Privacy Policy
Last updated: April 2026
Who does this notice apply to:
This privacy notice explains how The Bishop Radford Trust (“BRT”, “the Trust”, “we”, “us” and “our”) collects, uses, stores and protects personal data. It is intended to apply to people who apply to the Trust, people acting for applicant organisations, grantees, trustees, advisers, suppliers, and people who visit or use the Trust’s website.
The Bishop Radford Trust is a registered charity in England and Wales (Charity no. 1113562). For the purposes of UK data protection law, BRT is the data controller for the personal data described in this notice.
If you have any questions about this notice or how your personal data is used, please contact:
The Bishop Radford Trust
5th Floor
3 Dorset Rise
LONDON
EC4Y 8EN
Email: enquiries@bishopradfordtrust.org.uk
BRT is committed to protecting personal data and handling it lawfully, fairly and transparently. This notice explains what personal data is collected, why it is used, the lawful bases relied on, who it may be shared with, how long it is kept, and the rights available to individuals.
This notice may be updated from time to time. The latest version should be made available on the Trust’s website and used alongside any more specific privacy information provided at the point that personal data is collected.
The types of personal data BRT may collect
Depending on the nature of the relationship with the Trust, BRT may collect and use the following categories of personal data:
· identity and contact information, such as names, postal addresses, email addresses, telephone numbers and job titles.
· organisation information, such as the name of a church, charity or other body, charity number, role and relationship to an application or grant.
· application and grant information, such as information contained in grant applications, supporting papers, reports, correspondence and records of decisions.
· financial information, such as bank account details, payment records and information needed to process grants or other payments.
· governance and due diligence information, such as trustee names, declarations of interest, references, eligibility checks and records needed to administer the Trust properly.
· communication records, such as emails, letters, meeting notes and records of enquiries.
· website and technical information, such as IP address, browser type, device information, cookie preferences and information about how the website is used, where these are collected.
BRT asks that applicants and other contacts do not include unnecessary personal data in applications or correspondence. Where special category personal data is relevant to an application or to the Trust’s work, it should only be provided where necessary and appropriate.
How BRT collects personal data
Personal data may be collected:
· directly from individuals.
· from churches, charities and other organisation applying to the Trust or working with it;
· from trustees, referees, advisers and professional contacts.
· from publicly available sources, such as charity registers, organisational websites and Companies House or equivalent records where relevant.
· automatically through the Trust’s website application form, including through server logs, cookies or analytics tools where these are used.
Why BRT uses personal data, and the lawful bases relied on
BRT must have a lawful basis under UK data protection law for using personal data. The lawful basis relied on will depend on the purpose of the processing.
Applicants, applicant organisations and grantees
BRT may use personal data to:
· receive, assess and administer grant applications;
· carry out due diligence and make funding decisions;
· communicate with applicants and grantees;
· make grant payments and maintain financial records;
· monitor grants, receive reports and evaluate the Trust’s charitable activities;
· keep appropriate records of the Trust’s relationship with applicants and grantees.
For these purposes, BRT will usually rely on one or more of the following lawful bases:
· legitimate interests, namely the proper administration, governance and operation of the Trust and the delivery of its charitable purposes;
· compliance with a legal obligation, where the Trust must keep records or provide information to regulators or public authorities;
· performance of a contract or steps requested before entering into a contract, where this is relevant to a grant, consultancy, supplier arrangement or similar relationship;
· consent, where the Trust specifically asks for consent and relies on it.
Trustees, committee members, advisers and professional contacts
BRT may use personal data to:
· administer trustee, governance and advisory relationships;
· maintain statutory and internal records;
· arrange meetings, circulate papers and manage conflicts of interest;
· comply with legal, regulatory and reporting requirements;
· obtain professional advice and support the effective management of the Trust.
For these purposes, BRT will usually rely on legitimate interests and compliance with legal obligations.
Website users and people making enquiries
BRT may use personal data to:
· respond to enquiries and requests for information;
· operate, maintain and improve the website;
· keep the website secure and detect technical or security issues;
· understand how the website is used, where analytics or similar tools are enabled.
For these purposes, BRT will usually rely on legitimate interests for basic website administration and security. Where non-essential cookies or analytics tools are used, BRT will seek consent where required.
Special category data and criminal offence data
BRT does not seek to collect special category personal data or criminal offence data unless it is necessary for a clear and lawful purpose. In some cases, information provided in grant applications, due diligence checks, safeguarding matters or correspondence may reveal information such as religious belief, health information or other sensitive data.
Where this happens, BRT will only process that information where it is permitted by law, including where the processing is necessary for reasons of substantial public interest, for the establishment, exercise or defence of legal claims, where it is manifestly made public by the individual, or where explicit consent has been obtained if consent is the appropriate basis.
Who BRT may share personal data with
BRT does not sell personal data and will not share it with third parties for their own marketing purposes.
Personal data may, however, be shared where necessary with:
· trustees, staff, volunteers or consultants who need the information for Trust purposes;
· banks and payment service providers;
· accountants, auditors, legal advisers and other professional advisers;
· IT, website hosting, email, cloud storage and other service providers acting on the Trust’s behalf;
· regulators, public authorities, law enforcement bodies or courts where disclosure is required by law or is necessary to protect the Trust’s legal position;
· other parties where the individual has asked BRT to do so or where the individual has given consent.
Where service providers process personal data on the Trust’s behalf, BRT will seek to ensure that appropriate contractual and security measures are in place.
BRT aims to store and process personal data in the UK or, where appropriate, the EEA. Some service providers may process personal data outside the UK.
Where personal data is transferred outside the UK, BRT will take reasonable steps to ensure that appropriate safeguards are in place, such as a UK adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to standard contractual clauses, or another lawful transfer mechanism recognised under UK data protection law.
BRT will take appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. This may include access controls, password protection, secure storage, restricted sharing, encryption where appropriate, and arrangements with service providers requiring them to protect personal data.
Although BRT seeks to protect personal data, no internet-based transmission or storage system can be guaranteed to be completely secure. Individuals should therefore take care when sending information electronically.
How long BRT keeps personal data
BRT will keep personal data only for as long as necessary for the purpose for which it was collected, including to satisfy legal, accounting, regulatory and governance requirements.
Retention periods may vary depending on the category of data, but the Trust will generally apply the following approach:
· financial and payment records will usually be kept for at least 7 years where needed for accounting, audit and tax purposes;
· successful grant application records and related correspondence will be kept for as long as reasonably necessary to administer the grant, monitor outcomes and maintain a proper institutional record;
· unsuccessful grant application records will usually be retained for a limited period after the decision, unless a longer period is justified for governance, legal or audit reasons;
· trustee and governance records will be kept in line with legal, regulatory and operational requirements;
· website usage information will be kept in line with the Trust’s cookie and technical retention settings.
When personal data is no longer required, BRT will seek to delete, destroy or anonymise it securely.
The Trust’s website may use cookies or similar technologies. Some cookies are necessary for the operation and security of the website. Others, such as analytics cookies, may help the Trust understand how the website is used and improve it.
Where consent is required for non-essential cookies or analytics, these should only be used once the user has given that consent. Further information should be provided in the Trust’s cookie notice or cookie banner settings.
BRT does not currently carry out solely automated decision-making or profiling that produces legal effects, or similarly significant effects, for individuals.
Subject to applicable law, individuals have the right to:
· request access to the personal data BRT holds about them;
· request correction of inaccurate or incomplete personal data;
· request erasure of personal data in certain circumstances;
· request restriction of processing in certain circumstances;
· object to processing carried out on the basis of legitimate interests;
· where applicable, request the transfer of personal data to another organisation;
· withdraw consent at any time where processing is based on consent.
To exercise any of these rights, please contact enquiries@bishopradfordtrust.org.uk.
BRT will normally respond in line with the timescales required by data protection law. If an individual is dissatisfied with the way their personal data has been handled, they may complain to the Information Commissioner’s Office (ICO): www.ico.org.uk.
The Trust’s website may contain links to websites run by other organisations. This notice applies only to the Trust’s own website and processing activities. Individuals are encouraged to read the privacy notices of other websites they visit, as BRT is not responsible for their privacy practices.
Changes to this notice
BRT keeps this notice under review. Any future changes will be published on the Trust’s website and, where appropriate, brought to the attention of relevant individuals.
Date approved
Version 2.0