Current Version: 1.2
Mission Diverse CIC is committed to handling personal information lawfully, fairly, transparently and securely.
This policy explains how we collect, use, store, share and protect personal information relating to people who interact with Mission Diverse. It applies to clients, prospective clients, website visitors, training participants, current employees, former employees, workers, consultants, contractors, suppliers, partners, professional contacts and other individuals who engage or have previously engaged with us.
The personal information we process will depend on the nature of your relationship with us.
It may include:
We may also process special category personal data where necessary and where an appropriate lawful condition applies.
We may process personal information where reasonably necessary to:
We will identify an appropriate lawful basis for each processing activity.
Depending on the circumstances, we may process personal information because:
Should an individual does not give consent, or later withdraws consent, does not necessarily mean that all processing must stop. You understand consent is one lawful basis among several. Where another lawful basis applies, we may continue to process information in accordance with that basis and applicable law.
We may rely on legitimate interests where processing is reasonably necessary for a legitimate organisational, commercial, operational or professional purpose and those interests are not overridden by the rights and interests of the individual.
Our legitimate interests may include (but limited to):
Where we rely on legitimate interests, we may consider the purpose and importance of the processing, whether the processing is reasonably necessary, the individual’s reasonable expectations, the likely impact on them, any contractual arrangements and whether appropriate safeguards or less intrusive alternatives are available.
During employment, consultancy, contracting, training or other professional engagement with Mission Diverse, individuals may create, contribute to or appear in materials including:
Where these materials have been created or commissioned for a legitimate organisational or commercial purpose, Mission Diverse may retain and continue to use them where we have an appropriate lawful basis and the use remains necessary and proportionate.
This may include the continued use of materials containing an individual’s name, image, voice or other identifying information where the material was created for the purpose of providing services, training, education, organisational knowledge or another legitimate business activity.
The fact that an individual’s employment, engagement or professional relationship with Mission Diverse later ends does not of itself require the destruction, withdrawal or cessation of use of material lawfully created during that relationship.
Where possible and appropriate, we may remove or update contextual information that is no longer accurate while retaining the underlying material or resource.
Mission Diverse may retain records relating to its activities where reasonably necessary for operational, contractual, governance, evidential, historical, regulatory or legal purposes.
These may include correspondence, meeting notes, contracts, recordings, training records, project records, communications, decision records and other information created during the course of business.
The ending of an employment, consultancy, client or other relationship does not necessarily require the deletion of records relating to that relationship.
Information may be retained where necessary to maintain an accurate record of past events, demonstrate decisions or actions taken, meet contractual or legal obligations, protect the rights of Mission Diverse or others, or establish, exercise or defend legal claims.
Individuals may have the right to ask us to erase personal information in certain circumstances.
You understand the right to erasure is not absolute.
We may retain information where continued processing is lawful and necessary, including where:
We will consider requests individually and will explain our decision where required by law.
Individuals may object to certain processing of their personal information.
Where we process information on the basis of legitimate interests and receive an objection, we will consider the individual’s particular circumstances and the reasons for the objection.
An objection does not necessarily require processing to stop.
Where permitted by law, we may continue processing if we can demonstrate compelling legitimate grounds which override the individual’s interests, rights and freedoms, or where the processing is necessary for the establishment, exercise or defence of legal claims.
The right to object to processing for direct marketing purposes is different. Where an individual objects to direct marketing, we will stop using their personal information for that purpose.
Where we rely specifically on consent, an individual may withdraw that consent.
Withdrawal of consent does not affect processing that took place lawfully before consent was withdrawn.
It also does not necessarily affect processing undertaken on another lawful basis.
Where information is lawfully processed on the basis of contract, legal obligation, legitimate interests or another lawful basis, we may continue that processing where appropriate.
We process information relating to employees, workers, consultants and contractors where necessary to administer and manage the working relationship and our organisation.
This may include information relating to:
Some information may continue to be held following the end of an employment or professional relationship where there is an operational, contractual, regulatory, historical, evidential or legal reason to retain it.
Where necessary and proportionate, Mission Diverse may monitor or review the use of its systems, information, devices or business accounts for purposes including security, continuity, compliance, safeguarding, protection of confidential information and intellectual property, investigation of suspected misuse and protection of legal or contractual rights.
Any monitoring will be undertaken in accordance with applicable data protection law and appropriate internal policies.
We may receive personal information from third parties or obtain information from publicly available sources where lawful and relevant to our activities.
Sources may include:
Where required, we will provide appropriate privacy information about how that information is used.
We may share personal information where lawful, necessary and proportionate.
Recipients may include:
Where another organisation processes information on our behalf, appropriate contractual and security arrangements will be used where required.
We do not sell personal information.
We may process information relating to health, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, trade union membership or other special category information where necessary and where a lawful Article 9 condition applies.
Access to this information will normally be restricted and additional safeguards applied where appropriate.
When you use our website or other digital services, we may collect technical information including device, browser, usage and security information.
We may use cookies and similar technologies where necessary to operate our website and, where permitted, to understand website use, improve our digital services and support communications.
Where the law requires consent for non-essential cookies, we will seek that consent.
We may use appropriately selected digital tools to support administrative and operational activities, including transcription, summarisation, document management, search, workflow automation and similar functions.
Where these tools process personal information, their use will be subject to applicable data protection requirements and appropriate organisational controls.
We do not rely solely on automated systems to make significant decisions about individuals unless permitted by law and appropriate safeguards are in place.
We retain personal information for as long as reasonably necessary for the purpose for which it is held.
The period will depend on factors including:
Where information is subject to an actual or anticipated complaint, dispute, claim, investigation, legal process or regulatory matter, we may suspend normal deletion arrangements for as long as reasonably necessary.
We take reasonable organisational and technical measures to protect personal information against unauthorised access, disclosure, alteration, loss, misuse or destruction.
Access is limited according to operational need and may be withdrawn or restricted where appropriate.
Some service providers or digital systems we use may process information outside the United Kingdom.
Where an international transfer requires additional safeguards, we will use an appropriate mechanism recognised under applicable data protection law.
Depending on the circumstances and applicable legal exemptions, individuals may have rights including:
These rights are not absolute and their application depends on the circumstances and lawful basis for processing.
We may ask for information reasonably necessary to verify identity or understand the scope of a request.
Where we lawfully refuse or limit a request, we will provide the information required by applicable data protection legislation.
If you have questions or concerns about how Mission Diverse uses personal information, or wish to exercise a data protection right, please contact us using the details provided on our website.
You also have the right to complain to the Information Commissioner’s Office.
We may amend this policy to reflect changes in law, regulatory guidance, technology, services or our organisational activities.
The current version published on our website will apply from its stated effective date.
| Version | Effective Date | Amendments | Approved By |
| 1.0 | 5 October 2020 | Policy effective | Data Protection Officer |
| 1.1 | 5 October 2020 | Section added: “Complaints” | Data Protection Officer |
| 1.2 | 18 August 2026 | Section added: “International transfers” section | Data Protection Officer |