Local Family Links privacy notice
Who we are
Local Family Links Ltd, trading as Local Family Links, is the controller of the personal information described in this notice.
- Company number: 17389379
- Registered office: Shalom, Gellideg, Llandovery, Wales, SA20 0DB
- Privacy contact: Privacy Lead (Owner/Administrator)
- Email: [email protected]
- Telephone: 07508 390070
- Website: https://localfamilylinks.co.uk/
Information we may use
Depending on the service, we may use:
- your identity, address and contact details;
- enquiry, assessment and service-arrangement information;
- appointment, visit, action and communication records;
- accessibility, mobility, cognition, health, medication, disability, safety or safeguarding information that is necessary to assess or provide support;
- details of a person you nominate or who contacts us about you, including their relationship and authority;
- reports, documents or household information you ask us to help with;
- billing, invoice and payment-status information if payments are later enabled;
- your choices, consents, objections and information-rights requests; and
- technical security, access and audit information.
We may receive information directly from you, from a trusted person or formal representative, from our own observations during agreed services, or from another organisation where you have authorised this or the law permits it. We record the source where it matters.
Why and how we use it
We use necessary information to respond to enquiries, assess whether our service is suitable, agree and deliver services, arrange appointments and visits, communicate with you and authorised people, keep an accurate service record, manage safety, administer agreed charges, meet specific legal duties, handle complaints/claims, secure our systems and recover from incidents.
Our lawful bases are:
- steps you request before a contract, and performance of a contract with you;
- our legitimate interests in safe, proportionate service administration, continuity, family liaison, record-keeping, security and legal claims, after balancing those interests against your rights;
- a legal obligation, only where a specific law requires the processing;
- consent for genuinely optional uses; and
- vital interests only in a genuine emergency.
Health and other sensitive information
Some information about health, disability, cognition or medication is special-category information. We first need an Article 6 lawful basis for the purpose described above. Separately, for routine support planning where no other documented condition applies, our Article 9 condition is your explicit consent. We will explain the information, purpose and any sharing separately and record your specific, informed choice. You may withdraw consent. Withdrawal applies to future use and does not make earlier lawful processing unlawful. We may need to pause or stop affected work if we cannot provide it safely without the necessary information.
In an exceptional emergency or safeguarding situation, another legal condition may permit necessary use or disclosure. We will identify and document that condition before relying on it; we do not treat a family relationship as consent on a client's behalf.
Trusted people and sharing
We do not treat a family relationship as automatic authority. We record who you authorise, what we may share, for what purpose and for how long. We share only what is necessary. You may change or withdraw ordinary authority at any time. We may retain a minimal record of disclosures already made.
Formal attorneys or deputies must provide suitable evidence of their role and scope. We may share without ordinary authority only where the law permits or requires it, such as a properly assessed emergency or safeguarding situation.
If you give us another person's contact details, please tell them that we will use those details for the agreed contact purpose and direct them to this notice.
Who receives information
Access is limited to authorised LFL personnel who need it. Current hosting and technical processors include Supabase and Google Cloud. We may also disclose information to professional advisers, regulators, emergency services or other organisations where necessary and lawful.
Google Drive, Twilio/SMS, Stripe LIVE and outbound provider email are currently disabled for live client processing. If these services are activated later, we will review the processing and update this notice before using them.
Some processors or subprocessors may process information outside the UK. Their contractual terms include applicable UK transfer safeguards. We maintain and review a processor/subprocessor register and assess material changes.
How long we keep information
We keep information only while it is needed for the stated purpose, an active complaint/claim/safeguarding matter, or a documented legal obligation. Our initial business policy is normally 12 months for enquiries that do not proceed and six years after service closure for the core client and visit record. Different periods apply to short-lived working files, security logs, finance records and incidents. These are business-policy periods, not claims that the law always requires retention for that length. We periodically review necessity and obtain professional confirmation where finance, safeguarding or potential claims require it.
Encrypted backups are retained on an approximately 35-day rolling cycle. When live information is validly erased, it is placed beyond normal operational use in backups and expires through that cycle. If a backup is restored, the erasure instruction is reapplied before operational use.
Your rights
Depending on the processing, you may ask us to:
- provide access to your personal information;
- correct inaccurate or incomplete information;
- erase information where the right applies;
- restrict how we use it;
- provide certain information in a portable form;
- stop processing based on legitimate interests where your rights prevail; or
- recognise withdrawal of consent.
You can make a request verbally or in writing. We may ask for proportionate proof of identity or a representative's authority. We normally respond without undue delay and within one calendar month. Some rights are not absolute; if we cannot fully comply, we will explain why and tell you how to complain.
Contact [email protected] or write to the registered office above. We will use a verified, secure delivery method for sensitive responses.
Security and automated decisions
We use named access, multi-factor authentication, encryption, audit controls, monitoring and encrypted backups. No system is risk-free, so we also maintain incident and recovery procedures.
We do not use your information for solely automated decisions with legal or similarly significant effects, and we do not use client information for direct marketing under this notice.
Complaints
Please contact us first so that we can try to resolve a concern. You also have the right to complain to the Information Commissioner's Office: https://ico.org.uk/make-a-complaint/.
Changes to this notice
We will review this notice at least annually and before a material new use or provider is introduced. We will bring material changes to affected people's attention where appropriate.