Data Protection Notice and Privacy Policy

This privacy policy explains how The Hannah Dairy Research Foundation (“HDRF”) use any personal information we collect about you when you use our services.

HDRF is a “controller” of the personal information that you provide to us and complies fully with the requirements of  UK GDPR (referred to here as General Data Protection Regulation, “GDPR”). To that end, HDRF will ensure that all personal data are:

  1. collected and processed lawfully, fairly and in a transparent manner
  2. collected and processed for specific and legitimate purposes
  3. adequate, relevant and limited to what is necessary in relation to these purposes
  4. accurate and kept up to date
  5. kept in a form which permits identification of data subjects for no longer than is necessary for the stated purposes
  6. processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures

HDRF will not share your data with any third party other than those organisations and individuals directly involved with it nor will it undertake any automated decision making or profiling using your data.  HDRF will take all necessary steps to ensure your rights to privacy and confidentiality, ensuring that you have:

  1. The right to be informed
  2. The right of access
  3. The right to rectification
  4. The right to erasure
  5. The right to restrict processing
  6. The right to data portability
  7. The right to object

Operating as a Data Controller under the terms of the GDPR legislation, HDRF collects and processes data to achieve its stated purposes under the provision of Legitimate Interests, defined within GDPR  as:

Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data

HDRF understands its responsibility to protect your interests.   HDRF will:

  1. identify relevant legitimate interests
  2. Check that processing is necessary and there is no less intrusive way to achieve the same result
  3. undertake to use your data only in ways you would reasonably expect
  4. undertake not to use your data in ways which could cause you harm
  5. undertake through the use of opt out not to use your data in ways you would find intrusive

Further information on GDPR can be found in the relevant guidance provided by the UK’s Information Commissioners Office