Data Protection Policy
Introduction: Quest Mentoring is committed to protecting personal data in compliance with the General Data Protection Regulation (GDPR) and other relevant UK data protection laws.
1. Data Collection: We collect personal data necessary for our services, including:
-
Contact details (e.g., names, addresses, email, and phone numbers).
-
Date of birth and relevant demographic information.
-
Educational and health information pertinent to mentoring.
2. Lawful Basis for Processing: Personal data is processed under the following lawful bases:
-
Consent.
-
Contractual necessity.
-
Legal obligation.
-
Legitimate interests.
3. Data Use: Collected data is used to:
-
Deliver and manage mentoring services.
-
Communicate with mentees and their families.
-
Ensure the safety and well-being of mentees.
-
Comply with legal requirements.
4. Data Storage
-
Security Measures: We use encryption and access controls to secure data.
-
Retention Policy: Data is retained only as long as necessary for the purposes it was collected.
-
Disposal: Data that is no longer needed is securely destroyed.
5. Data Sharing Personal data is shared only:
-
When legally required.
-
To protect the safety of mentees.
-
With the data subject's consent.
-
With third parties under strict Data Processing Agreements ensuring GDPR compliance.
6. Rights of Data Subjects Individuals have the right to:
-
Access their personal data.
-
Request corrections to inaccurate data.
-
Request deletion of their data under certain conditions.
-
Object to processing.
-
Withdraw consent at any time.
​
7. Data Breach Procedures In the event of a data breach:
-
We will notify the relevant authorities, such as the Information Commissioner's Office (ICO), within 72 hours if the breach poses a risk to individuals' rights and freedoms.
-
Affected individuals will be informed if there is a high risk to their rights.
​
8. Data Protection Officer (DPO) For any queries related to data protection, please contact our DPO at: markgilbert@live.co.uk
9. Review and Updates This policy will be reviewed annually to ensure compliance and to incorporate best practices.