Privacy Policy

Overview

Lady of the Vale (“we” or “us”) is committed to data protection and data privacy. With the General Data Protection Regulation (GDPR) becoming enforceable from 25 May 2018, we have undertaken a GDPR readiness programme to review our entire business, the way we handle data and the way in which we use it to provide our services and manage business operations.

We hold personal data on all our employees to meet legal obligations and to perform vital internal functions. This notice details the personal data we may retain, process and share with third parties relating to your employment and vital business operations. We are committed to ensuring that your information is secure, accurate and relevant. To prevent unauthorised access or disclosure, we have implemented suitable physical, electronic, and managerial procedures to safeguard and secure personal data we hold.

Introduction

We have issued this notice to describe how we handle personal data that we hold about our Group Personnel (collectively referred to as "you"). For the purposes of this notice, the term "Group Personnel" includes all employees, workers, contractors, agency workers, volunteers, consultants, Directors, members and others in respective of the Group.

We respect the privacy rights of individuals and are committed to handling personal data responsibly and in accordance with applicable law. This notice sets out the personal data that we collect and process about you, the purposes of the processing and the rights that you have in connection with it.

If you are in any doubt regarding this notice, please contact our Data Protection Officer (DPO) on dpo@careportgroup.com

Types of personal data we collect

During your employment / assignment with us, or when making an application for employment / assignment, we may process personal data about you and your dependents, beneficiaries and other individuals whose personal data has been provided to us.

The types of personal data we may process include, but are not limited to:

  • Identification data – such as your name, gender, photograph, date of birth, staff member IDs.
  • Contact details – such as home and business address, telephone/email addresses, emergency contact details.
  • Health records – such as a health questionnaire or during your employment you may be referred to occupational health and/or a medical report from your GP – with your consent - following a request to HR by you or your line manager.
  • Employment details – such as job title/position, office location, employment contract, performance and disciplinary records, grievance procedures, accident records, attendance records and sickness/holiday records.
  • Training records
  • Background information – such as academic/professional qualifications, education, CV, criminal records data (for vetting purposes, where permissible and in accordance with applicable law).
  • Spouse and dependents information, marital status.
  • Financial information – such as banking details, tax information, salary, benefits, expenses, allowances, attachment of earnings notices, deductions (e.g. trade union memberships).
  • IT information – information required to provide access to and monitoring of our IT systems and networks such as IP addresses, log files and login information.
  • CCTV images within our Care Homes.
  • Any content featuring you produced for use on our website or social media such as videos, news articles, log posts.
  • If you are a temporary employee, volunteer, contract worker or consultant, the type of personal information we process is limited to that needed to manage your specific work assignment.
  • References relating to previous roles and employment conduct may be undertaken prior to commencement of employment. We will only gather references from referees provided to us by the employee, or prospective employee.
  • Provision of references to prospective employers. For example, we may be asked to confirm the dates of your employment and your job role.
  • Whistleblowing - we have a whistleblowing policy in place for employees and workers who make public disclosures, generally about wrong doings in the workplace. Although every effort will be taken to restrict the processing of your personal data and maintain confidentiality whether this is possible will be dependent on the nature of the concern and any resulting investigation.

Sensitive personal data (‘special categories of personal data’ under the General Data Protection Regulation) includes any information that reveals your racial or ethnic origin, religious, political or philosophical beliefs, genetic data, biometric data for the purposes of unique identification, trade union membership, or information about your health/sex life. Generally, we try not to collect or process any sensitive personal information about you, unless authorised by law or where necessary to comply with applicable laws. In some circumstances, we may need to collect some sensitive personal information for legitimate employment-related purposes: for example:

  • data relating to your racial/ethnic origin, gender and disabilities for the purposes of:
    • equal opportunities monitoring;
    • to comply with anti-discrimination laws; and
    • for government reporting obligations;
  • data relating to your physical or mental health to:
    • provide work-related accommodations,
    • health and insurance benefits to you and your dependents; or
    • to manage absences from work.

How do we get your information?

We get information about you from the following sources:

  • Directly from you.
  • An employment agency.
  • Your employer if you are a secondee.
  • Referees, either external or internal.
  • Occupational Health and other health providers.
  • Pension administrators and other government departments, for example tax details from HMRC.
  • Your Trade Union.
  • Providers of staff benefits.
  • CCTV images from our landlords or taken using our own CCTV systems.

Purposes for processing personal data Recruitment

If you are applying for a role with us then we collect and use this personal data for recruitment purposes – in particular, to determine your suitability for a specific role. This includes assessing your skills, qualifications and verifying your information, carrying out pre-employment checks (e.g. reference checks) and to generally manage the hiring process and communicate with you about it.

If you are accepted for a role with us, the data collected during the recruitment process will form part of your ongoing employee record.

For more information, please see the recruitment privacy notice.

Employment

We collect and process personal data relating to our employees to meet our obligations under the employment contract and to comply with our legal obligations. We take the security of your data seriously and are committed to being transparent about how we collect and use that data and to meeting our data protection obligations.

Once you become an employee, we collect and use this personal data for managing our employment or working relationship with you – for example, your employment records and contract information (so we can manage our employment relationship with you), your bank account and salary details (so we can pay you), and details of your spouse and dependents (for emergency contact and benefits purposes).

Where we process special categories of personal data, such as information about ethnic origin,  sexual orientation, health or religion or belief, this is done for the purposes of equal opportunities monitoring. Data that we use for these purposes is anonymised or is only collected with the express consent of employees, which can be withdrawn at any time.

We have policies and controls in place to try to ensure that your data is not lost, accidentally destroyed, misused or disclosed, and is not accessed without authorisation and only accessed or used for specific legal purposes.

You have some obligations under your employment contract to provide the organisation with data. You may also have to provide the organisation with data in order to exercise your statutory rights, such as in relation to statutory leave entitlements. Failing to provide this data may mean that you are unable to exercise your statutory rights.

We process our employees' personal data through a global human resources system ("HR System") called Atlas for Head Office and Maxtime for Home based employees, which is a tool that helps us to administer HR and employee compensation and benefits at an international level and which allows staff members to manage their own personal information in some cases.

Atlas is provided by Citation who utilise third-party servers via Microsoft Azure to hold its HR System data and other business services; these are both based in the United Kingdom and have been assessed against stringent security requirements to ensure that all appropriate security controls are in place to protection personal information.

Maxtime is provided by Maxtime Limited who utilise third-party data centres to hold its system data and other business services; these are based in the United Kingdom and have been assessed  against stringent security requirements to ensure that all appropriate security controls are in place to protection personal information.

Azets Holdings Limited who utilise third-party data centres to hold its system data and other business services; these are based in the United Kingdom and have been assessed against stringent security

requirements to ensure that all appropriate security controls are in place to protection personal information.

Legitimate business purposes

We may also collect and use personal data when it is necessary for other legitimate purposes, such as to help us conduct our business more effectively and efficiently – for example, for general IT security management, accounting purposes or financial planning. We may also process your personal information to investigate violations of law or breaches of our own internal policies.

The IT Department will record and monitor usage of all our IT equipment, user activity, voice traffic, email and Internet usage as deemed necessary. The IT Department will observe the strictest confidentiality when undertaking these activities. They will make their report directly to the IT Manager who will determine the actions that may need to be taken in any particular case.

Some of our sites operate closed circuit television (CCTV) systems throughout their premises as deemed necessary and employees should expect all areas (other than those where use would contravene common decency) to be visible on a television monitoring system. Any information obtained from such systems will be used with strict adherence to the GDPR. Information will be used for the prevention and detection of crime and to ensure compliance with our policies and procedures and our legal obligations. This may include using recorded images as evidence in disciplinary proceedings.

Legal purposes

We may also use your personal data where we consider it necessary for complying with laws and regulations, including collecting and disclosing employee personal information as required by law (e.g. for tax, health and safety, anti-discrimination laws), under judicial authorisation, or to exercise or defend our legal rights.

Legal basis for processing personal data

Our legal basis for collecting and using the personal data described above will depend on the personal data concerned and the way we collect it. We will normally collect personal data from you only where we need it to perform a contract with you (i.e. to manage the employer/employee relationship), where we have your freely given consent to do so, or where the processing is in our legitimate interests and only where this interest is not overridden by your own interests or  fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect personal information from you or may otherwise need the personal information to protect your vital interests or those of another person.

Any processing based on consent will be made clear to you at the time of collection or use – consent can be withdrawn at any time by contacting our DPO.

How will we use this information?

Personal data supplied to us is used in a number of ways, including, but not limited to, the following:

  • To carry out the contract we have with you, provide you access to business services required for your role and manage our human resources processes.
  • Payment of your salary, pension and other employment related benefits. We also process it for the administration of statutory and contractual leave entitlements such as holiday or maternity leave.
  • To assess your performance, to conduct pay reviews and to deal with any employer / employee related disputes. We also use it to meet the training and development needs required for your role.
  • To assess your compliance with corporate policies and procedures and to ensure the security of our premises, IT systems and employees.
  • To comply with our legal obligations. We also use it to ensure the health, safety and wellbeing of our employees.

Who we share your personal data with?

We may share information regarding you and your employment with those who have a legitimate need to know, namely those at Annex A.

We take care to allow access to personal data only to those who require such access to perform their tasks and duties, and to third parties who have a legitimate purpose for accessing it. Whenever we permit a third party to access personal information, we will implement appropriate measures to ensure the data is used in a manner consistent with this notice and that the security and confidentiality of the data is maintained.

Transfers to third-party service providers

In addition, we make certain personal data available to third parties who provide services to us. We  do so on a "need to know basis" and in accordance with applicable data protection and data privacy laws.

For example, some personal data will be available to our third-party suppliers who provide us with employment law advice, health and safety support, payroll support services, expenses, tax and travel management services.

Transfers to other third parties

We may also disclose personal data to third parties on other lawful grounds, including:

  • To comply with our legal obligations, including where necessary to abide by law, regulation or contract, or to respond to a court order, administrative or judicial process
  • In response to lawful requests by public authorities (including for national security or law enforcement purposes)
  • As necessary to establish, exercise or defend against potential, threatened or actual litigation
  • Where necessary to protect the vital interests of our employees or another person
  • In connection with the sale, assignment or other transfer of all or part of our business; or
  • With your freely given and explicit consent

Transfer of personal data abroad

We may need to transfer personal data to countries outside of the United Kingdom – in such cases approval by the DPO or a Director is required. When we export your personal data to a different country, we will take steps to ensure that such data exports comply with applicable laws.  For example, if we transfer personal data outside the European Economic Area (EEA), such as to the United States, we will implement an appropriate data export solution such as entering into contracts with the data importer that contain EU model clauses or taking other measures to provide an adequate level of data protection.

Data storage

Your personal data will be stored securely within the Group’s IT systems or on the systems of our trusted suppliers.

Data retention

Personal data will be stored in accordance with applicable laws and kept for as long as needed to carry out the purposes described in this notice or as otherwise required by law. Generally, this means your personal information will be retained until the end or your employment, employment application,

or work relationship with us plus a reasonable period of time thereafter to respond to employment or work-related inquiries or to deal with any legal matters (e.g. judicial or disciplinary actions), document the proper termination of your employment or work relationship (e.g. to tax authorities), or to provide you with ongoing pensions or other benefits.

For more information, please see our Data Retention Policy, which outlines our current document retention schedule.

Your rights

You may exercise the rights available to you under data protection law as follows:

  • The right to be informed.
  • The right of access.
  • The right to rectification.
  • The right to erasure.
  • The right to restrict processing.
  • The right to data portability.
  • The right to object.
  • Rights in relation to automated decision making and profiling.

If you would like to exercise any of your rights or request a copy of some or all of your personal information, please complete the Data Subject Access Request form (available on www.mariposacare.com) No charge will be made for this service.

We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws. You can read more about these rights at:

https://ico.org.uk/for-the-public/is-my-information-being-handled-correctly/ To exercise any of these rights, please contact our DPO.

Issues and complaints

We try to meet the highest standards when collecting and using personal data. For this reason, we take any complaints we receive about this very seriously. We encourage people to bring it to our attention if they think that our collection or use of information is unfair, misleading or inappropriate.  We would also welcome any suggestions for improving our procedures.

This notice was drafted with clarity in mind. It does not provide exhaustive detail of all aspects of our collection and use of personal data. However, we are happy to provide any additional information or explanation needed.

If you want to make a complaint about the way we have processed your personal data, you can contact the Information Commissioner’s Office in their capacity as the statutory body which oversees data protection law – www.ico.org.uk/concerns.

Updates to this notice

This notice may be updated periodically to reflect any necessary changes in our privacy practices. In such cases, we will inform you by email, on the intranet, in team meetings etc. We encourage you to check this notice periodically to be aware of the most recent version.

Contact details

Please address any questions or requests relating to this notice to the Data Protection Officer (DPO) at dpo@careportgroup.com or FAO DPO, Careport Group, Scholes Mill, Old Coach Road, Tansley, Derbyshire, DE4 5FY.

Annex A – Third-Party Processors Key third-party processors

The following are our key third-party processors who will, during your employment, process your

personal data.

Citation (including the Atlas HR System)

We outsource our HR system to Citation who may hold records on all our employees, which may include:

  • Name and address
  • Email address
  • Salary and conditions of employment
  • Performance
  • Disciplinary and grievance notes
  • Qualifications and training records

We outsource our Health and Safety management to Citation, who may hold records on the following:

  • Incidents involving our employees
  • Risk assessments relating to our employees
  • Training records

Citation’s systems use a secure cloud solution. Information on Citation’s security is available by contacting the HR Director.

Altura Maxtime

Azets Holdings Limited NOW Pensions