Privacy Policy
Last updated: May 2026
This Privacy Policy explains how [ORGANISATION NAME] ("we", "us", "our") collects, uses, and protects information when you visit our website or make a donation.
Who we are
[ORGANISATION NAME] is a charitable organisation based in London, United Kingdom, supporting primary and secondary education in Zanzibar. You can contact us at info@zanzibaredusupport.org.
Information we collect
We collect information you give us directly when you:
- Make a donation: name, email address, phone number, postal address, donation amount, and Gift Aid status
- Send a contact message: name, email address, optional phone number, and your message
- Set up a Direct Debit: name, email, address, sort code and account number (collected and stored by GoCardless, not by us)
We also automatically collect limited technical information through our hosting provider (Vercel) and analytics tools, including IP address, browser type, and pages visited. This is used to keep the site running and secure.
How we use your information
We use your information to:
- Process your donation and issue a receipt
- Claim Gift Aid from HMRC where you have indicated you are a UK taxpayer
- Respond to your enquiry
- Send occasional updates about our work, if you have asked to receive them
- Meet our legal and regulatory obligations (including charity reporting and HMRC requirements)
Legal basis for processing
Under UK GDPR, we rely on the following legal bases:
- Contract: processing your donation, setting up Direct Debits
- Legal obligation: Gift Aid records (HMRC requires us to retain these for 6 years), charity accounting records
- Legitimate interests: responding to enquiries, keeping basic donor records to acknowledge your support
- Consent: any optional marketing or newsletter emails (you can withdraw consent at any time)
Who we share your information with
We share information only with the following:
- GoCardless — to process Direct Debit donations (they are the data controller for your bank details)
- Stripe — if card payments are enabled, for processing card donations
- Firebase / Google Cloud — secure cloud storage of donation records and contact messages
- HMRC — for Gift Aid claims (name and address only)
- Our trustees and authorised staff — to manage donations and respond to enquiries
We do not sell your data, and we do not share it with marketers.
How long we keep your information
- Donation records with Gift Aid: 6 years (HMRC requirement)
- Donation records without Gift Aid: 6 years (UK charity accounting standard)
- Contact messages: up to 2 years, unless you ask us to delete sooner
- Direct Debit mandates: 14 months after cancellation (Bacs requirement)
Your rights
Under UK GDPR you have the right to:
- Access the information we hold about you
- Correct inaccurate information
- Request deletion of your information (subject to our legal obligations to retain donation records)
- Restrict or object to processing
- Request a copy of your data in a portable format
- Withdraw consent at any time
- Lodge a complaint with the Information Commissioner's Office (ICO)
To exercise any of these rights, email info@zanzibaredusupport.org. We will respond within 30 days.
Cookies and tracking
Our website uses only essential cookies needed for the site to function and for the secure admin login. We do not currently use advertising or marketing cookies. See our Cookies page for details.
Children
Our website is not aimed at people under 18. We do not knowingly collect data from children. If you believe a child has provided us with data, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. The date at the top will reflect the most recent change. Material changes will be flagged on our homepage.
Contact
For any privacy questions or data requests: info@zanzibaredusupport.org