Data Handling Policy
Data Handling Policy
This policy explains how SimpalUK collects, stores, accesses, retains and disposes of applicant, beneficiary and donor data, including special category health data. Last updated 20 July 2026.
This policy is for internal governance and is published here for transparency. It should be read alongside our Privacy Policy, which explains your rights as a data subject.
This policy was last updated on 20 July 2026.
Who This Policy Applies To
This policy applies to all trustees, volunteers, and anyone acting on behalf of Your Simpal who has access to applicant, beneficiary, donor, or referrer data. Everyone covered by this policy is expected to have read and understood it before handling personal data.
Data Minimisation
We only ask for the information we need to assess eligibility and provide support. We do not collect data speculatively or retain it for possible future use.
How Application Data is Collected
Applications and referrals are submitted through forms on our website. These forms are configured for email delivery only. Submissions are sent directly to the relevant volunteer’s inbox and are not stored in the website’s database at any point.
Database retention of form submissions must remain disabled at all times. This is a standing rule for the website, not a one-off configuration choice, and it must not be re-enabled for any reason.
Where Data is Stored
Once a submission reaches an inbox, it is held within our Google Workspace email accounts, which apply encryption at rest. Access to these accounts is restricted to the individuals who need it to process the application or referral in question.
We do not export, copy, or forward application data to personal devices, personal email accounts, or third-party tools outside our Google Workspace environment, except where necessary to arrange delivery of a SIM card or device to the applicant.
Who Can Access What
Access to applicant and beneficiary data is limited to the volunteers directly involved in processing that application. We do not give blanket access to all volunteers as a default.
Our Data Protection Officer, Mr Chris Lewis, has oversight of how data is handled across the charity and is the first point of contact for any data protection question or concern.
Special Category Data
Some of the information we handle, including health and medical information, and information relating to domestic abuse or human trafficking, is special category data under the UK GDPR. We take particular care with this data:
- It is only accessed by volunteers directly involved in assessing or fulfilling the application.
- It is never used or referenced for any purpose beyond assessing eligibility and providing the support requested.
- It is not discussed outside the context of processing the application, including with other volunteers who do not need to know it.
Referrals From Professionals
Where a referral is made on an applicant’s behalf by an NHS worker, social worker, hospice worker, or other professional, we handle the information they provide under the same principles set out in this policy. We do not share what a referrer has told us with the applicant or any third party without good reason.
Retention
- Application and beneficiary records are kept for a maximum of twelve months from the date of last contact, in line with our Privacy Policy.
- Donor records are kept for seven years from the date of the last donation, in line with financial record-keeping requirements.
- General correspondence is kept for three years unless it relates to a matter requiring a longer period.
When a retention period ends, the relevant emails and any associated records are permanently deleted, not simply archived or moved.
Account Security
All Google Workspace accounts used to receive application or beneficiary data must have two-factor authentication enabled. This is a precondition for any volunteer being given access to these accounts.
Volunteer Confidentiality
Every volunteer handling personal data is expected to keep it confidential, both during and after their time volunteering with us. This includes information learned informally in the course of processing an application, not only what is written down.
If Something Goes Wrong
If a volunteer becomes aware of a data breach, a misdirected email, unauthorised access, or any other incident involving personal data, they must report it to Chris Lewis immediately. We will assess whether the breach needs to be reported to the Information Commissioner’s Office and, where required, will do so within 72 hours of becoming aware of it.
Review
This policy is reviewed annually, or sooner if our systems, processes, or legal obligations change.