01248 670 852 enquiry@nwaaa.co.uk

independent advocacy – ynys mon & gwynedd

Privacy Policy

Who We Are

NWAAA (North Wales Advice and Advocacy Association) is committed to protecting the privacy and security of your personal information. We act as the Data Controller for the information we collect and process.

Data Protection Contact:

Jon Stevens
13a Ash Court, Parc Menai, Bangor, Gwynedd, LL57 4DF

What Information We Collect:

We collect different types of personal data depending on your relationship with us:

Advocacy Partners (Service Users)


  • Personal details, health, court and legal documents, assessments, case records, care and treatment plans, reports, and video recordings.

Employees & Trustees


  • Contact details, payroll information, NI number, bank details, job history, training and performance records, health information where required, and video recordings.

Contractors


  • Data may include contact details, bank details, contracts and payment records.

Significant Others & Professionals


  • Contact details, role and job title, and relevant case information where required.

Why We Collect Your Data:

We collect and process personal data to:

  • Deliver advocacy services and support
  • Meet legal and contractual obligations (e.g. employment, tax, safeguarding)
  • Manage HR, payroll, pensions, and staff performance
  • Communicate with stakeholders and partners
  • Safeguard vulnerable individuals

Lawful Bases for Processing:

We rely on the following lawful bases under UK GDPR:

  • ContractWhere processing is necessary for an employment or service contract.
  • Legal obligationTo comply with the law — tax, safeguarding, employment law.
  • Legitimate interestsTo manage operations effectively and provide services.
  • ConsentIn limited cases where no other basis applies. You may withdraw consent at any time.

Special Category Data:

We may process sensitive data (e.g. health, ethnicity, religion, trade union membership) where necessary for employment law and health & safety, safeguarding and vital interests, or where explicit consent has been given.

Who We Share Your Data With:

We may share your data with the following, only where necessary and with appropriate safeguards in place:

  • HMRC, pension providers, and insurers
  • Occupational health and training providers
  • Local authorities, courts, and NHS professionals (for service delivery and safeguarding)
  • Law enforcement where legally required
  • Approved cloud and ICT service providers

International Transfers:

If we use cloud-based systems located outside the UK or EEA, we ensure they meet UK GDPR standards and have appropriate safeguards in place.

How long we keep your data

Employee records


  • Retained for the duration of employment plus 6 years.

Payroll Data


  • Retained for up to 7 years.

Advocacy Partner Records


  • Retained for the duration of service plus our policy timeframe.

Contractor Records


  • Retained for 6 years following the end of contract.

Your Rights

Under UK GDPR, you have the right to:

Be Informed

Access your data

Correct Inaccuracies

Request deletion

Restrict processing

Data portability

Object to processing

Challenge to automated decisions

Data Security:

We protect your information with technical and organisational measures including encrypted systems and secure servers, strong password policies, locked storage for paper files, and restricted access to authorised staff only.

Data Breaches:

If a data breach occurs, we will record it in our Data Breach Register, notify the ICO within 72 hours if legally required, and inform you if your personal data is affected.

Complaints:

If you are unhappy with how your data has been handled, please contact us in the first instance. You also have the right to complain to the Information Commissioner’s Office (ICO):

Website: www.ico.org.uk

Questions about your information?

Get in touch and we will be happy to explain how we handle your data and what rights you have.