How we use your data
Goodbase Digital Ltd (“Goodbase”, “we”, “us”) is a company registered in England and Wales, company number 12581462, with its registered office at Unit 1c Eagle Industrial Estate, Church Green, Witney, Oxfordshire OX28 4YR. We are registered with the Information Commissioner’s Office under reference ZA793153 (opens in a new tab).
We handle personal data in two distinct roles, and your rights differ depending on which one applies:
- As a data controller — for visitors to this website, people who email us, and the contacts at our client organisations. We decide why and how this data is used. Part 1 covers this.
- As a data processor — for the personal data held inside the systems we build and run for our clients. Our client decides why and how that data is used, and we act only on their instructions. Part 2 covers this.
If you are an individual whose data sits in a system we operate for one of our clients — for example a foster carer, volunteer, mentor or someone using a service — Goodbase is not the controller of your data. Please contact the organisation you deal with directly. Their privacy notice, not this one, explains how your data is used.
Part 1 — Where Goodbase is the data controller
Visitors to our website
We do not use cookies, analytics, tracking pixels, embedded fonts or any similar technology on www.goodbase.co.uk, and we do not operate a server that records your visit. This site makes no requests to any third party.
The site is hosted on GitHub Pages. As with any website, your device’s IP address is necessarily transmitted to GitHub’s servers in order to deliver these pages to you. We have no access to that information and hold no record of your visit. GitHub’s privacy statement explains what GitHub does with it.
People who email us
If you email us, we hold your message and your contact details so that we can reply and keep a record of our correspondence.
- Lawful basis: our legitimate interests (Article 6(1)(f)) in responding to enquiries addressed to us.
- How long we keep it: two years after our last correspondence with you. If we go on to work together, we keep it for the period described under Our clients and prospective clients below.
We use Google Workspace to manage and store our email. See Who else handles your data below.
Our clients and prospective clients
When you contract with us, or you are a named contact at an organisation that does, we collect the following, without which we cannot provide our services:
- Your name and job role
- Company name and company details
- Telephone number
- Address
- Email address
We use it for the following purposes, relying on the lawful basis shown against each:
- Delivering our services, and communicating with you about technical issues on your project — performance of a contract (Article 6(1)(b)) where you contract with us personally, and otherwise our legitimate interests (Article 6(1)(f)) in administering the client relationship.
- Sending invoices, reminders and statements — as above.
- Keeping accounting and tax records — a legal obligation (Article 6(1)(c)) under the Companies Act 2006 and HMRC requirements.
- Notifying you of changes to our terms and conditions — a legal obligation, or our legitimate interests in keeping you informed.
- Telling you about changes to our service, such as new team members or price changes — our legitimate interests (Article 6(1)(f)) in keeping clients informed about a service they use.
Where a message from us is not strictly necessary to providing your service, we will always give you a way to stop receiving similar messages. Reply to any message, or email privacy@goodbase.co.uk to express your preference.
How long we keep it: for the duration of our relationship, and then for six years after our final invoice. That is the period for which we must retain accounting records, and the limitation period for contractual claims.
Who else handles your data
We use a small number of suppliers to run our business. Those that handle personal data on our behalf do so under contract and on our instructions only:
- Google (Google Workspace) — email, documents and calendars.
- GitHub — hosting this website.
- Our accounting and bookkeeping software provider — invoicing and accounts.
We do not sell your information, and we do not share it for anyone else’s marketing. We may work with a trusted delivery partner on a project, and where that happens we will always tell you in advance. If you would like the suppliers that hold your personal information named individually, email privacy@goodbase.co.uk and we will tell you.
Sending data outside the UK
Our email provider, Google, is based in the United States. Google is certified under the UK Extension to the EU–U.S. Data Privacy Framework, which the UK government has recognised as providing an adequate level of protection for personal data. Your data therefore receives essentially equivalent protection to that required under UK law.
Our contract with Google also incorporates the Information Commissioner’s International Data Transfer Addendum to the EU Standard Contractual Clauses, as a fallback safeguard. You can request details by emailing privacy@goodbase.co.uk.
This website is hosted by GitHub, also based in the United States and certified under the same framework. As explained above, we do not send GitHub any information about you. Your IP address reaches GitHub directly, as our host, in order to deliver these pages to you.
Your rights
Under UK GDPR you have the right:
- To be informed about how your data is used — this notice, along with email updates when things change
- To request a copy of the personal data we hold about you
- To have inaccurate data corrected
- To have your data erased
- To restrict how we process your data
- To data portability
- To object to processing based on legitimate interests
- Not to be subject to solely automated decision-making
Not all of these rights are absolute. For example, we cannot erase records that we are legally required to keep for tax purposes.
To exercise any of them, email privacy@goodbase.co.uk. We will respond within one month, and there is no charge.
Automated decision-making
We do not make decisions about you by solely automated means, and we do not carry out profiling.
If something goes wrong
If we suffer a personal data breach affecting your data, we will report it to the Information Commissioner’s Office within 72 hours where the law requires it, and tell you directly without undue delay where the breach is likely to result in a high risk to you.
You have the right to complain to us at privacy@goodbase.co.uk. If you are unhappy with our response, you have the right to complain to the Information Commissioner’s Office.
Part 2 — Where Goodbase is the data processor
Our work for a client typically involves the development, deployment and support of a data control system for their organisation.
The data in that system remains our client’s data throughout. They are the controller and we are the processor, and we only process it on their documented instructions.
Our data processing agreement
Before we process any personal data for a client, we sign a data processing agreement meeting the requirements of Article 28 of UK GDPR. It commits us to:
- Processing only on the client’s documented instructions
- Ensuring that everyone with access is bound by confidentiality
- Appropriate technical and organisational security measures, set out in full in the agreement
- Helping the client respond to requests from individuals exercising their rights
- Helping the client with data protection impact assessments and breach reporting
- Returning or deleting the data at the end of the contract, at the client’s choice
- Making information available for audit
Sub-processors
We use a small number of sub-processors to deliver our service, principally cloud hosting providers.
Every sub-processor is named specifically in the data processing agreement we sign with each client, together with the service it provides and the country in which it processes data. We do not add or change a sub-processor without our client’s prior written agreement.
We impose the same data protection obligations on every sub-processor by contract, and we remain fully liable to our client for their performance. A current list, reflecting each client’s agreed schedule, is available to clients on request.
Where client data is held
We host client systems in the United Kingdom or the European Economic Area, so client data is not subject to a restricted international transfer.
Where a client requires or agrees to processing elsewhere, that is set out specifically in their data processing agreement, together with the transfer mechanism and the safeguards that apply.
Security breaches
If we become aware of a personal data breach affecting a client’s data, we will notify that client without undue delay, so that they can meet their own reporting duties. Our notification will include, so far as we know it at the time:
- The dates and times of the security event
-
The details of the event including:
- A description of the data involved in the event
- The facts of the event or details of the decision to investigate a suspected event
- The steps we are taking or planning to take to remedy or mitigate the vulnerability
Changes to this privacy notice
We keep our privacy notice under regular review, and we will tell clients by email about any material change. This privacy notice was last updated on , and replaces our previous notice of .
How to contact us
Our data protection lead is Vicky Close. For any question, request or complaint about this notice or about how we handle data, email privacy@goodbase.co.uk.