Secret Garden Data Protection Policy
Data Protection and GDPR Policy
Secret Garden - Page Hall Medical Centre
Last reviewed 10/9/26
1. Statement of Intent
The Secret Garden Page Hall values the privacy of all participants and visitors. We are committed to protecting any personal information shared with us in line with UK Data Protection law and the General Data Protection Regulation (GDPR).
We only collect and use personal information where it is necessary to support communication about the garden group and activities, and we do so transparently and fairly.
2. Personal Data We Collect
● Names (if provided)
● Phone numbers (if provided)
● Email addresses (if provided)
Providing personal details is entirely voluntary. Participants may join garden sessions without sharing any personal information.
3. Purpose of Collecting Data
Personal contact details are collected solely to:
● Share information about weekly garden sessions and related activities.
● Notify participants of changes, cancellations, or special events.
No other use of personal data will take place without prior consent.
4. Legal Basis for Processing
The legal basis for processing personal data is consent. We will only keep and use contact details where individuals have freely chosen to provide them.
Consent can be withdrawn at any time by contacting the group coordinator.
5. How Data is Stored and Shared
● Contact details will be stored securely (e.g. on a password-protected document or system managed by the coordinator).
● Access will be limited to the garden group coordinator and designated session leaders.
● GP practice staff may, with explicit verbal permission from the individual, use the practice’s communication streams to share further information about the garden or related activities.
6. Data Sharing
We will never sell, trade, or pass on personal data to third parties. Information will only be shared where:
● The individual has given clear consent, or
● It is required by law.
7. Retention of Data
● Contact details will be kept for as long as a person is actively involved in the garden group.
● If a person leaves the group or withdraws consent, their details will be securely deleted within one month.
8. Individual Rights
In line with GDPR, participants have the right to:
● Access the personal data we hold about them.
● Request corrections to inaccurate information.
● Request deletion of their data.
● Withdraw consent for use of their data at any time.
● Complain to the Information Commissioner’s Office (ICO) if they believe their rights have been breached.
9. Data Breach
In the event of a data breach (e.g. loss, theft, or unauthorised access of personal data):
● The coordinator will take immediate action to secure information.
● Affected individuals will be informed promptly.
● Where legally required, the ICO will be notified within 72 hours.
10. Review
This policy will be reviewed annually or sooner if laws, guidance, or group practices change.
10/9/26
