How we use your personal data
Summary
The Ileostomy and Internal Pouch Association (IA) (“we”, “our”, “us”) abides by the UK’s General Data Protection Regulation (GDPR). In so doing, we respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our website or interact with us in other ways.
We are a registered charity in England and Wales (no.1172338 ) and registered with the supervisory authority, the Information Commissioner’s Office (ICO) under registration number ZC261857 . IA is the data controller for the personal information we collect. This means we decide how and why your data is used and ensure it is processed lawfully, fairly and securely.
1. Information We Collect
Depending on your interaction with IA, we may collect:
Identity and Contact Data
- Name and contact details (address, email, telephone)
- Demographic information (date of birth, ethnicity)
- Notes about the issues you raise and what support we have provided.
- Information from third parties: personal data from trusted third parties such as fundraising platforms, healthcare partners, or event organisers, where you have given them permission to share your details
Technical Data
- IP address, browser type, and device identifiers.
- Device information
- Cookies and website analytics information
Financial Data
- Bank account information
- Details of payments or donations
Special Category Data
Some information relating to health conditions, surgery, treatment or support needs is classified as Special Category Data under UK GDPR. We process this data only where necessary to provide services and support, with appropriate safeguards including restricted access, staff and volunteer training, and secure systems.
2. How we use your information
We only use your personal data where the law allows. This includes:
- To provide you with support, information and resources
- To keep internal records and manage member and supporter relationships
- To invite you to events, webinars, or community activities
- To operate, moderate and safeguard our online support activities, including verifying membership requests and responding to welfare or safeguarding concerns where appropriate
- To process donations and payments and maintain financial records
- To monitor and improve our website, social media and support services and security through analytics
- To send you information about our work, campaigns, or fundraising – but only where you have given us your consent or where we are allowed by law
- To send you email or post from third parties (where you have opted in); we may include information from our partners in our communications, but we do not share your data with third parties for their own marketing
- To monitor the issues people contact us about, to develop our work
- To invite you to give feedback on our support services
- To fulfil legal and regulatory obligations
3. Lawful Bases for Processing
We always ensure there is a valid legal basis before processing your data. We rely on one or more of the following regarding lawful bases:
- Consent (Art. 6(1)(a)) – when you agree for us to contact you or share your data.
- Legitimate interest (Art. 6(1)(f)) – for running our charity effectively, maintaining supporter records, safeguard and moderate those using our support services, and improving our services
- Legal obligation (Art. 6(1)(c)) – where we must keep records for HMRC or regulatory purposes
- Special category data (Art. 9(2)(d)) – as a not-for-profit body, we process health data to provide support services, with appropriate safeguards in place
- Contract (Art. 6(1)(b)) – where processing is necessary to administer membership, event bookings, purchases or other services requested by you
4. Sharing your information
We may share information with:
- Local IA branches/groups/affiliate charities;
We may share your information with trusted third-party service providers, such as:
- Professional service providers e.g. counsellors
- Payment processors
- IT and cloud service providers
- Printer and mailing houses for sending literature
- Fundraising or event platforms (e.g. JustGiving, Eventbrite)
- Professional advisers and regulators (e.g. auditors, HMRC)
- Regulators, government bodies and law enforcement where required
All third parties are required to keep your data secure and act only on our instructions.
International Transfers Some service providers may store or process information outside the United Kingdom and, where applicable, the European Economic Area (EEA). Where this occurs, IA ensures appropriate safeguards are in place through adequacy regulations, recognised certification frameworks, or approved contractual safeguards.
Social Media For social media, your data privacy agreement is with the relevant companies and not IA. However, please be assured that we use these media strictly in accordance with their terms and conditions and will never use or share any information about you that we may receive through your use of them.
We never sell personal information.
5. Cookies and website analytics
We use cookies and similar tools to:
- Improve website functionality
- Analyse visitor behaviour (e.g. which pages are most popular)
- Tailor content and marketing (where consent is given)
You can manage or disable cookies at any time through your browser or our Cookie Policy. For more details, please see our Cookie Policy – Ileostomy & Internal Pouch Association
6. How long we keep your information
Personal information is retained only as long as necessary for the purposes it was collected and to meet legal, regulatory and financial obligations. A detailed retention schedule is maintained by IA:
| Data Type | Retention |
| Membership records | Membership duration + 7 years |
| Financial records | 7 years |
| General Enquiries | 1 year after closure |
| Delivery of support services | 5-7 years after last interaction |
| Campaign contributions | 18 months |
| Content contributions | Retain the underlying consent records for 6 years after the content is last used |
| Nursing service enquiries | 6 years, sometimes longer depending on risk and circumstances |
| Safeguarding information | 7 years, sometimes longer depending on risk and circumstances |
| Complaints | 6 years after closure |
| Event registrations | 1 year |
| Website logs | 1 year |
| Marketing and newsletter subscriptions | Consent duration and then suppressed |
| Recruitment documents | 1 year |
7. Your rights
You have the following rights under UK GDPR:
- To access your personal data
- To have incorrect data corrected
- To request deletion of your data (“right to be forgotten”) in certain circumstances
- To restrict or object to processing of your data where we rely on legitimate interests as our lawful basis
- To withdraw consent at any time (where processing is based on consent)
- To request transfer of your data to another organisation (where applicable) (“data portability”)
- To lodge a complaint with the ICO if you are unhappy with how we handle your data
- To object to us using your information for feedback purposes
- We do not use your personal data for automated decision-making or profiling that has legal or significant effects on you
To exercise your rights, please contact us using the details noted under point 11, below.
8. Children’s data
We do not knowingly collect personal data from children under 18 without parental consent. If we become aware we have collected such data, we will delete it promptly.
9. How we protect your information
We maintain organisational and technical safeguards designed to protect personal information against accidental loss, unauthorised access, disclosure, alteration or destruction.
10. Complaints
Individuals may raise concerns using IA’s Data Protection Complaints Procedure. If dissatisfied with our response, individuals may contact the Information Commissioner’s Office (ICO) at www.ico.org.uk.
11. Contact us
If you have any questions about this policy or wish to exercise your data rights, please contact:
IA
Danehurst Court
35-37 West Street
Rochford
Essex SS4 1BE
0800 0184 724
Email: [email protected]
Website: www.iasupport.org
We review this policy annually or whenever there are significant changes to our data processing. Updates will be published on our website with a new ‘last updated’ date.
Glossary of Terms:
Aggregated Data – Information that has been combined and anonymised so that it cannot identify individual users.
Consent – Freely given, specific, informed and unambiguous agreement by the data subject to the processing of their data.
Data Breach – A security incident leading to accidental or unlawful destruction, loss, alteration, or disclosure of personal data.
Data Controller – The organisation or person that determines why and how personal data is processed.
Data Processor – A third party that processes personal data on behalf of the controller (e.g. a cloud service).
Data Protection Officer (DPO) – The individual responsible for overseeing GDPR compliance within an organisation.
Data Subject – The individual whose personal data is being processed.
Data Subject Rights – The rights individuals have under GDPR, including access, rectification, erasure (“right to be forgotten”), restriction, portability, and objection.
Lawful Basis – The legal reason for processing data (e.g. consent, contract, legal obligation, legitimate interest).
Personal Data – Any information relating to an identified or identifiable person (e.g. name, email, IP address).
Processing – Any operation performed on personal data, such as collection, storage, use, or deletion.
Supervisory Authority – The national body responsible for enforcing GDPR (e.g. the ICO in the UK).

