Data Protection Policy updated January 2024
Introduction
The Mindfulness Association (MA) CIC (including its directors, employees, advisors and self-employed contractors) will to the best of its ability adhere to the data protection principles of the Data Protection Act (DPA) which comes into force on 25 May 2018, which are:
- Personal data shall be processed fairly and lawfully.
- Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes.
- Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed.
- Personal data shall be accurate and, where necessary, kept up to date
- Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.
- Personal data shall be processed in accordance with the rights of data subjects under this Act.
- Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.
- Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
Use of personal data
The records we use that contain personal data are hosted by the following DPA compliant software providers:
- Customer Relationship Manager (CRM) software provider ‘Infusionsoft’;
- document storage provider ‘DropBox’;
- Merchant account provider ‘Paypal’;
- and bank account provider ‘Triodos’.
These records are used solely for the purposes of administering course attendance and supporting continued engagement by individuals with the work of the MA. The personal data typically includes name, address, email address, payment card details (not accessible to MA employees), emails sent to individuals via the CRM, courses attended and other engagement with the work of the MA (eg. being a member, on email list, etc.) for the purposes of administering attendance on MA courses and supporting continued engagement with the work of the MA.
Individual emails to and from the @mindfulnessassociation.net email addresses are hosted by our DPA compliant email provider GoDaddy, for the purposes of administering attendance on MA courses and supporting continued engagement with the work of the MA, and will be reviewed and if no longer needed for these purposes will be deleted after a period of 1 year.
Personal data will be shared only with MA employees and self-employed MA tutors (also subject to the DPA) delivering the courses participated in and only to the extent necessary for administering the attendance of individuals on MA courses and supporting engagement with the work of the MA.
Personal data will not be shared with third parties.
Privacy Notice
The data you provide to Mindfulness Association CIC (MA) will be stored securely and will be used for the purposes of administering your attendance on MA courses and supporting your continued engagement with the work of the MA in accordance with our data protection policy, which can be downloaded from the MA’s website and is in accordance with the UK Data Protection Act. To support your engagement with us we will contact you from time to time via email with guidance to support your ongoing mindfulness practice, including details of upcoming courses, which may be of interest to you. You can opt out of receiving emails from the MA, at any time, by clicking the ‘Unsubscribe’ link at the bottom of our emails or by contacting info@mindfulnessassociation.net.