0
You have 0 items in your cart
0
You have 0 items in your cart
Privacy Policy | Kashmir Welfare Foundation

Your information. Your rights. Our responsibility.

Your privacy matters.

Whether you make a donation, sponsor a beneficiary, volunteer your time, create an account, receive our updates or simply visit our website, you trust Kashmir Welfare Foundation with information about you. We take that responsibility seriously. This policy explains in plain English what we collect, why we use it, who we share it with, how long we keep it and the choices and rights available to you.

Organisation: Kashmir Welfare FoundationStatus: UK registered charityLast updated: July 2026

1. Overview

This Privacy Policy explains how Kashmir Welfare Foundation (“KWF”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal information. It also explains the rights available to individuals under applicable data protection law.

We aim to handle personal information lawfully, fairly, transparently and only for clear purposes connected with our charitable work, administration, fundraising, safeguarding, supporter services, employment, volunteering and legal obligations.

This policy is intended to provide a broad and accessible explanation. In some situations, we may give you an additional or more specific privacy notice when collecting information, for example in relation to employment, volunteering, beneficiary registration, medical services, safeguarding, a particular campaign, photography or a research project. That specific notice should be read together with this policy.

Important distinction:

This policy covers personal information generally, including email marketing. Our separate Cookie Policy explains cookies, pixels, local storage, analytics and advertising technologies in greater detail.

2. Who we are

Kashmir Welfare Foundation is a UK registered charity supporting people and communities, including through humanitarian relief, healthcare, food support, water projects, shelter, education, income generation, sponsorship, emergency response and other charitable programmes.

For most activities described in this policy, Kashmir Welfare Foundation is the data controller. This means that we decide why and how personal information is processed. In some limited circumstances, we may act jointly with another organisation or process information on another organisation’s instructions. Where that materially affects you, we will explain the arrangement at the appropriate time.

Before publishing

Add KWF’s registered charity number, registered office address and, if applicable, company number in this section and the contact section. These details have not been inserted because they were not supplied for this draft.

3. Scope of this policy

This policy may apply when you:

  • visit or use our website at kashmirwelfare.org.uk;
  • make a one-off or recurring donation;
  • use Stripe, PayPal or another available donation method;
  • claim or authorise Gift Aid;
  • create or use a donor, WooCommerce, staff, volunteer or other portal account;
  • sponsor a child, family, project, case or programme;
  • create, support or participate in a fundraiser or campaign;
  • register for events, appeals, challenges or community activities;
  • subscribe to newsletters, campaign updates or fundraising emails;
  • contact us by email, telephone, web form, post, social media or messaging service;
  • apply to volunteer, work, partner or provide services to us;
  • receive assistance, referral, medical support, welfare support or other charitable services;
  • appear in photographs, video, testimonials, case studies or impact reporting;
  • interact with our staff, trustees, volunteers, field teams, suppliers or partners.

External websites, payment providers, social networks or other services linked from our website operate under their own privacy policies. We encourage you to read those policies.

4. Personal information we collect

The information we collect depends on how you interact with KWF. We do not collect every type of information listed below from every person.

Identity

Identity and contact details

  • name, title and date of birth;
  • postal address and country;
  • email address and telephone number;
  • username, account identifier and profile details;
  • identity documents where necessary for verification or safeguarding.
Supporter activity

Donation and engagement records

  • donation amount, date, campaign and frequency;
  • Gift Aid status and declaration details;
  • sponsorship, fundraiser and campaign participation;
  • communication preferences and consent records;
  • event attendance, survey answers and feedback.
Account data

Portal and security information

  • login records, session information and account role;
  • password reset and verification activity;
  • portal permissions, preferences and saved settings;
  • audit trails and administrative actions;
  • security, fraud and misuse indicators.
Technical data

Device and website information

  • IP address, browser, device and operating system;
  • pages viewed, links clicked and visit timestamps;
  • referring website, campaign source and approximate location;
  • cookie choices and identifiers;
  • error logs, diagnostic data and website interactions.

Payment and financial information

We may collect transaction references, payment status, payment method, limited card information such as card type or final digits where supplied by a payment provider, billing address, refund information, chargeback information and accounting records. Full card numbers, security codes and online banking credentials are processed by payment providers and are not stored in KWF’s own website dashboard.

Communications

We may keep records of emails, telephone calls, messages, letters, support requests, complaints, enquiries, social-media interactions and notes made by authorised staff or volunteers about the communication.

Employment, volunteering and supplier information

This may include employment history, qualifications, references, right-to-work or identity evidence, availability, emergency contact details, training records, expenses, bank details, performance information, disciplinary or grievance information, safeguarding checks and information needed to manage a working or volunteering relationship.

Beneficiary and programme information

Where necessary to provide aid or manage a programme, we may collect household details, identity information, family relationships, financial circumstances, disability or health information, needs assessments, location, supporting documents, photographs, consent records, referral information, assistance provided, follow-up notes and safeguarding information. We apply additional care to this information.

Images, video and stories

We may collect photographs, video, audio, interviews, testimonials and case studies for programme records, reporting, accountability, education or fundraising. Where appropriate, we seek consent and explain the intended use, particularly where a child, vulnerable person or sensitive circumstances are involved.

5. Where personal information comes from

We may obtain personal information:

  • directly from you when you donate, register, apply, contact us or complete a form;
  • from a parent, guardian, authorised representative or family member;
  • from fundraising participants or supporters acting on your instructions;
  • from payment providers such as Stripe or PayPal;
  • from Gift Aid, accounting, banking or fraud-prevention systems;
  • from our staff, volunteers, trustees, field officers and authorised programme teams;
  • from partner charities, schools, healthcare providers, community organisations or referral agencies;
  • from public sources, social media or professional platforms where appropriate;
  • automatically through our website, cookies, logs, analytics and security tools;
  • from previous interactions with KWF where the continued use is lawful and relevant.

Where someone provides information about another person, they should have authority to do so and should direct that person to this policy or an applicable specific privacy notice.

6. How we use personal information

We may use personal information to:

  • accept, process, acknowledge and administer donations;
  • manage recurring giving instructions and donation schedules;
  • provide receipts, confirmations and donor statements;
  • claim, administer and audit Gift Aid;
  • create and manage portal or website accounts;
  • provide dashboards, donation histories and account services;
  • deliver sponsorship, welfare, healthcare, education and humanitarian programmes;
  • assess eligibility, need, risk and programme impact;
  • manage volunteers, staff, trustees, contractors and suppliers;
  • organise events, fundraising activities and community engagement;
  • respond to enquiries, complaints, refunds and support requests;
  • send newsletters and fundraising communications where permitted;
  • send essential service, security, payment and account communications;
  • measure and improve our website, campaigns and services;
  • protect KWF, our users and beneficiaries from fraud, misuse and cyber threats;
  • maintain financial records, audit trails and governance documentation;
  • comply with tax, charity, employment, safeguarding and legal obligations;
  • establish, exercise or defend legal rights;
  • produce aggregated or anonymised statistics and impact reports;
  • maintain appropriate records of consent, objections and communication preferences.

We will not use personal information for a new purpose that is incompatible with the original purpose unless the law permits it or we provide further information and, where required, obtain consent.

7. Our lawful bases

Data protection law requires us to identify a lawful basis for each use of personal information. The appropriate basis depends on the context.

Lawful basisWhen it may applyExamples
ContractProcessing is necessary to enter into or perform an agreement with you.Processing a donation, operating an account, providing a booked service, managing an employment or supplier relationship.
Legal obligationProcessing is necessary to comply with a legal duty.Tax, Gift Aid, accounting, employment, safeguarding, regulatory, court or law-enforcement requirements.
Legitimate interestsProcessing is necessary for KWF’s or another person’s legitimate interests and those interests are not overridden by your rights.Charity administration, supporter care, fraud prevention, service improvement, governance, limited postal or business communications, and maintaining suppression lists.
ConsentYou have made a specific, informed and freely given choice that can be withdrawn.Optional email marketing where required, certain photography, optional cookies, sensitive case studies or programme communications.
Vital interestsProcessing is necessary to protect someone’s life.Emergency medical assistance or urgent safeguarding situations where consent cannot reasonably be obtained.
Public taskProcessing is necessary for a task in the public interest or under official authority.This basis is less commonly used by KWF and would only apply where a specific legal function supports it.

Legitimate interests assessments

Where we rely on legitimate interests, we consider the purpose, necessity and likely effect on individuals. We seek to use information in ways people would reasonably expect, apply safeguards and provide a right to object where applicable.

Consent

Where processing depends on consent, you may withdraw that consent at any time. Withdrawal does not make earlier processing unlawful, but we will stop the consent-based activity unless another lawful basis properly applies.

8. Sensitive and special category information

Some KWF activities may involve information that receives additional legal protection, such as information about health, disability, religion, ethnicity, biometric identification, sexual life or orientation, political opinions or trade-union membership. Criminal offence information is also subject to separate protections.

We only collect or use such information where it is genuinely necessary and where both a general lawful basis and an additional legal condition apply. Depending on the situation, this may include explicit consent, employment and social-protection law, protection of vital interests, legal claims, substantial public interest, medical or social care, public health, or information that you have manifestly made public.

Examples may include health details needed for medical support, disability information needed to assess welfare needs, religious information relevant to a Zakat eligibility assessment, or safeguarding and criminal-record information needed for a regulated role.

Data minimisation:

We seek to collect only what is necessary. Sensitive information should not be collected merely because it may be interesting or convenient.

9. Children and vulnerable people

KWF supports children and people who may be vulnerable because of age, disability, health, displacement, poverty, bereavement, emergency circumstances or other factors. We recognise that their personal information requires particular care.

Depending on the programme, we may:

  • seek consent from a parent, guardian or person with appropriate authority;
  • provide age-appropriate explanations directly to a child;
  • consider the child’s capacity, maturity and best interests;
  • restrict access to case records and identifying information;
  • use coded identifiers or limited details in public materials;
  • avoid publishing precise locations or information that could create a safeguarding risk;
  • share information where necessary to protect a child or vulnerable person from harm.

Data protection law does not prevent appropriate safeguarding information sharing. Where there is a risk of serious harm, we may share relevant and proportionate information with emergency services, social services, healthcare professionals, safeguarding leads, police or other competent bodies.

Children have data protection rights in their own name. A parent or guardian may sometimes exercise rights on a child’s behalf, but we will consider the child’s capacity, wishes and best interests.

10. Donations, recurring giving and Gift Aid

Donation records

When you donate, we may record your name, contact details, amount, date, campaign, donation purpose, frequency, payment status, transaction reference, Gift Aid choice, communication preferences and related correspondence. Logged-in donors may be able to view donation information within their protected dashboard.

We use these records to process and acknowledge donations, provide receipts, answer enquiries, manage recurring giving, allocate funds, account for restricted and unrestricted income, prevent fraud, produce financial reports and comply with charity and tax requirements.

Recurring and scheduled giving

If you choose weekly, monthly, annual or another scheduled giving arrangement, we process the information required to create and manage that instruction. Depending on the service, this may include the donation amount, schedule, selected campaign, start and end date, payment-provider reference, status, pause or cancellation instructions and payment history.

Gift Aid

If you make a Gift Aid declaration, we may collect your full name, home address, declaration date, donation history, confirmation of UK taxpayer status and any cancellation or amendment. We use this information to submit and support claims to HM Revenue & Customs, respond to audits and meet legal record-keeping duties.

Gift Aid information may need to be retained for longer than ordinary supporter records. HMRC currently requires charities to retain a record of a Gift Aid declaration for six years after the most recent donation covered by it.

Anonymous donations

You may be able to make a donation without having your name displayed publicly. This does not necessarily mean that the donation is anonymous to KWF, our payment provider, bank, auditors or regulators. We may still need to keep internal transaction and compliance records.

11. Payments, Stripe, PayPal, refunds and fraud prevention

Online payments may be processed by Stripe, PayPal or another clearly identified provider. These providers receive information needed to process, authenticate and protect the payment. They operate under their own privacy terms and may act as an independent controller for parts of their processing.

KWF does not store full payment-card numbers, card security codes or online-banking credentials in its website dashboard. We may receive and retain limited payment information, such as payment-provider customer or transaction identifiers, card brand, final digits, expiry month or year, billing details, payment status, fraud indicators and refund information.

We may process and share relevant information to detect or investigate suspected fraud, misuse, chargebacks, sanctions concerns, stolen payment methods, unauthorised transactions, money laundering or other financial crime. This may include sharing with payment providers, banks, professional advisers, insurers, regulators or law-enforcement bodies where lawful.

Refund and dispute records may include the reason for the request, evidence supplied, correspondence, payment references, delivery or fulfilment information and our decision.

12. Website accounts, dashboards and internal portals

KWF operates donor, staff, volunteer and other internal portals, as well as WooCommerce account functions. Account information may include identity and contact details, username, password hash, role, permissions, donation history, tasks, programme records, documents, notifications, activity history and preferences.

We use this information to:

  • authenticate users and maintain secure sessions;
  • apply role-based access restrictions;
  • present relevant records, donations, tasks and notifications;
  • allow authorised users to update information or take permitted actions;
  • investigate misuse, errors, unauthorised access or security incidents;
  • maintain audit trails and operational accountability;
  • support password resets, account recovery and “Remember me” functionality.

Passwords should be stored using secure one-way hashing rather than readable text. Users are responsible for keeping login details confidential, signing out of shared devices and notifying us if they suspect unauthorised access.

“Remember me” may keep a user signed in for longer on the selected device. It should not be used on a public or shared computer.

13. Beneficiaries, applications, referrals and programme casework

To assess and deliver charitable support, KWF may process information about applicants, beneficiaries, family members, witnesses, guardians and referrers. This may include identity details, household composition, income, circumstances, disability or health needs, housing, education, employment, photographs, supporting documents, location, assistance received and follow-up outcomes.

We use this information to assess eligibility and priority, prevent duplicate assistance, plan and deliver support, monitor outcomes, protect funds, carry out audits, respond to safeguarding concerns and demonstrate charitable impact.

Access should be limited to people who need the information for authorised duties. Public stories or fundraising materials should use the minimum identifying detail necessary and should not expose a person to avoidable embarrassment, stigma, exploitation or danger.

Where partners, field teams or medical professionals are involved, KWF may share relevant information so that support can be delivered safely and effectively. We seek to use written agreements, confidentiality expectations, role controls and secure transfer methods where appropriate.

14. Volunteers, staff, trustees, applicants and suppliers

If you apply for or hold a role with KWF, we may process information needed for recruitment, selection, onboarding, management, training, safeguarding, expenses, payroll, performance, disciplinary processes, health and safety, access control and ending the relationship.

Depending on the role, this may include CVs, application forms, interview notes, qualifications, references, identity and right-to-work information, criminal-record checks, health or adjustment information, bank details, tax information, emergency contacts, attendance, training and conduct records.

Suppliers, contractors and professional advisers may provide contact, identity, banking, insurance, tax and contractual information. We use it to procure and manage services, authorise payments, maintain records and protect KWF’s legal and financial interests.

More detailed workforce privacy notices may be provided where appropriate.

15. Fundraising, sponsorships, appeals and public recognition

If you create or participate in a fundraiser, sponsor a programme, submit a story, join an event or support an appeal, we may process your profile, fundraiser title, target, campaign, story, images, updates, donation totals, supporter messages and public display choices.

Some information may be visible publicly where that is part of the service you requested. We aim to make public visibility clear at the point of collection and provide settings where available. You should avoid posting sensitive personal information about yourself or another person in a public fundraiser description or comment.

We may contact supporters about the administration and progress of an active fundraiser, sponsorship or event. These operational messages are distinct from general marketing.

We may also use appropriately anonymised or aggregated donation and impact data in annual reports, public statistics, campaign reporting and funding applications.

16. Email marketing and fundraising communications

We may send newsletters, appeals, campaign updates, impact stories, event invitations, volunteering opportunities and other fundraising communications by email. Electronic marketing is governed by both data protection law and the Privacy and Electronic Communications Regulations (“PECR”).

When we rely on consent

Where PECR requires consent, we will seek a clear, specific and informed opt-in before sending marketing emails. Consent should not be bundled with unrelated terms or treated as a condition of making a donation where it is not necessary.

We keep appropriate records of what you agreed to, when, how and what information was shown at the time. You may withdraw consent at any time.

Existing supporter communications and the soft opt-in

The PECR “soft opt-in” is primarily designed for commercial sales and negotiations. As a charity, KWF will not assume that every donation automatically gives us permission to send electronic fundraising marketing. We will use consent where required and only rely on another permitted route where we have assessed that the legal conditions are properly met.

Legitimate interests

Legitimate interests may apply to some non-electronic communications, certain business contacts, supporter analysis, record management and limited fundraising administration. It does not override PECR where PECR requires consent for an electronic marketing message.

What marketing may include

  • newsletters and impact updates;
  • emergency and seasonal appeals;
  • new campaigns and ways to support our work;
  • Ramadan, Zakat, Qurbani, winter and other programme communications;
  • event, volunteering and community invitations;
  • surveys or requests for feedback connected with supporter engagement;
  • selected updates based on interests or previous support, where lawful.

Personalisation and segmentation

We may use information such as campaign interests, donation history, location, language, communication engagement or stated preferences to make communications more relevant and avoid sending unsuitable requests. We seek to keep this proportionate and do not use sensitive beneficiary information for supporter profiling.

Tracking in marketing emails

Marketing platforms may use tracking pixels or tagged links to show whether an email was delivered, opened or clicked. Where required, we will seek consent or provide controls. You may also be able to reduce this tracking by blocking remote images in your email client.

Unsubscribing

Every marketing email should contain a clear unsubscribe link. You may also contact us at info@kashmirwelfare.org.uk. We will act on objections to direct marketing and stop the relevant marketing within a reasonable period.

We may keep a minimal suppression record, such as your email address and opt-out date, so that we do not accidentally add you back to marketing lists. This is not used to continue marketing.

Your right to object to direct marketing is absolute.

You do not need to give a reason. Unsubscribing from marketing will not prevent essential donation receipts, account security messages or communications needed to provide a service you requested.

17. Essential, transactional and service communications

Some messages are not marketing. We may send them where necessary to provide a service, perform an agreement, protect an account or meet a legal obligation, even if you have unsubscribed from marketing.

Examples include:

  • donation confirmations and receipts;
  • payment failures, refunds, chargebacks and recurring-payment notices;
  • Gift Aid confirmations or queries;
  • password resets, login alerts and security notifications;
  • account verification and material service changes;
  • updates necessary to administer an active sponsorship or fundraiser;
  • volunteer, event or appointment information you requested;
  • responses to enquiries, complaints or rights requests;
  • legal, safeguarding or fraud-prevention communications.

We will not disguise promotional content as a service message. Where a message contains both service and marketing content, we will assess the communication as a whole and apply the appropriate rules.

18. Website analytics, improvement and advertising

Subject to cookie choices and applicable law, we use technologies including Google Analytics 4, Google Tag Manager and Microsoft Clarity to understand how visitors use our website, identify errors, measure campaign performance and improve journeys.

Analytics information may include device and browser details, approximate location, referral source, pages visited, clicks, scrolling, session duration, interactions and technical diagnostics. We configure these services to limit data use where reasonably available and do not intentionally submit full payment details or highly sensitive beneficiary information to analytics tools.

Subject to consent, we may use Google Ads, Meta Pixel, TikTok Pixel and LinkedIn Insight Tag to measure advertising results, attribute visits or donations, optimise campaigns and create or reach audiences. These providers may combine information with data they already hold under their own terms.

Google Tag Manager is a tag-management system. The legal category depends on the tag it deploys. It should be configured so that optional analytics and advertising tags do not load before the relevant CookieYes permission.

19. Social media, YouTube, Google Maps and embedded content

KWF uses social-media accounts and may embed YouTube videos, Google Maps, Facebook posts and other third-party content. If you interact with us on a social platform, both KWF and the platform may process information about the interaction.

Embedded content may allow a provider to receive your IP address, device information, page viewed and interaction details, and may recognise you if you are logged into that service. Optional embeds should be controlled through the relevant CookieYes category where technically possible.

Messages sent through social media or messaging platforms may be retained where necessary to respond, keep an appropriate record or manage a safeguarding, complaint or service issue. Avoid sending highly sensitive information through an insecure public channel.

20. Cookies and similar technologies

Cookies and related technologies support security, consent management, login sessions, donation baskets, language and currency choices, dark mode, donation preferences, analytics, advertising and embedded content.

Our separate Cookie Policy explains the categories, services, choices and current CookieYes declaration in detail. Marketing-email consent is managed separately from cookie consent.

21. Who we share personal information with

We do not sell personal information. We may share it where necessary and lawful with:

  • authorised KWF trustees, staff, volunteers and field teams;
  • hosting, website, cloud, email, CRM, security and IT providers;
  • Stripe, PayPal, banks and payment or fraud-prevention providers;
  • accountants, auditors, insurers, lawyers and professional advisers;
  • HMRC, the Charity Commission, courts, regulators and public authorities;
  • delivery, event, printing, communications and fundraising service providers;
  • partner charities, schools, medical providers and community organisations;
  • emergency services, safeguarding bodies or law enforcement where necessary;
  • analytics, advertising and social-media providers where permitted;
  • a successor organisation if KWF restructures, merges or transfers a programme lawfully.

Where a supplier processes personal information only on our instructions, we seek to use a written data-processing agreement requiring confidentiality, security, assistance with rights and appropriate deletion or return of information.

Some recipients, such as banks, payment providers, social networks, regulators or professional advisers, may act as independent controllers and use information under their own legal duties and privacy notices.

22. International processing and transfers

KWF operates internationally and supports work outside the United Kingdom. Some staff, volunteers, field partners, beneficiaries and service providers may be located abroad. Technology providers may also store or access information from multiple countries.

When personal information is transferred from the UK to a country not covered by UK adequacy regulations, we seek to use an appropriate safeguard where required, such as the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses, or another legally recognised mechanism. We may also rely on a specific legal exception where it genuinely applies.

We consider the nature of the information, destination, recipient, security, necessity and risk. Particularly sensitive beneficiary, health, safeguarding or identity information should receive additional protection and should not be transferred merely for convenience.

23. How long we keep information

We keep personal information only for as long as reasonably necessary for the purposes described, including legal, tax, accounting, safeguarding, audit, fraud-prevention, contractual and dispute requirements.

Retention depends on the record and circumstances. The periods below are indicative and may be adjusted where a legal duty, ongoing programme, complaint, investigation, safeguarding need or legal claim requires longer retention.

Record typeTypical approach
Gift Aid declarations and supporting recordsNormally at least six years after the most recent donation covered by the declaration, or longer where required by HMRC.
Donation, accounting and transaction recordsNormally retained in line with tax, accounting, audit and charity-law requirements, commonly at least six financial years.
Marketing consent and suppression recordsConsent evidence is retained while relied upon and for an appropriate period afterwards. Minimal suppression records may be retained to honour an opt-out.
Inactive website accountsReviewed periodically and deleted or anonymised when no longer needed, subject to linked donation, legal, security or programme records.
General enquiries and complaintsKept for a period appropriate to the issue, usually long enough to manage follow-up, demonstrate the response and address possible disputes.
Volunteer, employment and recruitment recordsRetained according to employment, safeguarding, tax, pension, insurance and limitation requirements. Unsuccessful applicant records are normally kept for a shorter period.
Beneficiary and safeguarding recordsBased on programme need, accountability, risk, age, safeguarding guidance, funder requirements and potential legal claims. Sensitive records are reviewed carefully rather than deleted automatically.
Website logs and security recordsUsually retained for a shorter operational period unless needed to investigate fraud, misuse or a security incident.
Images, video and case studiesReviewed according to consent, purpose, safeguarding risk, publication context and ongoing historical or reporting value.

At the end of a retention period, information may be securely deleted, anonymised or, where appropriate, preserved in a restricted archive for historical or governance purposes. Anonymised information that no longer identifies anyone may be retained indefinitely.

24. How we protect personal information

We use reasonable technical and organisational measures designed to protect information against loss, misuse, unauthorised access, alteration, disclosure or destruction.

Measures may include:

  • role-based access and least-privilege permissions;
  • password hashing, authentication controls and secure password-reset processes;
  • encrypted website connections and secure payment-provider integrations;
  • software updates, backups, monitoring and malware protection;
  • audit logs and investigation of suspicious activity;
  • staff and volunteer confidentiality expectations and training;
  • secure document storage and controlled sharing;
  • data minimisation, pseudonymisation or anonymisation where suitable;
  • supplier checks and contractual security requirements;
  • incident-response and breach-assessment procedures.

No internet service or storage system can be guaranteed completely secure. You should use a strong and unique password, keep account details confidential and contact us promptly if you suspect unauthorised access.

Personal data breaches

If a security incident involves personal information, we assess the likely risk to people. Where required, we notify the Information Commissioner’s Office and affected individuals within the applicable legal timescales. We may also take steps to contain the incident, preserve evidence, recover systems and prevent recurrence.

25. Automated decision-making and profiling

KWF does not currently intend to make decisions producing legal or similarly significant effects about individuals solely through automated processing without meaningful human involvement.

We may use automated tools for lower-risk functions, such as fraud alerts, spam filtering, donation reminders, audience segmentation, website personalisation, campaign attribution or prioritising administrative work. These tools support rather than replace appropriate human judgement where a decision could materially affect a person.

If we introduce solely automated decision-making with significant effects, we will provide additional information about the logic, significance, consequences and available rights, and carry out any required impact assessment.

26. Your data protection rights

Depending on the circumstances and applicable law, you may have the following rights:

Be informed

To receive clear information about how your personal information is used.

Access

To ask whether we process your information and receive a copy and supporting details.

Rectification

To correct inaccurate information or complete information that is incomplete.

Erasure

To request deletion in certain circumstances. This right is not absolute.

Restriction

To ask us to limit processing in certain circumstances.

Data portability

To receive certain information in a structured, commonly used and machine-readable format.

Object

To object to processing based on legitimate interests and to object absolutely to direct marketing.

Withdraw consent

To withdraw consent at any time where consent is the basis for processing.

Automated decisions

To obtain safeguards in relation to certain solely automated decisions with significant effects.

Complain

To raise a concern with KWF or complain to the Information Commissioner’s Office.

Rights may be limited by exemptions or the rights of other people. For example, we may need to retain donation records for tax purposes, protect confidential safeguarding information or withhold information that identifies another person.

27. How to exercise your rights

You may contact us using the details below. A request can be made verbally or in writing, although a written request may help us understand and record what you need.

We may ask for information needed to confirm identity and protect personal information from unauthorised disclosure. We will not ask for more identification than is proportionate.

We normally respond within one month. The law may allow additional time for a complex or multiple request, in which case we will explain the extension. Rights requests are normally free, although the law permits a reasonable fee or refusal in limited cases involving manifestly unfounded or excessive requests.

A third party may act on your behalf where they provide appropriate authority. Parents, guardians and representatives do not automatically receive all information about another person; we consider authority, capacity, confidentiality, safeguarding and best interests.

Make a data protection request

28. Questions and complaints

We would welcome the opportunity to resolve a privacy concern directly. Please contact us at info@kashmirwelfare.org.uk and mark the message for the attention of the person responsible for data protection.

You also have the right to complain to the UK Information Commissioner’s Office (“ICO”), the independent regulator for data protection. Information about complaints and current contact methods is available at ico.org.uk.

If you live outside the United Kingdom, you may also be entitled to complain to the supervisory authority that applies in your country.

29. Changes to this Privacy Policy

We may update this policy when our activities, systems, suppliers or legal obligations change. The date at the top shows the latest revision.

Where a change is significant, we may provide additional notice through our website, account dashboard or direct communication. Where the law requires fresh consent, continued use of the website will not be treated as a substitute for that consent.

30. Contact us

For privacy questions, requests, objections or complaints, contact:

Kashmir Welfare Foundation
UK registered charity
Registered charity number: 1206824
Registered office: 127-129 Clarence Road, Derby, DE23 6LS
Email: info@kashmirwelfare.org.uk
Website: kashmirwelfare.org.uk

Please write “Data Protection” in the subject line where possible. If KWF formally appoints a Data Protection Officer in the future, this page should be updated with that officer’s contact details.

This Privacy Policy should be read with KWF’s Cookie Policy, website terms, donation terms, safeguarding information and any specific privacy notice provided for a particular service.