independent advocacy – ynys mon & gwynedd
Privacy Policy
Who We Are
NWAAA (North Wales Advice and Advocacy Association) is committed to protecting the privacy and security of your personal information. We act as the Data Controller for the information we collect and process.
Data Protection Contact:
Jon Stevens13a Ash Court, Parc Menai, Bangor, Gwynedd, LL57 4DF
What Information We Collect:
We collect different types of personal data depending on your relationship with us:
Advocacy Partners (Service Users)
- Personal details, health, court and legal documents, assessments, case records, care and treatment plans, reports, and video recordings.
Employees & Trustees
- Contact details, payroll information, NI number, bank details, job history, training and performance records, health information where required, and video recordings.
Contractors
- Data may include contact details, bank details, contracts and payment records.
Significant Others & Professionals
- Contact details, role and job title, and relevant case information where required.
Why We Collect Your Data:
We collect and process personal data to:
- Deliver advocacy services and support
- Meet legal and contractual obligations (e.g. employment, tax, safeguarding)
- Manage HR, payroll, pensions, and staff performance
- Communicate with stakeholders and partners
- Safeguard vulnerable individuals
Lawful Bases for Processing:
We rely on the following lawful bases under UK GDPR:
- ContractWhere processing is necessary for an employment or service contract.
- Legal obligationTo comply with the law — tax, safeguarding, employment law.
- Legitimate interestsTo manage operations effectively and provide services.
- ConsentIn limited cases where no other basis applies. You may withdraw consent at any time.
Special Category Data:
We may process sensitive data (e.g. health, ethnicity, religion, trade union membership) where necessary for employment law and health & safety, safeguarding and vital interests, or where explicit consent has been given.
Who We Share Your Data With:
We may share your data with the following, only where necessary and with appropriate safeguards in place:
- HMRC, pension providers, and insurers
- Occupational health and training providers
- Local authorities, courts, and NHS professionals (for service delivery and safeguarding)
- Law enforcement where legally required
- Approved cloud and ICT service providers
International Transfers:
If we use cloud-based systems located outside the UK or EEA, we ensure they meet UK GDPR standards and have appropriate safeguards in place.
How long we keep your data
Employee records
- Retained for the duration of employment plus 6 years.
Payroll Data
- Retained for up to 7 years.
Advocacy Partner Records
- Retained for the duration of service plus our policy timeframe.
Contractor Records
- Retained for 6 years following the end of contract.
Your Rights
Under UK GDPR, you have the right to:
Be Informed
Access your data
Correct Inaccuracies
Request deletion
Restrict processing
Data portability
Object to processing
Challenge to automated decisions
Data Security:
We protect your information with technical and organisational measures including encrypted systems and secure servers, strong password policies, locked storage for paper files, and restricted access to authorised staff only.
Data Breaches:
If a data breach occurs, we will record it in our Data Breach Register, notify the ICO within 72 hours if legally required, and inform you if your personal data is affected.
Complaints:
If you are unhappy with how your data has been handled, please contact us in the first instance. You also have the right to complain to the Information Commissioner’s Office (ICO):
Website: www.ico.org.ukTel: 0303 123 1113
Questions about your information?
Get in touch and we will be happy to explain how we handle your data and what rights you have.