, setting out our procedures for compliance with the data protection principles when we process special category data and criminal offence data.

5. How we share personal data

We share personal data only where it is necessary to do so for the purposes set out in this policy, and only with recipients who are appropriate and (where they are processors acting on our behalf) bound by a written processing agreement. The recipients we share personal data with include:

•  Our clients, where we are processing data on their behalf, and (with appropriate authority) third parties they ask us to share data with;

•  Approved suppliers and subcontractors, including IT and cloud service providers, professional advisers (including lawyers, accountants, and HR advisers), payroll and payment providers, marketing service providers, training providers, and venue operators, where they need access to personal data in order to provide services to us or to our clients;

• Funders, regulators, auditors, and statutory bodies, where we are required or permitted to share data with them under the contractual or statutory framework that applies to a particular programme;

•  Law enforcement, regulators, and other public authorities, where we are legally required to share data or where we consider sharing is necessary to protect a vital interest, prevent serious harm, or protect the integrity of our organisation;

•  Third parties involved in any actual or proposed reorganisation, merger, sale, or transfer of assets affecting our organisation, subject to appropriate confidentiality safeguards.

We do not sell personal data and we do not share personal data with third parties for their own independent marketing purposes.

6. International transfers

Most personal data that we process is stored on systems located in the United Kingdom or the European Economic Area. Some of the third-party service providers we use (for example, providers of website analytics, email, and cloud storage services) operate platforms that involve transfers of personal data to countries outside the UK, including the United States.

Where we transfer personal data outside the UK to a country that is not the subject of UK adequacy regulations, we put in place one of the safeguards permitted by the UK GDPR. These include the UK International Data Transfer Agreement, the UK Addendum to the European Commission’s Standard Contractual Clauses, or, where applicable, our supplier’s certification under the UK extension to the EU-US Data Privacy Framework. We carry out a transfer risk assessment before relying on these mechanisms.

You can request further information about the safeguards we apply to a particular transfer by contacting us using the details in section 2.

7. How long we keep personal data

We keep personal data only for as long as we need it for the purposes for which it was collected, plus any further period that is necessary to meet our legal, regulatory, or accounting obligations or to manage potential disputes. The table below summarises our standard retention periods. Where a specific contract, funder requirement, or legal obligation requires a different period, that period takes precedence.

  • Category of data

  • Retention period

  • Notes

  • Client engagement records

  • 7 years from end of the engagement

  • Limitation Act / accounting

  • POD and programme participant records

  • 7 years from end of participation, unless a longer period is required by a funder or by safeguarding policy

  • Programme-specific

  • Safeguarding records (adults at risk)

  • 6 years from closure of the concern, or longer where required by a specific funder, regulator, or by safeguarding guidance applicable to the circumstances

  • Safeguarding

  • Equality and diversity monitoring data

  • Aggregated and anonymised at the earliest opportunity; underlying records held for the duration of the relevant programme

  • Anonymised

  • Business development and prospect contact data

  • 3 years from last meaningful engagement, subject to refresh

  • Reviewed annually

  • Marketing consent and opt-out records

  • Retained for as long as needed to evidence compliance with PECR and the UK GDPR; opt-out records retained indefinitely as a suppression record

  • PECR evidence

  • Supplier records

  • 7 years from end of supplier relationship

  • Accounting

  • Website analytics data

  • As set out in section 9 and in our cookie notice

  • See cookie table

  • Records relating to the exercise of data subject rights

  • 3 years from completion of the response

  • Accountability

  • Personal data breach records

  • 6 years from the date the breach is closed

  • Article 33(5) UK GDPR

When the retention period for a record expires, we securely delete electronic data and securely destroy physical records. Where we need to keep some data to evidence the fact that you have asked us to stop processing (for example, on a marketing suppression list), we keep the minimum information required for that purpose.

8. Your rights

You have a number of rights under the UK GDPR in relation to personal data we hold about you. We will respond to a valid request to exercise these rights within one month of receipt. We may extend this period by up to a further two months where a request is complex or where we receive a number of requests from you, and will tell you within the first month if we need to do so.

•  Right to be informed. You have the right to be told what personal data we hold about you, how we use it, and who we share it with. This policy is part of how we meet that duty.

•  Right of access. You have the right to request a copy of the personal data we hold about you and information about how we are using it. There is no charge unless your request is manifestly unfounded or excessive, or you ask for additional copies of the same information.

•  Right to rectification. You can ask us to correct personal data that is inaccurate or incomplete.

•  Right to erasure. In certain circumstances you can ask us to delete personal data we hold about you. This right is not absolute and does not apply where we are required or permitted by law to keep the data.

• Right to restriction of processing. In certain circumstances you can ask us to limit how we use your personal data, for example while we investigate a complaint about its accuracy.

•  Right to data portability. Where we process your personal data by automated means on the basis of your consent or a contract with you, you can ask us to provide it to you (or to a third party you nominate) in a structured, commonly used, machine-readable format.

•  Right to object. You have the right to object to our processing of your personal data where we are relying on legitimate interests. You have an absolute right to object to processing for direct marketing purposes.

•  Rights relating to automated decision-making and profiling. You have the right not to be subject to a decision based solely on automated processing which produces legal or similarly significant effects on you. We do not make decisions of this kind (see section 11).

•  Right to withdraw consent. Where we rely on your consent to process your personal data, you can withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of any processing carried out before you withdrew it.

To exercise any of these rights, please contact us using the details in section 2. We may ask you for information to verify your identity before responding.

9. Cookies and analytics

Cookies are small text files that are placed on your device when you visit a website. We use cookies on our website to make it work, to remember your preferences, and to understand how visitors use the site. The table below describes the cookies we use and their purpose.

We do not place non-essential cookies on your device unless you have given consent through our cookie banner. You can change or withdraw your consent at any time using the cookie settings on the website. You can also control cookies through your browser settings.

  • Cookie / category

  • Purpose

  • Provider

  • Duration

  • Strictly necessary cookies

  • Make the website function (session management, security, load balancing)

  • SharpFutures Manchester CIC

  • Session

  • Cookie consent record

  • Remember your cookie preferences

  • SharpFutures Manchester CIC

  • Up to 12 months

  • Google Analytics (GA4)

  • Analyse how visitors use the website, in aggregate; help us improve content and performance

  • Google LLC (data transfers to the US under the UK extension to the EU-US Data Privacy Framework)

  • Up to 14 months (configurable)

  • Email tracking pixels

  • Measure open and click rates of our email communications

  • Our email service provider

  • Per email campaign

  • Marketing / remarketing cookies

  • Used only where you have given consent; allow us to show relevant advertising to people who have previously visited our site

  • Google Ads and similar providers

  • Up to 12 months

Google Analytics collects information that may include IP addresses (which are truncated before storage), device and browser information, and aggregated information about how visitors use the website. We do not use this information to identify individual visitors. Google’s privacy information is available at policies.google.com/privacy.

10. Direct marketing

We send marketing communications about our work and services to clients, prospects, partners, and people who have asked to hear from us. We always make it easy to opt out, and we keep a record of opt-outs so that we do not contact you again by that channel.

You can opt out of marketing communications at any time by:

•  Clicking the unsubscribe link in any marketing email;

•  Emailing dataprotection@sharpfutures.org.uk or marketing@sharpfutures.org.uk;

• Writing to us at the address in section 2.

Opting out of marketing does not stop us from sending you communications that we are required to send in order to deliver a service to you (for example, information about a programme you are taking part in or about an order you have placed with us).

11. Automated decision-making and profiling

We do not make decisions about you that are based solely on automated processing and that produce legal or similarly significant effects on you. We use website analytics to understand aggregate patterns of website use, but this analysis is not used to make decisions about individuals.

12. How we protect personal data

We have appropriate technical and organisational measures in place to protect personal data against unauthorised access, accidental loss, alteration, and disclosure. These include access controls, encryption in transit and at rest where appropriate, secure premises and storage, staff training on data protection, and contractual safeguards with the suppliers and processors we use.

Where we need to share or store particularly sensitive material (for example, a client data file for a fulfilment project), we apply additional controls including password protection, encrypted storage, restricted access, and secure destruction at the end of the engagement. We document these controls and can provide a summary to clients on request.

13. Personal data breaches

We take any actual or suspected personal data breach seriously. Where we become aware of a breach that is likely to result in a risk to the rights and freedoms of individuals, we will report it to the Information Commissioner’s Office within 72 hours, in line with Article 33 of the UK GDPR. Where the breach is likely to result in a high risk to the rights and freedoms of individuals, we will notify those individuals without undue delay, unless one of the exceptions in Article 34(3) applies.

If you believe that a personal data breach affecting you has occurred and we have not contacted you about it, please get in touch using the details in section 2.

14. Complaints

If you are unhappy with how we have handled your personal data, please contact us first using the details in section 2 so that we have the opportunity to put things right. If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (ICO):

• Website: ico.org.uk

• Helpline: 0303 123 1113

• Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

15. Changes to this policy

We review this policy regularly and may update it from time to time to reflect changes in our processing activities, in the law, or in regulatory guidance. The current version is identified in the footer of this document. Where changes are significant, we will publish notice of them on our website and (where appropriate) contact you directly.

This policy supersedes any previous version of the SharpFutures privacy policy.

A thick, zig-zag doodle shape in a neon green colour