Customers and tenants
Subject access request:
Click here to request access to your personal data
Individuals right request:
Click here to complete an individuals right request
Your rights under GDPR. For example, right to erasure of your personal data.
Businesses
Disclosure request:
Click here to complete a disclosure request
Apply for personal data held by Bolton at Home.
For further information
For further information on GDPR and your personal data please look at the Information Commissioners Office website.
Bolton at Home's Privacy Notice
We've divided our Privacy Notice into a question and answer format to make it easier for you to read, understand and digest.
Click or tap any of the sections to read further details.
Who are we?
At Bolton at Home (BH), we are committed to maintaining the trust of our customers, tenants, workers and job applicants. In particular, we want you to be confident that we are handling your personal data in accordance with the Data Protection Act 2018 (DPA) and UK General Data Protection Regulation (UK GDPR).
We are registered as the data controller with the Information Commissioner's Office under ZA304342 as we will decide how and why we process your personal data.
If you would like to know when and why we collect your personal data, how we use it, the limited conditions under which we may disclose it to others and how long we may keep it for, please read on.
What personal data do we collect and why?
We may collect your personal data and / or special category personal data from you. Personal data are any information that can directly or indirectly identify you. This could include your name, date of birth, IP address and other identifiable data. Special category personal data are any information about your biometrics, ethnic or racial origin, genetics, health, political opinions, religion, sex life, sexual orientation and trade union membership.
Data subjects |
Categories of personal data |
Purposes for processing |
Basis / condition for processing |
|
Customers and tenants. |
Personal data and / or Special category data. |
Tenancy applications and support (e.g. property allocation and bids, support to sustain tenancy). |
Legal bases for processing:
Condition for processing:
|
|
Customers and tenants. |
Personal data and / or Special category data. |
Property repair and maintenance (e.g. disability adaptations, general repairs). |
Legal bases for processing:
Condition for processing:
|
|
Customers and tenants. |
Personal data and / or Special category data. |
Support into work (e.g. CV writing support, training, work placements). |
Legal bases for processing:
Condition for processing:
|
|
Customers and tenants. |
Personal data and / or Special category data. |
Welfare support (e.g. budgeting, debt advice Urban Care and Neighbourhood Centres [UCANs]). |
Legal bases for processing:
Condition for processing:
|
|
Customers and tenants. |
Personal data and / or Special category data. |
Financial processes(e.g. grant applications, rent payments). |
Legal bases for processing:
Condition for processing:
|
|
Customers and tenants. |
Personal data and / or Special category data. |
General service enquiries. |
Legal basis for processing:
Condition for processing:
|
|
Customers and tenants. |
Personal data and / or Special category data. |
Legal requirements (e.g. criminal offences, court proceedings, insurance claims). |
Legal bases for processing:
Condition for processing:
|
|
Customers and tenants. |
Personal data and / or Special category data. |
Property purchases (new build and ‘right to buy’). |
Legal bases for processing:
Condition for processing:
|
|
Customers and tenants. |
Personal data and / or Special category data. |
Neighbourhood safety (e.g. anti-social behaviour, hazard and fault reporting, outreach groups). |
Legal bases for processing:
Condition for processing:
|
|
Customers and tenants. |
Personal data and / or Special category data. |
Support for tenants with disability (e.g. Careline, property adaptations, rapid response service). |
Legal bases for processing:
Condition for processing:
|
|
Customers and tenants. |
Personal data and / or Special category data. |
Customer complaints, feedback and service evaluation (in relation to service accessed or tenancy). |
Legal bases for processing:
Condition for processing:
|
|
Workers. |
Personal data and / or Special category data. |
Training & development (e.g. job related and or mandatory training). |
Legal bases for processing:
Condition for processing:
|
|
Workers. |
Personal data and / or Special category data. |
Health and safety (e.g. health and safety and / or risk assessments, occupational health, and public health). |
Legal basis for processing:
Condition for processing:
|
|
Workers. |
Personal data and / or Special category data. |
Facilities management (e.g. access fobs, identity badges, lockers). |
Legal basis for processing:
Condition for processing:
|
|
Workers. |
Personal data and / or Special category data. |
Human resources (e.g. absence, employment contracts performance monitoring). |
Legal basis for processing
Condition for processing:
|
|
Tenants, customers and workers. |
Personal data and / or Special category data. |
Partnerships and communications (e.g. corporate events, corporate Facebook account, filming and photographs for marketing). |
Legal bases for processing:
Condition for processing:
|
|
Workers. |
Personal data and / or Special category data. |
On boarding new starters (induction process). |
Legal basis for processing:
Condition for processing:
|
|
Job applicants. |
Personal data and / or Special category data. |
Recruitment and selection (recruitment process). |
Legal basis for processing:
Condition for processing:
|
|
Others. | Personal data and / or Special category data. | Health and safety (e.g. warning codes). |
|
Where you do not provide this personal data and / or special category personal data above, we may not be able to fulfil the corresponding purposes and this may adversely impact on the Services that we are able to provide to you.
We may carry out profiling for the purposes of the Careline and Concierge Services, debt enforcement and recovery, marketing, money advice, property maintenance and repair, recruitment of Board members, tenancy applications and sign up and terminations, and workers’ development and training.
Who do we share your personal data with?
We may share your personal data in certain circumstances with one or more of the following: BH subsidiaries such as Maxmedia and Starts With You, British Gas, DBS check providers, educational and training organisations, external auditors, external property valuers, external service providers, financial organisations, health and social welfare organisations including NHS agencies, care providers, companies directly involved with the provision of food parcels, Support Groups for people who are enlisted to provide emergency responses to vulnerable groups, Home Swapper, insurance companies, local and national government bodies, other employers regarding job references, other housing associations or landlords, pension providers, prison service, regulatory authorities, research organisations, solicitors, the media, trade unions, Trustmarque, and where required by law, with other bodies such as the courts and the police.
How long do we keep your personal data?
We may keep your personal data for no longer than necessary and for a period of up to 15 years in order to provide our Services to you and to fulfil legal, contractual and regulatory requirements.
Why do we conduct data matching?
We are supporting computerised data matching. It is part of the Cabinet Office’s National Fraud Initiative (NFI) and will help us to identify fraudulent claims and payments.
Data matching works by comparing sets of computer records held within or between organisations. This is usually personal data. Where records are found to be inconsistent, the reason needs to be investigated.
The Cabinet Office carries out the NFI data matching exercise. By volunteering our data for this, we are taking action to protect ourselves and others against fraud.
We provide specific sets of data, including details of our creditors, as set out in their guidance.
The use of data by the Cabinet Office in a data matching exercise is carried out with statutory authority under Part 6 of the Local Audit and Accountability Act 2014. It does not require your consent under the DPA and GDPR.
Data matching by the Cabinet Office is also subject to the Code of Data Matching Practice.
For further information on the Cabinet Office’s legal powers and the reasons for matching particular information, you may wish to consider their Privacy Notice.
How do we keep your personal data secure?
We have implemented appropriate technical and organisational measures to protect the confidentiality, integrity and availability of your personal data against unauthorised, unlawful or accidental loss, destruction or damage, including:
- mandatory and ongoing training and awareness for BH workers to help them understand the importance of information security;
- conducting a Data Protection Impact Assessment (DPIA) when the intended processing of your personal data is likely to result in a high risk to your rights and freedoms;
- restricting access to your personal data;
- contracts and data sharing agreements with other organisations to help them understand what they are allowed to do with your personal data;
- use of secure email;
- regular system back-ups; and
- secure deletion and / or shredding when your personal data are no longer required.
What rights do you have in respect of your personal data?
You have rights, subject to exemptions, under the DPA and GDPR:
- to be informed via this Privacy Notice about our collection and use of your personal data;
- to withdraw your consent at any time, where we are relying on your consent as a basis and / or condition for processing;
- to make a subject access request for a copy of your personal data;
- to request that we correct your personal data if it is inaccurate or out of date;
- to request that we erase your personal data where it is no longer necessary for us to retain it;
- to request a restriction is placed on further processing where there is a dispute in relation to the accuracy or processing of your personal data;
- to request that we provide you with your personal data and where possible, transmit that data directly to another data controller;
- to object to the processing of your personal data;
- to not be subject to automated decision making including profiling; and
- to lodge a complaint with the Information Commissioner's Office by writing to: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF or casework@ico.org.uk.
You may be able to exercise these rights on behalf of other individuals with their express permission.
However, information about a deceased person does not constitute personal data and is not subject to the DPA and GDPR. Therefore, we are not obliged and we will not respond to, requests under the DPA and GDPR in respect of the information of deceased individuals (regardless of your relationship to them) as a matter of course.
How can you contact us about your personal data?
If you would like to make a subject access request to BH, please complete the online request form here or you can print a copy and submit by post to the address below, if preferred Subject access form[docx] 678KB
Bolton at Home ,
Information Governance Team,
Valley House,
98 Waters Meeting Road,
Bolton BL1 8SW
or email IG@boltonathome.org.uk.
Please ensure that you follow the instructions within the form, such as the requirement to provide proof of your identity, as failure to do so may delay our processing of your request.
You can also contact us at the same address if you have any questions or complaints about how we handle, or you would like to exercise your other rights in respect of, your personal data.
Why are we not subject to Freedom of Information?
We are a charitable Community Benefit Society. We do not constitute a public authority under the Freedom of Information Act 2000 (FOIA) and Environmental Information Regulations 2004 (EIR), and therefore, we are not obliged and we will not respond to, requests under such legislation as a matter of course.
However, you are able to consider corporate information that we have chosen to make publicly available in the 'About us' section of our website.
If you would like independent advice in regard to our status under the FOIA and EIR, you may wish to contact the Information Commissioner's Office, which is the regulator for this legislation, by writing to: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF or casework@ico.org.uk.
When do we update this Privacy Notice?
We will review this Privacy Notice annually, or sooner if required. The last date of review for this Privacy Notice was 05 February 2024.