Live£34,016deployedacross10projects

Privacy policy

Why this policy matters

At Pushpa, trust is everything. Protecting the personal data of our contributors, our team, the people our projects work with, and everyone else we deal with is a responsibility we take seriously.

This policy sets out how we collect, store, use and protect personal data.

What is covered

Pushpa holds personal information about a range of people: contributors, team members, volunteers, and the people taking part in the projects we fund. That means information which could identify someone, such as a name, an email address or a location, and information which may be sensitive.

It covers data in any format, whether that is a database, a spreadsheet, an email, a document, a photograph or a recording. It includes:

  • Information about our contributors, such as names, contact details and contribution history
  • Information about project participants, such as names, images and family members
  • Information about team members, past and present
  • Any data that can be linked to an individual person, directly or indirectly

Our principles

We follow six principles when handling personal data. These are rooted in good practice and in legal requirements, including UK GDPR.

Be fair, lawful and transparent. We only collect and use personal data when we have a clear, legal reason to do so, and we always explain what we are doing and why.

Collect only what is needed. We do not collect more data than we need, and we are clear about what we will use it for.

Keep it accurate and up to date. We do our best to make sure data is correct. If someone tells us their information has changed, we update it promptly.

Store it securely and responsibly. Sensitive data held in a shared drive is saved with access restricted to authorised people only. We avoid keeping physical records of confidential or sensitive information, and where physical copies are necessary they are destroyed as soon as they are no longer in use. Nobody at Pushpa has access to confidential or sensitive information unless it is relevant to their current work, and then only to what is necessary, for as long as it is necessary.

Do not keep it longer than necessary. We only hold data for as long as we need it, whether for reporting, legal or operational reasons.

Respect people's rights. Anyone can ask to see their data, correct it, or ask us to delete it, and we will always do our best to respond quickly and transparently.

Security

We use a mix of technical and organisational safeguards to keep data safe:

  • Password protection and access limits on shared folders and tools
  • Strong passwords, changed regularly
  • Avoiding storing other people's personal data on personal devices
  • Data backups and approved cloud services

Where we work with third parties, such as payment providers, we make sure they are also keeping data secure and compliant.

How long we keep data

We keep personal data only for as long as we need it, and we have set some broad timelines to guide us:

  • Contributor data: up to six years after a final contribution, for reporting, financial records and impact tracking
  • Team and volunteer data: up to six years after leaving, unless we need to keep it longer for legal reasons
  • Financial records: held in line with financial regulations and audit requirements

Once data is no longer needed, we delete or destroy it securely.

Your rights

Everyone whose data we hold, whether you contribute to Pushpa or take part in a project we fund, has the right to:

  • Know what data we hold and why
  • Access your own data
  • Ask us to correct, delete or stop processing your data
  • Object to how your data is being used
  • Ask for processing to be stopped or limited
  • Withdraw consent, where consent is the legal basis for processing

These rights are protected. We will never make the process complicated or ask you to justify the request. It is your data and your choice.

How to make a request

Email hi@pushpafund.com at any time to request access to, correction of, or deletion of your personal data.

Once we receive a request, we will:

  1. Acknowledge it within five working days
  2. Give a full response within 28 days, and often sooner
  3. Ask for proof of identity if we need it to protect your privacy

There is no charge for making a request.

What is held in a contributor profile

Depending on how someone supports Pushpa, we may hold:

  • Full name and contact details
  • Contribution history and preferences
  • Communication preferences, such as whether you have signed up for updates
  • Any messages or stories you have shared with us

This information is only used to manage contributions, communicate impact and share updates where consent has been given. Pushpa does not share or sell contributor data to third parties for marketing purposes. Ever.

If something goes wrong

If there is a data breach, meaning data is lost, stolen or accessed without permission, we will:

  1. Act quickly to contain it
  2. Report it to the relevant authorities if there is a risk to individuals
  3. Tell affected people as soon as possible
  4. Review what went wrong and improve our systems

Updates

This policy will change as we grow and as laws and best practice change. Our Operations Lead reviews it annually to make sure it stays accurate, practical and aligned with our obligations.

Last reviewed