Privacy Policy Statement
Appendix F
Date of last Review: September 2024
Date of next Review: September 2025
Purpose
This Information Security Policy aims to prevent or mitigate risks related to:
• Information that is collected, analysed, stored, communicated and reported upon may be subject to theft, misuse, loss and corruption.
• Information may be put at risk by poor education and training, and the breach of security controls.
• Information security incidents can give rise to embarrassment, financial loss, noncompliance with standards and legislation as well as possible judgements being made against hub South West Scotland Limited.
Information Security Policies
A set of lower level controls, processes and procedures for information security will be defined, in support of the high-level Information Security Policy and its stated objectives. This suite of supporting documentation will be approved by the Board, published, and communicated to Hub South West Scotland Limited users and relevant external parties.
hub SW Scotland Limited (hub South West) provides partnering services in the development of community facilities.
Types of Data we Collect and Why
We collect a variety of Personal Identifiable Information for various processes carried out at hub South West, which will be discussed in greater detail below.
We do not collect more information than we need to fulfil our stated purposes and will not retain it for longer than necessary.
In our Skills Academy and Supply Chain, we will gather names, work email addresses, work mobile numbers and age ranges for audit and KPI purposes, targeted marketing for future events and to measure event footfall to help plan future events.
In our marketing, we will use Google Analytics to measure web traffic volume and, in our newsletter, we will use email addresses and gather information for efficient distribution.
The Contact Us section on our website will use names, email addresses and contact numbers, if provided, to allow us to respond to enquiries. This information is held securely on Outlook and is encrypted and password protected.
Objectives
hub South West Scotland Limited security objectives are that:
• Our information risks are identified, managed and treated according to an agreed risk tolerance
• Our authorised users can securely access and share information in order to perform their roles
• Our physical, procedural and technical controls balance user experience and security
• Our contractual and legal obligations relating to information security are met
• Our activity considers information security
• Individuals accessing our information are aware of their information security responsibilities
• Incidents affecting our information assets are resolved, and learnt from to improve our controls.
Who We Share Information With
Information will be shared with external organisations such as, but not limited to, the Scottish Futures Trust. This information is shared as evidence of hub South West’s Key Performance Indicators and performance over various areas of the business.
In events supported by other organisations, they may wish to see attendance lists and/or numbers. In this case, the sign in sheet will be shared.
In the case of networking, delegate information may be shared, with the aim of promoting communication between delegates.
Security
We monitor all email correspondence, including file attachments, for viruses. Please be aware that you have the responsibility to ensure that any email you send us is within the bounds of the law.
All information is securely backed up with external servers based in the United Kingdom. When accessed, all computer systems are protected by a firewall maintained and regularly updated by Ridgewall. The in-house IT systems are password protected and all users are prompted to change this password at 90 day intervals to ensure the protection of information held within the accessible drives. Information is similarly stored and shared on Viewpoint for Projects. This information is securely encrypted in order to protect the integrity of the personal and private information held within. Similarly, this information is backed up on a central server located within the United Kingdom. This information is protected by the in-house firewall and a secure password system which is only known to the user.
Your rights
Under the General Data Protection Regulation which came into force on May 25, 2018, you have exercisable rights regarding the information that we hold about you. This includes the right to view, amend or request the erasure of this information. Please email any request to the Office Manager, Gail Dunn, on gdunn@hubsouthwest.co.uk.
Compliance
The design, operation, use and management of information systems will comply with all statutory, regulatory and contractual security requirements. Hub South West Scotland Limited will use a combination of internal and external audit to demonstrate compliance against chosen standards and best practice, including against internal policies and procedures.
Review
A review of this policy will be undertaken by the Information Security team annually or more frequently as required, and will be approved by the Board.
Signed
Michael Ross Chief Executive Officer