Privacy Notice
The Parochial Church Council (PCC) of St Ebbe’s Church, Oxford and The Rector of St Ebbe’s Church, Oxford
St Ebbe’s Church counts it a privilege and serious responsibility to hold your personal information. We are committed to ensuring your privacy is respected, and that we comply with both the letter and spirit of all applicable laws, as is our Christian duty. We will do all we can to protect your privacy and to ensure that any personal information you share with us is stored securely and is only used in a manner that you have consented to or would expect. We will never sell information about you.
This notice tells you what information we collect, how we use and share the information, what your rights are, and finally, how you can contact us with questions or concerns.
1. Your personal data – what is it?
Personal data relates to a living individual who can be identified from that data. Identification can be by the information alone or in conjunction with any other information in a data controller’s possession or likely to come into such possession. The processing of personal data is governed by the General Data Protection Regulation (the “GDPR”) and related regulations.
2. Who are we?
The PCC and Rector of St Ebbe’s Church, Oxford are each data controllers (contact details below). This means they decide how your personal data is processed and for what purposes.
3. How do we process your personal data?
The PCC and the Rector of St Ebbe’s Church, Oxford comply with their obligations under the “GDPR” by keeping personal data up to date; by storing and destroying it securely; by not collecting or retaining excessive amounts of data; by protecting personal data from loss, misuse, unauthorised access and disclosure and by ensuring that appropriate technical measures are in place to protect personal data.
We use your personal data for the following purposes:
- To administer membership of groups and committees;
- To provide pastoral care to our parishioners and members;
- To manage our employees and volunteers;
- To maintain our own accounts and records (including the processing of gift aid applications);
- To inform you of news, events, activities and services running at St Ebbe’s and elsewhere that we consider may be of interest to you;
- To operate the St Ebbe’s Church website and deliver services that individuals have requested;
- To fundraise and promote the interests of St Ebbe’s and charitable causes we support;
- To exercise statutory, governmental or other public functions, e.g. the registering of marriages, administering the Electoral Roll;
- To enable us to provide services for the benefit of parishioners and others in the local area.
4. What is the legal basis for processing your personal data?
We may process your personal data according any of the following permissible reasons:
- Where processing is necessary for carrying out our obligations under employment, social security or social protection law, or statutory obligations (e.g. for Gift Aid purposes);
- As a not-for-profit body with a religious aim provided:
- the processing relates only to members or former members (or those who have regular contact with it in connection with those purposes); and
- there is no disclosure to a third party without consent.
- We have received your explicit consent so that we can keep you informed about news, events, activities and services, or to be a registered user of our ChurchSuite church family database.
- Where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
5. Sharing your personal data
Your personal data will be treated as strictly confidential and will only be shared with other members of the church in order to carry out a service to other church members or for purposes connected with the church. Unless we receive your consent, your information will never be passed to other organisations except where this is considered necessary for our own operations (e.g. for payroll, data storage, mailings etc.). In such instances there are confidentiality agreements in place that restrict the use of your information to the purpose for which it is provided and ensure it is stored securely and kept no longer than necessary.
6. How long do we keep your personal data?
We keep data in accordance with the guidance set out in the guide ‘Keep or Bin: Care of Your Parish Records‘ which is available from the Church of England website. (Details about retention periods can currently be found in the Record Management Guides located on the Church of England website.)
Specifically, we retain electoral roll data while it is still current; gift aid declarations and associated paperwork for up to 6 years after the calendar year to which they relate; safeguarding records for up to 50 years; and parish registers (baptisms, marriages, funerals) permanently.
7. Your rights and your personal data
Unless subject to an exemption under the GDPR, you have the following rights with respect to your personal data:
- The right to request a copy of your personal data which the Rector or PCC of St Ebbe’s, Oxford holds about you;
- The right to request that we correct any personal data if it is found to be inaccurate or out of date;
- The right to request your personal data is erased where it is no longer necessary for us to retain such data;
- The right to withdraw your consent to the processing at any time;
- The right to request that the data controller provide the data subject with his/her personal data and where possible, to transmit that data directly to another data controller (known as the right to data portability), where applicable.
- The right, where there is a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing;
- The right to object to the processing of personal data (where applicable).
- The right to lodge a complaint with the Information Commissioners Office.
8. Further processing
If we wish to use your personal data for a new purpose, not covered by this Data Protection Notice, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, we will seek your prior consent to the new processing.
9. Contact Details
To exercise all relevant rights, queries or complaints please in the first instance contact the Operations Manager, via office@stebbes.org, or 2 Roger Bacon Lane, Oxford, OX1 1QE, or 01865 240438.
You can contact the Information Commissioners Office on 0303 123 1113 or via email or at the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire. SK9 5AF.
10. Cookies
We use cookies on our website. By using our website you agree to this Policy and you consent to our use of cookies in accordance with the terms of this Policy.
ABOUT COOKIES
A cookie is a small file which asks permission to be placed on your computer’s hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.
There are two main kinds of cookies: “session” cookies and “persistent” cookies. Session cookies only last for the duration of users using the website and are deleted from your computer when you close your browser, whereas persistent cookies outlast user sessions and remain stored on your computer until deleted, or until they reach their expiry date.
COOKIES ON THIS WEBSITE
We use both Session Cookie and Persistent Cookies on this website.
Generally, we use cookies to help us administer this website, to improve the website’s usability and for marketing purposes. We may also use cookies to identify which pages are being used. This helps us analyse data about webpage traffic and improve our website in order to tailor it to user needs. We only use this information for statistical analysis purposes and then the data is removed from the system.
Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not.
Cookies do not contain any information that personally identifies you, a cookie in no way gives us access to your computer or any information about you.
You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website.
Cookie Name | Cookie Category | Description | Duration |
wordpress_ | 2 | WordPress cookie for a logged in user. | session |
wordpress_logged_in_ | 2 | WordPress cookie for a logged in user | session |
wordpress_test_ | 2 | WordPress cookie for a logged in user | session |
wordpress_test_cookie | 2 | WordPress test cookie | session |
wp-settings- | 1 | WordPress also sets a few wp-settings-[UID] cookies. The number on the end is your individual user ID from the users database table. This is used to customize your view of admin interface, and possibly also the main site interface. | 1 year |
wp-settings-time- | 2 | WordPress also sets a few wp-settings-{time}-[UID] cookies. The number on the end is your individual user ID from the users database table. This is used to customize your view of admin interface, and possibly also the main site interface. | 1 year |
PHPSESSID | 1 | To identify your unique session on the website | session |
SESS | 1 | To ensure that you are recognised when you move from page to page within the site and that any information you have entered is remembered. | session |
__utma | 2 | This cookie keeps track of the number of times a visitor has been to the site pertaining to the cookie, when their first visit was, and when their last visit occurred. Google Analytics uses the information from this cookie to calculate things like Days and Visits to purchase. | permanent |
__utmb | 2 | __utmb is a Google Analytics cookie. It takes a timestamp of the exact moment in time when a visitor enters a site. | session |
__utmc | 2 | __utmc takes a timestamp of the exact moment in time when a visitor leaves a site. | 30 mins |
__utmz | 2 | Keeps track of where the visitor came from, what search engine you used, what link you clicked on, what keyword you used, and where they were in the world when you accessed a website. This cookie is how Google Analytics knows to whom and to what source / medium / keyword to assign the credit for a Goal Conversion or an Ecommerce Transaction. | 6 months |
THIRD PARTY COOKIES
We also use third party cookies to analyse the use of this website and improve its performance.
For this purpose we use Google Analytics. Google Analytics generates statistical and other information about website use by means of cookies, which are stored on users’ computers. The information generated relating to our website is used to create reports about the use of the website. Google will store and use this information. Read Google’s privacy policy. Find out more about Google Analytics opt out.
Most browsers allow you to reject all cookies, whilst some browsers allow you to reject just third party cookies.