Skip to content Skip to footer

Citizens Advice East End Privacy Policy – Paid Staff and Volunteers

Policy last reviewed 13 March 2024

If you are a client of Citizens Advice East End, please see our main privacy policy.

At Citizens Advice we collect and use your personal information relating to our paid staff and volunteers to help manage our service. As a paid employee or volunteer, you have a number of rights regarding your personal information:

  • The right to be informed about how we will use your personal data;
  • The right to access a copy of any personal data we hold about you;
  • The right to have personal data rectified if it is inaccurate or incomplete;
  • The right to request the deletion or removal of personal data;
  • The rights to restrict and object to processing of personal data;
  • The right to obtain and reuse your personal data for your own purposes;
  • Rights in relation to automated decision making and profiling;
  • The right to withdraw your consent for the processing of your personal data;
  • The right to lodge a complaint with us and/or the Information Commissioner’s Office.

We only ask for the information we need. We always let you decide what you’re comfortable telling us, explain why we need it and treat it as confidential.

When we record and use your personal information we:

  • Only access it when we have a good reason;
  • Only share what is necessary and relevant;
  • Don’t sell it to anyone.

At times we might use or share your information without your permission. If we do, we’ll always make sure there’s a legal basis for it. This could include situations where we have to use or share your information:

  • To comply with the law – for example, if a court orders us to share information. This is called ‘legal obligation’;
  • To protect someone’s life – for example, sharing information with a paramedic if a client was unwell at our office. This is called ‘vital interests’;
  • To carry out our legitimate aims and goals as a charity – for example, to create statistics for our national research. This is called ‘legitimate interests’;
  • For us to carry out a task where we’re meeting the aims of a public body in the public interest – for example, delivering a government or local authority service. This is called ‘public task’;
  • To carry out a contract we have with you – for example, if you’re an employee we might need to store your bank details so we can pay you. This is called ‘contract’;
  • To defend our legal rights – for example, sharing information with our legal advisers if there was a complaint that we gave the wrong advice.

We handle and store your personal information in line with the law – including the UK General Data Protection Regulation and the Data Protection Act 2018.

You can check our main privacy policy for how we handle our clients’ and service users’ personal information.

How we store your information

This page covers how we store and handle paid staff and volunteer information locally in our offices.

For everybody in the charity

Microsoft provides hosted email and collaboration tools through Office 365. You can access the data processing agreement we have with Microsoft here. The following personal data is recorded in Microsoft Entra which provides identity information to Office 365: your full name, your login name, your work email address, your encrypted password, your work address, your job-role, your relationship with your manager and those who you manage (if applicable). You may optionally provide your mobile phone number and/or a secondary email address for password recovery or multifactor authentication. This information is used to provide email and collaboration services that are relevant to your work.

We also subscribe to Google’s Workspace collaboration product to facilitate the management of Citizens Advice East End mobile devices, and access to information resources provided by National Citizens Advice. You can view the data processing agreement we have with Google here. The following personal data is recorded in Google Workspace: your full name, your login name, and your email address. If you have access to a Citizens Advice East End owned Chromebook or Android phone, the details of the device you use are also stored in Google’s Workspace product in a way that relates your login to the device’s unique identifier. In addition to the core Google Workspace products, we use Google Analytics and Google My Business to understand how our website is used, and you use the same login information for these services as for the core Workspace product.

If you use a personal device such as a laptop, tablet, or mobile phone, we keep a record of that device that includes a unique identifier, make, model, and operating system type and version linked to your login name in the device management system, Microsoft Intune.

Our SMS service is hosted by VoodooSMS. You can view the VoodooSMS privacy policy here. If you have requested and been given a personal login to use the SMS service, VoodooSMS will have a record of your full name, work email address, and, optionally, your work phone number and mobile phone number. When creating your login, the IT team enters a randomly generated phone and mobile number, and you do not have to provide any information other than your name and work email.

Our helpdesk service is provided by ManageEngine, a Zoho company. You can view the ManageEngine privacy policy here. The following personal data is recorded in the helpdesk: your full name, your email address, your work telephone number (where applicable) and the site(s) you work at. This information is recorded to help the IT team get in touch with you when you request IT support.

Our website is an instance of WordPress hosted by GoDaddy. You can view the GoDaddy privacy policy here. If you have been granted access to edit or update the Citizens Advice East End website, a record of your full name and email address is stored within the WordPress instance.

The IT team also uses a knowledge management product called Confluence, which is hosted by Atlassian. You can view the Atlassian Privacy Policy here. We store documentation about the IT equipment and IT services that we offer. Atlassian store the email address and full name of authorised users of this site. The IT documentation we maintain has a record of your name and email address under the following circumstances: (a) you have borrowed an item of Citizens Advice East End equipment such as a laptop, tablet, or phone; or (b) you are responsible for managing volunteers, and have information about volunteer Office 365 login accounts passed to you; or (c) you are responsible for managing information about our IT services.

Records relating to your employment or volunteering with us are held online in our Office 365 SharePoint sites. Only authorised staff are permitted to access these records in their day-to-day job roles.

Your name and Citizens Advice East End email address is recorded in the minutes of meetings, which are held online in our Office 365 SharePoint sites. Minutes of team meetings and committee meetings are generally available to all members of the organisation, and may be shared with third parties such as our auditors or National Citizens Advice.

For paid employees

Pay and pensions

Moorepay Ltd are our payroll bureau who are under contract to us, and run the monthly payroll and submit the BACs instruction to pay you your net pay.  You can view Moorepay’s privacy policy here. From May 2018’s payroll they will also arrange the payment of the PAYE and NI to HMRC.  They hold your name, date of birth, address, NI number, gender, salary rate, number of hours worked, pension contribution rates and your starting and leaving dates in order to be able to calculate your pay and so that they can report your salary figures and deductions to HMRC on the charity’s behalf as required by law.  You can view HMRC’s privacy charter here.

The charity has an auto enrolment pension scheme with TPT Retirement Solutions who hold your name, date of birth, address, NI number, gender, salary rate, number of hours worked and pension contribution amounts as well as your starting and leaving dates to be able to process your pension payments.  You can view the TPT Retirement Solutions privacy policy here.

The charity has a pension scheme with Aviva for certain employees. Aviva hold your name, date of birth, address, NI number, gender, salary rate, number of hours worked and pension contribution amounts as well as your starting and leaving dates to be able to process your pension payments.  You can view the Aviva privacy policy here.

Certain employees are members of the NACAB Pension Scheme, which holds the information given below. Citizens Advice act as our representative for this Pension Scheme. So, both national Citizens Advice and the NACAB Pension Scheme have this information regarding the members of the scheme.  National Citizens Advice have a data sharing agreement directly with the pension provider.

The following personal information is held by the NACAB Pension Scheme and National Citizens Advice:

Personal data, including name, gender, national insurance number, date of birth, home address and telephone number, personal e-mail address, current or former employer, the date the member joined and left employment and his/her employment status (for example, full time or part time), dates on which the member joined and left pensionable service, salary information, normal or anticipated retirement date, status as a member of the Plan, information relating to contributions to and benefits under the Plan (including any contracted-out benefits), information relating to any money purchase benefits in the Plan (including how these are invested), information relating to any pension sharing or earmarking order, tax information including members’ income tax band and any protections in relation to a member’s pension benefits, bank account details.

Special categories of personal data including marital status and family and/or dependants (for example, in relation to death benefits); information relating to health (for example, if a member cannot work any longer due to incapacity and wants to take his/her pension benefits early).

Other

Some staff may be members of a trade union. The trade union holds your name, address, gender, date of birth, NI number, payment frequency, payroll number and subscription amount to be able to check that you have paid the correct subscription amount compared with the level of benefits you have requested.  You can view the Unite the Union’s privacy policy here.

Citizens Advice East End’s auditors are RPG Crouch Chapman LLP. When conducting the annual audit of our accounts, our auditors may view the following information: staff contracts and payroll reports which include staff name, date of birth, NI number, and address. Auditors may also see pension reports which include staff name, date of birth, NI number, address and the percentage we and staff pay into the staff-member’s pension scheme.

We use uCheck to process DBS checks. You can view their data processing arrangement with us, and their applicant privacy policy.

For trustees

Information about trustees, including names and contact information, is shared with Companies House, the Charity Commission, and the Financial Conduct Authority for regulatory purposes.

Changes to this policy

13 March 2023: First publication: separated service user and employee/volunteer policies.