Privacy Policy
We are committed to protecting your personal data and handling it with transparency, care, and respect.
Who We Are
SENFOCUS is a dedicated support organisation delivering programmes for children and young people with special educational needs and disabilities (SEND). We believe every child deserves the opportunity to thrive, and our work is guided by that commitment.
For the purposes of UK data protection law, SENFOCUS acts as the Data Controller — meaning we determine how and why your personal data is processed.
Data protection enquiries can be directed to us at info@senfocus.co.uk. We aim to respond to all requests within 10 working days.
Personal Data We Collect
We collect only the personal data that is necessary to deliver safe, effective, and well-supported programmes. This may include:
- Parent & guardian names
- Child participant details
- Contact information
- Medical & emergency information
- Attendance records
- Payment records
- Website usage data
- Photographs & video recordings
- Communication records
Medical and special educational needs information is classified as special category data under UK GDPR and is handled with the highest level of care and security.
How We Collect Data
We collect personal data through the following channels:
- Registration forms — completed when joining a programme
- Consent forms — signed prior to participation
- Website submissions — via contact or enquiry forms on senfocus.co.uk
- Programme participation — through attendance, activities, and progress records
- Email communication — correspondence with parents, guardians, or referrers
- Cookies & website analytics — automatically when you visit our website
Why We Collect Personal Data
We process personal data only for clear, legitimate purposes. These include:
- Delivering safe and effective support programmes
- Maintaining safeguarding records in compliance with legal requirements
- Communicating with parents, guardians, and carers
- Meeting our legal and regulatory obligations
- Reporting to donors and funding organisations on programme impact
- Demonstrating outcomes and improving service delivery
- Managing funding requirements and grant conditions
Legal bases under UK GDPR — all processing is underpinned by at least one of the following lawful bases:
Photography & Media Use
SENFOCUS may capture photographs and video recordings during programme activities. Under UK GDPR, images and recordings of identifiable individuals are treated as personal data and are handled accordingly.
Recordings may be used for the following purposes:
- Programme documentation and internal records
- Reporting to donors and funding partners
- Public awareness and community engagement
- Staff training and safeguarding review
- Promotional materials and social media
Participation in SENFOCUS programmes requires agreement to media capture and use as outlined in the consent form provided at registration. If you have concerns about media use, please contact us before a session begins.
Data Storage & Security
We are committed to keeping your personal data secure. Our safeguards include:
- Secure systems with restricted access controls
- Password protection and multi-factor authentication where applicable
- Regular data backups to prevent loss
- Access limited to authorised staff and volunteers only
While no digital system can guarantee absolute security, we continuously review and strengthen our practices to protect against unauthorised access, loss, or disclosure.
How Long We Keep Data
We retain personal data only for as long as it is necessary for the purposes for which it was collected. Retention periods are determined by:
- Legal obligations — such as safeguarding and employment law requirements
- Safeguarding requirements — which may require records to be held for extended periods
- Funding and reporting needs — as required by grant agreements
When personal data is no longer required, it is securely and permanently deleted in line with our data retention schedule.
Sharing Personal Data
We do not sell personal data. We may share data with trusted third parties only where necessary and lawful, including:
- Safeguarding authorities — where we have a legal duty to disclose
- Funding organisations — to fulfil grant reporting obligations
- Professional service providers — such as auditors or legal advisors, under strict confidentiality
- IT and cloud storage providers — who process data on our behalf under Data Processing Agreements
Where data is shared with third parties outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR transfer rules.
Your Rights Under UK GDPR
Under UK data protection law, you have the following rights regarding your personal data:
Request a copy of the personal data we hold about you.
Ask us to correct inaccurate or incomplete data.
Request deletion of your data where there is no lawful reason to retain it.
Ask us to limit how we use your personal data.
Object to processing based on legitimate interests.
Request your data in a structured, machine-readable format.
To exercise any of these rights, please submit a written request to info@senfocus.co.uk. We will respond within one calendar month in line with UK GDPR requirements.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Cookies
Our website uses cookies — small text files stored on your device — to improve your experience and understand how visitors use our site. We use cookies for:
- Essential functionality — to keep the site working correctly
- Analytics — to understand which pages are visited and how users navigate the site
- Session management — to maintain continuity during your visit
You can control or disable cookies at any time through your browser settings. Please note that disabling certain cookies may affect website functionality. For more information, see your browser's help documentation.
Data Breaches
Despite our security measures, data breaches can occur. If a breach poses a risk to your rights and freedoms, we will:
- Investigate immediately and take steps to contain the breach
- Notify affected individuals directly where required
- Report the breach to the Information Commissioner's Office (ICO) within 72 hours, where legally required
We maintain an internal record of all data breaches, regardless of whether ICO notification is required, in line with our accountability obligations under UK GDPR.
Policy Updates
We may update this Privacy Policy periodically to reflect changes in our practices, services, or legal requirements. The most current version will always be available on our website at senfocus.co.uk.
Where changes are significant, we will make reasonable efforts to notify affected individuals directly. We encourage you to review this policy periodically.
Questions About Your Data?
We're here to help. If you have any questions about this policy or how we handle your personal data, please get in touch.
📧 info@senfocus.co.uk