Community Food and Health (Scotland) is delivered by NHS Health Scotland, a national NHS Board, by the community food team within the wider place and equity team.
We fully respect your right to privacy when using our services. Here you will find details of our privacy practices and what we do to maintain your right to privacy.
What information do we collect about you?
We collect information about you and your organisation when you access any of our services online, by phone or in writing. We only collect the information we ask from you, that you give us and consent to it being processed for the purpose of delivering the community food programme.
How will we use the information we collect?
We process your information for the purpose of providing you with services from Community Food and Health (Scotland). This includes some or all of the following:
- Managing your enquiries you have submitted to us
- Managing your subscriptions to our Fare Choice newsletter and e-bulletin that you have opted in to receive
- Administration of Community Food and Health (Scotland) funding schemes or programmes.
- Conducting data and statistical analysis to monitor performance of our services and make improvements.
NHS Health Scotland may share the information we collect with:
- The Scottish Government
- Our affiliates and service providers in the UK/EU as necessary for the purpose of keeping you updated on our products and services.
We may also disclose the information to a third party where we have a legal obligation to do so. NHS Health Scotland will not share with or sell your personal information to any other organisation.
How do we look after your information?
The information we collect about you and your organisation is stored securely in our contacts database on NHS Health Scotland systems hosted in the UK/EU. If you subscribe to our e-bulletin your email address will be stored in Campaign Monitor hosted on a secure server by a third party in the UK/EU. The website is hosted on a secure server by a third party in the UK, and is maintained by NHS Health Scotland staff.
The principles of the General Data Protection Regulation (GDPR) require us to make sure your data is accurate, kept up-to-date and that we keep it for no longer than is necessary.
To meet these requirements:
- We will update your data or remove it from our database at your request
- If you have opted in to get updates on our products or services, any information we send you will include details to let you unsubscribe
- We will perform data audits every 12 months and remove data that is inaccurate, out of date, or no longer required.
Website log files
Using our website will generate log files of your activity. These files do not capture personal information but do capture the user’s IP address. We store these log files on a secure server. We use Matamo to analyse these files regularly to monitor website usage and evaluate the effectiveness of our website. This information is not personally identifiable. For more information read about cookies on our Legal information page.
We make no attempt to identify individual users of this website, unless we suspect that unauthorised access to our systems is being attempted. We reserve the right to attempt to identify and track any individual who is reasonably suspected of trying to gain unauthorised access to computer systems or resources operating as part of NHS Health Scotland web services. As a condition of using this site, all users give permission for NHS Health Scotland to use its access logs to attempt to track users who are reasonably suspected of gaining, or attempting to gain, unauthorised access.
Under the General Data Protection Regulation (effective from 25 May 2018), there are a number of new rights relating to Data Protection:
You have the following rights:
- The right to be informed
- The right of access
- The right to rectification
- The right to erasure
- The right to restrict processing
- The right to data portability
- The right to object
- Rights in relation to automated decision making and profiling
You can find more information about these rights on the Information Commissioner’s website.
Access to your information, changes, and complaints
To request a copy of the information that we hold about you, correct any information that is inaccurate, unsubscribe from our services, or withdraw your consent, you can contact us or write to us at:
Community Food and Health (Scotland)
NHS Health Scotland
5 Cadogan Street
For enquiries about NHS Health Scotland (the Data Controller) data protection practices, you can contact Duncan Robertson, NHS Health Scotland’s Senior Policy, Risk and Data Protection Officer by email at firstname.lastname@example.org or by phone on 0131 314 5436.
Should you wish to make a complaint about NHS Health Scotland’s collection or use of data, the UK’s independent authority set up to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals is the Information Commissioner’s Office.
Last updated 24 May 2018.