Important Update: We’ve Refreshed Our Privacy Policy!

We are committed to protecting your personal information and being transparent about how we collect, use, and safeguard your data. To ensure we meet the highest standards for data privacy and to reflect recent improvements to our services, we’re announcing an update to our Privacy and Cookie Notice, effective 25th November 2025.

What’s Changing?

While our fundamental commitment to your privacy remains the same, we’ve made changes to make the policy clearer, easier to understand, and to better address new features and regulatory requirements.

Here is a summary of the detailed information now included in the policy:

1. Who We Are and Basis for Processing

The policy applies to My Charity University Hospital Sussex (registered charity 1050864). We process your personal information based on one of five lawful grounds:

Consent

Contractual Necessity

Legal Obligation

Legitimate Interest (for us or the data subject)

Public Interest

Our processing aligns with the Data Protection Act 2018 (UK GDPR) and the Privacy and Electronic Communications Regulations.

2. Personal Information Collected

We collect various types of personal data, divided into four categories, plus a special category for sensitive information:

Category Examples of Data
Identification Information Name, date of birth, contact details (email, phone, address), photography, and film.
Personal Life Information Family connections, job role, organization type, and activities of interest.
Economic and Financial Information Bank details, credit/debit card details, and UK taxpayer status (for Gift Aid).
Connection Information Browser information, device data, and location data.
Special Category (Sensitive) Health/medical information and criminal convictions (collected only when there is a clear reason).
3. How Information is Used and Collected

We collect information when you engage with us, such as when you ask about services, donate, register for an event, volunteer, engage with social media, or purchase items from our shop.

Our uses of this information are tied to the legal bases:

Contractual Necessity: To fulfill shop orders, administer raffles, and process direct debit donations.

Legal Obligation: For compliance with laws, administering your legal rights requests, and fraud prevention/money laundering monitoring.

Consent: For event participation, fundraising appeals, sharing photography/case studies, and giving information about celebratory donations.

Legitimate Interest: To process donations, send postal marketing (unless you opt out), for internal record-keeping, event management, identifying new supporters, data quality analysis, profiling, and using non-focused event photography.

4. Financial Security and Profiling

Payment Security: We accept donations via various methods. Credit/debit card payments are secured according to the Payment Card Industry Data Security Standard (PCI DSS). We do not store credit or debit card details.

Profiling: We use profiling techniques (analysing characteristics and using publicly available information/third-party services) to ensure our marketing and fundraising appeals are relevant and timely. You have the right to object to this.

High Value Fundraising: We conduct research (using public data and third-party sources) based on legitimate interests to identify major donors and partners. We also conduct due diligence to ensure funding is from appropriate sources.

5. Marketing and Communications

We use various channels to communicate with you:

Electronic (Email/Text) and Telephone: We will always ask for your prior consent before sending communications through these channels.

Post: Sent using the basis of legitimate interests. You can opt out at any time.

Social Media and Online Platforms: Used for communication and advertising (e.g., Meta, LinkedIn, X, TikTok, Instagram, Google).

Changing Preferences: You can update your choices or stop receiving marketing at any time by calling 01273 664708.

6. Website Tracking and Cookies

Our websites use cookies and other tracking technologies for functionality, monitoring traffic, and improving services. You can manage your preferences through our Cookie Preference Centre.

The types of cookies used include:

Essential (Necessary for website function).

Performance (To measure traffic and popular pages).

Functional (For enhanced personalization).

Social Media (To track browsing for content sharing).

Targeting (Used by advertising partners, including a Meta pixel for ad performance).

7. Information Sharing, Retention, and Your Rights

Information Sharing: We do not sell or swap your information for third-party marketing. We share data with carefully selected Data Processors who act on our instructions, and with third parties where legally required (e.g., police, regulators).

Accuracy and Retention: We use third-party services to keep records accurate. Information is retained according to our Records Retention Policy, and securely disposed of when no longer needed.

Protecting Vulnerable Adults: We adhere to sector best practice, including guidance from the Chartered Institute of Fundraising, to ensure ethical interactions.

Your Rights:

You have the right to:

Be Informed

Rectify Inaccurate Information

Restrict Processing

Data Portability

Access Your Data

Erasure (Right to be Forgotten)

Object to Processing (including for marketing and profiling)

What Do You Need to Do?

You do not need to take any immediate action. Your continued use of our services after 25th November 2025 will be considered acceptance of the new Privacy and Cookie Notice.

We strongly encourage you to review the full, detailed policy here:Privacy Policy | My University Hospitals Sussex