Privacy Policy
Introduction
New Testament Church of God Luton (“we”, “us”, “our”) is committed to protecting the privacy and personal data of everyone who interacts with us — whether you visit our website, attend our services, give to our ministry, volunteer with us, or receive pastoral care from our team.
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, how long we keep it, and what your rights are in relation to it. It applies to our website at lutonntcg.org.uk and to all the activities of NTCG Luton as a charitable organisation.
We take our responsibilities under data protection law seriously. Our aim is to be transparent, to collect only what we genuinely need, and to handle everything we do hold with integrity and care.
Who We Are
New Testament Church of God Luton is the data controller for the personal data described in this policy. This means we are responsible for deciding how and why your data is used.
Registered Charity Name: New Testament Church of God Luton
Charity Number: 250306
Registered Address: c/o St Pauls Church, New Town Street, Luton, Bedfordshire, LU1 3EB
National Body Registered Office: 3 Cheyne Walk, Northampton, NN1 5PT
Company Number: OC917145 (England and Wales)
Contact Email: hello@lutonntcg.org.uk
The Law That Governs This Policy
This Privacy Policy is written in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. These are the primary laws that govern how organisations in the United Kingdom must handle personal data. Where we refer to “data protection law” throughout this policy, we mean these laws collectively.
We are not currently required to appoint a Data Protection Officer, but we take our obligations as a data controller seriously and are committed to full compliance. If you have any questions or concerns about how we handle your data, please contact us at hello@lutonntcg.org.uk.
What Personal Data We Collect
We only collect personal data that is necessary for a specific and legitimate purpose. The types of data we may hold are set out below, along with the circumstances in which we collect them.
Data You Give Us Directly
We collect personal data when you voluntarily provide it to us. This happens in a number of ways:
- Contacting us — when you fill in a contact form, send us an email, or get in touch by phone, we receive your name, email address, phone number, and the content of your message.
- Registering for an event — when you sign up for a course, event, or programme, we collect your name, contact details, and any relevant information about your needs or preferences.
- Giving a donation — when you give online or complete a Gift Aid declaration, we collect your name, address, donation amount, and payment reference. We do not store your full card details — these are handled securely by our payment processor.
- Joining our mailing list — when you subscribe to our newsletter or opt in to communications, we collect your name and email address.
- Completing a connect card — when you fill in a new visitor or connect card, we collect your name, contact details, and any preferences you choose to share with us.
- Volunteering or serving — when you apply to serve in a ministry or volunteer role, we collect your name, contact details, relevant experience, and references.
- Children’s and youth registration — when you register a child for our children’s or youth activities, we collect the child’s name, date of birth, any relevant medical information, and the contact details of the parent or guardian.
- Pastoral care — when you engage with our pastoral team, relevant details shared in that context may be recorded for the purposes of supporting you. This is handled with particular sensitivity and care.
Data We Collect Automatically
When you visit our website, we may automatically collect certain technical information about your visit. This includes your IP address (in anonymised form where analytics are involved), the type of device and browser you are using, the pages you visit and how long you spend on them, the website you came from before visiting ours, and any errors you encounter.
This data is collected using cookies and similar technologies. Please see our Cookies Policy for full details of how we use cookies and how you can manage them.
Data We Receive From Third Parties
In some cases we may receive personal data about you from third parties. For example, if someone refers you to us for pastoral support, if a giving platform passes us your donation details and Gift Aid information, or if you interact with us through a social media platform. We will always handle data received from third parties in accordance with this policy and will only use it for the purpose for which it was shared.
Special Category Data
Some of the data we hold may be classed as “special category” data under UK GDPR — this means it is particularly sensitive and deserves extra protection. Special category data includes information about health and medical conditions, religious beliefs, and racial or ethnic origin.
As a Christian church, we will inevitably hold information about people’s religious beliefs in the context of our pastoral care, membership records, and ministry involvement. We handle this data with the highest level of care. We may also hold health information about children registered for our activities, or about individuals who have shared health details with our pastoral team. We will always seek your explicit consent before recording special category data, except where the law allows us to process it on another basis — for example, for safeguarding purposes.
Why We Use Your Personal Data
We use personal data only for the purposes for which it was collected. The main reasons we process personal data are set out below, along with the legal basis we rely on for each.
Running Our Church and Ministry
We process personal data to run our Sunday services, weekly programmes, events, and ministries. This includes keeping records of our congregation, communicating with members and regular attendees, organising activities and rotas, and fulfilling our responsibilities as a community of faith.
Legal basis: Legitimate interests — it is in the legitimate interests of NTCG Luton to maintain records necessary to operate effectively as a church and charitable organisation.
Processing Donations and Gift Aid
We use personal data to process charitable donations, issue receipts, administer Gift Aid claims with HMRC, and maintain the financial records required of us as a registered charity.
Legal basis: Legal obligation (Gift Aid and charity accounting requirements) and legitimate interests (administering giving to fund our charitable purposes).
Communicating With You
We use your contact details to send you information about our services, events, and news — but only if you have opted in to receive communications from us. We may also contact you in direct response to an enquiry you have made, or to provide information that is necessary for your participation in one of our activities.
Legal basis: Consent (for marketing and newsletter communications) and legitimate interests (for service-related communications directly related to your involvement with us).
Safeguarding Children and Vulnerable Adults
We process personal data — including special category data — for the purpose of safeguarding children and vulnerable adults who participate in our activities. This may include DBS check records for volunteers and staff working with children, medical and emergency contact information for children registered in our children’s activities, and records relating to safeguarding concerns or incidents.
Legal basis: Legal obligation (UK safeguarding law) and substantial public interest (protecting children and vulnerable adults from harm).
Pastoral Care and Support
We may keep records of pastoral care conversations and support provided by our ministry team, in order to provide consistent, appropriate, and effective care. This information is treated with the strictest confidence and is accessible only to those directly involved in providing that care.
Legal basis: Explicit consent (where you have shared information voluntarily in a pastoral context) and legitimate interests (in providing ongoing and effective pastoral support).
Managing Volunteers and Staff
We process personal data relating to volunteers and paid staff for the purposes of managing their involvement with NTCG Luton, conducting DBS checks where required, maintaining contact records, and fulfilling any legal obligations as an employer or organisation engaging volunteers.
Legal basis: Contract (where there is an employment or volunteer agreement), legal obligation (DBS checks and employment law), and legitimate interests.
Website Analytics and Improvement
We use anonymised analytics data to understand how visitors use our website and to improve its content and functionality. No individual user is identified through this process.
Legal basis: Legitimate interests (in maintaining an effective and informative website) — and consent where analytics cookies are used.
Compliance With Legal and Regulatory Obligations
We may process personal data where necessary to comply with our obligations under charity law, data protection law, employment law, safeguarding law, HMRC requirements, or any other applicable legal or regulatory framework.
Legal basis: Legal obligation.
How Long We Keep Your Data
We do not keep personal data for longer than is necessary for the purpose for which it was collected. Our retention periods are guided by legal requirements, charity best practice, and the ongoing needs of our ministry. The key retention periods we apply are set out below.
General Contact and Enquiry Records
Records of general enquiries and contact form submissions are retained for up to 2 years from the date of last contact, after which they are securely deleted unless there is an ongoing reason to retain them.
Donation Records and Gift Aid
Financial records relating to donations, Gift Aid declarations, and Gift Aid claims are retained for a minimum of 6 years from the end of the financial year in which the donation was made. This is required by HMRC and the Charities Act 2011.
Congregation and Membership Records
Records relating to active members and regular congregation members are retained for as long as that person maintains their involvement with NTCG Luton, plus a reasonable period after their departure — typically 3 years — unless they request earlier deletion.
Children’s Activity Records
Registration and consent records for children’s and youth activities are retained until the child reaches the age of 18, or for 3 years from the date of last registration — whichever is longer. Medical and emergency information is deleted promptly when it is no longer current.
Safeguarding Records
Safeguarding records are retained in accordance with the guidance of the New Testament Church of God denomination and UK safeguarding best practice. In general, records relating to safeguarding concerns are retained for a minimum of 25 years, as recommended by the NSPCC and relevant government guidance, to protect the welfare of children and vulnerable individuals.
DBS Check Records
We do not retain copies of DBS certificates. We record the date of the check, the certificate number, and the outcome only. This information is retained for the duration of a volunteer’s or staff member’s involvement with us, plus 6 months thereafter.
Volunteer and Staff Records
Records relating to volunteers are retained for 6 years after the end of their involvement. Employment records for paid staff are retained in accordance with employment law — typically 6 years after termination of employment.
Website Analytics
Anonymised analytics data is retained for up to 26 months, which is Google Analytics’ standard retention period. No individually identifiable data is retained beyond this point.
Who We Share Your Data With
We do not sell, rent, or trade your personal data. We share it only in the limited circumstances described below.
Within NTCG Luton
Personal data is accessible within NTCG Luton only to those who need it to carry out their role. For example, children’s workers can access registration information for children in their group, pastoral team members can access pastoral care records, and our administrators can access donation and Gift Aid records. Access is managed on a need-to-know basis.
The New Testament Church of God England and Wales
As a member church of the New Testament Church of God denomination, we may share certain data with the national body — for example, in relation to denominational records, pastoral appointments, or safeguarding matters. The national body operates under its own data protection policy.
Third-Party Service Providers
We use a small number of third-party services to help us operate. These may include our website hosting provider, email communication platform, online giving platform, and cloud storage or administration tools. Where these providers process personal data on our behalf, they do so as data processors under a contract that requires them to handle data in accordance with UK GDPR. We only use providers we trust and who can demonstrate appropriate data protection standards.
HMRC
We share donor names, addresses, and donation amounts with HMRC when making Gift Aid claims. This is required by law and is done securely through HMRC’s approved submission process.
DBS and Disclosure Services
Where required by our safeguarding obligations, we share relevant personal data with the Disclosure and Barring Service (DBS) for the purpose of carrying out background checks on volunteers and staff working with children or vulnerable adults.
Legal Authorities
We may be required to share personal data with the police, the Charity Commission, the Information Commissioner’s Office, or other statutory bodies where we are legally obliged to do so — for example, in response to a court order, a safeguarding disclosure, or a regulatory investigation.
Transfers Outside the UK
Some of the third-party services we use may process data in countries outside the United Kingdom. Where this is the case, we ensure that appropriate safeguards are in place — such as the use of the UK’s International Data Transfer Agreement or Standard Contractual Clauses — to ensure that your data continues to receive an equivalent level of protection. Key providers such as Google (Analytics) and Meta (social media) operate under their own approved transfer mechanisms.
Your Rights
Under UK GDPR, you have a number of important rights in relation to your personal data. We take these rights seriously and will always respond promptly and fully to any request you make.
The Right to Be Informed
You have the right to be informed about how we collect and use your personal data. This Privacy Policy is how we fulfil that right. If you have questions beyond what is covered here, please contact us.
The Right of Access
You have the right to request a copy of the personal data we hold about you. This is known as a Subject Access Request (SAR). We will respond to your request within one calendar month. We will provide the data free of charge in most cases. If a request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee or decline to respond, but we will always tell you why.
The Right to Rectification
If you believe that the personal data we hold about you is inaccurate or incomplete, you have the right to ask us to correct it. We will do so promptly — and in any event within one month.
The Right to Erasure
Also known as the “right to be forgotten”, this allows you to ask us to delete the personal data we hold about you. We will comply unless we have a legal obligation to retain it — for example, Gift Aid records required by HMRC — or unless there is a legitimate overriding reason, such as the retention of safeguarding records. We will always explain our reasoning if we are unable to comply in full.
The Right to Restrict Processing
You have the right to ask us to stop processing your personal data — or to limit how we use it — while a dispute about its accuracy or use is resolved. We will flag the data accordingly and ensure it is not used in any way you have objected to until the matter is resolved.
The Right to Data Portability
Where we process your personal data on the basis of consent or contract, and where processing is carried out by automated means, you have the right to receive your data in a structured, commonly used, and machine-readable format, and to have it transferred to another organisation where technically feasible.
The Right to Object
You have the right to object to us processing your personal data on the basis of legitimate interests, or for direct marketing purposes. Where you object to direct marketing, we will stop immediately. Where you object to processing based on legitimate interests, we will assess your objection and respond within one month.
Rights Relating to Automated Decision-Making
You have the right not to be subject to decisions made solely by automated processing — including profiling — that produce legal or similarly significant effects on you. We do not currently use automated decision-making of this kind.
How to Exercise Your Rights
To exercise any of the rights above, please contact us at hello@lutonntcg.org.uk with your name, contact details, and a clear description of your request. We will respond within one calendar month. We may need to verify your identity before processing certain requests.
If you are not satisfied with our response, you have the right to complain to the Information Commissioner’s Office (ICO) — the UK’s data protection regulator — at ico.org.uk/make-a-complaint or by calling 0303 123 1113.
Keeping Your Data Secure
We take the security of your personal data seriously and have put appropriate technical and organisational measures in place to protect it against accidental loss, unauthorised access, misuse, alteration, or disclosure.
Technical Measures
Our website uses HTTPS encryption to protect data in transit. Access to systems that hold personal data is protected by strong passwords and, where applicable, two-factor authentication. Our website is hosted on a secure platform and is kept up to date with security patches. Any electronic records containing personal data are stored in access-controlled environments.
Organisational Measures
Access to personal data is limited to those within NTCG Luton who need it for their specific role. We train our team and volunteers on data protection responsibilities. Pastoral care records are stored securely and are accessible only to those directly involved in that person’s care. We do not print unnecessary copies of personal data, and any paper records containing sensitive information are stored securely and disposed of by secure shredding.
Data Breaches
In the unlikely event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it, in accordance with our obligations under UK GDPR. Where a breach is likely to result in a high risk to you personally, we will also contact you directly without undue delay.
Children’s Privacy
We are deeply committed to protecting the privacy of children. The children and young people who participate in our activities are among the most important people we serve, and we take our responsibilities in relation to their data with the utmost seriousness.
Parental Consent
We require the explicit consent of a parent or guardian before collecting or processing personal data relating to a child under the age of 13. For young people between 13 and 17, we aim to involve parents or guardians in consent decisions wherever appropriate. Registration forms for all children’s and youth activities include a clear consent section for parents or guardians.
Data Minimisation for Children
We collect only the minimum data necessary to keep children safe and to run our activities effectively. For most activities, this means a name, date of birth, emergency contact, and any relevant medical information. We do not collect data about children for marketing or profiling purposes.
Photography and Media Involving Children
We obtain separate written consent from parents or guardians before photographing or filming children in our activities. This consent is specific and informed — it explains how images will be used and gives parents the right to withdraw consent at any time. We will never publish a photograph of a child with identifying information such as their full name, school, or address.
Links to Other Websites
Our website may contain links to other websites — including the national NTCG website, YouTube, social media platforms, and charitable giving platforms. This Privacy Policy applies only to our website. When you click a link to another website, you will be subject to that site’s own privacy policy. We are not responsible for the content or privacy practices of third-party websites and encourage you to read their policies before providing any personal information.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or applicable law. Any changes will be published on this page with an updated effective date. Where changes are significant, we will make reasonable efforts to bring them to the attention of our congregation and regular contacts.
We encourage you to review this policy periodically. Your continued engagement with NTCG Luton following any changes constitutes your acknowledgement of the updated policy.
Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have a concern about how we have handled your personal data, please contact us:
New Testament Church of God Luton
c/o St Pauls Church
New Town Street
Luton, Bedfordshire
LU1 3EB
Email: hello@lutonntcg.org.uk
Website: lutonntcg.org.uk
Charity Number: 250306
If you are not satisfied with our response to a complaint or concern, you have the right to contact the Information Commissioner’s Office (ICO) directly:
Information Commissioner’s Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk