Privacy, Cookies and Privacy Complaints
Her Safe Network takes privacy and confidentiality seriously. This page explains how we collect and use personal information, how we use cookies and similar technologies, and how you can raise a privacy complaint.
Please select the relevant section below to read our Privacy Policy, Cookie Policy or Privacy Complaints Policy.
If you have any questions about privacy or data protection, you can contact our Data Protection Officer at dpo@hersafenetwork.org.
Privacy Policy
1. About this policy
This Privacy Policy explains how Her Safe Network collects, uses, shares, protects and keeps personal information. It also explains your rights and how to raise a privacy concern.
This policy applies when you use our services, are referred to us, contact us, visit our website, apply to work or volunteer with us, or otherwise interact with the charity.
This policy reflects UK data protection law, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025. It should be read with our Cookie Policy and Privacy Complaints Policy. We may also provide you shorter privacy information when we collect information, including during referral, intake, recruitment or CCTV monitoring.
2. Who we are
Her Safe Network is a Charitable Incorporated Organisation registered in England and Wales under charity number 1208960. Our registered office is 86-90 Paul Street, London, EC2A 4NE. We provide safe accommodation and practical, trauma-informed support for people escaping domestic abuse, crisis or unsafe circumstances.
Her Safe Network is the data controller for the personal information described in this policy. We are registered with the Information Commissioner’s Office under registration number ZB720274.
Our external and independent Data Protection Officer is Alex Goodman. You can contact our DPO at:
- Email: dpo@hersafenetwork.org
- Post: Data Protection Officer, Her Safe Network, 86-90 Paul Street, London, EC2A 4NE
- Telephone: 020 4576 3308
3. Who this policy applies to
We may process personal information about people who use, are referred to, or apply for our accommodation and support services. We may also process information about children, dependants, family members, emergency contacts, referrers, advocates, partner organisations, employees, trustees, volunteers, contractors, job applicants, website visitors, complainants and professional contacts.
We may also process information about other people where this is necessary for safety, safeguarding, legal or service-delivery reasons.
4. How we collect personal information
We may collect personal information directly from you, including through conversations, forms, email, telephone, live-chat or in person.
We may also receive information from people acting for you, referring organisations, local authorities, housing providers, police, MARAC partners, health services, legal advisers, specialist support organisations, public authorities, recruitment processes, safeguarding processes, complaints processes and our website systems.
Where we receive information about you from someone else, we will provide privacy information where required by law, unless an exemption applies.
5. Personal information we may collect
Depending on your relationship with us, we may collect:
- identity and contact information, such as name, date of birth, address, telephone number, email address, signature or photograph;
- referral, risk and support information, including DASH assessments, safeguarding information, support plans, case notes and records of support provided;
- information about children, dependants, next of kin and emergency contacts;
- accommodation, housing, benefits, financial and practical-support information;
- identity, immigration and legal documents, where needed for support, safeguarding or legal purposes;
- health, wellbeing, disability, medication, risk or support-needs information;
- equality and identity information, such as racial or ethnic origin, religion or belief and sexual orientation, where relevant and lawful;
- criminal-offence, police, court or safeguarding information where necessary;
- staff, trustee, volunteer, contractor and recruitment information;
- website, enquiry, live-chat, cookie-choice and technical information; and
- CCTV footage from approved security areas at our properties.
We collect only the information that is relevant for the purpose.
6. Special category, children’s and criminal-offence information
Some personal information receives additional protection under data protection law. This includes information about health, racial or ethnic origin, religion or belief, sex life or sexual orientation, genetic information, and biometric information where used for unique identification.
We may process this information where it is necessary and lawful, for example to assess risk, provide support, safeguard adults or children, assist with legal or child-maintenance matters, or protect someone from harm.
We may also process criminal-offence information where necessary and lawful, including information about allegations, offences, police involvement, court proceedings or a person who may present a risk.
Where children’s information is involved, we take additional care and consider the child’s age, understanding, safety and safeguarding needs.
7. Why we use personal information
We use personal information to:
- assess referrals, eligibility, risk and support needs;
- provide safe accommodation and specialist support;
- safeguard adults and children;
- work with MARAC, police, local authorities, health services and other partners where necessary;
- assist with housing, benefits, immigration, legal, child-maintenance or practical matters;
- respond to enquiries, complaints and information-rights requests;
- recruit and manage staff, trustees, volunteers and contractors;
- protect our premises, systems, residents, staff and confidential locations;
- operate our website, forms, live chat and cookie choices;
- manage records, governance, legal claims, regulation and insurance; and
monitor and improve our services, using anonymised or aggregated information where possible
8. Our lawful bases
We use personal information only where we have a lawful basis under UK data protection law. The basis depends on why the information is needed. In summary, we may rely on:
- Contract: to provide accommodation or support under an agreement, or to manage employment and other contractual arrangements;
- Legal obligation: to meet employment, tax, regulatory, court or other legal duties;
- Vital interests: where processing is necessary to protect someone’s life in an emergency;
- Legitimate interests: to administer our services, respond to enquiries, protect people and premises, manage professional relationships and improve our services;
- Recognised legitimate interest: where processing is necessary for a recognised safeguarding or crime-prevention purpose and the legal conditions are met; and
- Consent: for genuinely optional activities, such as identifiable photographs, recordings or optional communications. Consent can be withdrawn at any time without affecting core support.
We do not usually rely on consent for accommodation, safeguarding or core support. Where we process special category information or criminal-offence information, we also rely on the additional conditions and safeguards required by the UK GDPR and the Data Protection Act 2018. These may include safeguarding, confidential support, employment, legal claims and preventing or detecting unlawful acts.
9. When information is required
Some information is needed to assess a referral, provide safe accommodation or support, protect people from harm, comply with law, or enter into an agreement with you.
If required information is not provided, we may be unable to assess the referral, offer accommodation, complete an application or provide part of the requested service. We will explain what information is required and why.
Optional information will not be made a condition of receiving core support.
10. Who we may share information with
We share personal information only where it is necessary, proportionate and lawful.
Depending on the circumstances, we may share information with police, emergency services, MARAC partners, local authorities, children’s services, housing providers, health services, legal advisers, courts, regulators, insurers, auditors, professional advisers, authorised staff, volunteers, contractors, IT and cloud-service providers, payroll providers, website providers, funders and commissioners.
We normally provide funders and commissioners with anonymised or aggregated information wherever possible.
We may share information without consent where this is necessary to protect someone from serious harm, safeguard a child or adult at risk, prevent or detect crime, comply with a court order or legal duty, or establish or defend legal claims.
We do not sell personal information.
11. International transfers
Some authorised contractors and service providers, including virtual assistants and interpreters, may access personal information from outside the UK. Current locations include Bangladesh, the Philippines and Pakistan. Overseas access is limited to the personal information necessary for authorised work.
Before permitting overseas access, we ensure that an appropriate transfer mechanism is in place. This may include UK adequacy regulations or, where these do not apply, safeguards such as the UK International Data Transfer Agreement. We also use written data-processing terms, confidentiality requirements, access controls and security measures.
You may contact our DPO to ask about the countries involved, the safeguards that apply and how to obtain a copy of relevant safeguards.
12. How long we keep personal information
We keep personal information only for as long as it is needed for the relevant purpose, legal obligations, safeguarding, regulatory requirements and potential legal claims. We then securely delete, destroy or anonymise it.
Our usual retention periods include:
- Adult service-user standard records: up to 6 years from case closure or last active contact;
- Special category case records, including health and DASH records: up to 7 years from case closure or last active contact;
- Records relating to children: normally until the child’s 25th birthday, or longer where required for safeguarding, legal claims, a statutory inquiry, legal hold or another lawful reason;
- CCTV footage: normally 31 days, unless needed for an incident, investigation, safeguarding matter or legal claim;
- Staff, trustee and volunteer records: normally 6 years after the engagement ends;
- Unsuccessful recruitment records: usually 6 to 12 months after the recruitment exercise;
- Financial, accounting and regulatory records: normally 6 years, or longer where required by law, audit, grant conditions or investigation; and
- Website enquiries, complaints and rights requests: for as long as needed to respond and meet legal, complaints or record-keeping requirements.
13. How we protect personal information
We use appropriate technical and organisational measures to protect personal information, taking account of its sensitivity and the risks involved.
Access to personal information, including service-user records, confidential accommodation locations and information that could reveal someone’s whereabouts, is limited to authorised people who need it for their role.
14. Website, forms, live chat and cookies
Information submitted through our website forms or live chat is personal information and is handled under this Privacy Policy.
Our use of cookies and similar technologies, including how to manage your choices, is explained separately in our Cookie Policy.
15. Your data-protection rights
Depending on the circumstances and the lawful basis used, you may have the right to:
- be informed about how we use your personal information;
- access your personal information and receive a copy;
- have inaccurate or incomplete information corrected;
- request deletion of your personal information in certain circumstances;
- request restriction of processing in certain circumstances;
- receive information you provided to us in a structured, commonly used and machine-readable format where the right to data portability applies;
- object to processing based on legitimate interests or recognised legitimate interest;
- object at any time to direct marketing;
- withdraw consent at any time where consent is our lawful basis;
- receive applicable safeguards where a significant decision about you is based solely on automated processing; and
- complain to us if you believe we have not handled your personal information in accordance with UK data protection law.
Her Safe Network does not currently make significant decisions about access to accommodation, support, employment or volunteering based solely on automated processing.
employment or volunteering based solely on automated processing.
Your right to object: You have an absolute right to object to direct marketing. You may also object, on grounds relating to your particular situation, to processing based on legitimate interests or recognised legitimate interest. We will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for legal claims. |
To exercise your rights, contact dpo@hersafenetwork.org. There is normally no fee. We will respond without undue delay and within the applicable legal time limit, which is normally one month. Where the law permits an extension because of the complexity or number of requests, we will tell you within the first month and explain why.
We may ask for information reasonably necessary to confirm your identity. These rights are subject to legal conditions and exemptions. If we cannot fully comply with a request, we will explain why unless the law prevents us from doing so.
16. Privacy complaints
If you believe that Her Safe Network has not handled your personal information in accordance with UK data protection law, you may make a complaint to us.
You can contact our DPO at dpo@hersafenetwork.org or use our Privacy Complaint Form: https://hersafenetwork.org/privacy-complaint-form/
Our Privacy Complaints Policy explains how to make a complaint and how we handle it.
We aim to acknowledge privacy complaints within 10 working days and, in any event, within 30 days of receiving your complaint. Without undue delay, we will take appropriate steps to respond, including making enquiries where appropriate, keeping you informed about progress and informing you of the outcome.
You may also complain to the Information Commissioner’s Office at any time. You are not legally required to complain to Her Safe Network first.
- ICO website: https://ico.org.uk/make-a-complaint/
- Telephone: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
17. Changes to this policy
We review this policy regularly and whenever our services, systems, suppliers, data-sharing arrangements or legal obligations change.
The current version will be published on our website. Where a change may materially affect you, we will take reasonable steps to bring it to your attention.
18. Contact details
Data Protection Officer: Alex Goodman
Email: dpo@hersafenetwork.org
Post: Data Protection Officer, Her Safe Network, 86-90 Paul Street, London, EC2A 4NE
Telephone: 020 4576 3308
Online Privacy Complaint Form: https://hersafenetwork.org/privacy-complaint-form/
ICO registration number: ZB720274
Policy version: Privacy Policy Website V1.0
Last review date: 30 Jul 2026
Next review date: To be confirmed on approval
Privacy Complaints Policy
1. Purpose
2. Scope
This policy applies to complaints about how Her Safe Network collects, uses, stores, shares, protects, retains or deletes personal data. It applies to service users, former service users, staff, volunteers, trustees, professional contacts, website users and other individuals whose personal data we process.
This policy is separate from our general complaints process, which covers service quality, staff conduct and other non-privacy complaints. It should be read alongside our Privacy Policy and Data Protection Policy.
3. Our Commitment
Her Safe Network is committed to handling personal data lawfully, fairly and transparently. If you believe we have handled your personal data in a way that does not comply with UK data protection law, we want to hear from you.
We will handle privacy complaints fairly, promptly and in confidence. Making a privacy complaint will not be used against you or affect your access to support from Her Safe Network.
4. How to Make a Privacy Complaint
Contact method:
Online form: Submit a privacy complaint using our secure Online Form, available through the Privacy Complaints page on our website.
Email: dpo@hersafenetwork.org.
Please mark the subject line ‘PRIVACY COMPLAINT – CONFIDENTIAL’ where possible.
Post: Data Protection Officer, Her Safe Network, 86-90 Paul Street, London, EC2A 4NE.
We will accept and record a privacy complaint however it reaches us and ensure that it is passed to the appropriate person for review. If you need an accessible format, language support or a safer contact arrangement, please tell us and we will try to help. In some cases, we may need to take reasonable and proportionate steps to verify your identity, or the identity of the person on whose behalf you are complaining, particularly where this is necessary to protect safety, privacy and confidentiality.
5. What Happens Next
All privacy complaints are logged, investigated and reviewed by our Data Protection Officer, or by a person acting under the Data Protection Officer’s direction.
- Acknowledgement: We aim to acknowledge your complaint within 10 working days of receiving it, and in any event within the statutory 30-day period.
- Review: We will review your complaint, make appropriate enquiries and keep you informed of progress. We may contact you if we need further information.
- Response: We aim to provide a full written response within one calendar month wherever possible. In all cases, we will take appropriate steps to consider the complaint, keep you informed about progress and provide an outcome without undue delay.
- Complex complaints: If your complaint is complex or requires further investigation, we may need more time. We will explain why, keep you informed of progress and provide our outcome as soon as possible and without undue delay.
- Records: We keep a record of privacy complaints and how they were received, handled and resolved, in line with our Data Retention Policy and our accountability obligations under data protection law.
- If we uphold your complaint: We will explain what went wrong, what we have done or will do to put things right, and any steps we will take to reduce the risk of the same issue happening again.
- If we do not uphold your complaint: We will explain our decision clearly and tell you about your right to complain to the Information Commissioner’s Office.
- Possible data breach: If your complaint suggests that a personal data breach may have occurred, we will also consider it under our data breach response process. Where required, we will notify the Information Commissioner’s Office and affected individuals in line with data protection law.
6. Our Data Protection Officer
Our Data Protection Officer is external to Her Safe Network and provides independent oversight of our data protection compliance. The Data Protection Officer reviews privacy complaints and advises us on how to meet our obligations under UK data protection law.
Data Protection Officer: Alex Goodman.
Email: dpo@hersafenetwork.org.
ICO registration number: ZB720274.
Privacy complaints will be handled confidentially and shared only with people who need the information to review, respond to, or act on the complaint. If we need to take action to protect you or another person from serious harm, we may share limited information with appropriate safeguarding, emergency or statutory services.
7. If You Are Not Satisfied
If you are not satisfied with our response, or if we have not responded within the timeframes above, you have the right to complain to the Information Commissioner’s Office, the UK’s independent data protection regulator.
You can complain to the ICO at any time. You do not have to complain to us first. However, if you contact us first, we will try to resolve your concern as quickly and fairly as possible.
You can make a complaint to the ICO at: https://ico.org.uk/make-a-complaint/
Policy version: Privacy Complaint Policy V1.0
Last review date: 15 Jul 2026
Next review date: To be confirmed on approval
Cookie Policy
1. Purpose
2. Legal Framework
3. What Are Cookies?
4. Types of Cookies and Technologies We Use
a. Necessary cookies
Necessary cookies and similar technologies enable essential website operation, security, cookie-choice recording, and features specifically requested by the visitor. They cannot be switched off through the cookie banner.
b. Performance cookies
Performance cookies and similar technologies help us measure and improve the website and may support optional preferences or enhanced features. They are used only where Performance cookies are accepted.
c. Marketing cookies
We do not currently use any Marketing cookies or similar technologies on our website.If this changes, we will update this policy and our cookie banner before any Marketing cookies or similar technologies are used.
Marketing cookies and similar technologies may be used by advertising partners or third-party services to measure campaign activity, support awareness campaigns, understand how visitors respond to campaign content, or show relevant advertising or campaign information. These technologies require explicit consent before they load.
5. Cookie and Technology List
The list below explains the cookies and similar technologies used on our website, including their provider, purpose, duration and category. Optional cookies are used in line with the choices you make in our cookie banner. Some technologies may only be used when you choose a particular feature, such as a form or live chat. Where a duration is described as persistent, the item remains in browser storage until it is cleared by you, your browser or the website.
5.1 cmplz_* or similar cookie-preference storage
Provider: Her Safe Network / Complianz
Purpose: Uses cookies or browser local storage to save your cookie choices and remember whether optional cookies were accepted or rejected.
Duration: Up to 12 months
Category: Necessary
5.2 wordpress_test_cookie
Provider: WordPress / Her Safe Network
Purpose: Checks whether the browser accepts cookies so WordPress login and security functions can operate.
Duration: Session
Category: Necessary
5.3 wordpress_sec_* or wordpress_logged_in_* if used
Provider: WordPress / Her Safe Network
Purpose: Supports secure authentication and session functions for authorised website administrators.
Duration: Usually 2 days; up to 14 days where ‘Remember Me’ is selected
Category: Necessary
5.4 _GRECAPTCHA or similar anti-spam technology
Provider: Google
Purpose: Helps protect website forms from spam, abuse and automated submissions by assessing browser and interaction signals to distinguish people from automated activity.
Duration: Up to 6 months
Category: Necessary
5.5 __cf_bm or similar Cloudflare security cookies
Provider: Cloudflare
Purpose: Provides website security and bot protection and supports website performance and reliability.
Duration: 30 minutes of user inactivity for __cf_bm; similar security cookies may vary
Category: Necessary
5.6 wpforms_* or similar
Provider: WPForms / Her Safe Network
Purpose: Enables secure form display, validation, submission handling and spam protection when you choose to use a form.
Duration: Session
Category: Necessary
5.7 Newsletter subscription token or similar
Provider: Newsletter tool / Her Safe Network
Purpose: Created only after you click Subscribe. Stores a random token needed to support the newsletter subscription, confirmation or preference function. The token does not expose personal data in the cookie.
Duration: Persistent, up to 12 months
Category: Necessary
5.8 tidio_state_*
Provider: Tidio
Purpose: Stores a visitor identifier, live-chat state and settings so the chat can work across pages and, where enabled, preserve chat history.
Duration: Persistent, up to 12 months
Category: Performance
5.9 tidio_page_views
Provider: Tidio
Purpose: Records page-view activity used to support and measure live-chat interactions.
Duration: Session
Category: Performance
5.10 tidio_chat_is_open
Provider: Tidio
Purpose: Remembers whether the live-chat widget is open or minimised while you browse.
Duration: Session
Category: Performance
5.11 _ga and _ga_* where Google Analytics is enabled
Provider: Google Analytics
Purpose: Helps us understand visits, page use and website performance so we can improve the website. These cookies are used only where Performance cookies are accepted.
Duration: Up to 2 years
Category: Performance
For these controls, Performance includes optional preference and enhanced-functionality technologies that are not used for marketing. WPForms storage listed as Necessary is limited to enabling and protecting a form that you choose to use. Elementor is included for transparency because it is part of the website’s core page-building and rendering system. It does not currently set cookies or local storage for this purpose. If Elementor popups are introduced, related storage will be reviewed and categorised before use. Tidio live chat technologies that remember visitors, preserve chat history or measure chat interactions are included under Performance and are used only where Performance cookies are accepted.
6. Tag Management, Performance Measurement and Marketing
We may use Google Tag Manager to manage website tags. Google Tag Manager does not usually set cookies itself, but it can be used to load other technologies. We do not use it to load optional Performance or Marketing technologies unless your cookie choice permits this and the technology is explained in this policy.
Optional Performance and Marketing technologies, including analytics, advertising and targeting technologies, are used only in the circumstances explained in Section 5. If we introduce additional optional technologies, we will update this policy and provide the required cookie choices before those technologies are used.
7. Third-Party Services
Some website features use third-party services, including Tidio live chat, Google reCAPTCHA, Elementor, WPForms and Cloudflare. Elementor is used for website design and layout, and we do not currently use Elementor popups. Tidio live chat is an optional feature and its Performance technologies are used only where Performance cookies are accepted. Where a third-party service uses cookies, local storage or similar technologies, it is included in Section 5 and handled in line with the cookie choices explained in this policy. Some of these providers may process information outside the UK; where this happens, it is carried out subject to the safeguards described in our Privacy Policy.
Tidio, our live chat provider, is based in the United States. Where chat data is processed outside the UK, this is carried out under Tidio’s certified data transfer safeguards, including the UK Extension to the EU-US Data Privacy Framework.
When you subscribe to our newsletter, your name and email address are also shared with Mailchimp, our email delivery provider, who process this data on our behalf under their standard data protection safeguards. Mailchimp is based in the United States.
Information submitted through a website form or live chat is not treated as a cookie. It is handled under our Privacy Policy, including our retention arrangements for enquiries, referral information and service records.
8. How to Manage Cookies
You can accept or reject Performance and Marketing cookies through our cookie banner or Cookie Settings link. Necessary cookies cannot be switched off through the banner because they are required for essential website operation, security, cookie-choice recording or a feature you have requested. You can withdraw your consent at any time using the Cookie Settings link; withdrawing consent is as easy as giving it and will not affect the lawfulness of any processing carried out before you withdraw it.
You can also block or delete cookies and clear local storage through your browser settings, although this may affect website functionality. If you reject non-essential cookies, you can still use the website, but some optional features may work differently.
9. Review and Contact
We review this Cookie Policy at least annually and whenever we change the cookies, tags, scripts, pixels or third-party tools used on our website, or where relevant legal or regulatory requirements relating to cookies or similar technologies change. We will update the cookie and technology list after each cookie scan or material website change.
If you have questions about cookies or privacy, contact our Data Protection Officer by email:
You also have the right to complain to the Information Commissioner’s Office (ICO). Information about how to complain is available at:
https://ico.org.uk/make-a-complaint/
Policy version: Cookie Policy V1.1
Last review date: 23 Jul 2026
Next review date: To be confirmed on approval
