Legal

Data policy

Mac Recycle is committed to transparency about how we collect and use personal data, and how we meet our data protection obligations. This statement explains how we ("we", "us", "our") handle and use personal data we collect about past, current and prospective clients, supporters, partners, volunteers, job applicants and employees ("you", "your").

Last updated 4 July 2026

1

About this statement

Mac Recycle is committed to transparency about how we collect and use personal data and how we meet our data protection obligations.

This statement explains how Mac Recycle ("we", "us", "our") handles and uses personal data we collect about past, current and prospective:

  • clients and non-enrolled clients
  • supporters, donors and trust funders
  • referral partners and corporate partners
  • volunteers
  • job applicants, workers, contractors, interns/students, employees and former employees (collectively, "you", "your").

In broad terms, we use personal data to:

  • tailor support to our clients and inform current and future delivery practice; and
  • update you on our activities and developments, and identify ways you can support us (financially and non-financially).

Mac Recycle acts as a Data Controller for most processing described in this statement, and may also act as a Data Processor where we process personal data on documented instructions from another controller, for example within a consortium arrangement.

2

Data protection principles

Mac Recycle processes personal data in accordance with the following principles:

  • Lawfulness, fairness and transparency.
  • Purpose limitation, for specified, explicit and legitimate purposes.
  • Data minimisation, keeping data adequate, relevant and necessary.
  • Accuracy, keeping data up to date and rectifying inaccuracies without delay.
  • Storage limitation, keeping data no longer than necessary.
  • Integrity and confidentiality, with security against unauthorised or unlawful processing, loss, destruction or damage.
  • We explain our purposes, uses and lawful bases in privacy notices, and do not process for incompatible purposes.
  • We update personal data promptly where you inform us it has changed or is inaccurate.
  • Staff and volunteers sign confidentiality agreements on joining.
  • We maintain records of processing activities as required under UK GDPR.
3

Key definitions

  • Personal data. Information relating to an identifiable individual, directly or indirectly.
  • Processing. Any operation on personal data, including collecting, storing, using, disclosing and deleting it.
  • Data Controller. Decides the purposes and means of processing personal data.
  • Data Processor. Processes personal data on behalf of a controller.
  • Special category data. Includes racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, and biometric data.
  • Criminal records data. Criminal convictions or offences and related allegations or proceedings.
4

Categories of individuals

For programme delivery, we categorise individuals as:

  • Clients. Beneficiaries of Mac Recycle programmes.
  • Contacts. Non-service users involved in Mac Recycle activities, for example trusts and foundations, corporate partners, referral partners, newsletter recipients and volunteers.
  • Non-enrolled clients. Potential clients whose details are held prior to their initial appointment.
5

Lawful bases for processing

We rely on one or more of the following lawful bases, depending on the context:

  • Consent, where explicit consent is provided.
  • Contract, where processing is necessary for a contract with you, or steps prior to entering a contract.
  • Legitimate interests, where our legitimate interests are not overridden by your rights and freedoms.

Where we process special category data or criminal records data in an HR context, we do so only where necessary to perform or exercise obligations or rights under employment law, and in line with our internal policy, or where we obtain consent for specific uses such as equality monitoring.

6

Programme data

6.1 How we collect programme data

Clients

  • Data is collected via Kobo Toolbox and Zoho Forms, which are password protected and meet our GDPR and UK GDPR commitments, and sometimes via paper forms.
  • Paper form data may be transferred to a Google Sheet. Hard copies are stored securely at Mac Recycle offices with access restricted to authorised staff.

Consent at collection

Before collecting or storing data, we request consent either verbally, for contact details, or within enrolment questionnaires.

Contacts

  • Contact details for volunteers, referral partners, donors and business supporters may be stored in systems such as Gmail, Dropbox, Mailchimp, Google Docs and Zoho, all password protected and aligned with GDPR and UK GDPR.
  • Newsletter contact details are stored in Mailchimp only with your permission, for example when you sign up.

Non-enrolled clients

Data may be provided by referral partners, who are responsible for obtaining the individual's consent to share, and/or by the individual directly when enquiring.

6.2 Where we store programme data

Programme data may be stored across multiple platforms due to operational needs, including:

  • Kobo Toolbox, Zoho, Dropbox, SharePoint, Google Docs and Sheets, and work computers.
  • Limited hard-copy records stored securely at Mac Recycle offices with restricted access.

6.3 What programme data we hold

Clients

  • Names, contact details and addresses.
  • Unique personal identifiers and background information, for example date of birth, country of origin, gender, religion, sexual orientation, asylum process length, education and employment history, and employer or organisation.
  • Psychological or self-reported information, for example confidence, stress, health and motivation.

Contacts

  • Name and contact details.
  • For volunteers: CV or short bio, whether actively volunteering, and hours, location and availability.
  • Organisation providing employment, where relevant.

Non-enrolled clients

  • Name and referral partner.
  • Short bio where provided, for example English level, date of birth, nationality and interests.
  • Email address and/or phone number.

6.4 How we use programme data

Clients

  • Identify suitable opportunities.
  • Record support provided and suggested next steps.
  • Record outcomes achieved.
  • Evidence reporting to donors or consortium managers.
  • Provide progress updates to referring organisations, where applicable and consented.
  • Brief volunteers supporting clients and share progress updates.
  • Analyse data to inform future programming and performance reporting, internally and externally.
  • Brief corporate partners on workshop attendees, for example CVs or bios, where consented.

Contacts

  • Distribute e-newsletters.
  • Promote events and opportunities.
  • Fundraising appeals and donation requests.
  • Donor stewardship.

Non-enrolled clients

Explain our services and book first appointments.

Communication channels

Communications may be sent by post, telephone, or electronic means.

6.5 Sharing programme data

  • Mac Recycle will not share personal data with third parties without your explicit consent, either at enrolment or later.
  • Clients may consent to sharing information with donors, volunteers, corporate partners and referral partners as part of enrolment.
  • We do not sell personal data to third parties under any circumstances.

6.6 Programme retention periods

Unless you ask us to do otherwise, and subject to legal or operational requirements:

  • Enrolled clients. Retained for 10 years from enrolment. If retained beyond 10 years, data will be anonymised.
  • Contacts. Retained for up to 5 years.
  • Non-enrolled clients. Retained for up to 2 months.
7

Human resources data

7.1 Scope

This section applies to personal data of job applicants and individuals who work with us, including employees, workers, contractors, interns, students and former employees, referred to as "HR-related personal data". It does not apply to programme participant data.

7.2 Why we process HR data

We process HR data to:

  • enter into and administer employment or engagement contracts, for example issuing contracts, payroll and benefits.
  • comply with legal obligations, for example right to work checks, tax, health and safety, and leave entitlements.
  • pursue legitimate business interests, including:
    • recruitment processes and offers.
    • maintaining accurate employment records and emergency contacts.
    • managing contractual and statutory rights.
    • disciplinary and grievance processes.
    • performance management and training needs.
    • absence management and pay and benefits administration.
    • occupational health or medical advice where necessary.
    • managing family leave, including maternity, paternity, adoption, shared parental and parental leave.
    • HR and business administration.
    • providing references on request.
    • responding to and defending legal claims.
    • equality in the workplace.

7.3 How we collect and store HR data

Collection sources

Application forms, CVs, identity documents such as a passport or driving licence, onboarding and employment forms, correspondence, and interviews, meetings and assessments.

Storage locations

  • Online platforms, for example Dropbox, SharePoint and Zoho.
  • Google cloud drives.
  • Digital personnel files on servers and computers.
  • Work laptops and mobile devices used for work purposes.
  • Third-party systems, for example payroll, pensions or benefits providers, accountants and auditors.
  • Hard-copy records held securely, including personnel files and the accident book.

7.4 What HR data we hold

We may collect and process:

  • Name, address, contact details, date of birth and gender.
  • Employment terms and conditions.
  • Qualifications, skills, training and employment history, including dates.
  • Remuneration and benefits, including pensions and salary sacrifice.
  • Bank details and National Insurance number.
  • Marital status, next of kin, dependants and emergency contacts.
  • Family leave information and entitlements.
  • Nationality and right to work in the UK.
  • Criminal record information, where applicable.
  • Working patterns and attendance.
  • Leave records, such as holiday, sickness, family leave and sabbaticals, and reasons.
  • Disciplinary and grievance records.
  • Performance and appraisal records, including improvement plans.
  • Training completed.
  • Health and medical information and disability adjustments, where applicable.
  • Expenses.
  • Equal opportunities monitoring data, such as age, ethnic origin, sexual orientation, health and religion or belief.

7.5 HR data sharing

We may share HR data with third parties where required by law or to meet contractual obligations, including:

  • HMRC and other government bodies.
  • Our payroll provider.
  • Accountants and auditors.
  • Our pension provider.

7.6 Special category data and criminal records data

  • We only process special category data where necessary to perform or exercise employment law obligations or rights, for example disability adjustments.
  • Where we use sensitive personal data for equality monitoring, we will seek consent.

7.7 HR retention

We maintain a register of HR-related personal data and apply retention periods based on purpose, business need and legal obligations. In general:

  • Recruitment records: 6 months after completion of the recruitment exercise.
  • Employee records: retained for the duration of employment.
  • Most ex-employee records: 12 months after employment ends.
  • Right to work records: 2 years post-employment.
  • Salary, bonus and commission records: 7 years after employment ends.
  • Health and safety incident records: 5 years.

7.8 Individual responsibilities

If you have access to others' personal data, you must:

  • access only authorised data for authorised purposes.
  • not disclose it except to appropriately authorised individuals.
  • follow password and secure working requirements, such as screen locking, a clean desk, secure printing, and secure disposal or shredding.
  • avoid using fax for personal data.
  • avoid storing personal data outside designated systems.
  • use appropriate security, such as encryption or password protection, if data must be taken off-site.

Breaches may lead to disciplinary action up to and including dismissal for gross misconduct.

8

Trust fundraising

8.1 Scope and approach

This section reflects Institute of Fundraising guidance on trust fundraising, agreed with the Information Commissioner's Office.

8.2 Personal data used for trust fundraising

Examples include:

  • Email address with contact name.
  • Direct phone or mobile numbers.
  • Correspondent or trustee names.
  • Trustees' and settlors' business dealings, as relevant to philanthropy.
  • Philanthropic activities and interests.
  • Records of contacts and communications stored on our database.

8.3 Lawful basis

  • Consent, where explicit consent is provided.
  • Contract, where there is an explicit contract with a donor.
  • Legitimate interests, for the majority of trust fundraising activity.

Legitimate interests safeguards

  • Contact is limited to post, phone or email, to the funder's stated email address.
  • We record and review legitimate interest considerations per trust record where needed.

8.4 Sources used

  • Trust databases, directories and websites.
  • Charity Commission records.
  • Mac Recycle's existing records.
  • Proportionate online research where required to clarify fit and approach, including the philanthropic behaviour of connected individuals.
  • Research phone calls, ensuring numbers are not listed on the Telephone Preference Service.

8.5 Purpose of research and balancing of interests

We use these sources to understand:

  • Trust interests and eligibility.
  • Potential size and timing of gifts.
  • Best engagement approach.
  • Stewardship and reporting requirements.

We maintain a suppression list for individuals who do not wish to be contacted, including individuals at trusts, noting we may still contact for necessary administrative purposes.

Most personal information obtained is in the public domain.

9

General provisions

This section applies across all processing described in this statement.

9.1 Information security and controls

We implement measures to protect personal data against loss, accidental destruction, misuse, or unauthorised access or disclosure.

Technical measures

  • A strong password policy and account sharing policy.
  • Restricted user access.
  • Only server administrators can set up new IT services or storage areas for personal data.
  • Security reviewed internally every six months.
  • Servers built and configured to standard build instructions.
  • Servers updated monthly.

Organisational measures

  • A Data Security Policy, regularly reviewed.
  • Scam and phishing awareness raised in team meetings.
  • Clean desk and shredding policies.
  • Starter and leaver processes.
  • Confidentiality agreements.
  • GDPR awareness and role-based training.
  • Incident processes for lost devices, hacking, malware and password compromise.
  • Contracts, instructions, confidentiality and security requirements for third-party processors.

9.2 Your rights

Where the lawful basis is consent, you can withdraw consent at any time, and this does not affect processing already carried out. Where we rely on legitimate interests, you may object where your interests override our grounds.

You have rights including:

  • Access, through a subject access request.
  • Rectification.
  • Erasure, the right to be forgotten, in certain circumstances.
  • Restriction of processing in certain circumstances.
  • Objection to processing in certain circumstances.
  • Complaint to the Information Commissioner's Office.

Subject access requests

We normally respond within one month of receipt. If we need more time, we will notify you within one month. If a request is manifestly unfounded or excessive, we may refuse it or charge a reasonable fee based on administrative costs.

9.3 Data disposal

When retention periods expire, or where erasure applies, we dispose of data securely:

  • Electronic data, including backups, is deleted.
  • Hard-copy data is shredded.

Where you opt out of all future communications or request erasure, we may retain a core suppression record, for example name, date of birth, organisation and country of origin, to ensure we do not contact you inadvertently, and to maintain an internal record of enrolment where appropriate. We may also retain certain records where required for statutory purposes.

9.4 Personal data breaches

If a breach poses a risk to individuals' rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of discovery. We will record all breaches. Where a breach is likely to result in a high risk to individuals, we will also inform affected individuals and provide information on likely consequences and mitigation measures.

9.5 International data transfers

Mac Recycle uses Google for documents and storage. Google has confirmed its commitment to GDPR compliance across Google Cloud Platform services. Other than this, Mac Recycle does not transfer personal data outside the EEA.

9.6 Training

All staff and volunteers receive information about data protection responsibilities as part of induction. Roles with regular access to personal data, or responsibility for implementing this policy or responding to subject access requests, receive additional training.

9.7 Policy review and updates

This statement will be reviewed annually in May, and earlier if:

  • Data collection, storage or use methods change materially, or
  • UK data protection regulations change.

An updated version will be published on our website, and significant changes will be communicated to affected parties promptly.

Questions about your data?

If anything here isn't clear, or you'd like to know exactly what we hold about you, get in touch and we'll help.

Contact us