Privacy Policy
NeuroDiverse Community CIC Privacy Policy
Organisation: NeuroDiverse Community CIC
Contact email: info@neurodiverse-community.co.uk
Registered office: 24 Bishops Way, Catterick, Richmond, North Yorkshire, DL10 7UA
ICO Registration Number: ZC089153
Effective from: 20 August 2026
Review date: August 2027, or earlier where legislation, regulatory guidance or NDC’s processing activities change
1. Introduction
NeuroDiverse Community CIC (“NDC”, “we”, “us” or “our”) is committed to protecting the privacy, dignity and personal information of everyone who engages with our organisation.
We work with children, young people, adults, parents and carers, members of the Armed Forces community, volunteers, professionals, partner organisations, employees, job applicants, trainees, customers and members of the wider community. Some of the information entrusted to us can be particularly sensitive, including information relating to disability, neurodivergence, health, education, family circumstances and safeguarding.
We therefore take our responsibilities for data protection seriously and are committed to processing personal information lawfully, fairly, transparently and securely.
This Privacy Policy explains how NDC collects, uses, stores, shares and protects personal information and explains the rights individuals have in relation to their information.
This policy is intended to comply with applicable UK data protection and privacy legislation, including:
- the UK General Data Protection Regulation (“UK GDPR”);
- the Data Protection Act 2018 (“DPA 2018”);
- the Data (Use and Access) Act 2025 (“DUAA”);
- the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), as amended;
- relevant safeguarding legislation and statutory guidance; and
- other applicable legislation governing employment, health and safety, financial records, service delivery and information sharing.
2. Who is responsible for your personal information?
For the purposes of UK data protection law, NeuroDiverse Community CIC will normally be the data controller for personal information that it determines how and why to process.
In some circumstances, NDC may process information jointly with another organisation, or may process information on behalf of another organisation under a contractual arrangement.
Questions about how NDC uses personal information should be directed to:
Data Protection Lead
NeuroDiverse Community CIC
Email: info@neurodiverse-community.co.uk
Address: 24 Bishops Way, Catterick, Richmond, North Yorkshire, DL10 7UA
3. Our data protection principles
NDC will ensure that personal information is:
- processed lawfully, fairly and transparently;
- collected for specified, explicit and legitimate purposes;
- adequate, relevant and limited to what is necessary;
- accurate and, where necessary, kept up to date;
- retained for no longer than necessary;
- protected using appropriate technical and organisational security measures; and
- processed in a way that enables NDC to demonstrate compliance with its legal obligations.
We apply the principles of data protection by design and by default, particularly when developing new services, forms, systems, digital platforms or projects involving children or sensitive information.
4. Personal information we may collect
Depending upon how an individual interacts with NDC, we may collect and process information including:
Identity and contact information
This may include:
- name;
- title;
- date of birth;
- age;
- postal address;
- email address;
- telephone number;
- emergency contact information; and
- parent, carer or representative details.
Family and household information
Where relevant to the support being provided, this may include:
- family composition;
- parental or caring responsibilities;
- relationships between family members;
- housing or accommodation circumstances;
- Service family information;
- deployment or posting information where relevant to support;
- financial hardship information; and
- information about other agencies supporting the individual or family.
Education and SEND information
Where necessary for SEND advice, advocacy, casework or support, we may process information including:
- Special Educational Needs and Disabilities information;
- Education, Health and Care Plans;
- educational assessments;
- school reports;
- attendance information;
- professional reports;
- correspondence with schools, local authorities and other professionals;
- tribunal or mediation documentation;
- educational history;
- reasonable adjustments;
- support plans; and
- information supplied by parents, carers, educational settings or professionals.
Health, disability and neurodivergence information
We may process information relating to:
- disabilities;
- diagnosed or suspected neurodevelopmental conditions;
- physical or mental health;
- medical conditions;
- allergies;
- medication;
- accessibility requirements;
- communication needs;
- sensory needs;
- behavioural or emotional support requirements; and
- other health or care information required to provide safe and appropriate support.
Much of this information constitutes special category personal data and receives additional legal protection.
Safeguarding information
Where a safeguarding concern arises, NDC may process information concerning:
- safeguarding disclosures;
- allegations or concerns;
- incidents;
- injuries;
- risk assessments;
- referrals;
- information received from or shared with statutory agencies;
- child or adult protection information;
- domestic abuse or family safety concerns; and
- information relating to potential criminal conduct where relevant and lawful.
Access to safeguarding information is strictly controlled.
Service and casework records
We may maintain records of:
- referrals;
- assessments;
- support requested;
- advice provided;
- meetings;
- telephone calls;
- emails;
- case notes;
- professional correspondence;
- actions agreed;
- outcomes;
- signposting and referrals;
- advocacy undertaken on an individual’s behalf; and
- closure or review information.
Event, group and programme information
For NDC sessions, programmes, events and activities, we may collect:
- booking information;
- attendance;
- emergency contacts;
- accessibility requirements;
- medical or allergy information where required for safety;
- consent information;
- participation records;
- incident information;
- feedback and evaluation information; and
- photographs or video where appropriate permissions have been obtained.
Employment and volunteering information
For employees, workers, trustees, directors, contractors, volunteers and applicants, information may include:
- CVs and application forms;
- employment history;
- references;
- qualifications;
- training records;
- right-to-work information;
- DBS information where applicable;
- safeguarding checks;
- payroll and banking details;
- emergency contacts;
- attendance;
- performance and supervision records;
- disciplinary or grievance information;
- health and reasonable adjustment information; and
- other records required to manage the employment or volunteering relationship.
Training and professional services information
Where individuals or organisations purchase or attend NDC training, consultancy or casework services, we may collect:
- attendee names;
- professional roles;
- employer or organisation;
- contact information;
- bookings;
- payment records;
- attendance;
- assessment or evaluation information;
- certificates;
- feedback; and
- correspondence relating to the service.
Financial and transaction information
Where payments, purchases, donations, grants or other financial transactions take place, we may collect:
- transaction details;
- billing information;
- invoice information;
- payment status;
- purchase history; and
- financial records required for accounting or audit purposes.
NDC does not normally retain complete payment-card information where payments are processed through a third-party payment provider.
Website and digital information
When individuals use our website or digital services, we may collect information such as:
- IP address;
- device or browser information;
- website usage;
- pages visited;
- cookie identifiers;
- online enquiry information; and
- technical information required for website security and operation.
Further information may be provided through our Cookie Policy.
5. Information about children and young people
NDC provides services that may involve children and young people and recognises that their personal information requires particular protection.
When processing children’s information, NDC will consider the child’s age, maturity, understanding, circumstances and best interests.
We will use clear and accessible privacy information wherever appropriate and will only collect information that is reasonably necessary for the relevant service, activity, safeguarding responsibility or other legitimate purpose.
Parental or carer involvement will be considered where appropriate, but children and young people have their own data protection rights. A parent or carer does not automatically have an unrestricted right to access all information held about a child.
Where a sufficiently competent child or young person is capable of exercising their own data protection rights, NDC will take this into account.
When providing online services likely to be accessed by children, NDC will consider children’s specific needs and apply appropriate privacy and safeguarding protections.
6. How we obtain personal information
We may obtain information:
- directly from the individual;
- from a parent, carer or authorised representative;
- through referrals;
- from schools, colleges or educational professionals;
- from local authorities;
- from NHS or healthcare professionals where lawful;
- from social care or safeguarding professionals;
- from Armed Forces welfare or support services;
- from partner organisations;
- from employers or training commissioners;
- through booking, payment and event platforms;
- through our website and online forms;
- from publicly available sources where appropriate and lawful; or
- from other organisations where information sharing is lawful and necessary.
Where information has not been obtained directly from the individual, NDC will provide appropriate privacy information unless a lawful exemption applies.
7. Why we use personal information
NDC may process personal information in order to:
- respond to enquiries;
- provide community services and activities;
- provide SEND advice, support, casework and advocacy;
- provide family support;
- make or receive referrals;
- coordinate support with other organisations;
- provide training and professional services;
- manage bookings and attendance;
- provide safe and appropriate reasonable adjustments;
- administer programmes including EmployAbility and other NDC services;
- safeguard children and adults at risk;
- manage incidents, accidents and emergencies;
- comply with legal and regulatory duties;
- maintain appropriate case records;
- manage employees, volunteers, contractors and applicants;
- process payments, purchases, refunds and invoices;
- manage donations and funding;
- monitor and evaluate our services;
- demonstrate outcomes and impact to commissioners or funders;
- improve our services;
- administer our website;
- maintain information and cyber security;
- prevent or detect fraud, misuse or unlawful activity;
- respond to complaints;
- establish, exercise or defend legal claims; and
- communicate information about NDC’s services, training, activities and opportunities where legally permitted.
8. Our lawful bases for processing
UK data protection law requires NDC to identify a lawful basis before processing personal information.
Depending on the circumstances, NDC may rely upon one or more of the following:
Consent
Where an individual has given NDC clear permission to process information for a specific purpose.
Where consent is our lawful basis, it may be withdrawn at any time. Withdrawal will not affect processing which was lawful before consent was withdrawn.
Contract
Where processing is necessary to enter into or perform a contract with an individual, including where someone purchases a service, training course or product from us.
Legal obligation
Where processing is necessary for NDC to comply with a legal obligation.
This may include obligations concerning employment, taxation, safeguarding, health and safety, financial records or other statutory responsibilities.
Vital interests
Where processing is necessary to protect someone’s life or physical safety and another lawful basis is not more appropriate.
This is likely to arise only in limited or emergency circumstances.
Legitimate interests
NDC may process personal information where this is necessary for our legitimate interests or those of another person or organisation, provided those interests are not overridden by the rights and freedoms of the individual.
Examples may include:
- providing and improving our services;
- responding to enquiries;
- maintaining appropriate operational records;
- protecting NDC’s systems, property and services;
- preventing fraud or misuse;
- establishing, exercising or defending legal rights;
- communicating appropriately with professional contacts; and
- carrying out proportionate organisational administration.
Where we rely on legitimate interests, we will consider the necessity and proportionality of the processing and its potential impact upon the individual. Additional care will be taken where children or vulnerable individuals are involved.
Recognised legitimate interests
Where permitted by current UK data protection legislation, NDC may rely upon a recognised legitimate interest where the processing falls within one of the purposes specifically recognised by law and the applicable statutory conditions are satisfied.
Public task
NDC will only rely upon public task where it is carrying out a function in the public interest that has a sufficiently clear basis in law.
NDC will not assume that providing services benefiting the community is, by itself, sufficient to rely on public task.
9. Special category personal information
Some information requires greater protection under UK data protection law.
Special category information includes information about:
- health;
- disability where it reveals health information;
- racial or ethnic origin;
- religious or philosophical beliefs;
- political opinions;
- trade union membership;
- genetic information;
- certain biometric information;
- sex life; and
- sexual orientation.
Where NDC processes special category information, we must have both:
- an appropriate lawful basis for processing under Article 6 of the UK GDPR; and
- an appropriate additional condition under Article 9 of the UK GDPR and, where required, the Data Protection Act 2018.
Depending upon the circumstances, the relevant special-category condition may include:
- explicit consent;
- employment, social security or social protection obligations and rights;
- protection of vital interests;
- establishment, exercise or defence of legal claims;
- substantial public interest;
- safeguarding children or individuals at risk;
- equality of opportunity or treatment where the statutory conditions are satisfied; or
- health or social care purposes where the legal requirements for that condition are met.
NDC will identify and document the appropriate condition before relying upon it.
Where required by the Data Protection Act 2018, NDC will maintain an Appropriate Policy Document explaining how relevant special category and criminal offence information is processed and retained.
10. Criminal offence information
NDC may occasionally need to process information concerning criminal allegations, proceedings, convictions or offences, particularly in relation to:
- safeguarding;
- safer recruitment;
- DBS checks;
- allegations involving children or adults at risk;
- prevention or detection of unlawful acts; or
- legal claims.
Criminal offence information will only be processed where NDC has a lawful basis and appropriate authority under UK law.
Access to this information will be restricted to those who genuinely need it.
11. Safeguarding and information sharing
The protection of children and adults at risk is of paramount importance.
NDC will normally seek to be transparent with individuals about how their information is used and shared. However, consent is not always required before safeguarding information can lawfully be shared.
Where NDC reasonably believes that a child or adult may be at risk of harm, or where there is another lawful safeguarding reason, relevant information may be shared with appropriate organisations or professionals.
These may include:
- local authority children’s or adult social care services;
- the police;
- NHS or healthcare professionals;
- schools or education providers;
- Designated Safeguarding Leads;
- Armed Forces safeguarding or welfare services;
- emergency services; or
- other organisations with a legitimate safeguarding role.
Any safeguarding information sharing will be considered on a case-by-case basis and should be necessary, proportionate, relevant, adequate, accurate, timely and secure.
Where appropriate and lawful, individuals will be informed about information sharing. NDC may withhold advance notification where doing so could increase risk, prejudice an investigation, place someone in danger or otherwise be inappropriate or unlawful.
NDC will maintain records of significant safeguarding information-sharing decisions.
12. SEND casework, advocacy and professional information sharing
Where NDC is providing SEND, education or family casework, we may need to communicate with third parties on an individual’s behalf.
Depending upon the case, this may include:
- schools;
- SEND teams;
- local authorities;
- health professionals;
- social care;
- educational psychologists;
- therapists;
- solicitors or legal representatives;
- mediation services;
- SEND Tribunal services;
- alternative education providers; and
- other professionals involved in the individual’s support.
Where appropriate, we will obtain authority from the individual, parent, carer or representative before acting on their behalf.
This does not prevent NDC from sharing information without consent where another lawful basis applies, including safeguarding, legal obligations, vital interests or the establishment, exercise or defence of legal claims.
13. Photographs, video and media
NDC may take photographs or video at certain activities and events.
Where photographs or recordings are intended for identifiable promotional, publicity or marketing purposes, NDC will use an appropriate lawful basis and obtain appropriate permission where required.
Particular care will be taken where images involve children, young people or adults who may be vulnerable.
Where consent is relied upon:
- participation will not be made conditional on agreeing to promotional photography unless photography is genuinely integral to the activity;
- individuals may refuse photography without unfair disadvantage;
- consent can be withdrawn for future use; and
- NDC will take reasonable steps to cease future use following withdrawal.
Withdrawal cannot always reverse uses that have already lawfully taken place. For example, printed materials may already have been distributed, and NDC may not be able to control copies independently shared by third parties.
Photography required solely for safeguarding, incident management, evidential purposes or another lawful operational reason will be considered separately from marketing consent.
14. Who we may share information with
NDC does not sell personal information.
Where necessary and lawful, we may share information with organisations including:
- local authorities;
- schools and education providers;
- NHS organisations and healthcare professionals;
- social care services;
- police and emergency services;
- safeguarding organisations;
- Armed Forces welfare and support services;
- professional advisers;
- legal representatives;
- insurers;
- auditors and accountants;
- commissioners and funders;
- regulatory bodies;
- IT, cloud-storage and software providers;
- email and communications providers;
- website hosting providers;
- event-booking providers;
- payment processors;
- training platforms;
- DBS or safer recruitment providers;
- payroll providers; and
- other organisations necessary for the delivery, administration or protection of NDC’s services.
Where another organisation processes information on NDC’s behalf, NDC will use appropriate contractual and organisational safeguards as required by data protection law.
When sharing monitoring or impact information with funders, commissioners or partners, NDC will use anonymised or aggregated information wherever reasonably possible.
15. Confidentiality
Information shared with NDC is treated with respect and appropriate confidentiality.
However, confidentiality is not absolute.
Information may be disclosed where:
- an individual has authorised disclosure;
- disclosure is necessary to provide the requested service;
- NDC is legally required to disclose information;
- there is a safeguarding concern;
- disclosure is necessary to protect someone’s vital interests;
- disclosure is required to prevent or detect serious unlawful activity;
- disclosure is necessary in connection with legal proceedings; or
- another lawful basis permits or requires the disclosure.
Staff and volunteers will only be given access to personal information where they have a legitimate need to know it.
16. Service providers and data processors
NDC may use third-party systems and service providers to support our work.
Before appointing providers that process personal information on our behalf, we will take reasonable steps to consider their data-protection and security arrangements.
Where required, appropriate data-processing agreements will be used addressing matters such as:
- confidentiality;
- information security;
- processing instructions;
- use of subcontractors;
- assistance with individual rights;
- personal data breaches;
- deletion or return of information; and
- audit and compliance obligations.
17. International transfers
Some technology, cloud, communication or other service providers used by NDC may process or store information outside the United Kingdom.
Where this results in a restricted international transfer of personal information, NDC will ensure that an appropriate legal transfer mechanism is in place.
Depending on the destination and circumstances, this may include:
- UK adequacy regulations;
- appropriate contractual safeguards;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved contractual clauses;
- another legally recognised transfer safeguard; or
- a specific statutory exception where applicable.
Where required, NDC will undertake an appropriate transfer risk assessment and implement additional safeguards.
18. Data security
NDC takes reasonable and proportionate technical and organisational measures to protect personal information from:
- accidental loss;
- unauthorised access;
- unlawful disclosure;
- alteration;
- destruction;
- misuse; and
- cyber-security threats.
Measures may include:
- password protection;
- multi-factor authentication where available;
- role-based access controls;
- restricted access to sensitive files;
- secure cloud storage;
- secure devices;
- appropriate encryption;
- secure disposal;
- staff and volunteer confidentiality requirements;
- data-protection and safeguarding training;
- secure sharing methods;
- software updates;
- backup arrangements; and
- procedures for identifying and responding to personal data breaches.
Security measures will be reviewed proportionately to the sensitivity and volume of information being processed.
19. Personal data breaches
A personal data breach may involve the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal information.
NDC will record and assess suspected personal data breaches.
Where a breach is likely to result in a risk to people’s rights and freedoms, NDC will notify the Information Commissioner’s Office as required by law.
Where a breach is likely to result in a high risk to an affected individual, NDC will also inform that person without undue delay unless a lawful exception applies.
Staff and volunteers must report suspected personal data breaches promptly in accordance with NDC’s internal procedures.
20. How long we retain personal information
NDC will not retain identifiable personal information for longer than is reasonably necessary.
Retention periods vary according to:
- the purpose for which the information was collected;
- the nature and sensitivity of the information;
- safeguarding considerations;
- the age of the individual;
- contractual obligations;
- statutory record-keeping requirements;
- taxation and accounting requirements;
- insurance requirements;
- applicable limitation periods;
- regulatory requirements;
- ongoing disputes or legal proceedings; and
- whether information is required to establish, exercise or defend legal claims.
NDC will maintain a Data Retention and Disposal Schedule setting out appropriate retention periods for different categories of information.
When information is no longer required, it will be securely deleted, destroyed or anonymised unless continued retention is lawfully justified.
Safeguarding records will be subject to particular consideration and will not be destroyed merely because an individual has stopped accessing NDC services where continued retention is necessary and proportionate for safeguarding, legal or regulatory reasons.
21. Marketing communications
NDC may communicate information about its services, training, events, projects and activities.
Electronic direct marketing will be undertaken in accordance with UK GDPR, the Data Protection Act 2018 and PECR.
Where consent is required, NDC will obtain a clear and affirmative opt-in.
Where permitted by law, NDC may rely on another lawful mechanism, including the existing customer “soft opt-in” for marketing NDC’s own similar products or services, where every statutory requirement for that exemption has been satisfied.
As NeuroDiverse Community CIC is a Community Interest Company, NDC will not rely upon the charitable-purpose electronic marketing soft opt-in unless and until the organisation carrying out the marketing legally qualifies as a charity for the purposes of the relevant legislation.
Individuals may unsubscribe or object to direct marketing at any time.
Every electronic marketing communication to which PECR applies will provide an appropriate method of opting out.
NDC will maintain suppression records where necessary to ensure that individuals who have opted out are not inadvertently re-added to marketing lists.
22. Cookies and website technologies
Our website may use cookies and similar technologies.
Some cookies are necessary for the website to function and may be used without consent where the applicable legal requirements are satisfied.
Non-essential cookies, including certain analytics, advertising or tracking technologies, will only be used where permitted by PECR and other applicable data protection legislation.
Where consent is required, users will be given an appropriate opportunity to accept or reject non-essential cookies.
Further details should be provided in NDC’s separate Cookie Policy and cookie consent mechanism.
23. Social media
NDC uses social-media platforms to communicate with the community.
Where an individual interacts with NDC through a social-media platform, the platform provider may also process personal information independently under its own privacy terms.
Individuals should avoid posting sensitive personal or safeguarding information publicly on social media.
Where sensitive information needs to be discussed, NDC may ask the individual to move the conversation to a more secure communication channel.
24. Online payments and purchases
Where purchases or payments are made through NDC’s website, shop, booking system or another payment platform, payment information may be processed by an external payment provider.
The payment provider may act as an independent data controller for some aspects of the transaction.
NDC will retain transaction and accounting information where required for contractual, financial, audit, taxation or legal purposes.
25. Funders, commissioners and impact reporting
NDC may be required to demonstrate the reach, outcomes and impact of funded or commissioned services.
Where possible, statistical, aggregated or anonymised information will be used.
Where identifiable information must be supplied to a commissioner or funder, NDC will ensure that there is an appropriate lawful basis and that individuals receive appropriate privacy information unless an exemption applies.
Receiving a grant or funding award does not, by itself, give a funder unrestricted access to individual service-user records.
26. Research, surveys and evaluation
NDC may invite individuals to provide feedback, complete surveys or participate in service evaluation.
Where the activity involves personal information, NDC will identify an appropriate lawful basis and provide relevant privacy information.
Information used for statistical or research purposes will be anonymised wherever reasonably possible.
Participation in optional research or feedback activity will not normally affect an individual’s ability to access NDC’s core services.
27. Automated decision-making and artificial intelligence
NDC will ensure that any use of artificial intelligence or automated systems involving personal information complies with applicable data protection legislation.
NDC will not make a solely automated decision producing legal or similarly significant effects on an individual unless that processing is specifically permitted by law and appropriate safeguards are in place.
Where NDC introduces technology involving significant profiling or automated decision-making, additional privacy information and, where required, a Data Protection Impact Assessment will be completed before implementation.
Sensitive casework, safeguarding and SEND decisions will not be delegated to an automated system without appropriate human oversight.
28. Data Protection Impact Assessments
NDC will conduct a Data Protection Impact Assessment (“DPIA”) before commencing processing that is likely to result in a high risk to individuals’ rights and freedoms.
A DPIA may be particularly appropriate where NDC introduces:
- new technology;
- large-scale processing of sensitive information;
- systematic monitoring;
- innovative uses of children’s information;
- significant profiling;
- biometric technology;
- new case-management systems;
- data matching or linkage;
- large-scale information sharing; or
- other processing presenting heightened privacy risks.
29. Your data protection rights
Depending upon the circumstances and the lawful basis used, individuals may have rights including:
Right to be informed
You have the right to clear information about how your personal information is collected and used.
Right of access
You may request confirmation that NDC processes your personal information and request a copy of information we hold about you. This is commonly known as a Subject Access Request (SAR).
Subject Access Requests can be made verbally or in writing.
NDC will normally respond without undue delay and within one month, subject to the provisions of data protection law.
Where legally permitted, the response period may be extended for particularly complex or numerous requests. NDC will inform the requester where an extension applies.
NDC will undertake a reasonable and proportionate search for relevant information.
Right to rectification
You may ask us to correct personal information that is inaccurate or complete information that is incomplete.
Right to erasure
In certain circumstances, you may ask us to delete your personal information.
The right to erasure is not absolute. NDC may need to retain information where there is a legal, safeguarding, contractual or other lawful reason for doing so.
Right to restriction
In certain circumstances, you may ask us to restrict how we use your personal information.
Right to data portability
Where the statutory conditions apply, you may request that certain information you have provided to NDC is supplied in a structured, commonly used and machine-readable format or transferred to another organisation.
Right to object
You have the right to object to certain processing of your personal information.
In particular, you have an absolute right to object to the use of your personal information for direct marketing purposes.
Where processing is based on legitimate interests or certain other lawful grounds, you may also have a right to object depending upon the circumstances.
Rights relating to automated decision-making
You may have rights where a decision producing legal or similarly significant effects is made solely by automated means.
Right to withdraw consent
Where NDC relies on consent, you may withdraw that consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
30. Exercising your rights
Requests concerning personal information can be sent to:
Data Protection Lead
NeuroDiverse Community CIC
Email: info@neurodiverse-community.co.uk
You do not need to use specific legal wording for a request to be valid.
NDC may need to request reasonable information to confirm identity or authority before disclosing personal information.
Where a person makes a request on behalf of somebody else, NDC may require evidence that they have authority to act for that individual.
31. Data protection complaints
If you believe NDC has handled your personal information incorrectly or has failed to comply with data protection legislation, you have the right to make a data protection complaint directly to us.
Complaints can be made by emailing:
info@neurodiverse-community.co.uk
NDC will:
- provide an accessible means of making a data protection complaint;
- acknowledge receipt of the complaint within 30 days;
- take appropriate steps to investigate the complaint;
- make enquiries to the extent appropriate in the circumstances;
- keep the complainant appropriately informed about progress; and
- communicate the outcome without undue delay.
Data protection complaints will be handled fairly and should, where reasonably possible, be reviewed by someone with sufficient independence from the matter complained about.
Making a complaint will not adversely affect an individual’s access to NDC services.
32. Complaints to the Information Commissioner’s Office
You also have the right to raise concerns with the Information Commissioner’s Office (ICO), the UK’s independent data-protection regulator.
Information about raising a concern is available at:
The ICO can also be contacted through the contact details published on its website.
We would welcome the opportunity to consider and resolve concerns directly, but contacting NDC first does not remove your right to approach the ICO.
33. Requests from law enforcement or public authorities
NDC will not disclose personal information merely because an organisation requests it.
Requests from law-enforcement bodies, public authorities or other agencies will be considered carefully and information will only be disclosed where there is an appropriate lawful basis or legal requirement.
NDC may request further information about the purpose, legal authority, scope and necessity of a request before information is released.
34. Changes to this Privacy Policy
We may update this Privacy Policy when:
- data protection law changes;
- regulatory guidance changes;
- NDC introduces a new service or system;
- our processing activities materially change; or
- a review identifies that clarification or additional safeguards are required.
The current version will be made available through NDC’s website.
Where a change significantly affects how we use personal information, we will take reasonable steps to bring the change to the attention of affected individuals.
35. Related NDC policies and documents
This Privacy Policy should be read alongside NDC’s relevant organisational policies and procedures, including where applicable:
- Data Protection Policy;
- Data Retention and Disposal Schedule;
- Appropriate Policy Document for Special Category and Criminal Offence Data;
- Data Breach Procedure;
- Data Protection Complaints Procedure;
- Subject Access Request Procedure;
- Cookie Policy;
- Safeguarding Children Policy;
- Safeguarding Adults Policy;
- Armed Forces Safeguarding Policy;
- Confidentiality Policy;
- Information Sharing Procedure;
- Photography and Media Consent Procedure;
- IT and Information Security Policy;
- Records Management Procedure; and
- relevant employee and volunteer privacy notices.
36. Contact us
For questions, concerns, rights requests or complaints concerning personal information, please contact:
Data Protection Lead
NeuroDiverse Community CIC
Email: info@neurodiverse-community.co.uk
Address: 24 Bishops Way, Catterick, Richmond, North Yorkshire, DL10 7UA
Policy owner: NeuroDiverse Community CIC
Approved by: Board of Directors
Date approved: 20 August 2026
Version: 1.0
Next scheduled review: August 2027