Privacy Policy

We are committed to respecting your privacy when we use your personal data. We use your data as described below to allow you to use the Website, enhance your experience, comply with applicable data protection laws and ensure that no good cause goes unfunded.

Who are we?

Golden Giving Limited, whose registered office is at 85 Great Portland Street, London, W1W 7LT (Companies House registration number 06688164), trading as People's Fundraising ("PF"), operates https://fundraising.headwaythamesvalley.org.uk (the "Website"). This Privacy Policy governs your use of the Website. Please read this Privacy Policy carefully. If you do not want to be bound by the Privacy Policy, you should not continue to use or access the Website.

How to reach our Data Protection Officer (DPO)?

To contact the Data Protection Officer regarding our processing of your personal data, email qrahim@headwaythamesvalley.org.uk. Postal contact: 85 Great Portland Street, London W1W 7LT.

How do we notify you of changes to this policy?

We keep this Policy under regular review and place updates on /privacy-policy. We will provide notifications of material changes via email or other channels where appropriate. Continued use of the Services after we notify you constitutes acceptance of the updated Privacy Policy. If you do not accept the changes you may delete your account as set out below.

What are your rights?

You have rights in relation to your personal data. These include the right to access, correct, erase, restrict processing, object to processing, and portability where applicable. You can control whether you receive marketing emails by changing the notification preferences on your account.

To exercise any rights, please contact us via our feedback form or email the DPO. For security we may request proof of identity before fulfilling certain requests. We will normally respond within one month. Complex requests may need an extension of up to two further months, in which case we will notify you and explain the reason for the extension.

If you remain dissatisfied you have the right to lodge a complaint with the UK Information Commissioner's Office at https://ico.org.uk/.

What data do we collect?

We only collect personal data you provide to us or that we generate in the course of providing the Services. Typical categories are:

  • Account information: name, email, username and password (hashed).
  • Donation & payment information: billing address, payment transaction details (processed by our payment providers).
  • Public page information: name and donation amounts (unless you choose to be anonymous).
  • Usage data: clickstream, logs and technical data to operate and improve the Website.
  • Support & communications: messages you send to our support team, survey responses and marketing preferences.

What happens if you don't want us to have your data?

You are not required to provide personal data to us. However, if you withhold required information we may not be able to provide the Services (for example, we cannot process a donation without payment details). To delete your account, use the account deletion process or contact the DPO.

How do we use your data?

We use personal data to provide services you request, to administer the site, to communicate with you, to process donations and Gift Aid, and to improve our services. In particular:

  • Provide and manage your account and pages (donation pages, fundraising pages, event pages).
  • Process payments and claim Gift Aid where applicable.
  • Send transactional and operational emails (some of which you cannot opt out of).
  • Send marketing and informational messages where you have consented or where we have a lawful basis.
  • Perform analytics and service improvements (aggregated or pseudonymised where possible).

On what legal bases do we process your data?

We rely on the legal bases set out in data protection laws. Below is a high-level mapping of common activities and the most relevant lawful basis. This is intended to increase transparency — specific processing may rely on more than one basis.

Processing activity Lawful basis
Creating and managing accounts Performance of a contract / necessary to provide the Service
Processing donations and payments (including Gift Aid) Performance of a contract and legal obligation (HMRC requirements)
Platform security, fraud prevention Legitimate interests (protecting the Website, users and funds)
Marketing communications Consent where required (or legitimate interests where permitted and you are given an opt-out)
Analytics and product improvement Legitimate interests (to improve the Service), with opt-out options

How are we using your data based on our legitimate interests?

Where we process data on a legitimate interest basis we balance our interests against your rights. Typical legitimate interests include securing the platform, preventing fraud, improving the Website and providing non-intrusive fundraising recommendations. You can object to legitimate-interest processing by contacting our DPO; we will then assess and respond to your objection.

Automated decision-making and profiling

We do not use automated decision-making that produces legal effects or similarly significant effects for individuals. We may use automated analytics and non-decisioning profiling (for example to personalise content or fundraising suggestions). Such systems do not make final or legally binding decisions about individuals. If we introduce any automated decision-making with significant effect in future, we will provide clear notice and any required rights to challenge or request human review.

With whom are we sharing your data?

We will not disclose your data to unrelated third parties except as described below or where required by law. Categories of recipients include:

  • Payment processors and banks (to authorise and complete transactions).
  • Fraud prevention and payment-card industry services.
  • IT, hosting and security providers (cloud services, backups, monitoring).
  • Email and communications providers (to deliver notifications and marketing where permitted).
  • Nonprofits and page owners (where you donate or fundraise, and only with your permission when applicable).

All processors we use are subject to written Data Processing Agreements and must only act on our instructions. A current list of categories of processors, subprocessors and the countries where they operate is available on request from the DPO.

How do Nonprofits use my data?

If you donate or buy a ticket, the relevant page creator and the Nonprofit supported will receive donor details unless you elect to remain anonymous. When we pass your details to a Nonprofit they become a separate controller for those purposes and are responsible for their use of your personal data. If you want to amend preferences or withdraw consent held by a Nonprofit, contact the Nonprofit directly — we cannot always act on preferences you set with third parties.

Where are we sending your data?

The Website stores users' personal data in the UK and EU. Where we or our processors transfer data outside the UK or the European Economic Area, we will ensure appropriate safeguards are in place — for example, an adequacy decision, Standard Contractual Clauses (SCCs) approved for use by the UK/EU, binding corporate rules, or other lawful safeguards permitted under applicable data protection law. You can request further information about the safeguards in place by contacting the DPO.

How do we use personal data of our partner users?

If you work for a Nonprofit or partner organisation we collect business contact details (name, work email, telephone) to enable access to reporting and to provide business services. You may opt out of marketing communications but will continue to receive service-related emails connected to requested functionality.

How long do we keep your data?

We retain personal data only as long as necessary for the purposes for which it was collected, including to meet legal, accounting or reporting requirements. Examples:

Category Retention period Reason
Account/profile information While account is active + 12 months after deletion (unless otherwise required) Account management, fraud prevention
Donation & payment records (including Gift Aid) At least 6 years after the end of the relevant tax year HMRC and accounting requirements
Support logs & audit logs 12–36 months Customer support and security investigations
Marketing preferences Until you withdraw consent or opt out To respect your contact choices
Aggregated / anonymised analytics Indefinitely in anonymised form Service improvement and research

For more details or if you wish us to delete or restrict data sooner, contact the DPO. Note that legal obligations (e.g., Gift Aid) may require longer retention for some records.

Security & breach notification

We implement appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, regular backups, vulnerability scanning and staff security training. In the event of a personal data breach, we will assess the risk to individuals and notify the ICO and affected individuals where required by law without undue delay (and within 72 hours to the ICO where feasible).

Cookies & tracking

Our Website uses cookies and similar technologies for functionality, analytics and marketing. For details of the specific cookies we use, their purpose and retention, and how to control them, see our Cookie Policy: (or use the cookie banner on first visit).

How to exercise your rights or contact us

To exercise your rights or for any questions about this Policy contact:
Data Protection Officer: qrahim@headwaythamesvalley.org.uk
Postal: 85 Great Portland Street, London W1W 7LT
Or use our feedback/contact form: /feedback_input

Start Fundraising
In-memory
Donate to honour or remember someone special - a heartfelt way to celebrate their life while supporting a cause that matters.
Fundraisers
Invite supporters to donate and help reach your fundraising target - every contribution brings you closer and makes a real difference.
Group fundraisers
Centralize all your team's fundraisers onto a single page, streamlining the process and maximizing collective efforts.
Raffles
Offer raffle tickets for sale, giving supporters the chance to win prizes through random selection, adding an element of excitement to your fundraising efforts.
Auctions
Host live or silent auctions, offering supporters the excitement of competitive or discreet bidding - all while raising funds and awarding desirable items.
Sign Up
Individual fundraiser
Sign up to start fundraising for your favourite good cause.

If you require assistance, please Get in Touch.

Sign In

If you don’t have an account yet, please Sign Up to get started.   If you’ve forgotten your password, you can Reset It.