Privacy Policy

Make a complaint

The RSE collects personal information relating to a variety of data subjects from Fellows of the RSE and members of the Young Academy of Scotland through to attendees at events, awards applicants, venue clients and staff members throughout the course of its activities. This document delineates the types of personal information that the RSE is likely to collect, the ways in which we collect and process personal information and the rights of data subjects as outlined by the General Data Protection Regulation (GDPR, 2018).

What types of personal information is the RSE likely to collect?

The RSE may collect a number of different personal details which are about a person and which, either on their own or in combination with other information already held about that person, will allow us to identify that person as an individual. Depending on the nature of your relationship with the RSE, these details may include but are not limited to the following:

  • title;
  • first name;
  • surname;
  • login credentials (including username and password);
  • postal address (including billing/shipping addresses);
  • telephone number (including home and mobile telephone numbers);
  • email address;
  • social media account ID (including Facebook usernames and Twitter handles);
  • photographs;
  • device information (such as MAC address, IP address, operation system and browser type);
  • location information (such as GPS signal emitted by your mobile device);
  • age;
  • date of birth;
  • gender;
  • information necessary for legal compliance (including details of ethnicity or disability access requirements);
  • payment information (such as bank account, debit or credit card details);
  • educational institute details (such as your school, university or college);
  • marketing preferences (for example where you have opted in to receive our newsletter(s));
  • reason(s) for contacting us (such as requests or enquiries);
  • opinions, preferences, feedback, complaints, comments and /or suggestions (including comments made on our social media pages);
  • online browsing habits, activities and behaviour (i.e. which RSE web pages you have visited and when);
  • visit history, habits, activities and behaviour (i.e when you have visited the RSE’s premises, attended an event or participated as a committee member);
  • preferences, access needs and dietary requirements;
  • employment related information;
  • security related information (including security incident reports and CCTV footage of our public areas).

In accordance with GDPR, the RSE endeavours to collect personal information directly from the data subject and will use all such information solely for the predefined purpose(s) for which that information has been provided.

The RSE may collect information from and/or combine any personal information which has been provided by a data subject with other sources when it is lawful to do so and when so doing is likely to enhance the efficiency and relevance of the services that we provide to others. Such sources may include:

  • Google or other internet search engine results or publicly available data from Facebook, Twitter and similar social medial, or other information in the public domain;
  • individuals and/or organisations whom you have confirmed may provide us with personal information;
  • government, tax or law enforcement agencies;
  • other sources (such as when personal information about you is volunteered by a third party, e.g. in a complaint or as part of a group booking).

The RSE may also on occasion collect and use sensitive personal information such as dietary or access and assistance requirements which may indicate a health condition. In all such instances, however, we will ask you to provide the necessary details only. For example, we may need to collect sensitive personal information in order to assist with any access requirements that you may have and to comply with our legal obligations under equality legislation. In other cases, we will collect this type of information only with your clear consent. Should you provide us with any sensitive personal information in any other instance, you will be deemed to have consented to our collection and use of that information.

How does the RSE collect personal information?

The RSE collects personal information through one or more of the following data collection media:

  • our physical site (i.e. through the data subject’s interaction with staff members, systems or equipment located within 22-26 George Street, Edinburgh);
  • websites and micro sites as may be updated and/or extended from time to time, including our main website at www.rse.org.uk and the individual web portals associated with our services;
  • other online/mobile interactive features;
  • official social media pages (which may be provided in partnership with a third party social media platform such as Facebook or Twitter where other privacy policies and practices will apply);
  • communication channels (i.e. telephone, SMS/text message, email and fax).

The personal information collected may be stored in electronic and/or hard copy formats.

How does the RSE use personal information?

The RSE may use personal information for a variety of purposes, depending upon the data subject’s relationship with the RSE and/or the specific service(s) that have been requested. The RSE will use personal information for one or more of the following purposes:

  • to enable the data subject to participate in and/or use our services;
  • to respond to, action and/or deal with the data subject’s feedback, requests and enquiries;
  • to ensure that our services are provided in the most effective manner for the data subject and the device that he/she is using;
  • to manage and improve services;
  • to review and analyse the data subject’s use of our services in order to develop and improve the quality of our offering and strengthen our relationship with him/her;
  • to personalise our services and present the data subject with content and information which are tailored to his/her needs;
  • to send the data subject communications (including e-mail marketing and fundraising communications) with his/her consent where required;
  • to invite the data subject to provide feedback, assist with surveys and input into consultation exercises;
  • to provide the data subject with administrative information and/or service announcements and updates (including changes to our policies and terms);
  • to ensure our records are accurate and up to date;
  • to fulfil any contractual obligations assumed by the RSE (e.g. in the provision of tickets for an event, the processing of payments and/or the delivery of services);
  • to comply with our legal obligations and to perform our statutory and public functions and duties;
  • to administer our legitimate internal management analysis, audit, forecasts and business plans and transactions;
  • to enforce our rules and policies (e.g. our Diversity Policy);
  • to ensure the data subject’s safety and the security of our premises;
  • to establish, defend or exercise our legal rights;
  • to comply with orders, requests received from public, regulatory, governmental and judicial bodies;
  • to comply with our legal, regulatory and internal governance obligations (e.g. record retention policies).

Personal information will, however, be processed if and only if one or more of the following conditions has been satisfied:

  • The data subject has provided informed, unambiguous consent for his/her information to be used for a specified purpose(s);
  • It is necessary for the RSE’s fulfilment of a contract with you (e.g. the purchase of tickets or the hiring of a room);
  • It is necessary for the purposes of the RSE’s legitimate interests;
  • The RSE is under a legal obligation to do so (e.g. for equality monitoring, employment or health and safety purposes);
  • It is in the public interest and required in the performance of our official duties.

Does the RSE share personal information with third parties?

Personal information will be made available to members of the RSE’s staff who need to see it in order to perform their functions/roles/responsibilities in respect of the services that have been requested and/or agreed upon. Information may be held in our Customer Relationship Management (CRM) database in order to consolidate details of a data subject’s dealings with the RSE in its entirety and may be shared with service providers such as caterers, sister academies and funding bodies on a need-to-know basis. The RSE will, however, ensure that a confidentiality agreement has been put in place with all such parties prior to the disclosure of any personal data.

How does the RSE keep personal information safe?

The RSE takes all possible steps to protect the security of personal information in accordance with our legal obligations with information being stored either in secure storage or electronically in a secure server and/or databases that are password protected and made accessible to staff on a need-to-know basis only.

Please note, however, that the RSE cannot guarantee the security of the transmission of personal information via the internet. All personal information should therefore be submitted online if and only if the data subject is accepting of the incumbent security risks.

For how long will the RSE retain personal information?

The RSE will keep personal details on record until we have dealt completely with a data subject’s request, enquiry or contract and then for a reasonable period thereafter in accordance with data protection and other legislation as set out in the RSE’s Records Management Policies and Procedures.

Should the RSE decide that the retention of personal information is no longer necessary, all such information will be destroyed/deleted in a secure and confidential manner.

Any personal information provided to the RSE in relation to its Fellows, Young Academy of Scotland members and recipients of awards may, however, be kept indefinitely for the purposes of maintaining a comprehensive archive of the RSE’s activities.

What rights do data subjects have in relation to personal information?

Data subjects are entitled to request:

  • If and how their personal data is being collected and processed;
  • A description of the nature of the personal data that is being collected and processed;
  • Copies of, and/or to access their own personal information (see How do I make a subject access request? below);
  • That their personal information be corrected and/or amended where inaccurate or incomplete;
  • That their personal data be deleted or that the RSE stop using their personal data where there is no longer a need to do so;
  • That the RSE stop sending direct marketing communications.

How do I make a subject access request?

A subject access request should be submitted in writing to the RSE’s Data Protection Officer:

Email:
dataprotection@therse.org.uk

Mail:
The Data Protection Officer
The Royal Society of Edinburgh
22-26 George Street
Edinburgh
EH2 2PQ

The RSE may require an individual to verify his/her identity and/or to provide further details in order to locate the required information but will endeavour to respond to all such enquiries within one calendar month once the necessary information has been provided.

In instances where a subject access request is likely to result in the disclosure of personal information relating to a third party, the RSE will require that third party to consent to the disclosure. If consent from that person cannot be obtained, the subject access request may be denied.

What action(s) will the RSE take in response to a personal data breach?

A personal data breach is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. In instances where a data breach is likely to endanger the data subject’s rights or freedoms, the RSE will notify the ICO within 72 hours of becoming aware of the breach by completing and submitting a Data Protection Breach Notification Form and will record the breach in the RSE’s Data Protection Breach Log. Both documents will state:

  • The date and time of the breach (or an estimate);
  • The date and time that the breach was detected;
  • Basic information about the nature of the breach;
  • Basic information about the personal data concerned;
  • The effects of the breach; and
  • Any remedial action taken.

Whenever possible, they will include also:

  • Full details of the incident,
  • The number of individuals affected and its possible effect(s) on them,
  • The measure(s) taken to mitigate those effects, and
  • Details of the RSE’s notification of the breach to affected data subjects.

If these details are not yet available, the RSE will provide them or an indication of the likely timescale required to provide them to the Information Commissioner’s Office (ICO) by completing and submitting a second notification form within three days of the initial notification.

If a personal data breach is likely to affect the personal data or privacy of the RSE’s data subjects adversely, the RSE will notify them of the breach without unnecessary delay, detailing:

  • The RSE’s name and contact details;
  • The estimated time and date of the breach;
  • A summary of the incident;
  • The possible effect(s) that the breach could have on the individual;
  • The measures taken by the RSE to address the breach;
  • How the affected individuals can mitigate any possible adverse impact of the breach.

Who should I contact for further information?

For further information relating to the RSE and data protection, please contact the RSE’s Data Protection Officer via dataprotection@therse.org.uk.


The RSE collects personal information relating to a variety of data subjects from Fellows of the RSE and members of the Young Academy of Scotland through to attendees at events, awards applicants, venue clients and staff members throughout the course of its activities. This document delineates the types of personal information that the RSE is likely to collect, the ways in which we collect and process personal information and the rights of data subjects as outlined by the General Data Protection Regulation (GDPR, 2018).

What types of personal information is the RSE likely to collect?

The RSE may collect a number of different personal details which are about a person and which, either on their own or in combination with other information already held about that person, will allow us to identify that person as an individual. Depending on the nature of your relationship with the RSE, these details may include but are not limited to the following:

  • title;
  • first name;
  • surname;
  • login credentials (including username and password);
  • postal address (including billing/shipping addresses);
  • telephone number (including home and mobile telephone numbers);
  • email address;
  • social media account ID (including Facebook usernames and Twitter handles);
  • photographs;
  • device information (such as MAC address, IP address, operation system and browser type);
  • location information (such as GPS signal emitted by your mobile device);
  • age;
  • date of birth;
  • gender;
  • information necessary for legal compliance (including details of ethnicity or disability access requirements);
  • payment information (such as bank account, debit or credit card details);
  • educational institute details (such as your school, university or college);
  • marketing preferences (for example where you have opted in to receive our newsletter(s));
  • reason(s) for contacting us (such as requests or enquiries);
  • opinions, preferences, feedback, complaints, comments and /or suggestions (including comments made on our social media pages);
  • online browsing habits, activities and behaviour (i.e. which RSE web pages you have visited and when);
  • visit history, habits, activities and behaviour (i.e when you have visited the RSE’s premises, attended an event or participated as a committee member);
  • preferences, access needs and dietary requirements;
  • employment related information;
  • security related information (including security incident reports and CCTV footage of our public areas).

In accordance with GDPR, the RSE endeavours to collect personal information directly from the data subject and will use all such information solely for the predefined purpose(s) for which that information has been provided.

The RSE may collect information from and/or combine any personal information which has been provided by a data subject with other sources when it is lawful to do so and when so doing is likely to enhance the efficiency and relevance of the services that we provide to others. Such sources may include:

  • Google or other internet search engine results or publicly available data from Facebook, Twitter and similar social medial, or other information in the public domain;
  • individuals and/or organisations whom you have confirmed may provide us with personal information;
  • government, tax or law enforcement agencies;
  • other sources (such as when personal information about you is volunteered by a third party, e.g. in a complaint or as part of a group booking).

The RSE may also on occasion collect and use sensitive personal information such as dietary or access and assistance requirements which may indicate a health condition. In all such instances, however, we will ask you to provide the necessary details only. For example, we may need to collect sensitive personal information in order to assist with any access requirements that you may have and to comply with our legal obligations under equality legislation. In other cases, we will collect this type of information only with your clear consent. Should you provide us with any sensitive personal information in any other instance, you will be deemed to have consented to our collection and use of that information.

How does the RSE collect personal information?

The RSE collects personal information through one or more of the following data collection media:

  • our physical site (i.e. through the data subject’s interaction with staff members, systems or equipment located within 22-26 George Street, Edinburgh);
  • websites and micro sites as may be updated and/or extended from time to time, including our main
  • website at www.rse.org.uk and the individual web portals associated with our services;
  • other online/mobile interactive features;
  • official social media pages (which may be provided in partnership with a third party social media platform such as Facebook or Twitter where other privacy policies and practices will apply);
  • communication channels (i.e. telephone, SMS/text message, email and fax).

The personal information collected may be stored in electronic and/or hard copy formats.

How does the RSE use personal information?

The RSE may use personal information for a variety of purposes, depending upon the data subject’s relationship with the RSE and/or the specific service(s) that have been requested. The RSE will use personal information for one or more of the following purposes:

  • to enable the data subject to participate in and/or use our services;
  • to respond to, action and/or deal with the data subject’s feedback, requests and enquiries;
  • to ensure that our services are provided in the most effective manner for the data subject and the device that he/she is using;
  • to manage and improve services;
  • to review and analyse the data subject’s use of our services in order to develop and improve the quality of our offering and strengthen our relationship with him/her;
  • to personalise our services and present the data subject with content and information which are tailored to his/her needs;
  • to send the data subject communications (including e-mail marketing and fundraising communications) with his/her consent where required;
  • to invite the data subject to provide feedback, assist with surveys and input into consultation exercises;
  • to provide the data subject with administrative information and/or service announcements and updates (including changes to our policies and terms);
  • to ensure our records are accurate and up to date;
  • to fulfil any contractual obligations assumed by the RSE (e.g. in the provision of tickets for an event, the processing of payments and/or the delivery of services);
  • to comply with our legal obligations and to perform our statutory and public functions and duties;
  • to administer our legitimate internal management analysis, audit, forecasts and business plans and transactions;
  • to enforce our rules and policies (e.g. our Diversity Policy);
  • to ensure the data subject’s safety and the security of our premises;
  • to establish, defend or exercise our legal rights;
  • to comply with orders, requests received from public, regulatory, governmental and judicial bodies;
  • to comply with our legal, regulatory and internal governance obligations (e.g. record retention policies).

Personal information will, however, be processed if and only if one or more of the following conditions has been satisfied:

  • The data subject has provided informed, unambiguous consent for his/her information to be used for a specified purpose(s);
  • It is necessary for the RSE’s fulfilment of a contract with you (e.g. the purchase of tickets or the hiring of a room);
  • It is necessary for the purposes of the RSE’s legitimate interests;
  • The RSE is under a legal obligation to do so (e.g. for equality monitoring, employment or health and safety purposes);
  • It is in the public interest and required in the performance of our official duties.

Does the RSE share personal information with third parties?

Personal information will be made available to members of the RSE’s staff who need to see it in order to perform their functions/roles/responsibilities in respect of the services that have been requested and/or agreed upon. Information may be held in our Customer Relationship Management (CRM) database in order to consolidate details of a data subject’s dealings with the RSE in its entirety and may be shared with service providers such as caterers, sister academies and funding bodies on a need-to-know basis. The RSE will, however, ensure that a confidentiality agreement has been put in place with all such parties prior to the disclosure of any personal data.

How does the RSE keep personal information safe?

The RSE takes all possible steps to protect the security of personal information in accordance with our legal obligations with information being stored either in secure storage or electronically in a secure server and/or databases that are password protected and made accessible to staff on a need-to-know basis only.

Please note, however, that the RSE cannot guarantee the security of the transmission of personal information via the internet. All personal information should therefore be submitted online if and only if the data subject is accepting of the incumbent security risks.

For how long will the RSE retrain personal information?

The RSE will keep personal details on record until we have dealt completely with a data subject’s request, enquiry or contract and then for a reasonable period thereafter in accordance with data protection and other legislation as set out in the RSE’s Records Management Policies and Procedures.

Should the RSE decide that the retention of personal information is no longer necessary, all such information will be destroyed/deleted in a secure and confidential manner.

Any personal information provided to the RSE in relation to its Fellows, Young Academy of Scotland members and recipients of awards may, however, be kept indefinitely for the purposes of maintaining a comprehensive archive of the RSE’s activities.

What rights do data subjects have in relation to personal information?

Data subjects are entitled to request:

  • If and how their personal data is being collected and processed;
  • A description of the nature of the personal data that is being collected and processed;
  • Copies of, and/or to access their own personal information (see How do I make a subject access request? below);
  • That their personal information be corrected and/or amended where inaccurate or incomplete;
  • That their personal data be deleted or that the RSE stop using their personal data where there is no longer a need to do so;
  • That the RSE stop sending direct marketing communications.

How do I make a subject access request?

A subject access request should be submitted in writing to the RSE’s Data Protection Officer:

Email: dataprotection@theRSE.org.uk

Mail:
The Data Protection Officer
The Royal Society of Edinburgh
22-26 George Street
Edinburgh
EH2 2PQ

The RSE may require an individual to verify his/her identity and/or to provide further details in order to locate the required information but will endeavour to respond to all such enquiries within one calendar month once the necessary information has been provided.

In instances where a subject access request is likely to result in the disclosure of personal information relating to a third party, the RSE will require that third party to consent to the disclosure. If consent from that person cannot be obtained, the subject access request may be denied.

What action(s) will the RSE take in response to a personal data breach?

A personal data breach is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. In instances where a data breach is likely to endanger the data subject’s rights or freedoms, the RSE will notify the ICO within 72 hours of becoming aware of the breach by completing and submitting a Data Protection Breach Notification Form and will record the breach in the RSE’s Data Protection Breach Log. Both documents will state:

  • The date and time of the breach (or an estimate);
  • The date and time that the breach was detected;
  • Basic information about the nature of the breach;
  • Basic information about the personal data concerned;
  • The effects of the breach; and
  • Any remedial action taken.

Whenever possible, they will include also:

  • Full details of the incident,
  • The number of individuals affected and its possible effect(s) on them,
  • The measure(s) taken to mitigate those effects, and
  • Details of the RSE’s notification of the breach to affected data subjects.
  • If these details are not yet available, the RSE will provide them or an indication of the likely timescale required to provide them to the Information Commissioner’s Office (ICO) by completing and submitting a second notification form within three days of the initial notification.

If a personal data breach is likely to affect the personal data or privacy of the RSE’s data subjects adversely, the RSE will notify them of the breach without unnecessary delay, detailing:

  • The RSE’s name and contact details;
  • The estimated time and date of the breach;
  • A summary of the incident;
  • The possible effect(s) that the breach could have on the individual;
  • The measures taken by the RSE to address the breach;
  • How the affected individuals can mitigate any possible adverse impact of the breach.

Who should I contact for further information?

For further information relating to the RSE and data protection, please contact the RSE’s Data Protection Officer via dataprotection@theRSE.org.uk


Development

Introduction

The Royal Society of Edinburgh (RSE) is committed to protecting your personal data.

This policy outlines the types of personal data the RSE is likely to collect, and how we ensure this information is held securely and respectfully. The RSE is a registered Scottish Charity (SC000470), and is the parent charity of the RSE Scotland Foundation, a registered Scottish Charity (SC024636).

Personal data means any information about you through which you can be identified. This could include your name and contact details, biographical information, information about your interests and qualifications, or an image of yourself.

Special categories of personal data require a higher level of protection. This data includes information about a person’s race, ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification purposes, health data, and sexual orientation.

Changes to this privacy policy

This policy is kept under regular review, and may be modified from time to time. This policy was last updated and approved by the RSE’s Senior Leadership Team on 08/06/2026.

Legal Basis for Processing

By ‘processing’, we mean what happens to your personal data – this could be collecting, recording, keeping, storing, sharing, archiving, deleting, and destroying it.

The lawful bases set out in the GDPR that we use to process your information are:
(a) Consent: we will ask for your consent to process your data. This includes but is not exclusive to marketing preferences, use of cookies, and processing Diversity, Equality, & Inclusion data. Data subjects will always be given visibility of our Privacy Policy and the option to opt-out under this basis;
(b) Contractual obligation: we are required to process your data in order to fulfil the terms of a contract we have with you;
(c) Legal obligation: we are required to keep some data for legal obligations, for example, tax purposes;

(d) Vital interests: we will use personal data if necessary to protect your life, for example, using health information in the event of a medical emergency.
(e) Public task: we are required to support public organisations by supplying them with certain information, for example, the Home Office in its statutory duties;
(f) Legitimate interest: we require your personal information in order to enable us to manage and carry out our core interests as an organisation. Data subjects will always be given visibility of our Privacy Policy and the option to opt-out under this basis.

Your rights:

You have the right to request access to the personal data we process regarding you, and have the right to request rectification of your personal data if there are inaccuracies. Under certain circumstances, you are entitled to request the erasure of your personal data, restrict the processing of your personal data, or object to our processing of your personal data.

Under certain circumstances, you are entitled to receive the personal data concerning you in a structured, commonly used and machine-readable format, and you have the right to transmit your personal data to another data controller.

You have the right to fully or partially withdraw consent previously given regarding the processing of personal data at any time, with effect from the time of the withdrawal. Parents may also fully or partially withdraw consent previously given regarding the processing of their child’s data.

If you have any complaints regarding our processing of your personal data you have the right to lodge a complaint with the RSE, either by either using our online form or by writing directly to the DPO.

You also have the right to lodge a complaint with the Information Commissioner (the UK’s independent authority for data protection and information rights).

To make a subject access request, please submit your request in writing to the RSE’s Data Protection Officer:

Email:
dataprotection@therse.org.uk

Mail:
The Data Protection Officer
The Royal Society of Edinburgh
22-26 George Street
Edinburgh
EH2 2PQ

Subject access requests will usually be answered within one month. If we require additional information to confirm your identity or clarify the scope of your request, we will contact you as soon as possible. In certain circumstances (for example where a request is particularly complex, or where we have received a number of requests from the same individual) we may extend the response period by up to two months. If an extension is required, we will inform you within one month of receiving your request and explain the reasons for the delay.

In instances where a subject access request is likely to result in the disclosure of personal information relating to a third party, the RSE may ask that third party to consent to the disclosure. If consent from that person cannot be obtained, the subject access request may be fully or partially denied, or redaction may be applied.

What action will the RSE take in response to a personal data breach?

A personal data breach is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. In instances where a data breach is likely to endanger the data subject’s rights or freedoms, the RSE will notify the ICO within 72 hours of becoming aware of the breach by completing and submitting a Data Protection Breach Notification Form and will record the breach in the RSE’s Data Protection Breach Log. Both documents will state:

  • The date and time of the breach (or an estimate);
  • The date and time that the breach was detected;
  • Basic information about the nature of the breach;
  • Basic information about the personal data concerned;
  • The effects of the breach; and
  • Any remedial action taken.

Whenever possible, they will include also:

  • Full details of the incident,
  • The number of individuals affected and its possible effect(s) on them,
  • The measure(s) taken to mitigate those effects, and
  • Details of the RSE’s notification of the breach to affected data subjects.

If these details are not yet available, the RSE will provide them or an indication of the likely timescale required to provide them to the Information Commissioner’s Office (ICO) by completing and submitting a second notification form within three days of the initial notification.

If a personal data breach is likely to affect the personal data or privacy of the RSE’s data subjects adversely, the RSE will notify them of the breach without unnecessary delay, detailing:

  • The RSE’s name and contact details;
  • The estimated time and date of the breach;
  • A summary of the incident;
  • The possible effect(s) that the breach could have on the individual;
  • The measures taken by the RSE to address the breach;
  • How the affected individuals can mitigate any possible adverse impact of the breach.

Who should I contact for further information?

For further information relating to the RSE and data protection, please contact the RSE’s Data Protection Officer via dataprotection@therse.org.uk.

Supporting the RSE

For the purposes of engaging supporters with our fundraising efforts, the RSE may collect and review your personal information including:

  • your name and contact details;
  • information about your current employment, education, and career history;
  • your interests and activities;
  • information about previous interactions with the RSE (such as events attended and invited to, participation in and communications about RSE activities, donations made or legacies pledged, and gift aid status);
  • information that is publicly available about you, such as content on social media (including LinkedIn and Facebook), professional profiles and publicly available biographies, information from sites such as Companies House, and reports in print publications (such as newspapers and magazines).

This information will be used to inform you about upcoming events and activities, provide you with networking opportunities, and notify you about our fundraising activities, including requests to consider giving financial support to the RSE, or to ask you to consider supporting us in other ways. The RSE may also use this information to ask you to fill in surveys to improve our fundraising activities and supporter engagement. You may opt out of fundraising or marketing communications at any time by using the unsubscribe link in our communications or by contacting us.

Information related to donors is held securely in our contact management system, CiviCRM.

The RSE processes personal data for these purposes on the basis of its legitimate interests in promoting and securing support for its charitable objectives, to comply with legal obligations, and, where relevant, on the basis of consent. Where we rely on legitimate interests, we will balance our fundraising activities with individuals’ privacy rights and expectations.

Making a donation

If you make a donation to the RSE, we will use your information to securely process your donation, and to claim Gift Aid. Information shared in a completed Gift Aid declaration will be shared with HMRC to enable us to collect the tax on your donations.

If necessary, we will use publicly available sources to carry out due diligence on donors to comply with applicable legal, regulatory, and ethical obligations, including due diligence requirements.

Following a donation and in agreement with you, we may include your name on a list of donors and legacy pledgers to the RSE and you will be recognised on our Donor List which may be produced both in print and online. You can opt to remain anonymous when making any donation or pledging a legacy gift to us. The RSE may retain records of donations and philanthropic support for archival, historical, and statutory reporting purposes in accordance with our retention policies.

Wealth screening

In order to ensure requests for support are targeted and proportionate, including reducing generic communications and unsuitable asks, the RSE will undertake in-house research to analyse the personal information of our community, and assess the likelihood of an individual supporting the RSE. In doing so, we may use profiling techniques, and will use information you have already provided us with, and information that is publicly available about you. This helps us understand our donors and potential donors and ensures, as far as possible, that only relevant communications are sent to you.

In addition to in-house research, we may use a third party to carry out wealth screening. This will involve gathering information from the public domain. Any third-party provider engaged for wealth screening or related services will process personal data under a written data processing agreement containing appropriate confidentiality, security, and data protection obligations. This profiling does not involve solely automated decision-making that produces legal or similarly significant effects. We do not intentionally collect or use special category personal data (such as information about health, ethnicity, religious beliefs, political opinions, or sexual orientation) for fundraising profiling or wealth screening purposes unless you have chosen to provide us with this.

You also have the right to object to the processing of your personal data, including profiling related to fundraising activities, at any time. You may opt-out of wealth screening at any time by contacting our Director of Development, Andrew Grant at agrant@theRSE.org.uk or the Data Protection Officer at dataprotection@theRSE.org.uk.

Making a complaint

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

All complaints relating to personal data processing will be referred to the Data Protection Officer (DPO). Once a complaint has been received, proportionate checks will be undertaken to confirm the identity of the data subject. Complaints will be investigated objectively, resolved without undue delay, and documented for audit purposes.

In many cases, it may not be appropriate for the DPO to handle the complaint, for example, if they handled the subject access request about which a complaint has been made. In this case, a member of staff who has not been involved in the complaint to date will be identified, with senior staff prioritised to carry out the investigation.

If you are unhappy with the way the RSE has handled your complaint, you have the right to raise your concerns with the Information Commissioner. Information about doing so can be found: https://ico.org.uk/make-a-complaint/

Name*