KEEN London Privacy Policy

Introduction 

KEEN London is a registered charity, number 1124915. It is also a limited company registered in England (number 6579658), and its registered office is Unit W1, 8 Woodberry Down, London, N4 2TG. 

We must process data, including special category data, to deliver our services and activities. As such, we act as a Data Controller. Our Data Protection Lead can be contacted at dataprotection@keenlondon.org

We comply with the UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025. We also follow the ICO’s Age-Appropriate Design Code for services likely to be accessed by children. 

Data Protection Governance 

We take the following actions to maintain compliance: 

  • Annual policy review
  • Quarterly data cleansing.
  • Regular staff training on data protection and GDPR.
  • Prompt handling of subject access requests.
  • Breach assessment and reporting to the ICO within 72 hours where required, as well as notifying individuals affected by a breach that may pose a high risk to them. 
  • Our Lawful Bases for Processing (see below)

Lawful Bases for Processing Personal Data

We process personal data under the following lawful bases under UK GDPR Article 6:

  • Contract: To enter into or perform a contract with you (e.g., employment agreements, service provision).
  • Legal obligation: To comply with statutory duties (e.g., UK safeguarding legislation, HMRC tax compliance).
  • Legitimate interests: To administer our programmes, manage volunteer and athlete schedules, evaluate organisational effectiveness, and undertake charity operations and fundraising.
  • Consent: For direct email marketing, corporate communications, media/photography, and specific optional queries.

Special Category Data (UK GDPR Article 9)

Where we process sensitive personal data (such as health information, medical conditions, disability details, or ethnicity), we rely on one of the following additional conditions under Article 9:

  • Article 9(2)(a) — Explicit Consent: For marketing media, public photography, or non-essential health disclosures.
  • Article 9(2)(b) — Employment & Social Protection: To fulfil our obligations under UK employment and health and safety law regarding current and prospective staff and volunteers.
  • Article 9(2)(c) — Vital Interests: To protect the health or life of an athlete, volunteer, or staff member in an emergency situation.
  • Article 9(2)(d) — Not-for-Profit Activities: For legitimate internal operations relating directly to our registered athletes, families, supporters, and regular contacts. 
  • Article 9(2)(g) — Substantial Public Interest: Specifically for Safeguarding of children and individuals at risk and Equality of opportunity or treatment (in addition to Data Protection Act 2018, Schedule 1, Part 2).

Data We Collect 

We collect different types of data from the following groups: 

  • Athletes: personal, educational, and relevant safeguarding information from parents/​guardians and schools, as well as local authorities and health professionals where appropriate.
  • Parents/Guardians/Carers: contact information for messaging and group communications. 
  • Volunteers: contact information for messaging and group communications, demographic, DBS, references, and relevant safeguarding information.
  • Funders/​supporters:  contact, donation, and engagement history.
  • Staff:  employment, payroll, emergency contact, performance, and safeguarding information. 
  • We may collect photos and video footage for fundraising and marketing (where consent has been explicitly granted). 

How We Store and Protect Your Data 

We store data in secure systems including Salesforce, Google Workspace, FormAssembly, Mailchimp, Checks Direct and Dropbox. All devices used to access data are password-protected, encrypted, protected with anti-virus software, and require multi-factor authentication (MFA). Backups are encrypted and stored securely. 

We utilise cloud service providers (like Google Workspace and Salesforce) that may process or store data outside the UK. These platforms have appropriate safeguards that protect data, including compliance with the UK International Data Transfer Agreement (IDTA) and the UK Addendum to the EU Standard Contractual Clauses (SCCs) as stated in their Data Protection Agreements. 

We also use third party communication tools such as Whatsapp for operational updates. We have a charity-wide Whatsapp Policy and Risk Assessment that governs how we use Whatsapp, including a set of ‘House Rules’ that apply to all group chats. By joining and remaining in a WhatsApp group, participants agree to KEEN London using their mobile number and name for the purpose of sending and receiving essential communications relating to KEEN London activities and services. The participant also consents to other members of the group chat being able to see their name and phone number within the group chat membership list. Participants can withdraw consent by leaving the group at any time.

We may contact existing donors or individuals who have previously engaged with KEEN London by email or SMS about our work and ways to support us using the ​‘soft opt-in’ provision under the Privacy and Electronic Communications Regulations as amended by the Data (Use and Access) Act 2025. You can opt out at any time. 

Data Retention 

The following table outlines KEEN London’s approach to retaining and securely disposing of data. It specifies the retention periods for key data types relating to families, volunteers, staff, and governance.

Data Type Examples Retention Period Rationale / Notes
Child and Family Application Forms Registration and consent forms, emergency contacts, medical info, SEND needs, school details, addresses 6 years after the child’s last engagement Evidence of service delivery, safeguarding history, and potential legal claims.
Baseline Assessments / Impact Tracking Attendance, progress reports, wellbeing or behaviour assessments 6 years after last engagement (anonymised after 2 years) Legal limitation period; anonymised for evaluation purposes.
Safeguarding Records (Children or Families) Incident reports, concerns, referrals, follow-up records 6 years after case closure Follows NSPCC and statutory safeguarding guidance.
Volunteer Application Data (Successful Applicants) Application form, ID verification, DBS details, references, induction records 6 years after volunteer ceases involvement Supports safeguarding or reference requests; evidences safer recruitment.
Volunteer Data (Unsuccessful / Withdrawn Applicants) Application form, references, DBS outcomes 6 months from decision date Allows audit, feedback, and compliance with safer recruitment principles.
Volunteer Performance / Support / Concerns Supervision notes, support plans, performance discussions, complaints 6 years after volunteer ceases involvement Potential safeguarding or legal relevance.
Safeguarding Records (Volunteers) Safeguarding concerns, investigations, referrals 75 years if substantiated / 10 years if unsubstantiated Reflects long-term safeguarding obligations.
Staff Records (Employment) Contracts, payroll, supervision notes 6 years after employment ends Statutory HR and legal compliance.
Governance / Trustee Records Board minutes, contact details, declarations of interest 10 years Charity Commission and governance record-keeping guidance.
Financial Records Invoices, payroll, receipts, grant documents 6 years after end of financial year HMRC requirement.
Photographs and Media Consent Images and videos used for marketing, social media, or reports For duration of consent and active use; reviewed annually Remove or delete if consent withdrawn or media no longer in use.
Incident / Accident Reports Injury logs, near-miss forms, incident records 6 years after incident Safeguarding and insurance purposes.
DBS Certificates Original DBS certificates where Update Service checks are performed Destroy within 6 months of recruitment decision Retain only certificate number and outcome decision.

Cookies and Tracking Technologies 

Our website uses cookies — small text files that are placed on your machine to help the site provide a better user experience. In general, cookies are used to retain user preferences and provide anonymised tracking data to third party applications like Google Analytics.

As a rule, cookies will make your browsing experience better. However, you may prefer to disable cookies on this site and on others. The most effective way to do this is to disable cookies in your browser. We suggest consulting the Help section of your browser or taking a look at the About Cookies website which offers guidance for all modern browsers.

Who We Share Your Data With 

We may need to disclose your personal data to certain third party organisations who are handling that data on our behalf and in accordance with our instructions under contract (called ‘data processors’) in the following circumstances:

  • Companies and/or organisations that act as our service providers (e.g. suppliers of IT and online services, such as SurveyMonkey, and third party fundraiser companies) or professional advisers. 
  • Companies and/or organisations that assist us in processing and/or otherwise fulfilling transactions that you have requested (e.g. payment processors).

In order to deliver our services and/or fulfil our legal obligations, we may need to share data with schools, local authorities and safeguarding partners. We may also be required to share data with emergency medical services in the event of an accident or major incident, and our external insurers in the event of a liability claim. 

We may also from time to time share anonymised outcome data with our funders in order to demonstrate the impact of KEEN London activities and services. 

Other than as described above, we will treat your personal data as private and will not disclose your personal data to third parties without you knowing about it. The exceptions are in relation to legal and/or safeguarding proceedings where we are legally required to do so and cannot tell you. 

We will never sell your data. 

In all cases we always aim to ensure that your personal data is only used by third parties for lawful purposes and in compliance with applicable Data Protection Law, which may include ensuring certain safeguards and contractual arrangements have been put in place.

Your Data Protection Rights 

In accordance with your legal rights under applicable law, you have a ‘subject access request’ right under which you can request information about the personal data that we hold about you, what we use that personal data for and who it may be disclosed to as well as certain other information. We would normally expect to respond to a subject access request within a month, but in case of complex requests, we may require a further two months to respond. The Charity will use all reasonable measures to verify the identity of a data subject who requests access so we avoid a data breach (that is, disclosing personal data to a third party unlawfully). A copy of a passport or driving licence may be requested if there is genuine doubt about the identity. We may also require further information to locate the specific information you seek before we can respond in full and apply certain legal exemptions when responding to your request. For any further copies requested by the data subject after the first one has been issued, we may be allowed to charge a reasonable fee. 

Under Data Protection Law you also have the following rights, which are exercisable by making a request to us in writing:

  • That we correct personal data that we hold about you which is inaccurate or incomplete;
  • That we erase your personal data without undue delay if we no longer need to hold or process it;
  • To object to any automated processing (if applicable) that we carry out in relation to your personal data, for example if we conduct any automated credit scoring;
  • To object to our use of your personal data for direct marketing;
  • To object and/or to restrict the use of your personal data for purposes other than those set out above unless we have a legitimate reason for continuing to use it; or
  • That we transfer personal data to another party where the personal data has been collected with your consent or is being used to perform contact with you and is being carried out by automated means.
  • All of these requests may be forwarded on to a third party provider who is involved in the processing of your personal data on our behalf.

Under UK Data Protection law, rights belong to the individual. Where a young person is 16 or over and has sufficient understanding and maturity (competence) to make their own data decisions, they may exercise their data rights directly or authorize a parent/guardian to act on their behalf. However, as our active Athletes are all younger children where competence is not yet established, parents or legal guardians hold and exercise these rights in the child’s best interests. 

How to complain about the way we handle your data 

If you would like more information, a request or wish to raise a concern about the way we have handled your data email our Data Protection Lead at dataprotection@keenlondon.org

You also have the right to raise concerns to the Information Commissioner’s Office on 0303 123 1113 or at https://​www​.ico​.org​.uk 

Last Updated: July 2026