Introduction

Cerebrospinal Fluid Leak Association (CSF Leak Association) is a registered charity (Charity Number: SC046319) in the UK, working to improve understanding and treatment of cerebrospinal fluid (CSF) leaks and associated conditions, such as intracranial hypotension.

We are registered as a data controller with the Information Commissioner’s Office (registration number: ZB804603).

When we process your personal data, we are considered to be the data controller for your personal data. This means that we determine why and how we use it and are responsible for protecting it. When we process your personal data, we must comply with the rules set out in the Data Protection Legislation (the Data Protection Act 2018, the UK General Data Protection Regulation – UK GDPR and the Privacy and Electronic Communications (EC Directive) Regulations 2003 - PECR).

We understand how important your personal data is and we will only process it when we have a lawful reason to do so, when it is necessary and in accordance with the Data Protection Legislation. This Privacy Policy explains how and why we use the information we collect about you; how your personal information will be processed, stored and used; and information about your information rights and how to access them.

What is personal data?

Personal data means any identified or identifiable information that relates to or is about you. This could be your name, contact details, a username, or an IP address. This can be information that can directly identify you or information that can indirectly identify you, such as when it is combined with other information.

Some personal data is considered to be sensitive; this is called ‘special categories of personal data’ and includes information relating to your health or sexual orientation, for example. We must comply with additional requirements when processing this type of data and ensure that we process it securely.

What personal data do we collect?

The personal data that we collect and process about you will vary depending on the relationship that we have with you or are interacting with you. Schedule 1 outlines what personal data we process about you according to our identified purposes for processing it.

How do we obtain your personal data?

In most cases, we will collect your personal data directly from you. For example, if you visit our website, fill out a form, provide personal data by email or through our social media channels.

Which lawful grounds do we have to process your personal data?

When we process personal data, we must have a lawful basis (lawful grounds) to do so. There are six lawful grounds that we can process personal data under and the lawful basis will depend on the reasons why we need to process it and your relationship with us.

The lawful grounds that we use for processing your personal data is outlined in Schedule 1 to this Privacy Policy.

Why do we process your personal data?

The reasons why we process your personal data will vary depending on the reasons why we are interacting with you or the services that we are offering. The purposes for processing your personal data is outlined in Schedule 1 to this Privacy Policy

There may be some circumstances where we need to process your personal data for reasons not set out in in this Privacy Policy. For example, when we are required to by law (such as when it is necessary to comply with a legal obligation or a Court Order) or need to share information for the purposes of the prevention or detection of crime. When this is the case, we will only do so when it is necessary and when it is lawful under the Data Protection Legislation.

Special Category Data

We process special category data (sensitive personal data) in specific circumstances, including:

Health Information:

  1. When you provide medical information as part of your membership
  2. When you share your CSF leak experience through member stories

Legal Basis for Processing Special Category Data:

We rely on the following conditions under Article 9 of the UK GDPR:

  1. Explicit consent (for member stories and research participation)
  2. Substantial public interest
  3. Research and statistical purposes

How long do we keep your personal data?

We will only keep your personal data for as long as is necessary for the purposes that we have outlined, or for as long as is necessary by law. After this time, we will either anonymise it so that it can no longer identify you or securely destroy or delete it.

Please contact us with if you would like to know more about how long we process your personal data for.

Consent

Where we are processing your personal data with your consent, or explicit consent for special categories of personal data; you have the right to withdraw that consent at any time. When you withdraw your consent, it will not affect the lawfulness of the processing before you withdrew the consent.

We will take measures to stop processing your personal data as soon as we can. However, there may be a short delay while we put these in place. For example, you may still receive communications from us until we have amended our records. We will aim to stop processing your personal data within one month of you withdrawing your consent.

You can withdraw your consent at any time by contacting us with the contact information in this policy.

Am I required to provide us with information?

You are not required under law or contract to provide us with or share any personal data with us. However, if we were unable to process your personal data we would be unable to provide you with a service or facilitate you volunteering with us.

Who do we share your personal data with

We will never sell your personal data to any other organisation or use it in ways that are beyond your reasonable expectations, or in ways we haven’t told you about.

We may use data processors who provide services to us such as IT infrastructure, data storage or for processing payments. When we use a data processor, we will have a contract in place with them, or their terms and conditions will outline that they can only process your personal data in accordance with our instructions and that they provide sufficient guarantees that they secure your personal data to a high standard and they comply with the requirements set out in the data protection legislation.

Some data processors we use are:

Organisation

Services

Microsoft

IT Services

Monday CRM

Customer Relationship Management Services

Postmark

Email delivery services

Mailchimp

Email delivery services

Stripe

Administration of payments

WebDNA

Website Services

Spreadshop

Online Store

There may be other circumstances where we need to share your personal data with other organisations such as law enforcement or other organisations when we have a legal obligation do so, such as a court order. If we need to do this, we will only do so when it is necessary, lawful and in accordance with the data protection legislation.

If we believe that there is an immediate risk to your life or safety, we may share information with relevant authorities for safeguarding purposes or to protect your vital interests. We will always consider whether we can obtain your consent to do this, though we may need to rely on other lawful grounds such as vital interests for sharing this information if we cannot obtain that consent or you are incapable of providing consent.

Automated decision making and profiling

The CSF Leak Association does not make any automated decisions about you using your personal data that would have legal or similarly significant effects on you.

Do we process your personal data in other countries?

Generally we process your personal data in the United Kingdom (UK) or European Economic Area (EEA).

We may use data processors who provide us with email, payment services or other IT infrastructure that store your personal data outside of the UK or European Economic Area. When this is the case, they will be contractually obliged to protect your personal data to the high standards of the UK data protection legislation.

When your personal data is processed outside of the UK or EEA, we rely on the following mechanisms to ensure that there are appropriate safeguards in place to protect it and to ensure that you have enforceable information rights:

  • The transfer is based on an adequacy regulation – This is where the UK have decided that the data protection laws in these countries provide for equivalent protections (this is the case with the EEA, and under the UK extension to the EU-US Data Privacy Framework); or
  • The transfer is based on ‘standard contractual clauses’ - This is where there are contractual obligations in place to provide for appropriate safeguards and enforceable rights. This will generally be achieved by implementing the Information Commissioner’s Office International Data Transfer Agreements (IDTAs) or International Data Transfer Addendums.

Social Media and Third-Party Platforms

We maintain presence on social media platforms including:

  • Facebook
  • X
  • LinkedIn
  • Instagram
  • BlueSky

When you interact with us on social media:

  • These platforms may collect your data independently
  • Their privacy policies will apply to your interactions
  • We may receive aggregated analytics about our social media presence
  • We may use social media messaging for communications if you contact us through these platforms
  • We encourage you to review the privacy policies of any social media platforms you use to interact with us.

How we protect your personal data

When we process your personal data, we must comply with the data protection principles under the UK GDPR. This includes the responsibility to implement appropriate organisational and technical measures to protect your personal data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to your personal data.

We do this by implementing security measures such as our data protection policy and processes; training for mentors; information security and cyber security measures such as firewalls; controlling access to our systems such as password protection and encryption; and only sharing your personal data by secure means.

We also have policies and procedures in place to deal with personal data breaches to ensure that we can effectively deal with any risks posed and can comply with our notification obligations under the UK GDPR.

Your information rights

The Data Protection Legislation gives you rights over your personal data and we will always help you to exercise these; the information rights are:

Right of access

This gives you the right to a copy of the personal data that we are processing about you.

Right to rectification

This gives you the right to have inaccurate personal data about you corrected or incomplete personal data completed.

Right to erasure (right to be forgotten)

This gives you the right to have the personal data about you deleted or erased in some circumstances.

Right to restriction of processing

This gives you the right to ask us to stop processing your personal data in certain ways in some circumstances.

Right to data portability

This gives you the right to have your personal data transferred to another data controller in an easily accessible format.

Right to object to processing

This gives you the right to object to, or tell us to stop processing your personal data when we are using legitimate interest to process it, in some circumstances.

If we are processing your personal data under legitimate interest for direct marketing purposes, this right is absolute.

Not all of these rights are absolute, they do not apply in every circumstance and they may be restricted under certain conditions. For example, if we have a legal obligation to continue processing your personal data or when an exemption applies under the Data Protection Act 2018. If we need to restrict these rights, we will always consider this on a case-by-case basis, only when it is necessary, lawful to do so and in accordance with the Data Protection Legislation.

Exercising your information rights

You can exercise your information rights at any time by letting us know or by contacting us at dataprotection@csfleak.uk.

When you exercise your information rights, we usually have one month to comply with the request unless it is considered to be complex. If we consider your rights request to be ‘complex’, we may extend this timeframe to a total of three months. We will let you know if this is the case within one month of receiving your request.

We may ask you for proof of identity when considering an information rights request to ensure that we protect it from unlawful disclosure or from unauthorised alteration or processing.

Ordinarily, we will not charge you a fee for exercising your information rights unless we consider it to be manifestly (or clearly) unfounded or excessive. This includes situations where repeat requests are made within a short timeframe; or where the request is clearly intended to cause disruption. In this case, you may be charged an administrative fee. Alternatively, we may refuse to comply with your request. We will always inform you if this is the case.

Information Commissioner’s Office (ICO)

The Information Commissioner’s Office (ICO) regulates and enforces data protection compliance in the UK. Their website has useful guidance on data protection matters, you can find it here: www.ico.org.uk

You have the right to lodge a complaint to the ICO at anytime, if you are unhappy with how we have processed your personal data or if you think we have not followed the rules. You can contact the ICO here - https://ico.org.uk/make-a-complaint/data-protection-complaints/data-protection-complaints/

Changes to this privacy policy

We will regularly review this privacy policy and publish any new versions on our website. You should regularly check our privacy information to ensure that you have the most up to date version.

Version: 1.0

Last review: 31-JAN-2025

Next review date: 31-JAN-2027

Schedule 1: Purposes of processing, personal data and lawful grounds

When you visit our website

Why we process your personal data

  • To provide and maintain website functionality
  • To analyse website usage and improve user experience
  • To ensure website security
  • To enable interactive features where requested
  • To remember your preferences
  • To measure the effectiveness of our content
  • To process online forms and requests
  • To enable secure member login

What personal data we process

Automatically Collected Data:

  • IP addresses (pseudonymized)
  • Browser type and version
  • Operating system
  • Device type
  • Page views and navigation
  • Time and date of visits
  • Referring website
  • Geographic location (country level)
  • Language preferences

Cookie-Related Data:

  • Session cookies for essential functions
  • Authentication cookies for logged-in users
  • Preference cookies for site customization
  • Analytics cookies for site improvement

User-Provided Data:

  • Contact form submissions
  • Newsletter subscriptions
  • Account registrations
  • Search queries
  • Form completions

Our lawful basis for processing your personal data

Essential Processing:

  • Contract (for providing requested services)
  • Legitimate interests (for website security and functionality)

Optional Processing:

  • Consent (for analytics and non-essential cookies)
  • Legitimate interests (for website improvement)

How long we keep your personal data for

Automatically Collected Data:

  • IP addresses: 90 days
  • Server logs: 90 days
  • Analytics data: 26 months (anonymized)

Cookie Data:

  • Session cookies: Until browser closes
  • Authentication cookies: 30 days maximum
  • Preference cookies: 12 months maximum
  • Analytics cookies: 24 months maximum

User-Provided Data:

  • Contact forms: 2 years
  • Newsletter subscriptions: Until unsubscribed
  • Account data: Duration of account plus 1 year

When you volunteer for us

Why we process your personal data

  • To manage volunteer applications and onboarding
  • To maintain records of volunteer activities and contributions
  • To communicate about volunteer opportunities and tasks
  • To verify volunteer identity where required
  • To manage volunteer roles and responsibilities
  • To ensure appropriate support and supervision
  • To maintain emergency contact information
  • To process expense claims where applicable
  • To provide references upon request

What personal data we process

Core Volunteer Information:

  • Full name
  • Contact details (email, phone, address)
  • Volunteer role(s)
  • Start date and duration of volunteering
  • Skills and experience
  • Areas of interest
  • Training completed
  • Hours contributed

Role-Specific Information (where applicable):

  • ID verification documents
  • References
  • Emergency contact details
  • Bank details (for expense claims)
  • Health information (only where relevant to role)
  • Access requirements
  • DBS check results (for applicable roles)

Our lawful basis for processing your personal data

  • Legitimate interests (for managing volunteer relationships)
  • Legal obligation (for health and safety, safeguarding where applicable)

How long we keep your personal data for

Active Volunteer Records (retained while actively volunteering):

  • Contact details
  • Role information
  • Training records
  • Supervision notes
  • Hours logs
  • Correspondence
  • Post-Volunteering Records (retained for 3 years after volunteering ends):
  • Full name
  • Roles held
  • Dates of service
  • Training completed
  • Notable contributions
  • Reference information

Shorter Retention Periods:

  • ID verification documents (1 months after checking)
  • DBS results (6 months after checking)
  • Financial records (6 years for accounting purposes)
  • Unsuccessful applications (6 months)

When you donate to us

Why we process your personal data

  • To process and record your donation
  • To claim Gift Aid where applicable
  • To thank you for your support
  • To maintain accurate financial records
  • To comply with financial regulations and charity law
  • To communicate about the impact of donations
  • To maintain donation history
  • To prevent fraud and ensure security

What personal data we process

Core Donation Information:

  • Full name
  • Email address
  • Postal address (for Gift Aid)
  • Donation amount
  • Donation date
  • Donation method
  • Gift Aid declaration (if applicable)
  • Communication preferences

Payment Processing:

  • We do not collect or store payment card details
  • Payments are processed securely by our payment partners:
    • Stripe
    • JustGiving
    • [Other payment processors as applicable]

Our lawful basis for processing your personal data

  • Legal obligation (for financial records and Gift Aid)
  • Legitimate interests (for donation processing and thanking donors)
  • Contract (for processing the donation)

How long we keep your personal data for

Financial Records:

  • Donation records: 6 years (accounting requirements)
  • Gift Aid declarations: 6 years after last donation
  • Donation correspondence: 6 years

Contact Information:

  • Basic donor information: 6 years from last donation
  • Communication preferences: Until withdrawn

Third-Party Processors:

  • Payment details: Not stored by us
  • Processed according to payment provider policies

When you become a member

Why we process your personal data

  • To manage member applications and renewals
  • To provide member services and support
  • To understand the needs of our member community
  • To communicate important updates and information
  • To maintain accurate membership records
  • To process membership payments
  • To send member-only communications and resources
  • To gather anonymized statistics about CSF leaks
  • To support research and advocacy work
  • To process Gift Aid claims where applicable

What personal data we process

Core Membership Information:

  • Full name
  • Contact details (email, phone, address)
  • Date of birth
  • Gender
  • Membership start and end date
  • Membership status
  • Payment information
  • Gift Aid declarations (if applicable)

Health and Support Information:

  • CSF leak status (e.g., diagnosed, suspected)
  • Type of CSF leak
  • Cause of leak
  • Medical professional status (if applicable)
  • Support needs
  • How they heard about us

Our lawful basis for processing your personal data

Primary bases:

  • Contract (for providing membership services)
  • Legitimate interests (for communications and research)
  • Legal obligation (for Gift Aid and financial records)

For health data:

  • Explicit consent
  • Substantial public interest (for research and statistics)

How long we keep your personal data for

For the duration of your membership plus six years

When you become a trustee

Why we process your personal data

  • To maintain statutory records of charity trustees
  • To facilitate trustee governance and administration
  • To maintain organizational history and corporate memory
  • To meet our regulatory obligations
  • To manage trustee appointments and resignations
  • To communicate about trustee matters
  • To verify trustee identity and eligibility

What personal data we process

Core Governance Information:

  • Full name
  • Date of birth
  • Dates of service
  • Trustee positions/roles held
  • Declarations of interests
  • Participation in key decisions
  • Contributions to annual reports

Administrative Information:

  • Contact details (email, phone, address)
  • ID verification documents
  • References
  • Skills and experience information
  • Emergency contact details
  • Bank details (for expense claims)

Our lawful basis for processing your personal data

  • Legal obligation (for statutory records)
  • Legitimate interests (for administrative purposes and maintaining organisational history)

How long we keep your personal data for

Core Governance Information (retained permanently):

  • Full name
  • Dates of service
  • Roles held
  • Meeting minutes and decisions
  • Annual reports
  • Historical governance documents

Administrative Information (retained for 6 years after end of service):

  • Contact details
  • Financial records
  • References
  • Personal correspondence
  • Skills assessments
  • Bank details

Administrative Information (retained 1 month after checking):

  • ID verification documents

When you tell us about your experiences or stories

Why we process your personal data

  • To share experiences that may help others with CSF leaks
  • To raise awareness about CSF leaks
  • To demonstrate the impact of CSF leaks on daily life
  • To support our advocacy work
  • To inform healthcare professionals about patient experiences
  • To contribute to research and understanding of CSF leaks
  • To support funding applications and impact reporting
  • To update our website and social media channels

What personal data we process

Core Information:

  • Name (or pseudonym if preferred)
  • Email address
  • Contact preferences
  • Date story submitted

Story Content:

  • Personal health experiences
  • Medical journey details
  • Impact on daily life
  • Treatment experiences
  • Support received
  • Photographs (if provided)
  • Videos (if provided)

Our lawful basis for processing your personal data

Primary basis:

  • Legitimate interests (for sharing experiences to help others)
  • Explicit consent (for health data and public sharing)

How long we keep your personal data for

Story Content:

  • Published content: Until removal is requested
  • Original submissions: Duration of use plus 2 years
  • Contact details: Duration of use plus 2 years

Administrative Records:

  • Consent records: Duration of use plus 2 years
  • Correspondence: 2 years from last contact

Archive Copies:

  • May be retained for organizational record
  • Fully anonymized after retention period

When are a member of our Medical Advisory Committee (MAC)

Why we process your personal data

  • To maintain accurate records of MAC membership
  • To facilitate MAC meetings and communications
  • To manage MAC contributions and advice
  • To publish MAC membership information on our website
  • To document medical guidance received
  • To coordinate review of materials and publications
  • To maintain professional credentials records
  • To manage conflicts of interest
  • To comply with governance requirements

What personal data we process

Professional Information:

  • Title
  • Full name
  • Professional qualifications
  • Specialty/expertise
  • Current position
  • Hospital/Institution affiliation
  • NHS Trust affiliation
  • Professional registration numbers
  • Professional biography
  • Areas of expertise
  • Research interests

Contact Information:

  • Professional email address
  • Work telephone number
  • Professional postal address
  • Assistant's contact details (if applicable)
  • Preferred contact method

Administrative Information:

  • Date joined MAC
  • Term of appointment
  • Meeting attendance records
  • Contributions made
  • Conflict of interest declarations
  • Correspondence history
  • Document review history

Our lawful basis for processing your personal data

Primary basis:

  • Legitimate interests (for managing MAC relationship)
  • Contract (for MAC appointment terms)

How long we keep your personal data for

Active MAC Member Records:

  • All professional and contact information while actively serving
  • Meeting records and contributions
  • Correspondence and reviews
  • Current conflict of interest declarations

Historical Records (retained permanently):

  • Name
  • Professional role
  • Dates of service
  • Key contributions
  • Published guidance
  • Official opinions

Administrative Records (retained for 6 years after service ends):

  • Contact details
  • Correspondence
  • Meeting attendance
  • Contribution records
  • Conflict of interest declarations

When you purchase from our online store

Why we process your personal data

  • To process and fulfil your orders
  • To manage order communications
  • To handle shipping and delivery
  • To process payments securely through Stripe
  • To maintain order history
  • To handle returns or queries
  • To comply with financial regulations
  • To prevent fraud

What personal data we process

Order Information:

  • Full name
  • Email address
  • Shipping address
  • Order details
  • Order history
  • Order correspondence

Payment Information:

  • We do not collect or store payment card details
  • All payments are processed securely by Stripe
  • We receive confirmation of payment success/failure
  • We store order total and transaction reference

Our lawful basis for processing your personal data

  • Contract (for processing and fulfilling orders)
  • Legal obligation (for financial records)
  • Legitimate interests (for order management and communication)

How long we keep your personal data for

Order Records:

  • Basic order information: 6 years (financial regulations)
  • Shipping addresses: 6 years from last order
  • Order correspondence: 2 years from order completion

Payment Records:

  • Transaction references: 6 years
  • Payment confirmation: 6 years
  • No card details stored

Get Involved

You can support the mission of the CSF Leak Association in many different ways. If you want to help you can find out how by following the links and deciding which method fits you best. We appreciate any help you are able to give..

Simple profile silhouette icon in yellow representing a member Become a Member T-shirt icon in yellow representing charity store Online Store Open hand holding money icon in yellow representing a donation Donate Two hands raised upward icon in yellow representing volunteering Volunteer