This Privacy Notice will illustrate how your personal data and, if applicable, special categories of personal data will be used by Horizon Housing Association [Horizon]. It will provide you with information about your rights under the General Data Protection Regulation (EU) 2016/679 [GDPR] and the Data Protection Act 1998 (as amended) [the Data Protection Legislation] and how to action these rights.
Who we are
Horizon is part of the Link group of companies and is committed to protecting your privacy. The Link group is made up of Link Group (the parent company), Link Housing Association, LinkLiving, Link Property, Horizon, Larkfield Housing Association, West Highland Housing Association and Lintel Trust. Each member of the group is registered as a controller with the Information Commissioner’s Office [ICO].
Each Link group company has entered into a Data Processing Agreement with the other Link companies, which sets out clearly how and why information may be shared. This ensures that we can provide you with the services you expect from us at the same time as meeting our data protection obligations.
The data protection principles set out how personal data should be managed.
- 1. Lawfulness fairness and transparency
We need to be clear and upfront about what we use your data for.
- 2. Purpose limitation
We will only use your data for specific reasons which are set out in this guide.
- 3. Data minimisation
We will only collect data which is necessary for us to provide a service to you and will delete data when it becomes out of date.
- 4. Accuracy
We will ensure that any personal data we collect is correct and up to date.
- 5. Storage limitation
We will keep only what’s necessary in line with our Data Retention Schedule
- 6. Integrity and confidentiality
We will ensure we have appropriate security to protect the data we process about you
We aim for this privacy notice to be clear but comprehensive and provide you with all the information you need to understand how we will manage your data.
What is Data?
- Personal data
Personal data means any identifiable information about a living person. This can include:
- Telephone Number
- Date of Birth
- Tenancy Reference Number
- National Insurance Number
- Special categories of personal data
Special categories of personal data are defined as personal data relating to a person’s:
- Racial or ethnic origin
- Political opinions
- Religious or other beliefs
- Trade Union membership
- Sex life or sexual orientation
- Genetic or biometric data used to uniquely identify a person
Horizon is a controller of your personal data. This means that we decide the purpose and conditions of processing of your personal data.
Any supplier, contractor or other third party with whom we share data is called a processor.
What are the conditions of processing?
The conditions of processing are basically the legal reasons for processing your personal data. We have to make it very clear why we process your data. In processing your personal data or special category personal data, Horizon will rely on one or more of the following conditions of processing, depending on what we are using your personal data for:
For Personal Data
You have given your consent to the processing of your personal data.
Processing of personal data is necessary for the performance of a contract with you or for Horizon to take pre-contractual steps at your request.
- Legal Obligation
Processing of personal data is necessary for Horizon to comply with a legal obligation.
- Vital Interests
Processing of personal data is necessary to protect your vital interests or another individual's vital interests (this means life or death situations).
- Public Task
Processing of personal data is necessary for the performance of a task carried out in the public interest or in the exercise of official authority conferred on Horizon.
- Legitimate Interests
Processing is necessary for Horizon’s legitimate interests or a third party's legitimate interests, unless these interests are overridden by your interests or fundamental rights.
For Special Categories of Personal Data
- Explicit Consent
You have given your explicit consent to the processing of your personal data.
- Employment Law
Processing is necessary for carrying out obligations under employment, social security or social protection law.
- Vital Interest
Processing is necessary to protect your vital interests of or another person's vital interests where the data subject is physically or legally incapable of giving consent.
- Legal Claims
Processing is necessary for the establishment, exercise or defence of legal claims.
- Public Interest
Processing is necessary for reasons of substantial public interest, under law.
- Medical Diagnosis and Treatment
Processing is necessary for the purposes of the provision of health or social care or treatment or the management of health or social care systems.
You have a number of rights under the Data Protection Legislation which are outlined and explained below.
- The right to be informed how your personal data is processed
This guide informs you how your data will be processed and sets out clearly Horizon's lawful basis for processing.
- The right to access your personal data
You can submit a Subject Access Request to access the personal data that Horizon holds about you. You can do this by writing to:
Managing Director or Company Secretary
Horizon Housing Association
Or e-mailing: firstname.lastname@example.org
Horizon will then have 30 days to respond to your request. As part of the subject access request process we will ask for two forms of identification to be submitted before any information is released.
- The right to rectification
If any of the personal data we hold about you is wrong, you have the right to ask us to correct it.
- The right to erasure
You may request that Horizon erase any of your personal data that is processed by us. This is also known as the ‘right to be forgotten’. Please note that this is subject to a number of exemptions and so is not an absolute right.
- The right to restrict processing
If you believe that we are processing personal data unlawfully, where it is no longer needed or think that the personal data held is inaccurate you can ask us not to process that personal data.
- The right to data portability
You can ask us to pass on the personal data we hold about you to a third party, where you have provided that personal data to us and we have been processing it to deliver a service to you.
- The right to object
You have the right to object to our processing of your personal data. However, if Horizon can demonstrate that there is an appropriate ‘condition of processing’ in place then we may refuse to stop processing your personal data.
- Rights in relation to automated decision-making and profiling
You have the right not to be subject to a decision solely based on automated processing. If a decision is made by an automated process you may ask Horizon to have the decision investigated by a member of staff.
- How to action your rights under the Data Protection Legislation
If you wish to object to the use of your personal data, would like to restrict processing or have data rectified, please contact email@example.com.
- The right to complain to the ICO
If you have a concern about the way Horizon is processing your personal data, you may raise a complaint with the Information Commissioner’s Office.
Information Commissioner's Office
0303 123 1113
We will never share or sell your personal data to a third party for marketing purposes.
Electronic information that contains personal information is kept in secure systems. Laptop computers and other devices which may be taken out of the office are encrypted and password protected. Any paper files containing personal information are stored in locked filing cabinets.
Horizon Housing Association Care and Repair Privacy Notice
Horizon Housing Association is a Registered Social Landlord and is a subsidiary of Link Group Limited. A registered Scottish Charity, Horizon is also registered with the Financial Conduct Authority and the Scottish Housing Regulator.
Horizon manages Care and Repair services in West Lothian and North Lanarkshire.
- What information do we collect?
To allow us to provide the service you would expect from us, we may process the following information about you:
- Telephone number
- Date of Birth
- E-mail address
- Next of kin (if needed for access arrangements)
- Physical and mental health (if needed for access arrangements)
- Benefits eligibility
- Why we need this information and how it will be used
The reason we collect your information is:
- to enable us to supply you with the services and information which you have requested or expect from us
- to enable us to respond to any complaints made about our services
- to analyse the information we collect so that we can administer, support and improve our business and the services we offer
- to contact you in order to send you details of any changes to our services which may affect you
- for all other purposes consistent with the proper performance of our operations and business
- to contact you for your views on our services.
- Where we store your data
Your personal data will be securely stored electronically on computers, laptops and other devices which are password protected and encrypted. Paper files will be stored in locked cabinets.
- How long we will keep your information
We review our data retention periods regularly and will only hold your personal data for as long as is necessary for the relevant activity, or as required by law (we may be legally required to hold some types of information), or as set out in any relevant contract we have with you. For example, adaptation files will normally be held for 12 months after the work has been completed.
We will generally keep your information for the minimum period stated on our retention schedule, after which it will be destroyed if it is no longer required for the reasons it was obtained.
Our full retention schedule is available here.
- Sharing your Information
The information you provide to us will be treated by us as confidential.
We may disclose your information to third parties who act for us for the purposes set out in this notice or for purposes approved by you, including the following:
- If we enter into a joint venture or merge with another business entity, your information may be disclosed to our new business partners or owners;
- If we instruct adaptation or maintenance works, your information may be disclosed to any contractor;
- If we are conducting a survey of our products and/or service, your information may be disclosed to third parties assisting in the compilation and analysis of the survey results;
- If we refer you to the Scottish Fire and Rescue Service for a home safety check;
- If we apply to charities for funding towards your adaptation;
- In the event that we are unable to provide the service requested, we may share your details with another support service.
- Receiving data about you
We may receive the following information from third parties:
- Benefits information;
- Referrals from Council employed occupational therapists;
- Service requests from other parties including relatives and voluntary organisations
- Updating your information
If your details change, please contact 0330 303 0089 or firstname.lastname@example.org to inform us to ensure that all of the information we hold about you is up to date.