Privacy policy.
Updated July 2026 Next Review June 2027
Who we are
Revelation Community is committed to protecting your personal data. Under the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and the Data (Use and Access) Act 2025, Revelation Community is a Data Controller. This Privacy Notice explains how we collect, use, store and protect (“process”) the personal information you entrust to us.
If you have any questions about this Notice or the way we handle your personal data, please contact:
Andy Haddow - Data Protection Officer
Email: andy@revelation.org.uk
Address: Revelation Community, 104 The Hornet, Chichester, PO19 7JR
The personal data we process
We collect and process personal data in connection with the general administration of the church, our projects and our charitable purpose. This includes information you give us when you complete a Get Connected card, register on ChurchSuite, sign up to one of our groups (RevsKids, RevsYouth, Sparklers), volunteer, attend an event, make a donation, contact us by email, or visit our website.
The personal data we process may include:
name, address, email, telephone number;
date of birth, age, gender, family/next-of-kin information;
attendance and membership records;
volunteer applications, agreements and training records;
DBS information and references for those working with children or vulnerable adults;
financial information relating to donations, Gift Aid and event payments;
pastoral notes and support records;
consent records (including marketing, photography and cookie consents);
IP address, device information and other technical data when you visit our website.
Special category data
Some of the information we hold is treated as “special category” data under the UK GDPR. We aim to keep this to a minimum, but we do hold:
Religious belief - implicit in church membership and explicit on Get Connected cards and similar forms. We process this on the basis of Article 9(2)(d) UK GDPR (legitimate activities of a not-for-profit body with a religious aim) and only in respect of our members and people in regular contact with us.
Health information - for example, dietary, medical or accessibility information you give us on RevsKids, RevsYouth or Sparklers consent forms, or sickness absence information for staff. We process this with your explicit consent, or where necessary for employment, social security or social protection law, or to protect someone’s vital interests.
Where we process special category data, we do so in line with our internal Data Protection and Privacy Policy and our Appropriate Policy Document.
Criminal records data
We process criminal records data, for example through DBS disclosures, only as necessary for safeguarding and in line with the substantial public interest condition in Schedule 1 of the Data Protection Act 2018.
Children
We process personal data about children through RevsKids, RevsYouth and Sparklers. Where we rely on consent, we obtain parental or guardian consent for children under 13. Privacy information is given to children in clear, age-appropriate language and parents/guardians may withdraw consent at any time.
Cookies
Our website uses cookies and similar technologies. Strictly necessary cookies are used without consent. Analytics and functionality cookies are used in line with the relaxed rules introduced by the Data (Use and Access) Act 2025 (in force from 5 February 2026), which allow such cookies to be set without prior consent provided we give clear information and an easy opt-out. All other cookies, including advertising and third-party cookies,are only set with your prior consent. Please see our Cookie Policy on the website for full details and to manage your preferences.
How we use your personal data
We use your personal data for the following purposes:
to provide a service for the benefit of the public in the geographical area specified in our governing document;
the day-to-day administration of the church and its projects, including managing attendance records, preparing rotas, maintaining financial records and managing employees and volunteers;
to provide pastoral care, including calls and visits;
to operate the Revelation Community website and social media accounts and deliver the services you have requested;
to inform you of news, events, activities, resources and services consistent with our charitable purpose;
to fundraise for, and promote the work of, the Charity;
to maintain our own accounts and records (including Gift Aid claims to HMRC);
to conduct surveys and research that help us evaluate our activities and services; and
to fulfil our legal and regulatory obligations, including in relation to safeguarding.
Our lawful bases
We rely on the following lawful bases under Article 6 UK GDPR:
Consent - where you have given us specific permission, for example to receive certain marketing emails (where consent is required), to use your image on promotional material, or to set non-essential cookies. You can withdraw consent at any time without affecting prior processing.
Contract - where we need to process your data to provide a service you have asked us to provide, or to take steps before entering a contract, for example, registering a child for RevsKids or signing up for a paid event.
Legal obligation - where the law requires us to process your data, including HMRC and Gift Aid records, statutory employment records, accident records and safeguarding referrals.
Vital interests - to protect someone’s life in an emergency.
Legitimate interests - for the everyday running of the Charity, including communicating with attendees, providing services, coordinating volunteers and statistical analysis. We always balance our interests against your rights.
Recognised legitimate interests - a new lawful basis introduced by the Data (Use and Access) Act 2025 covering, among other things, safeguarding vulnerable individuals and responding to emergencies. We rely on this basis for certain safeguarding activities.
For special category data we rely on the Article 9 conditions described above.
Marketing
We may contact you with information about our charitable activities, events and fundraising. We do this in line with the Privacy and Electronic Communications Regulations 2003 (“PECR”) and the Data (Use and Access) Act 2025:
where you have given us consent to receive marketing by email, SMS or social media direct message; or
under the new charitable soft opt-in (in force from 5 February 2026), where you have expressed an interest in or offered to support our charitable purpose. In that case, we will tell you when we collect your details and give you an easy way to opt out at that point and in every subsequent communication. The charitable soft opt-in only applies to communications about our charitable purpose; it does not apply to the sale or promotion of products or services.
You have an absolute right to object to direct marketing at any time. To opt out, please use the unsubscribe link in any of our emails, contact us at andy@revelation.org.uk, or write to us at the address above.
Disclosure of your personal data
Your personal data is treated as strictly confidential. Within Revelation Community, access is limited to authorised individuals — staff, the leadership team and Trustees — on a need-to-know basis.
We share personal data with the following categories of recipient where necessary:
Our cloud and software providers acting as processors - including ChurchSuite, Google (Workspace), Xero and Slack;
Payment and donation platforms - for processing event payments and donations;
HMRC - for Gift Aid claims;
Regulators and statutory authorities - including the Charity Commission, the ICO and, where required, the police, social services or local safeguarding partners;
Professional advisers - for example our auditors, insurers and legal advisers, where required.
We do not sell or rent your personal data, and we do not pass it to other organisations or individuals for their own use without your consent, except where we are legally required or permitted to do so (including for safeguarding purposes).
International transfers
Some of our cloud and software providers, notably Google Workspace and Slack, are operated by US-headquartered companies and may transfer or process personal data outside the UK in the ordinary course of providing the service. Where this happens, we rely on appropriate safeguards under the UK GDPR, including:
the UK extension to the EU–US Data Privacy Framework (where the relevant entity is certified);
the International Data Transfer Agreement (“IDTA”) or the UK Addendum to the EU Standard Contractual Clauses (“SCCs”); and
additional technical and organisational measures (such as encryption in transit and at rest).
Other providers, including ChurchSuite, are UK-hosted.
If you would like more detail about the safeguards we rely on for any specific transfer, please contact the Data Protection Officer.
How we protect your personal data
We have put in place security measures designed to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. Access to ChurchSuite, Xero, Google Workspace and Slack is restricted to authorised staff, the Core Leadership Team, Trustees and volunteer Team Leaders, all of whom are subject to a duty of confidentiality. All of our data processing platforms are password-protected and use multi-factor authentication where available.
In the unlikely event of a personal data breach, we have procedures in place to identify and contain the issue and to mitigate any damage or risk of harm. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) without undue delay and, where feasible, within 72 hours. Where it is likely to result in a high risk, we will also notify you in clear, plain language, with information about what has happened, the likely consequences, and the steps we are taking.
You can find more information about the ICO’s data breach reporting at https://ico.org.uk.
We may anonymise your personal data so that you can no longer be identified from it, in which case we may use that anonymised information indefinitely without further notice to you.
Our website may include links to third-party websites, plug-ins and applications. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party sites and are not responsible for their privacy statements. We encourage you to review the privacy notice of any website you visit through a link from ours.
Data retention
We keep your personal data for no longer than is reasonably necessary for the purposes for which it was collected, and in compliance with our Finance Policy, Safeguarding Policy and applicable law.
Category of data
Examples
Retention period
Reason for retention
Personnel / HR records
Employee contracts, training, performance reviews
6 years after employment ends
Limitation Act 1980, potential claims, safeguarding
Volunteer records
Volunteer applications, agreements, training records
3 years after volunteering ends
Operational reasons, safeguarding
Safeguarding / child protection records
Disclosures, concerns, incidents
Generally 7 years after involvement ends, longer where guidance requires
Safeguarding best practice
DBS disclosure information
Certificate number, date, level, decision
Generally no longer than 2 Years
DBS Code of Practice
Financial records
Invoices, receipts, expenses, donations, Gift Aid
7 years (current + 6)
HMRC / tax compliance
Attendance / membership records
Church membership and attendance lists
3 years after last contact or involvement
Operational and historical records
General communications
Emails, general correspondence
2 years (or as needed for operational use)
Operational reasons
Health & safety records
Accident book entries, risk assessments
3 years (longer for incidents involving minors)
Health and safety legislation
Marketing / mailing lists
Mailing lists, consent records, soft opt-in records
Until consent is withdrawn or opt-out is exercised; otherwise 2 years after last engagement
PECR / direct marketing compliance
Pastoral care / support records
Notes, support logs
3 years after last pastoral contact
Pastoral care and safeguarding
Data subject rights requests
Access, rectification, erasure, objection requests
3 years
ICO guidance on complaints handling
CCTV / surveillance footage
CCTV recordings
30 days, unless required for incident investigation
Best practice and ICO guidance
Photos / video for promotional use
Images of identifiable individuals
While consent is in force; reviewed every 3 years
Consent-based processing
Your rights
Subject to certain exceptions in the UK GDPR and the DPA 2018, you have the following rights in relation to your personal data:
the right to request a copy of the personal data we hold about you (a “subject access request”);
the right to ask us to correct inaccurate or out-of-date personal data;
the right to ask us to erase your personal data where it is no longer necessary for the purposes it was collected for;
the right, where there is a dispute about accuracy or processing, to ask us to restrict further processing;
the right to data portability, where data is processed by automated means;
the right to object to processing in certain circumstances; your right to object to direct marketing is absolute;
the right to be informed when automated decision-making and profiling are used and to ask for human intervention;
the right to withdraw your consent at any time, where consent is the lawful basis we rely on. Withdrawing consent does not affect the lawfulness of processing carried out before your withdrawal.
We will respond to your request without undue delay and at the latest within one calendar month of receipt. Where a request is complex or numerous, we may extend that period by up to two further months and will let you know if we need to do so.
For more information about your rights, please visit the ICO’s website: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/.
Automated decision-making and profiling
We do not use any form of solely automated decision-making with legal or similarly significant effects in the running of the Charity. If this position changes, we will update this Privacy Notice and tell you about your rights to seek human intervention and to challenge the decision.
Keeping your data up to date
We try to ensure the personal data we hold is accurate and up to date. Please tell us if any of your details change, for example your address or contact number, by emailing andy@revelation.org.uk so that we can update our records.
How to make a complaint
If you are unhappy with how we have handled your personal data, please contact our Data Protection Officer in the first instance:
Andy Haddow - Data Protection Officer
Email: andy@revelation.org.uk
FAO Data Protection Officer
Revelation Community
104 The Hornet
Chichester
PO19 7JR
We will acknowledge your complaint within 30 days and provide a substantive response within a reasonable period thereafter.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: https://ico.org.uk
Changes to this Notice
We review this Privacy Notice at least annually. Any changes will be reflected in the version date below. The next scheduled review is June 2027, or earlier if required.
Version
Date
Notes
1.0
June 2024
Original notice
2.0
June 2025
Annual review
3.0 (DRAFT)
June 2026
Annual review; updated to reflect Data (Use and Access) Act 2025; honest position on special category data and international transfers; added charitable soft opt-in, post-DUAA cookies, recipients, complaints procedure, children’s data and photos/video.
Revelation Community — Company number 07381412
104 The Hornet, Chichester, PO19 7JR
