AIMS Data Protection and Privacy policy

Introduction

This document describes the personal data that AIMS keeps about its members, donors, and other contacts:

  • What information and why we keep it,
  • Where we get the information,
  • What we do with it,
  • How we protect that data

Where We Get Personal Information

All personal information is obtained directly from individuals. This includes AIMS members, donors, customers, contractors, employees and those who have requested to be put on our mailings list.

AIMS does not record any personal information from any third parties.

AIMS does not share or sell any information about its past or present members or contacts with any third parties.

What Information we keep and why we keep it

Members

We record and keep members’ contact details so that we can manage their membership and meet our obligations to provide them with information about the AGM and other members’ meetings.

We also use their email addresses to send them newsletters, notifications about AIMS events, fundraising, Journals and other publications, and opportunities to get involved with AIMS volunteering, campaigning and other activities, as well as to inform them about maternity services issues, research studies and campaigns that may be of interest.

This information is kept as a ‘Legitimate Interest’ under the terms of the GDPR legislation because:

  • We need to be able to contact members about matters concerning their membership such as renewals, and to inform them of the AGM and other members' meetings.

  • We need members’ email contact details in order to keep them informed of what the charity is doing, including events, campaigns, local activities, publications etc., as well as to offer them opportunities to get involved with AIMS work on an occasional basis or to help fundraise for AIMS. Members can choose to opt out of these mailings if they wish.

The members’ personal information we keep consists of the following:

  • First name, last name and title
  • Organisation (optional)
  • Date joined
  • Renewal status and next renewal date
  • Postal address
  • Telephone number(s)
  • Email address
  • GiftAid declaration with date
  • Past payment history for each member:
    • Date
    • Amount
    • Purpose (memberships subscription, donation)
    • Method
    • GiftAid claimed or not

Lapsed and ex-members

If an individual has not renewed their membership, they will be classified as a lapsed member. Their personal details will be kept on the membership database for a maximum of 12 months from their last renewal date. If they do not re-join in this time they will be treated as ex-members (see below).

If an individual has informed us that they are not renewing their membership, or if their membership has not been renewed for over 12 months, they will be classified as an ex-member. We will retain the information below for archive purposes but remove all contact details from our database.

  • First name, last name and title
  • Date joined
  • Date left/membership lapsed

Volunteers

In addition to the information we hold on them as members, those who wish to Volunteer with AIMS are asked to provide information about their qualifications, skills, experience and interests. AIMS has a ‘Legitimate Interest’ in storing this information as we need it to enable us to identify roles or tasks which may be of interest to a Volunteer.

Mailing-list subscribers

We also hold contact details for people who are not members but have asked to be kept informed about AIMS activities, and about maternity services issues and campaigns that may be of interest. This information is kept with the individual’s “Consent” under the terms of the GDPR because:

  • The individual has asked to be added to our mailing-list in order to be kept informed of AIMS and other events, information about AIMS Journals, books and website content, maternity issues and campaigns that may be of interest. This could include offering them opportunities to get involved with AIMS work on an occasional basis or to help fundraise for AIMS.
  • Individuals can request to unsubscribe from the mailing-list at any time.

The information we keep for these people consists of:

  • First name, last name and title
  • Email address
  • Date joined list

Job applicants and employees

Applicants for paid or unpaid roles with AIMS may supply us with personal information as part of their application. This information is used purely for the purpose of recruitment, or in the case of successful applicants for paid roles, for HR and employment purposes. Details of unsuccessful applicants will be destroyed once the appointment is complete.

AIMS holds information on its paid employees to enable us to manage their employment. This includes:

  • First name, last name and title
  • Postal address, telephone and email details
  • Bank account details
  • Performance review details
  • Other HR and employment-related information.

Contractors

AIMS sometimes employs individuals as contractors. We need to hold thir contact information in order to liaise with them about their current work or new opportunities to do work for the charity., and bank account details on their invoices to enable payment to be made. The information we hold on contractors may include some or all of:

  • First name, last name and title
  • Postal address
  • Telephone number
  • email address
  • Bank account details

Personal data associated with financial transactions

We keep records of all the income that we have received and payments we have made. Income includes membership subscriptions, donations and payments from AIMS shop customers or those booking tickets for AIMS events. Payments include Volunteers' expenses, employees' salaries and expenses, and payments to suppliers or contractors.

We need to keep this information, which may include personal information and bank account details, so that we have a proper record of all the charity’s income and expenditure. This is kept for contractual and audit reasons and is a Legitimate Interest under the terms of GDPR because:

  • AIMS needs to prepare proper accounts for the Charity Commission and other regulatory bodies
  • AIMS needs to maintain an audit trail, including the data HMRC requires us to keep for all gift aid claims
  • AIMS must be able to answer queries from members about their past membership payment history, including investigation of claims of overpayment and accidental double payment
  • AIMS needs to be able to check with donors if there are any queries about their donation and may also wish to thank them personally. (Note that contact details of donors are used only for matters relating to their donation.)
  • AIMS needs to be able to contact people who have booked tickets for our events in order to inform them of event details, to send them certificates of attendance (if appropriate) and to solicit their feedback on the event. (Note that the names and contact details of people who book for events are used only for matters relating to the event and will be deleted once all these have been dealt with.)
  • AIMS needs to be able to manage the fulfilment of purchases from the AIMS shop. (Note that contact details of purchasers are used only for matters relating to their purchase.)

For Volunteers who claim expenses we keep the following personal information

  • Name
  • Bank account details for payment

Volunteers who wish to claim expenses incurred for their AIMS volunteering work provide us with this information as part of their expense claim to enable payment to be made.

For Donors we keep the following personal information

  • First name, last name and title
  • House name or number
  • Postcode
  • Date of donation
  • Amount given
  • GiftAid declaration and date
  • Email address

For Customers we keep the following personal information

  • Name
  • Postal address
  • Date paid
  • Amount paid
  • Email address

How we protect the personal information we keep

Individuals can request a copy of the Personal Information that AIMS holds on them, ask for this information to be amended or for it to be deleted by emailing datacontroller@aims.org.uk.

All membership data is stored in a secure database with access limited to a small number of volunteers. All access to the membership database is through individual accounts of authorised users and all accounts are protected by passwords. All use of the membership database is logged, including the timestamp of the interaction, the user account used and any queries or actions carried out. The system administrator is automatically notified by email of any anomalous events or errors in the membership database system. All those with access to the membership database receive training in their responsibilities as Data Processors under the GDPR.

Completed Volunteer application forms are stored securely by the Office Manager. In addition, Volunteers’ contact details are shared with all active Volunteers to enable them to contact each other for purposes relating to their AIMS volunteering work. This information is stored in documents on the AIMS Google Drive. Access to this drive is limited to active AIMS Volunteers who received training and signed an undertaking to abide by the AIMS privacy policy and their responsibilities as data processors under the GDPR legislation. Access is removed from anyone who ceases to be an active Volunteer.

Emailing platform

We use MailChimp as our emailing platform. Mailchimp’s servers are based in the USA, but they state that they have implemented “strong privacy protections that mean we’re handling your contacts’ data appropriately and in line with EU legal requirements.” Individuals are asked when they give permission for AIMS to contact them by email to acknowledge that the information they provide will be transferred to MailChimp for processing in accordance with their Privacy Policy and Terms.

Access to the Mailchimp members' and subscribers' mailing lists is restricted to a small number of volunteers and access is protected with 2-factor authentication (password and SMS codes.)

Financial information

Expense claim forms and invoices are stored in electronic format in a Dropbox to which only members of the Finance team have access. These are retained to provide an audit trail.

Payments and donations are processed through PayPal, Stripe, Linnworks and BT MyDonate. These companies have all published their own privacy policies confirming that their data processing meets EU standards.

AIMS receives downloads of data from these companies when people make payments or donations, and these include email and postal addresses as well as some payment information. AIMS retains only the minimum information on these transactions that are required for legitimate purposes such as accounting and reporting to the Charity Commissioners. Other information in these records such as postal addresses and any payment information is deleted immediately on receipt of the download.

Note specifically that AIMS does not hold any details of any donor’s or customer’s bank or credit/debit card or any other accounts. Card details of members who pay their annual membership through the website are held in encrypted form in a database, access to which is through individual accounts of authorised users and all accounts are protected by passwords.

AIMS Helpline: Data Protection and Privacy Policy

Introduction

The AIMS helpline is a confidential information and support service provided by a small group of volunteers (the Helpline Group). This document describes the personal data that AIMS keeps about people who contact the helpline:

  • What information we hold and why we keep it,
  • Where we get the information,
  • What we do with it,
  • How we protect that data

What Information we keep and why we keep it

AIMS records the personal information of enquirers to the helpline in the form of emails and voicemails as a “Legitimate Interest” under the terms of the GDPR because

  • Without contact details we would not be able to provide enquirers with the information and support that they have requested.

AIMS also records personal information including details of the enquiry and our response(s) to it in a database with consent because

  • It may help us to respond more effectively to any future enquiries you make
  • It enables us to contact you to seek your views to inform our campaigns.

If you prefer for us not to record your personal details in the database we will record details of your enquiry and our response(s) in anonymised form to enable us to use this information for research, quality assurance and training purposes.

The information can roughly be grouped into two areas:

Firstly, there is the direct personal information about the person making the enquiry. This makes it simple to maintain the context of an ongoing enquiry across possibly several helpline volunteers. It also helps if the same person contacts AIMS again with a subsequent enquiry which could be years later. This information may include some or all of the following:

  • First name, last name, familiar name or nickname, and title
  • Telephone number(s)
  • Email address

Secondly, there is the less-direct information about the enquiry itself. The Helpline database keeps the text of the email enquiries and responses, and notes about conversations etc with the enquirer and with possibly multiple AIMS helpline volunteers, and there may be personal information such as names, dates and locations included in those notes and messages.

AIMS helpline volunteers work from home so all may have copies of emails and other communications in their personal electronic devices and similarly online including online email and messaging accounts.

You can check what information we have on you in the database or ask us to delete your personal data from it by emailing datacontroller@aims.org.uk If you ask us to delete your personal information we will retain your records in anonymised form.

Where we get the information

All personal information is obtained directly from individuals who call or email the AIMS helpline.

AIMS does not record any personal information from any third parties.

AIMS does not share or sell any information about the people who make helpline enquiries with any third parties.

If you speak to a helpline volunteer by phone you do not need to tell them your name or contact details unless you wish to do so. However, the volunteer may ask for these details for the purposes described above.

If you leave a voicemail, an email which includes your phone number and a recording of your message will be sent to all our helpline volunteers, so that one of them can call you back as soon as possible. Similarly, if you email helpline@aims.org.uk your email address and message will be seen by all our helpline volunteers so that we can respond to you as soon and as fully as possible.

What we do with your personal information

We take your confidentiality very seriously and we will not share your personal information or the details of what you tell us with anyone outside the Helpline Group without your permission.

Occasionally we may ask your permission to share your personal information with another organisation, for example to find additional information or sources of support for you.

The only exception to this would be in the very rare situation where there is a safeguarding issue. In this case if we have information that identifies the enquirer and their location we might tell someone else in order to get help for them. This might be that an enquirer is at risk of harm and unable to help themselves (for example, if they have a medical condition which is worsening), or that they’ve told us that they or a child is at risk of being hurt by someone else. We would never do this without telling the person concerned what we were doing.

Data Protection

All helpline data is stored in a secure database with access limited to a small number of volunteers. All access to the helpline database is through individual accounts of authorised users and all accounts are protected by passwords.

All use of the helpline database is logged, including the timestamp of the interaction, the user account used, and any queries or actions carried out.

The system administrator is automatically notified by email of any anomalous events or errors in the helpline database system.
Helpline volunteers receive training in their responsibilities as Data Processors under the GDPR, and have signed an undertaking which requires them to:

  • Keep your personal details confidential and not share them with anyone outside the Helpline Group without your permission (other than for safeguarding issues as described above).
  • Ensure that any electronic devices (computers, laptops, tablets, smartphones etc.) on which they receive helpline emails are password protected and not left unattended where anyone else might access them.
  • Delete any emails you send to the helpline group from their electronic devices after a maximum of 6 months (or as soon as you request it), unless we are still actively supporting you, in which case they will be deleted once the support is no longer needed.
  • If they take any written notes during a conversation to destroy these as soon as they have dealt with your query.

You can ask us at any time to delete all helpline emails to and from your email address by emailing helpline@aims.org.uk .

Updated May 2018

Latest Content

Journal

« »

Report of Parliamentary Debate on B…

AIMS Journal, 2024, Vol 36, No 1 By Elle Gundry The first parliamentary debate on birth trauma took place in the House of Commons on Thursday 19th October 2023. [1] Thank…

Read more

Doulas supporting clients to make a…

AIMS Journal, 2024, Vol 36, No 1 By Anne Glover I work with women from all walks of life, but one thing that is important to them all, is having a positive and satisfying…

Read more

My Complaint

AIMS Journal, 2024, Vol 36, No 1 Editor’s note: In this quite shocking account of disrespect and neglect, Grace describes the arrival of her first baby. With Grace’s perm…

Read more

Events

« »

MaMA conference - 26/ 27 April 2024

MaMa Conference is the largest & longest running annual midwifery & maternity conference in the UK. Over the past 12 amazing years we have created an original and unique…

Read more

AIMS Workshop: The Foundation Stone…

Join us for an interactive online AIMS workshop: " The Foundation Stones for Supporting the Physiological Process in Pregnancy and Birth ". In this workshop discussion we…

Read more

Midlands 2024 Maternity and Midwife…

"The Maternity and Midwifery Festivals are back face to face and we’re looking forward to meeting you in 2024. Nine events across the UK and Ireland – all of them free of…

Read more

Latest Campaigns

« »

What are the priorities for midwife…

AIMS is proud to be supporting the RCM's Research Prioritisation project as a Project Partner and with one of our volunteers on the Steering Group www.rcm.org.uk/promotin…

Read more

Parliamentary Inquiry into Birth Tr…

Introduction to AIMS and why AIMS is making a submission Since 1960, AIMS has been the leading advocate for improvements in UK maternity care. We have national and intern…

Read more

BICS Conference poster: AIMS Campai…

AIMS Campaigns Team volunteers are presenting a poster about our campaign for Physiology-Informed Maternity Services at the 2023 conference of the British Intrapartum Car…

Read more