Privacy Policy
What does this Privacy Policy cover?
Romodels (Charity number: 1197650) (“Romodels”, “we”, “us” or “our”) understands that your privacy is important to you and that you care about how your Personal Data is used. We respect your privacy and are committed to protecting your Personal Data.
This Privacy Policy applies to our collection, use and sharing of your Personal Data when making available our websites that link to this Privacy Policy, including www.romodels.org (together, the “Site”) and providing you with access to our proprietary cloud-based software-as-a-service platform, which can be accessed via www.romodels.thinkifc.com (the “Platform”), as well as associated marketing activities and any other activities described in this Privacy Policy. Under the GDPR, we are a ‘controller’ for the activities covered by this Privacy Policy.
For reference, when we refer to “Personal Data”, we mean any information which identifies you as an individual or which otherwise renders you identifiable. When we use the term “GDPR”, we are referring to the so-called UK General Data Protection Regulation (“UK GDPR”).
What Personal Data we collect
The Personal Data we typically collect about you is outlined below:
Contact Data
Your full name, email address, the name of the educational institution (e.g., the school) for whom you work and your role/title, the name of the local authority for the educational institution for whom you work.
As a note: some of this information may be provided to us by the educational institution for whom you work.
Authentication Data
Authentication information to verify that you are a valid authorised user of the Platform and to manage your access to the Platform.
Technical Data
Internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access the Site and/or Platform.
Communications Data
Data you exchange with us in your communications with us, your preferences relating to our communication preferences (e.g., whether you have opted in to receive marketing communications), and your interactions with our communications (e.g., whether you open and/or forward emails). This includes any Personal Data you provide in any free-text ‘message’ fields via which you can communicate with us on the Site (e.g., using the ‘Get Involved’ functionality).
Analytics Data
Statistical demographic or event-based analytics based on your use of the Site and/or Platform.
Payment Data
Information relating to payments (if any) made by you on behalf of the educational institution for whom you work.
No obligation to provide Personal Data.
You do not have to provide Personal Data to us. However, where we need to process your Personal Data either to comply with applicable law or to deliver our Platform and/or Site, and you fail to do so where required, we may not be able to provide some or all parts of our Platform and/or Site (as applicable). We will notify you if this is the case at the time.
Don’t give us personal data relating to students.
We ask that you do not provide us with any personal data in respect of students of the educational institution for whom you work – whether through the Site, the Platform or otherwise. For example, please do not input any such data in any free-text ‘message’ fields via which you can communicate with us on the Site and/or the Platform (e.g., using the ‘Get Involved’ functionality).
Don’t give us sensitive information.
We ask that you do not provide us with any sensitive types of Personal Data (e.g., health-related information, information related to racial or ethnic origin, political opinions, religion or other beliefs, criminal convictions information etc) – whether through the Site, the Platform or otherwise. For example, please do not input any of these types of sensitive information in any free-text ‘message’ fields via which you can communicate with us on the Site and/or the Platform (e.g., using the ‘Get Involved’ functionality).
How we use your Personal Data and why
We use your Personal Data for the purposes listed below and any associated sharing of Personal Data (see the section called ‘How we share your Personal Data’, below).
In respect of each of the purposes for which we use your Personal Data, the GDPR requires us to establish a ‘legal basis’ for that use. Our legal bases for processing your Personal Data described in this Privacy Policy are listed below.
-
Where we need to perform a contract we have entered into with you or are about to enter into with you (“Contractual Necessity”).
-
Where it is necessary for our pursuit of legitimate interests and your interests and fundamental rights do not override those interests (“Legitimate Interests”).
-
Where we need to comply with a legal or regulatory obligation (“Compliance with Law”).
-
Where we have your specific consent to carry out the processing for the purpose in question (“Consent”).
SITE OPERATION
Purpose: To provide, operate and secure the Site.
Categories of Personal Data:
-
Contact Data
-
Technical Data
Legal basis:
-
Contractual Necessity
-
Legitimate Interests. We have a legitimate interest in ensuring the ongoing security and proper operation of our Site, our operations as a charitable entity and associated IT services, systems and networks.
PLATFORM OPERATION
Purpose: To provide, operate and secure the Platform – including: managing access and use of the Platform, allowing us to perform our agreements with educational institutions (including the educational institution for whom you work), and securing the operation of and access to the Platform.
Categories of Personal Data:
-
Contact Data
-
Authentication Data
-
Technical Data
Legal basis: Legitimate Interests. We have a legitimate interest in managing access of authorised users, ensuring the ongoing security and proper operation of our Platform, as well as performing our obligations under our agreements with educational institutions (including the educational institution for whom you work).
ADMINISTRATION AND OPERATION OF OUR ACTIVITIES
Purpose: Administration and operation of our activities as a charitable entity, including contracting and negotiation (e.g., with the educational institution for whom you work), and strategy planning activities, including to analyse, adapt and improve these processes and activities.
Categories of Personal Data:
-
Contact Data
-
Communications Data
-
Technical Data
-
Analytics Data
Legal basis: Legitimate Interests. We have a legitimate interest in administering and operating our activities as a charitable entity, including contracting and negotiation, and strategy planning practices (including associated analysis, adaptation and improvement).
PAYMENTS
Purpose: To process payments made by you on behalf of the educational institution for whom you work.
Categories of Personal Data:
-
Contact Data
-
Communications Data
-
Payment Data
Legal basis: Legitimate Interests. We have a legitimate interest in processing payments under the contracts we enter into with the educational institutions to whom we provide our services.
PERSONALISATION
Purpose: To personalise your experience with the Site and/or Platform (including remembering your selections and preferences as you navigate).
Categories of Personal Data:
-
Contact Data
-
Authentication Data
-
Technical Data
Legal basis:
-
Legitimate Interests. We have a legitimate interest in providing you with a good service which is personalised to you and that remembers your selections and preferences.
-
Consent. Applicable in respect of any optional processing relevant to such personalisation (including processing directly associated with any optional cookies used for this purpose).
DEALING WITH YOUR CONTACTS WITH US
Purpose: To deal with any contact you might make with us using any 'Get Involved' or similar function on the Site or via any other method of communication (e.g., by email), as well as any issues arising from such contacts (including replying to you).
Categories of Personal Data:
-
Contact Data
-
Technical Data
-
Communications Data
Legal basis: Legitimate Interests. We have a legitimate interest in communicating with you and dealing with your contacts with us, as well as handling any issues that may arise from such contacts.
MARKETING
Purpose: To communicate with you (including to provide updates on our activities, the Site, the Platform and any other products or services). For example, we may send you emails about the Site, the Platform, related course(s), registration, course content or other updates.
Categories of Personal Data:
-
Contact Data
-
Communications Data
Legal basis:
-
Legitimate Interests. We have a legitimate interest in promoting our operations as a charitable entity and sending marketing).
-
Consent. Applicable in circumstances or in jurisdictions where consent is required for the sending of any given marketing communications.
IMPROVEMENT AND ANALYTICS
Purpose: To analyse your usage of our Site and Platform, understand user activity, and improve the Site and Platform.
Categories of Personal Data:
-
Technical Data
-
Analytics Data
Legal basis:
-
Legitimate Interests. We have a legitimate interest in improving our Site and Platform.
-
Consent. Applicable in respect of any optional cookies used for this purpose and associated processing.
PRIVACY PROTECTIVE STEPS
Purpose: We may aggregate, deidentify or anonymise certain Personal Data in the conduct of our operations. If we aggregate, deidentify or anonymise your Personal Data such that it is no longer Personal Data (i.e., it can no longer be associated with you), we may use this information as non-Personal Data indefinitely without further notice to you.
Categories of Personal Data: Any and all data types relevant in the circumstances.
Legal basis: Legitimate Interests. We have a legitimate interest in taking steps to ensure that how we use Personal Data is as un-privacy intrusive as possible. We believe it is also in your interests that we take these privacy protective steps.
COMPLIANCE AND PROTECTION
Purpose: To comply with applicable laws, lawful requests, and legal process (such as to respond to disclosure orders or similar, as well as investigations or requests from government authorities); to protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims); to audit our internal processes for compliance with legal and contractual requirements or our internal policies; to enforce the terms of agreements that govern access to the Site and/or Platform (including our agreements with educational institutions); and to prevent, identify, investigate and deter fraudulent, harmful, unauthorised, unethical or illegal activity, including cyberattacks and identity theft.
Categories of Personal Data: Any and all data types relevant in the circumstances.
Legal basis:
-
Compliance with Law.
-
Legitimate Interests. Where Compliance with Law is not applicable, we and any relevant third parties have a legitimate interest in participating in, supporting, and following legal process and requests, including through cooperation with authorities. We and any relevant third parties may also have a legitimate interest of ensuring the protection, maintenance, and enforcement of our and their rights, property, and/or safety.
RE-STRUCTURING AND FUNDRAISING EVENTS
Purpose: To facilitate or carry out any structuring and/or fundraising events (including providing Personal Data to allow third parties to perform diligence into our operations).
Categories of Personal Data: Any and all data types relevant in the circumstances.
Legal basis: Legitimate interests. We and any relevant third parties have a legitimate interest in us providing information to certain third parties who are involved in or assisting with actual or prospective re-structuring and/or fundraising events for these purposes.
FURTHER USES
Purpose: We may use your Personal Data for further uses beyond those described above, we only do this with your consent or whether those further purposes are compatible with the initial purpose for which Personal Data was collected.
Categories of Personal Data: Any and all data types relevant in the circumstances.
Legal basis:
-
The original legal basis, for ‘compatible further uses’.
-
Consent. Applicable for ‘non compatible further uses’.
How we use cookies & other similar technologies
We also use cookies and other similar technologies on our Site and Platform.
Your rights
What are your rights?
The GDPR may give you certain rights regarding your Personal Data and how we process it in certain circumstances, meaning you may ask us to take the following actions in relation to your Personal Data:
-
Access. Provide you with information about our processing of your Personal Data and give you access to your Personal Data.
-
Correct. Update or correct inaccuracies in your Personal Data.
-
Delete. Delete your Personal Data where there is no good reason for us continuing to process it - you also have the right to ask us to delete or remove your Personal Data where you have exercised your right to object to processing (see below).
-
Transfer. Transfer to you or a third party of your choice a machine-readable copy of your Personal Data which you have provided to us.
-
Restrict. Restrict the processing of your Personal Data, for example if you want us to establish its accuracy or the reason for processing it.
-
Object. Object to our processing of your Personal Data where we are relying on Legitimate Interests – you also have the right to object where we are processing your Personal Data for direct marketing purposes.
Exercising your rights
-
To exercise any of the rights described above, please contact us using the contact details shown below.
-
We may request specific information from you to help us confirm your identity and process your request. Whether or not we are required to fulfil any request you make will depend on a number of factors (e.g., why and how we are processing your Personal Data), if we reject any request you may make (whether in whole or in part) we will let you know our grounds for doing so at the time, subject to any legal restrictions. Typically, you will not have to pay a fee to exercise your rights; however, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.
Timing
We try to respond to all legitimate requests within a month of receipt. It may take us longer than a month if your request is particularly complex or if you have made a number of requests; in this case, we will notify you and keep you updated.
How we share your Personal Data
We may share your Personal Data with the following categories of recipient and as otherwise described in this Privacy Policy, in other applicable notices, or at the time of collection.
Educational Institutions. We may share certain Personal Data we collect about you with the educational institution for whom you work and on whose behalf you use the Platform (e.g., where needed to perform our agreement with that institution).
Service providers. Third parties that provide services on our behalf or help us operate parts of the Site or the Platform (such as our hosting providers, information technology/security providers, customer support, email delivery, marketing, research and analytics).
Professional advisors. Professional advisors, such as lawyers, auditors, bankers and insurers, where necessary in the course of the professional services that they render to us.
Authorities and others. Law enforcement, government authorities, the Charity Commission, and private parties, as we believe in good faith to be necessary or appropriate in the circumstances.
Parties to restructuring or fundraising events. We may disclose Personal Data in the context of actual or prospective restructuring or fundraising events (e.g., investments in Romodels, financing of Romodels, or the sale, transfer or merger of all or part of the assets or operations of Romodels), for example, we may need to share certain Personal Data with prospective counterparties (including acquirers and assignees) and their advisers.
Transfers outside Europe
We may share your Personal Data with third parties who are based outside the UK and European Economic Area (“Europe”), including the United States.
Where we share your Personal Data with third parties who are based outside Europe, we try to ensure a similar degree of protection is afforded to it by implementing one of the following mechanisms:
-
Transfers to territories without an adequacy decision.
-
We may transfer your Personal Data to countries or territories whose laws have not been deemed to provide such an adequate level of protection (e.g., the United States).
-
However, in these cases:
-
we may use specific appropriate safeguards, which are designed to give Personal Data effectively the same protection it has in Europe – for example, standard-form contracts approved by relevant authorities for this purpose; or
-
in limited circumstances, we may rely on an exception, or ‘derogation’, which permits us to transfer your Personal Data to such country despite the absence of an ‘adequacy decision’ or ‘appropriate safeguards’ – for example, reliance on your explicit consent to that transfer.
Security
We employ technical, organisational and physical safeguards designed to protect your Personal Data (including to prevent your Personal Data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed). For example, we limit access to your Personal Data to only those employees and other staff who have a business need to have such access. All such people are subject to a duty of confidentiality.
In addition, we have put in place procedures to deal with potential personal data breaches affecting your Personal Data. In the event of any such breach, we have systems in place to notify and work with applicable regulators where required. In addition, in certain circumstances (e.g., where we are legally required to do so) we may notify you of more serious personal data breaches affecting your Personal Data.
Please note that despite the efforts described above, as our Site and Platform are hosted electronically, we can make no guarantees as to the security or privacy of your information.
Retention
We are committed to only keeping your Personal Data for so long as we reasonably need to use it for the purposes set out above. This general rule applies unless a longer retention period is required by law.
To determine the appropriate retention period for Personal Data, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal requirements.
When we no longer require the Personal Data that we have collected about you, we will either delete or anonymise it or, if this is not
possible (for example, because your Personal Data has been stored in backup archives), then we will securely store your Personal Data and isolate it from any further processing until deletion is possible.
Third-party links
This Site and Platform may include links to third-party websites, platforms, plug-ins and applications (including to access and integrate your accounts on those other services). Clicking on those links or enabling those connections may allow third parties to collect or share your Personal Data.
We do not control these third-party websites and are not responsible for their privacy statements or practices. When you leave our Site or Platform, we encourage you to read the privacy policy of every site you visit.
Complaints
If you would like to make a complaint regarding this Privacy Policy or our practices in relation to your Personal Data, please contact us using the contact details shown below. We will reply to your complaint as soon as we can.
If you feel that your complaint has not been adequately addressed, please note that data protection laws give you the right to contact the regulator directly:
The contact information for the UK data protection regulator can be found here: https://ico.org.uk/make-a-complaint/
Contact details
Contact Romodels
You can contact us directly using the following contact details:
Email: laura@romodels.org
Updates
Any changes will be made available here (or another page we notify to you at a later date) and where applicable we might also notify you via email and/or in our Site or Platform.