COBALT HOUSING PRIVACY POLICY

Introduction and purpose

Cobalt Housing Limited (‘we,’ ‘us,’ ‘our,’ ‘Cobalt’) is committed to protecting the privacy and security of personal information. This policy describes how we, our partners and contractors collect and use personal information about you.

We are a ‘data controller’. This means that we are responsible for deciding how we hold and use personal information. We are required under data protection laws to notify you of the information contained in this policy. We are registered with the Information Commissioner’s Office (ICO) with registration number Z6774791.

This policy applies to the personal data of past and present tenants, leaseholders, residents, housing applicants and subscribers. For the purposes of this policy, subscribers means anyone that has signed up to one of our newsletters or bulletins, attended our events, followed us on social media or accessed our website.

If you are a past or present employee, board member, advisor or supplier of Cobalt, we may hold further personal data about you. For further information please contact our DPC using the details below. Please note that you may fall into more than one of the categories above so we may hold your personal data in a number of capacities.

This policy does not form part of any contract, lease or tenancy that you have with Cobalt.

Data Protection Co-ordinator

We have appointed a Data Protection Co-ordinator (DPC) to oversee compliance with data protection laws and this policy. If you have any questions about this policy or how we handle personal data, please contact the DPC using the details below.

Email: dataprotection@cobalthousing.org.uk 

Postal address:

Data Protection Co-ordinator Cobalt Housing Limited

199 Lower House Lane Liverpool

L11 2SF

For telephone enquiries, please contact our customer services team on 0330 303 2222.

Summary

Cobalt collects a wide variety of personal data about you. Some of that personal data will be sensitive data, for example about your health or criminal records. We only use this lawfully and in accordance with this policy.

Though we may ask for your consent for certain purposes, for other purposes we will use, store and share data without your consent where we have a lawful basis to do so. Our lawful bases are explained in more detail below.

You have rights in relation to your data and these are explained in detail below. You can exercise your rights at any time by contacting our DPC using the details above.

Changes to this policy

We reserve the right to update this policy at any time and we will make a copy of the updated version available to you.

1. The Data Protection Principles

We will comply with data protection law. The law says that the personal data that we hold must be:

  1. Used in a lawful, fair and transparent way
  2. Collected only for valid purposes that we have clearly explained and not used in any way that is incompatible with those purposes
  3. Relevant to the purposes for which it was collected and limited only to those purposes
  4. Accurate and kept up to date
  5. Kept only as long as necessary for the purposes for which it was collected
  6. Kept securely

2. What personal data we collect about you

Personal data means any information about a living individual from which that person can be identified. It does not include data where the individual’s identity has been removed (such as anonymous data).

Much of the data Cobalt holds relates to our properties and their maintenance and repair. We do not consider property information when identified by an address alone to be personal data. As soon as your name, contact details or other identifying information is used with property information, such as during a visit to repair your house, then the property information becomes personal data and we will only use it in accordance with this policy.

The data that we collect about you will depend on your relationship with us.

2.1  For tenants and leaseholders we collect:

Your basic contact details, including your name, address, telephone number, email address.

Your financial and identity information, including your banking and card details, housing eligibility information, photographic ID and national insurance number.

Service management information, including compliments, complaints and other feedback and records of property visits. This includes recording calls made to our customer contact centre.

Health and welfare information, including details of your physical or mental health and any disabilities or vulnerabilities you may have. This is a special category of sensitive personal data and is subject to additional safeguards.

Equality information, including your racial or ethnic origin, your sexual orientation and your religious or philosophical beliefs. This is a special category of sensitive personal data and is subject to additional safeguards.

Management and order information, including details of any alleged or actual anti-social behaviour or criminal offences and CCTV images from our offices and developments. This includes special category sensitive personal data and the sensitive aspects of this category are subject to additional safeguards.

2.2   For housing applicants we collect:

Your basic contact details, including your name, address, telephone number, email address.

Your financial and identity information, including your banking and card details, housing eligibility information, photographic ID and national insurance number.

Health and welfare information, including details of your physical or mental health and any disabilities or vulnerabilities you may have. This is a special category of sensitive personal data and is subject to additional safeguards.

Equality information, including your racial or ethnic origin, your sexual orientation and your religious or philosophical beliefs. This is a special category of sensitive personal data and is subject to additional safeguards.

Service management and monitoring information, including CCTV images from our offices and developments, if you have visited and recordings of calls made to our customer contact centre, if you have called.

2.3  For residents who are not tenants, leaseholders or housing applicants we collect:

Your basic contact details, including your name, address, telephone number, email address.

Service management information, including compliments, complaints and other feedback and records of property visits. This includes recording calls made to our customer contact centre.

Health and welfare information, including details of your physical or mental health and any disabilities or vulnerabilities you may have. This is a special category of sensitive personal data and is subject to additional safeguards.

Equality information, including your racial or ethnic origin, your sexual orientation and your religious or philosophical beliefs. This is a special category of sensitive personal data and is subject to additional safeguards.

Management and order information, including details of any alleged or actual anti-social behaviour or criminal offences and CCTV images from our offices and developments. This includes special category sensitive personal data and the sensitive aspects of this category are subject to additional safeguards.

2.4  For subscribers we collect:

Your basic contact details, including your name, address, telephone number, email address.

Your online identification information, including details of whether you have visited our site before, which pages you visit on our site and how you navigated to our site.

Your social media information, including your username, personal data you have shared on your profile and engagement information (your likes, shares and retweets).

Service management and monitoring information, including CCTV images from our offices and developments, if you have visited and recordings of calls made to our customer contract centre, if you have called.

3. How we collect your personal data

We collect your personal data directly from you via our forms, surveys, telephone calls (including recording of calls made to our customer contact centre), written communications including email and via cookies on our website. Our Policy relating to the use of cookies can be found on this website.

We also collect personal data about you from third parties, including credit reference agencies, courts and tribunals, previous landlords and, particularly in respect of residents who are not tenants, leaseholders or housing applicants, via our tenants or leaseholders.

We operate a continuous CCTV system at all our office premises for the detection and prevention of crime.

When we collect your information, we will:

  • tell you why we need it and how it will be used;
  • collect only as much as we need for the relevant purpose;
  • take steps to ensure that we record your personal data accurately and keep it up to date;
  • make sure that we do not keep it longer than necessary; and
  • keep it secure and confidential

In return, we ask that you:

  • provide accurate information; and
  • tell us as soon as possible about any change in your circumstances

If any of your personal details or circumstances do change, then please let us know using the contact details at the beginning of this policy.

4. How we use your personal data

We will only use your personal data when the law allows us to. The law says that we must identify a lawful basis for each use of your personal data. We rely on a number of lawful bases, including:

  1. Where we have obtained freely given, specific, informed and unambiguous consent from you to use your personal information in certain ways
  2. Where we need to perform a contract that we have entered into
  3. Where we need to comply with a legal obligation
  4. Where we need to protect your vital interests
  5. Where it is necessary in the public interest for us to use the personal information
  6. Where it is necessary for us to use personal information to pursue our legitimate interests (or those of a third party) and we believe that using personal information in that way is not overridden by the interests or fundamental rights of the person to whom the information relates.

Below, we have set out the purposes for which we use personal data and the lawful bases which are relevant to those purposes.

‘Special categories’ of particularly sensitive personal information require higher levels of protection. We need to have further justification for collecting, storing and using this type of personal data. Below we have identified where special category data is relevant and listed the further justification on which we are relying to process your special category personal data. We have in place an appropriate policy and safeguards which we are required by law to maintain when processing such data.

4.1 Managing your tenancy or leasehold

For tenants and leaseholders only, we use your personal data to manage your tenancy or leasehold agreement or other contract between you and Cobalt Housing.

The processing activities we conduct can be summarised as:

  • Managing your account charges and payments, including arrears. Our lawful basis for this is that it is necessary for the performance of our contract with you.
  • Managing the repairs, maintenance and adaptations of our properties.  Our lawful basis for this is that it is necessary for the performance of our contract with you. We may use special category personal data such as information about your physical or mental health for this purpose and our further justification for that is that we either have your explicit consent or where it is necessary for the provision of health or social care.
  • Ensuring tenancy (or contract) conditions are complied with, such as dealing with anti- social behaviour or fraud. Our lawful basis for this is that it is necessary for the performance of our contract with you. We may use special category personal data such as information about actual or alleged criminal offences for this purpose and our justification for that is that it is necessary for the establishment, exercise or defence of legal claims.

4.2 Managing our properties

For residents that are not tenants or leaseholders only, we use your personal data to properly manage our properties.

The processing activities we conduct can be summarised as:

  • Managing the repairs, maintenance and adaptations of our Our lawful basis for this is that it is necessary to pursue the legitimate interests of Cobalt and our residents in ensuring that our properties are maintained, accessible and fit for purpose. We may use special category personal data such as information about your physical or mental health for this purpose and our further justification for that is that it is necessary for the provision of health or social care.
  • Ensuring tenancy (or contract) conditions are complied with, such as dealing with anti- social behaviour or fraud. Our lawful basis for this is that it is necessary to pursue the legitimate interests of Cobalt and our residents in maintaining a welcoming environment in and around our properties. We may use special category personal data such as information about actual or alleged criminal offences for this purpose and our justification for that is that it is necessary for the establishment, exercise or defence of legal claims.
  • Cobalt does not normally process children’s information as part of a tenancy, as all tenants are adults. However, we record children’s basic information if they live in one of our properties, including their name and date of birth. This is required for checking the property is not overcrowded and to assess other tenancy management issues where all householders and ages are required to be known.  Our lawful basis for this is that that we either have your explicit consent or where it is necessary for the provision of health or social care.

4.3 Processing your housing application

For housing applicants only, we use your personal data to process your application and to administer our waiting lists. Our lawful basis for this is that it is necessary for the purposes of entering into a contract with you at your request.

4.4 Ensuring equality of treatment or opportunity

For tenants, leaseholders, housing applicants and other residents only, we use special category personal data relating to your health including any disability or vulnerability, ethnicity, religion, race, philosophical beliefs and sexual orientation for equal opportunities monitoring. Our lawful basis for this is our legitimate interest in ensuring that we treat everyone equally. Our further justification is that it is in the public interest to ensure meaningful equal opportunities monitoring and reporting.

4.5 Complying with our legal obligations

For tenants, leaseholders, housing applicants and other residents only, we use your personal data to comply with our legal obligations under housing legislation. This includes conducting checks and reporting to regulators in line with relevant legislation. Our lawful basis for this is that it is necessary to comply with our legal obligations.

4.6  Complaints and disputes

We use your personal data (including recordings of calls made to our customer call centre) to manage and resolve any complaints or disputes that may arise over the course of our relationship with you. Our lawful basis for this is that it is necessary to pursue the legitimate interests of Cobalt in ensuring that any complaints or disputes are resolved effectively. We may use special category personal data such as information about actual or alleged criminal offences and information about your physical or mental health for this purpose and our further justification for that is that it is necessary for the establishment, exercise or defence of legal claims.

4.7 Reviewing and improving our services

We also use your personal data (including recordings of calls made to our customer call centre) to continuously review and improve our processes, procedures and training. Our lawful basis for this is that it is necessary to pursue the legitimate interests of Cobalt in ensuring that it has effective and efficient processes, procedures and training in place.

4.8 Running our website

We use your personal data to track the performance of our website and measure engagement with it. Our lawful basis for this is that it is necessary to pursue our legitimate interest in operating a functioning and useful website.

4.9 Providing additional services

We offer additional, optional services including:

  • Organising and assisting community events;
  • Offering opportunities to be involved; and
  • Providing welfare, benefits and debt advice

We use your personal data in the course of delivery of these services. Our lawful basis for this is your consent.

We also offer an optional service to make adaptations to your house to ensure its accessibility and suitability for your particular needs. We use special category personal data relating to your physical and mental health including any disabilities or vulnerabilities when making these adaptations. Our lawful basis and further justification for this is your explicit consent to us using your data for this purpose.

We will ask for your consent when you indicate that you would like to take advantage of these optional services or property adaptations. You do not have to give your consent and may withdraw it at any time. If you do not consent, or you withdraw your consent, we may not be able to make the relevant adaptations or offer these additional services.

4.10 Communicating with you

We use your personal data when we communicate with you. This includes when we send you newsletters and bulletins, when you engage with us on social media and when you give us feedback about our service. Our lawful basis for this is our legitimate interest in building a meaningful and informed relationship with our tenants, leaseholders, applicants, residents and subscribers. Where you are giving feedback on our services, our lawful basis is our legitimate interest in improving our services.

Where we need to communicate with tenants and leaseholders regarding your contract with us this will usually be in writing or by telephone but is more commonly becoming electronic and paperless. Many of our services will be moving to digital platforms (online) over time to allow convenient access such as a self-service portal.

Our tenants receive our newsletter with information about what is going on within the organisation. We are required by our Regulator to keep our tenants informed and to offer opportunities for involvement, but you may opt-out of receiving this by emailing dataprotection@cobalthousing.org.uk.

We will only discuss or communicate your tenancy or lease details with those named on the agreement or those authorised (temporarily or permanently) by you. You can authorise someone temporarily verbally over the phone or permanently in writing. Cobalt will wish to establish that the individual has consented to their details being shared so you will need to obtain their consent (signature) to share their details if the contact is to be in writing or ask them to speak directly to Cobalt if it is for verbal consent.

From time to time we may use your personal data to send direct marketing communications. Our lawful basis for this is that it is necessary to pursue the legitimate interests of Cobalt and our residents in communicating with you. You have the right to object to direct marketing by emailing dataprotection@cobalthousing.org.uk.

We will only send direct marketing to you by email or text where you have provided your consent. Text messages and contact via telephone provide a direct way to contact and share information with you about the services we can deliver to you. If you provide your telephone number we may keep in contact with you by text.

Examples of operational text messages include:

  • Confirming a repair and/or a time and date for a repairs contractor to visit
  • Confirming a home visit
  • Sending a reminder about an appointment
  • Asking you to contact a named person
  • Satisfaction surveys

5. If you fail to provide personal information

If you fail to provide certain personal data when we request it, we may not be able to perform our contract with you properly (such as entering into a lease or tenancy agreement) or we may be prevented from achieving our legitimate interests (such as running our website).

6. Change of purpose

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another purpose and that purpose is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the lawful basis which allows us to do so.

7. Automated decision-making

Automated decision-making takes place when an electronic system uses personal information to make a decision without human intervention. We are allowed to use automated decision- making where we have notified you of the decision and given you 21 days to request a reconsideration, where it is necessary to perform a contract with you or with your explicit written consent.

You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making, unless we have a lawful basis for doing so and we have notified you.

 8. Data sharing

Sometimes it’s in everyone’s best interests for us to share some of the information we have about our tenants with other organisations. This can be because we have a legal obligation to do so and sometimes it’s to ensure you get the best service possible. We require anyone that we share your personal data with to respect the security of your data and to treat it in accordance with the law.

8.1 We share details with certain third parties that provide services on behalf of us. All these third parties are required to take appropriate security measures to protect your personal information in line with our policies. We do not allow third parties to use your personal data for their own purposes. We only permit them to access your personal data for specific purposes and in accordance with our instructions.

Regardless of the circumstances, if we find ourselves in a situation where we need to share your information with another organisation and we can’t rely on the terms of your tenancy agreement or a legitimate interest and you haven’t already given your consent for us to do this, then we will ask for it before releasing any personal information about you.

Under no circumstances will Cobalt ever sell or pass on your information to businesses or organisations so they can get in touch with you directly either by phone, email or in writing in order to sell you their products or services.

We do not usually transfer your personal data outside the EU. If, exceptionally, we do, you can expect a similar degree of protection in respect of your personal information.

Transfers will always be subject to adequate safeguards.

These safeguards may take the form of an adequacy decision. Adequacy decisions are made by the European Commission in respect of certain countries. An adequacy decision means that the countries to which we transfer your data are deemed to provide an adequate level of protection for your personal information.

To ensure that your personal information does receive an adequate level of protection in the absence of an adequacy decision, we will put in place binding corporate rules or standard contractual clauses approved by the European Commission or the ICO to ensure that your personal information is treated by those third parties in a way that is consistent with and respects the EU and UK laws on data protection.

For more information about how your personal data may be shared, please contact our DPC using the details at the top of this policy.

9. Data security

We store personal information both electronically and in paper form.

We implement security policies, processes and technical security solutions to protect the personal information we hold from:

  • Unauthorised access
  • Improper use or disclosure
  • Unauthorised modification
  • Unlawful destruction or accidental loss

When you contact us, we may ask you to provide us with some information so that we can confirm your identity. If other people (e.g. family members, support workers, solicitors) act on your behalf we will take steps to ensure that you have agreed for them to do so. This may include asking them to provide us with supporting information to indicate your consent. We do this to protect you and to make sure that other people cannot find things out about you that they are not entitled to know.

Employees and third parties who have access to, or are associated with the processing of, your personal information are obliged to make reasonable efforts to safeguard it.

10. Data retention

We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect of our relationship with you.

Information relating to a tenancy or lease agreement will be kept for a period not exceeding Cobalt Housing’s retention period, as defined by National Housing Federation retention of documents schedule. The basic history of who held a tenancy at which property and when will be held indefinitely.

In addition, we may retain personal information about former tenants to comply with national laws, prevent fraud, collect any fees owed, resolve disputes, troubleshoot problems, assist with any investigation, and take other actions.

In some circumstances we may anonymise your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you.

11. Changes to your data

It is important that the personal data we hold about you is accurate and up to date. Please keep us informed if your personal data changes during your working relationship with us. If your personal data changes, please let us know using the contact details at the top of this policy.

12.      Your rights, the right to complain and the ICO

In certain circumstances, you have the following rights over your personal data:

Right of access: You have the right to obtain confirmation from Cobalt as to whether or not personal data concerning you is being processed, and, where that is the case, access to that personal data (see ‘Requesting a copy of your personal information’ below)

Right to rectification: You have the right to request Cobalt to rectify inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed by providing a supplementary statement.

Right to erasure (right to be forgotten): You have the right to request Cobalt to erase personal data concerning you.

Right to restriction of processing: You have the right to request Cobalt to restrict processing of your personal data. For example, you may request this if you are contesting the accuracy of personal data held about you.

Right to data portability: You have the right to request Cobalt to provide you with the personal data about you which you have provided to us in a structured, commonly used and machine- readable format. You also have the right to request Cobalt to transmit the data to another controller.

Right to withdraw consent: If the lawful basis for processing is consent, you have the right to withdraw that consent which you can exercise by writing to the DPC at the contact details provided at the top of this policy.

Right to object to direct marketing: Where your personal data are processed for direct marketing purposes, you have the right to object at any time to processing of your personal data for marketing.

Rights in relation to automated decision making and profiling: We do not perform any automated decision-making based on personal data that produces legal effects or similarly significantly affects you.

You can find more information about your rights, and Data Protection in general, on the website of the Information Commissioner’s Office here: https://ico.org.uk

If you wish to exercise any of your rights in relation to your personal data, please contact Data Protection Co-ordinator, Cobalt Housing Limited, 199 Lower House Lane, Liverpool, 11 2SF or dataprotection@cobalthousing.org.uk

 13. Requesting a copy of your personal data

If you would like to request a copy of the data we hold about you, please contact our DPC by emailing dataprotection@cobalthousing.org.uk or write to the Data Protection Co-ordinator, Cobalt Housing Limited, 199 Lower House Lane, Liverpool, L11 2SF.

Save for where the request is manifestly unfounded or excessive, we will respond within one calendar month of receiving your request. It will always help if you can be as specific about what personal data you want to see, what it relates to and within what timeframe, as that will assist our search.

14. Complaints

You have the right to complain about any matter relating to our service, including how we use your personal data: