Privacy Policy

Privacy, Cookies and Privacy Complaints

Her Safe Network takes privacy and confidentiality seriously. This page explains how we collect and use personal information, how we use cookies and similar technologies, and how you can raise a privacy complaint.
Please select the relevant section below to read our Privacy Policy, Cookie Policy or Privacy Complaints Policy.
If you have any questions about privacy or data protection, you can contact our Data Protection Officer at dpo@hersafenetwork.org.

Privacy Policy

1. About this policy

This Privacy Policy explains how Her Safe Network collects, uses, shares, protects and keeps personal information. It also explains your rights and how to raise a privacy concern.

This policy applies when you use our services, are referred to us, contact us, visit our website, apply to work or volunteer with us, or otherwise interact with the charity.

This policy reflects UK data protection law, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025. It should be read with our Cookie Policy and Privacy Complaints Policy. We may also provide you shorter privacy information when we collect information, including during referral, intake, recruitment or CCTV monitoring.

2. Who we are

Her Safe Network is a Charitable Incorporated Organisation registered in England and Wales under charity number 1208960. Our registered office is 86-90 Paul Street, London, EC2A 4NE. We provide safe accommodation and practical, trauma-informed support for people escaping domestic abuse, crisis or unsafe circumstances.

Her Safe Network is the data controller for the personal information described in this policy. We are registered with the Information Commissioner’s Office under registration number ZB720274.

Our external and independent Data Protection Officer is Alex Goodman. You can contact our DPO at:

  • Email: dpo@hersafenetwork.org
  • Post: Data Protection Officer, Her Safe Network, 86-90 Paul Street, London, EC2A 4NE
  • Telephone: 020 4576 3308

3. Who this policy applies to

We may process personal information about people who use, are referred to, or apply for our accommodation and support services. We may also process information about children, dependants, family members, emergency contacts, referrers, advocates, partner organisations, employees, trustees, volunteers, contractors, job applicants, website visitors, complainants and professional contacts.

We may also process information about other people where this is necessary for safety, safeguarding, legal or service-delivery reasons.

4. How we collect personal information

We may collect personal information directly from you, including through conversations, forms, email, telephone, live-chat or in person.

We may also receive information from people acting for you, referring organisations, local authorities, housing providers, police, MARAC partners, health services, legal advisers, specialist support organisations, public authorities, recruitment processes, safeguarding processes, complaints processes and our website systems.

Where we receive information about you from someone else, we will provide privacy information where required by law, unless an exemption applies.

5. Personal information we may collect

Depending on your relationship with us, we may collect:

  • identity and contact information, such as name, date of birth, address, telephone number, email address, signature or photograph;
  • referral, risk and support information, including DASH assessments, safeguarding information, support plans, case notes and records of support provided;
  • information about children, dependants, next of kin and emergency contacts;
  • accommodation, housing, benefits, financial and practical-support information;
  • identity, immigration and legal documents, where needed for support, safeguarding or legal purposes;
  • health, wellbeing, disability, medication, risk or support-needs information;
  • equality and identity information, such as racial or ethnic origin, religion or belief and sexual orientation, where relevant and lawful;
  • criminal-offence, police, court or safeguarding information where necessary;
  • staff, trustee, volunteer, contractor and recruitment information;
  • website, enquiry, live-chat, cookie-choice and technical information; and
  • CCTV footage from approved security areas at our properties.

We collect only the information that is relevant for the purpose.

6. Special category, children’s and criminal-offence information

Some personal information receives additional protection under data protection law. This includes information about health, racial or ethnic origin, religion or belief, sex life or sexual orientation, genetic information, and biometric information where used for unique identification.

We may process this information where it is necessary and lawful, for example to assess risk, provide support, safeguard adults or children, assist with legal or child-maintenance matters, or protect someone from harm.

We may also process criminal-offence information where necessary and lawful, including information about allegations, offences, police involvement, court proceedings or a person who may present a risk.

Where children’s information is involved, we take additional care and consider the child’s age, understanding, safety and safeguarding needs.

7. Why we use personal information

We use personal information to:

  • assess referrals, eligibility, risk and support needs;
  • provide safe accommodation and specialist support;
  • safeguard adults and children;
  • work with MARAC, police, local authorities, health services and other partners where necessary;
  • assist with housing, benefits, immigration, legal, child-maintenance or practical matters;
  • respond to enquiries, complaints and information-rights requests;
  • recruit and manage staff, trustees, volunteers and contractors;
  • protect our premises, systems, residents, staff and confidential locations;
  • operate our website, forms, live chat and cookie choices;
  • manage records, governance, legal claims, regulation and insurance; and

monitor and improve our services, using anonymised or aggregated information where possible

8. Our lawful bases

We use personal information only where we have a lawful basis under UK data protection law. The basis depends on why the information is needed. In summary, we may rely on:

  • Contract: to provide accommodation or support under an agreement, or to manage employment and other contractual arrangements;
  • Legal obligation: to meet employment, tax, regulatory, court or other legal duties;
  • Vital interests: where processing is necessary to protect someone’s life in an emergency;
  • Legitimate interests: to administer our services, respond to enquiries, protect people and premises, manage professional relationships and improve our services;
  • Recognised legitimate interest: where processing is necessary for a recognised safeguarding or crime-prevention purpose and the legal conditions are met; and
  • Consent: for genuinely optional activities, such as identifiable photographs, recordings or optional communications. Consent can be withdrawn at any time without affecting core support.

We do not usually rely on consent for accommodation, safeguarding or core support. Where we process special category information or criminal-offence information, we also rely on the additional conditions and safeguards required by the UK GDPR and the Data Protection Act 2018. These may include safeguarding, confidential support, employment, legal claims and preventing or detecting unlawful acts.

9. When information is required

Some information is needed to assess a referral, provide safe accommodation or support, protect people from harm, comply with law, or enter into an agreement with you.

If required information is not provided, we may be unable to assess the referral, offer accommodation, complete an application or provide part of the requested service. We will explain what information is required and why.

Optional information will not be made a condition of receiving core support.

10. Who we may share information with

We share personal information only where it is necessary, proportionate and lawful.

Depending on the circumstances, we may share information with police, emergency services, MARAC partners, local authorities, children’s services, housing providers, health services, legal advisers, courts, regulators, insurers, auditors, professional advisers, authorised staff, volunteers, contractors, IT and cloud-service providers, payroll providers, website providers, funders and commissioners.

We normally provide funders and commissioners with anonymised or aggregated information wherever possible.

We may share information without consent where this is necessary to protect someone from serious harm, safeguard a child or adult at risk, prevent or detect crime, comply with a court order or legal duty, or establish or defend legal claims.

We do not sell personal information.

11. International transfers

Some authorised contractors and service providers, including virtual assistants and interpreters, may access personal information from outside the UK. Current locations include Bangladesh, the Philippines and Pakistan. Overseas access is limited to the personal information necessary for authorised work.

Before permitting overseas access, we ensure that an appropriate transfer mechanism is in place. This may include UK adequacy regulations or, where these do not apply, safeguards such as the UK International Data Transfer Agreement. We also use written data-processing terms, confidentiality requirements, access controls and security measures.

You may contact our DPO to ask about the countries involved, the safeguards that apply and how to obtain a copy of relevant safeguards.

12. How long we keep personal information

We keep personal information only for as long as it is needed for the relevant purpose, legal obligations, safeguarding, regulatory requirements and potential legal claims. We then securely delete, destroy or anonymise it.

Our usual retention periods include:

  • Adult service-user standard records: up to 6 years from case closure or last active contact;
  • Special category case records, including health and DASH records: up to 7 years from case closure or last active contact;
  • Records relating to children: normally until the child’s 25th birthday, or longer where required for safeguarding, legal claims, a statutory inquiry, legal hold or another lawful reason;
  • CCTV footage: normally 31 days, unless needed for an incident, investigation, safeguarding matter or legal claim;
  • Staff, trustee and volunteer records: normally 6 years after the engagement ends;
  • Unsuccessful recruitment records: usually 6 to 12 months after the recruitment exercise;
  • Financial, accounting and regulatory records: normally 6 years, or longer where required by law, audit, grant conditions or investigation; and
  • Website enquiries, complaints and rights requests: for as long as needed to respond and meet legal, complaints or record-keeping requirements.

13. How we protect personal information

We use appropriate technical and organisational measures to protect personal information, taking account of its sensitivity and the risks involved.

Access to personal information, including service-user records, confidential accommodation locations and information that could reveal someone’s whereabouts, is limited to authorised people who need it for their role.

14. Website, forms, live chat and cookies

Information submitted through our website forms or live chat is personal information and is handled under this Privacy Policy.

Our use of cookies and similar technologies, including how to manage your choices, is explained separately in our Cookie Policy.

15. Your data-protection rights

Depending on the circumstances and the lawful basis used, you may have the right to:

  • be informed about how we use your personal information;
  • access your personal information and receive a copy;
  • have inaccurate or incomplete information corrected;
  • request deletion of your personal information in certain circumstances;
  • request restriction of processing in certain circumstances;
  • receive information you provided to us in a structured, commonly used and machine-readable format where the right to data portability applies;
  • object to processing based on legitimate interests or recognised legitimate interest;
  • object at any time to direct marketing;
  • withdraw consent at any time where consent is our lawful basis;
  • receive applicable safeguards where a significant decision about you is based solely on automated processing; and
  • complain to us if you believe we have not handled your personal information in accordance with UK data protection law.

Her Safe Network does not currently make significant decisions about access to accommodation, support, employment or volunteering based solely on automated processing.

employment or volunteering based solely on automated processing.

Your right to object: You have an absolute right to object to direct marketing. You may also object, on grounds relating to your particular situation, to processing based on legitimate interests or recognised legitimate interest. We will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for legal claims.

To exercise your rights, contact dpo@hersafenetwork.org. There is normally no fee. We will respond without undue delay and within the applicable legal time limit, which is normally one month. Where the law permits an extension because of the complexity or number of requests, we will tell you within the first month and explain why.

We may ask for information reasonably necessary to confirm your identity. These rights are subject to legal conditions and exemptions. If we cannot fully comply with a request, we will explain why unless the law prevents us from doing so.

16. Privacy complaints

If you believe that Her Safe Network has not handled your personal information in accordance with UK data protection law, you may make a complaint to us.

You can contact our DPO at dpo@hersafenetwork.org or use our Privacy Complaint Form: https://hersafenetwork.org/privacy-complaint-form/

Our Privacy Complaints Policy explains how to make a complaint and how we handle it.

We aim to acknowledge privacy complaints within 10 working days and, in any event, within 30 days of receiving your complaint. Without undue delay, we will take appropriate steps to respond, including making enquiries where appropriate, keeping you informed about progress and informing you of the outcome.

You may also complain to the Information Commissioner’s Office at any time. You are not legally required to complain to Her Safe Network first.

  • ICO website: https://ico.org.uk/make-a-complaint/
  • Telephone: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

17. Changes to this policy

We review this policy regularly and whenever our services, systems, suppliers, data-sharing arrangements or legal obligations change.

The current version will be published on our website. Where a change may materially affect you, we will take reasonable steps to bring it to your attention.

18. Contact details

Data Protection Officer: Alex Goodman

Email: dpo@hersafenetwork.org

Post: Data Protection Officer, Her Safe Network, 86-90 Paul Street, London, EC2A 4NE

Telephone: 020 4576 3308

Online Privacy Complaint Form: https://hersafenetwork.org/privacy-complaint-form/

ICO registration number: ZB720274

 

Policy version:                  Privacy Policy Website V1.0
Last review date:             30 Jul 2026
Next review date:            To be confirmed on approval

1. Purpose

This policy explains how individuals can make a privacy complaint to Her Safe Network and how we will respond. It supports our obligations under UK data protection law, including the UK GDPR, the Data Protection Act 2018, and the statutory right to complain directly to a controller introduced by the Data (Use and Access) Act 2025.

2. Scope

This policy applies to complaints about how Her Safe Network collects, uses, stores, shares, protects, retains or deletes personal data. It applies to service users, former service users, staff, volunteers, trustees, professional contacts, website users and other individuals whose personal data we process.

This policy is separate from our general complaints process, which covers service quality, staff conduct and other non-privacy complaints. It should be read alongside our Privacy Policy and Data Protection Policy.

3. Our Commitment

Her Safe Network is committed to handling personal data lawfully, fairly and transparently. If you believe we have handled your personal data in a way that does not comply with UK data protection law, we want to hear from you.

We will handle privacy complaints fairly, promptly and in confidence. Making a privacy complaint will not be used against you or affect your access to support from Her Safe Network.

4. How to Make a Privacy Complaint

Contact method:

Online form: Submit a privacy complaint using our secure Online Form, available through the Privacy Complaints page on our website.

Email: dpo@hersafenetwork.org.

Please mark the subject line ‘PRIVACY COMPLAINT – CONFIDENTIAL’ where possible.

Post: Data Protection Officer, Her Safe Network, 86-90 Paul Street, London, EC2A 4NE.

We will accept and record a privacy complaint however it reaches us and ensure that it is passed to the appropriate person for review. If you need an accessible format, language support or a safer contact arrangement, please tell us and we will try to help. In some cases, we may need to take reasonable and proportionate steps to verify your identity, or the identity of the person on whose behalf you are complaining, particularly where this is necessary to protect safety, privacy and confidentiality.

 

5. What Happens Next

All privacy complaints are logged, investigated and reviewed by our Data Protection Officer, or by a person acting under the Data Protection Officer’s direction.

  • Acknowledgement: We aim to acknowledge your complaint within 10 working days of receiving it, and in any event within the statutory 30-day period.
  • Review: We will review your complaint, make appropriate enquiries and keep you informed of progress. We may contact you if we need further information.
  • Response: We aim to provide a full written response within one calendar month wherever possible. In all cases, we will take appropriate steps to consider the complaint, keep you informed about progress and provide an outcome without undue delay.
  • Complex complaints: If your complaint is complex or requires further investigation, we may need more time. We will explain why, keep you informed of progress and provide our outcome as soon as possible and without undue delay.
  • Records: We keep a record of privacy complaints and how they were received, handled and resolved, in line with our Data Retention Policy and our accountability obligations under data protection law.
  • If we uphold your complaint: We will explain what went wrong, what we have done or will do to put things right, and any steps we will take to reduce the risk of the same issue happening again.
  • If we do not uphold your complaint: We will explain our decision clearly and tell you about your right to complain to the Information Commissioner’s Office.
  • Possible data breach: If your complaint suggests that a personal data breach may have occurred, we will also consider it under our data breach response process. Where required, we will notify the Information Commissioner’s Office and affected individuals in line with data protection law.

6. Our Data Protection Officer

Our Data Protection Officer is external to Her Safe Network and provides independent oversight of our data protection compliance. The Data Protection Officer reviews privacy complaints and advises us on how to meet our obligations under UK data protection law.

Data Protection Officer: Alex Goodman.

Email: dpo@hersafenetwork.org.

ICO registration number: ZB720274.

 

Privacy complaints will be handled confidentially and shared only with people who need the information to review, respond to, or act on the complaint. If we need to take action to protect you or another person from serious harm, we may share limited information with appropriate safeguarding, emergency or statutory services.

7. If You Are Not Satisfied

If you are not satisfied with our response, or if we have not responded within the timeframes above, you have the right to complain to the Information Commissioner’s Office, the UK’s independent data protection regulator.

You can complain to the ICO at any time. You do not have to complain to us first. However, if you contact us first, we will try to resolve your concern as quickly and fairly as possible.

You can make a complaint to the ICO at: https://ico.org.uk/make-a-complaint/

Policy version:                      Privacy Complaint Policy V1.0
Last review date:                  15 Jul 2026
Next review date:                  To be confirmed on approval

1. Purpose

This standalone Cookie Policy explains how Her Safe Network uses cookies and similar technologies on its website, why they are used, and how visitors can manage their choices. It should be read alongside our Privacy Policy.

2. Legal Framework

This policy supports the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), as amended by the Data (Use and Access) Act 2025, the UK GDPR, the Data Protection Act 2018 and current ICO guidance. Her Safe Network’s cookie controls use three categories: Necessary, Performance and Marketing. Necessary technologies are used only where they are essential to operate or secure the website, remember cookie choices, or provide a feature the visitor has requested. Optional technologies used for website measurement, preferences or enhanced functionality are included under Performance. Advertising, targeting and retargeting technologies are included under Marketing and require explicit consent before they load.

3. What Are Cookies?

Cookies are small files placed on your device when you visit a website. Similar technologies include scripts, pixels, tags, local storage and other tools that store or access information on your device. Some cookies and technologies are needed for our website to work, keep it secure and remember cookie choices. Others may help us improve the website, remember preferences, support optional tools or measure awareness and campaign activity.

4. Types of Cookies and Technologies We Use

a. Necessary cookies
Necessary cookies and similar technologies enable essential website operation, security, cookie-choice recording, and features specifically requested by the visitor. They cannot be switched off through the cookie banner.


b. Performance cookies
Performance cookies and similar technologies help us measure and improve the website and may support optional preferences or enhanced features. They are used only where Performance cookies are accepted.



c. Marketing cookies

We do not currently use any Marketing cookies or similar technologies on our website.If this changes, we will update this policy and our cookie banner before any Marketing cookies or similar technologies are used.

Marketing cookies and similar technologies may be used by advertising partners or third-party services to measure campaign activity, support awareness campaigns, understand how visitors respond to campaign content, or show relevant advertising or campaign information. These technologies require explicit consent before they load.

5. Cookie and Technology List

The list below explains the cookies and similar technologies used on our website, including their provider, purpose, duration and category. Optional cookies are used in line with the choices you make in our cookie banner. Some technologies may only be used when you choose a particular feature, such as a form or live chat. Where a duration is described as persistent, the item remains in browser storage until it is cleared by you, your browser or the website.

 

5.1 cmplz_* or similar cookie-preference storage

Provider: Her Safe Network / Complianz

Purpose: Uses cookies or browser local storage to save your cookie choices and remember whether optional cookies were accepted or rejected.

Duration: Up to 12 months

Category: Necessary

 

5.2 wordpress_test_cookie

Provider: WordPress / Her Safe Network

Purpose: Checks whether the browser accepts cookies so WordPress login and security functions can operate.

Duration: Session

Category: Necessary

 

5.3 wordpress_sec_* or wordpress_logged_in_* if used

Provider: WordPress / Her Safe Network

Purpose: Supports secure authentication and session functions for authorised website administrators.

Duration: Usually 2 days; up to 14 days where ‘Remember Me’ is selected

Category: Necessary

 

5.4 _GRECAPTCHA or similar anti-spam technology

Provider: Google

Purpose: Helps protect website forms from spam, abuse and automated submissions by assessing browser and interaction signals to distinguish people from automated activity.

Duration: Up to 6 months

Category: Necessary

 

5.5 __cf_bm or similar Cloudflare security cookies

Provider: Cloudflare

Purpose: Provides website security and bot protection and supports website performance and reliability.

Duration: 30 minutes of user inactivity for __cf_bm; similar security cookies may vary

Category: Necessary

 

5.6 wpforms_* or similar

Provider: WPForms / Her Safe Network

Purpose: Enables secure form display, validation, submission handling and spam protection when you choose to use a form.

Duration: Session

Category: Necessary

 

5.7 Newsletter subscription token or similar

Provider: Newsletter tool / Her Safe Network

Purpose: Created only after you click Subscribe. Stores a random token needed to support the newsletter subscription, confirmation or preference function. The token does not expose personal data in the cookie.

Duration: Persistent, up to 12 months

Category: Necessary

 

 

5.8 tidio_state_*

Provider: Tidio

Purpose: Stores a visitor identifier, live-chat state and settings so the chat can work across pages and, where enabled, preserve chat history.

Duration: Persistent, up to 12 months

Category: Performance

 

5.9 tidio_page_views

Provider: Tidio

Purpose: Records page-view activity used to support and measure live-chat interactions.

Duration: Session

Category: Performance

 

5.10 tidio_chat_is_open

Provider: Tidio

Purpose: Remembers whether the live-chat widget is open or minimised while you browse.

Duration: Session

Category: Performance

 

 

5.11 _ga and _ga_* where Google Analytics is enabled

Provider: Google Analytics

Purpose: Helps us understand visits, page use and website performance so we can improve the website. These cookies are used only where Performance cookies are accepted.

Duration: Up to 2 years

Category: Performance

 

For these controls, Performance includes optional preference and enhanced-functionality technologies that are not used for marketing. WPForms storage listed as Necessary is limited to enabling and protecting a form that you choose to use. Elementor is included for transparency because it is part of the website’s core page-building and rendering system. It does not currently set cookies or local storage for this purpose. If Elementor popups are introduced, related storage will be reviewed and categorised before use. Tidio live chat technologies that remember visitors, preserve chat history or measure chat interactions are included under Performance and are used only where Performance cookies are accepted.

 

6. Tag Management, Performance Measurement and Marketing

We may use Google Tag Manager to manage website tags. Google Tag Manager does not usually set cookies itself, but it can be used to load other technologies. We do not use it to load optional Performance or Marketing technologies unless your cookie choice permits this and the technology is explained in this policy.

Optional Performance and Marketing technologies, including analytics, advertising and targeting technologies, are used only in the circumstances explained in Section 5. If we introduce additional optional technologies, we will update this policy and provide the required cookie choices before those technologies are used.

 

7. Third-Party Services

Some website features use third-party services, including Tidio live chat, Google reCAPTCHA, Elementor, WPForms and Cloudflare. Elementor is used for website design and layout, and we do not currently use Elementor popups. Tidio live chat is an optional feature and its Performance technologies are used only where Performance cookies are accepted. Where a third-party service uses cookies, local storage or similar technologies, it is included in Section 5 and handled in line with the cookie choices explained in this policy. Some of these providers may process information outside the UK; where this happens, it is carried out subject to the safeguards described in our Privacy Policy.

Tidio, our live chat provider, is based in the United States. Where chat data is processed outside the UK, this is carried out under Tidio’s certified data transfer safeguards, including the UK Extension to the EU-US Data Privacy Framework.

When you subscribe to our newsletter, your name and email address are also shared with Mailchimp, our email delivery provider, who process this data on our behalf under their standard data protection safeguards. Mailchimp is based in the United States.

Information submitted through a website form or live chat is not treated as a cookie. It is handled under our Privacy Policy, including our retention arrangements for enquiries, referral information and service records.

8. How to Manage Cookies

You can accept or reject Performance and Marketing cookies through our cookie banner or Cookie Settings link. Necessary cookies cannot be switched off through the banner because they are required for essential website operation, security, cookie-choice recording or a feature you have requested. You can withdraw your consent at any time using the Cookie Settings link; withdrawing consent is as easy as giving it and will not affect the lawfulness of any processing carried out before you withdraw it.

You can also block or delete cookies and clear local storage through your browser settings, although this may affect website functionality. If you reject non-essential cookies, you can still use the website, but some optional features may work differently.

9. Review and Contact

We review this Cookie Policy at least annually and whenever we change the cookies, tags, scripts, pixels or third-party tools used on our website, or where relevant legal or regulatory requirements relating to cookies or similar technologies change. We will update the cookie and technology list after each cookie scan or material website change.

If you have questions about cookies or privacy, contact our Data Protection Officer by email:

dpo@hersafenetwork.org

You also have the right to complain to the Information Commissioner’s Office (ICO). Information about how to complain is available at:

https://ico.org.uk/make-a-complaint/



Policy version:                      Cookie Policy V1.1
Last review date:                  23 Jul 2026
Next review date:                 
To be confirmed on approval