Employee Privacy Policy
- Who we are and what we do?
- Where does Tommy’s collect your personal data from?
- What personal data does Tommy’s collect?
- How do we use your personal data?
- Who do we share your personal data with?
- Automated decision-making
- Storing your personal data outside the EEA
- Your rights
- Queries
At Tommy’s we are committed to protecting your personal data and helping you understand what we are doing with it. We will use your personal data in compliance with all data protection laws, keeping it safe and in ways you would reasonably expect.
This Employee Privacy Policy explains what personal information we hold in connection with your employment, how we may use it and what your rights are.
Tommy’s collects and processes personal data relating its employees to manage the employment relationship. Tommy’s seeks to be transparent about how it collects and uses that data and meets its data protection obligations.
1. Who are we and what do we do?
Tommy's exists to save babies' lives. We fund research into the causes and prevention of pregnancy complications that lead to miscarriage, stillbirth and premature birth. We also provide pregnancy health information for parents-to-be.
Tommy’s is registered as a charity in England and Wales (registered charity number 1060508), and in Scotland (registered charity number SC039280). We are also registered as a company limited by guarantee (company number 3266897).
There are two wholly owned subsidiary companies of Tommy’s.
- The Baby Fund Trading Limited (registered company in England and Wales number 2557706), to record our activity classed as trading including the selling of sponsorship rights, and
- LLHM Limited (registered company in England and Wales number 10584979), to manage our event-driven activity, specifically the London Landmarks Half-Marathon.
Within the context of this policy, ‘we’ means the charity Tommy’s, and The Baby Fund Trading Limited. LLHM Limited has its own Privacy Policy.
We are located at:
Nicholas House,
3 Laurence Pountney Hill,
London EC4R 0BB
Telephone: 0207 398 3400
Email: [email protected]
2. Where does Tommy’s collect your personal data from?
Tommy’s collects your personal data from the following places:
- When you give it to us
This is the main way that we collect personal data about you. You may give us information when you apply to work for us:- From your application forms or CVs
- From your passport or other identity documents such as your driving licence
- From forms completed by you at the start of or during your employment (such as forms completed during your HR induction)
- From correspondence with you
- From interviews, meetings or other assessments
- When you give permission to other organisations to provide Tommy’s with your personal data
We may receive personal data about you from third parties, such as references supplied by former employers, psychometric assessments and information from criminal records checks permitted by law.
These organisations will only provide us with your personal data if you have given your consent to do so.
3. What personal data does Tommy’s collect?
Personal data is information that can be used to identify you.
Tommy’s collects and stores the following personal data:
- your name, address and contact details, including your personal email address and telephone number, your date of birth and gender;
- the terms and conditions of your employment;
- details of your qualifications, skills, experience and employment history, including start and end dates, with previous employers and with Tommy’s;
- information about your remuneration, including entitlement to benefits such as pension;
- details of your bank account and national insurance number;
- information about your marital status, next of kin, dependants and emergency contacts;
- information about your nationality and entitlement to work in the UK;
- information about any criminal record you may have (if your role with Tommy’s requires you to have a Disclosure and Barring Service check);
- psychometric assessments during Tommy’s recruitment processes and when looking at people’s roles and behaviours in their team;
- details of your schedule (days of work and working hours) and attendance at work;
- details of periods of leave taken by you, including holiday, sickness absence, family leave and Sabbaticals, and the reasons for the leave;
- details of any disciplinary, sickness absence or grievance procedures in which you have been involved, including any warnings issued to you and related correspondence;
- assessments of your performance, including appraisals, performance reviews and ratings, performance improvement plans and related correspondence;
- information about medical or health conditions, including whether or not you may have a disability for which Tommy’s needs to make reasonable adjustments; and
- equal opportunities monitoring information including information about your age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, sexual orientation or any other protected grounds.
4. How do we use your personal data?
If you work for Tommy’s or have worked for Tommy’s in the past the details below set out what we are doing with your personal data, our lawful basis for processing your data, our legitimate interest (if we are relying on this).
We will only keep your information for as long as we need it.
What are we doing? |
Our lawful basis for processing your personal data |
Our legitimate interest, if this is our lawful basis for processing your data |
The maximum time we will hold this data |
Recruiting staff to join Tommy’s and to provide you with an employment contract and to establish that you have the right to work in the UK |
Fulfilling contracts Legal Obligations |
6 years following the end of your employment |
|
Performing psychometric assessments |
Our legitimate interest |
To recruit the right people to the right roles and to review people’s roles and behaviours in their teams |
6 months after the assessment if you do not join Tommy’s 6 years following the end of your employment |
Managing your employment by making such we provide you with the correct benefits and appropriate deductions |
Legal obligation |
6 years following the end of your employment |
|
Managing your performance in your employment with Tommy’s |
Our legitimate interest |
To enhance your and Tommy’s accuracy and efficiency |
1 year after the last day of your employment |
Processing any special category health, disability or criminal records data about you |
Legal obligation |
6 years following the end of your employment |
|
Processing reference requests for new/ex-employees |
Your consent |
6 years following the end of your employment |
|
To discharge a duty of care to employees by maintaining records (eg emergency records, absence and medical records) |
Our legitimate interest |
To take care our employees and their wellbeing. In an emergency to make sure that a next of kin can be informed. To manage absence to help the employee and their team. |
6 years following the end of your employment |
To defend against potential legal claims |
Legal obligation |
6 years following the end of your employment |
|
To provide a potential buyer of Tommy’s with appropriate staff information |
Fulfilling contracts |
6 years following the end of your employment |
|
Annual review of staff salaries and benefits |
Fulfilling contracts |
6 years following the end of your employment |
|
Paying staff salaries and processing deductions correctly |
Fulfilling contracts Legal obligation |
7 years after the financial yearend |
|
Processing staff pension contributions |
Fulfilling contracts |
100 years from joining the pension scheme |
|
Processing staff expenses |
Fulfilling contracts |
7 years after last interaction |
|
Processing childcare vouchers for staff |
Your consent |
7 years after last interaction |
|
Storing photographs of staff |
Our legitimate interest |
To ensure that only authorised people have access to our building |
7 years after last interaction |
Provision of IT support to staff both remotely and onsite |
Fulfilling contracts |
7 years after last interaction |
|
Systems administrator of all networks with access to all data |
Fulfilling contracts |
7 years after last interaction |
5. Who do we share your personal data with?
At Tommy’s we will only share your data when we have a need to do so. We will never sell your information to a third party for marketing purposes. We ensure that all organisations that are processing your personal data on our behalf have the highest standards of security and will not use your personal data for anything other than our agreed purposes that we have set out in this policy.
We will share your information with third parties in the following circumstances:
When we share your personal data |
The organisations we may share your personal data with |
Why we share your personal data |
If you apply for a role with us |
A specialist firm that provides software that performs psychometric assessments |
To strengthen our recruitment and people development process and ensure that the right people are matched to the right roles |
If you are sick for a long period of time |
Occupational health services |
To provide you with appropriate support when you are sick |
If Tommy’s is in sale negotiations |
Potential buyers of Tommy’s |
To ensure that any potential buyer of Tommy’s understands the extent of their potential liabilities to staff |
To maintain absence and staff records |
The specialist firm that provides an online absence and staff information system |
To ensure that we hold the right information about you and to facilitate absence management |
In providing human resources services to you and to Tommy’s |
Specialist firms that provide HR services |
To enhance our HR services capability |
When we defend potential legal claims made against us |
Specialist law firms |
To ensure that we meet our legal obligations |
When we pay your salary |
Payroll Software firm HMRC |
To ensure that you are paid and that the right amount of statutory deductions is made from your salary |
When we process your pension contributions |
Pension administrators |
To ensure that the right amount of pension contributions is made to your pension fund |
When we pay your staff expenses |
Our bank |
To ensure that you are repaid all staff expenses that are due to you |
If you have childcare vouchers that need to be processed |
Childcare voucher providers |
To ensure that childcare vouchers are processed accurately |
If you need IT support |
The specialist firm that provides IT support to staff |
To ensure that you can perform your role and have the IT support you need |
When you use any IT systems in the course of your work |
The specialist firm that is the system administrator of all networks with access to all systems |
To ensure that you can perform your role and have the IT support you need |
6. Automated decision-making
Tommy’s does not carry out profiling or take significant decisions about individuals by wholly automated means.
7. Storing your information outside the EEA
Your personal data is not stored outside the EEA.
8. Your rights
You have the following rights:
- The right to be informed of how your personal data is used – we do this in the Privacy Policy and providing links to this Privacy Policy when we are collecting personal data from you.
- The right to access your personal data – you can submit a request to find out about the information we hold about you.
- The right to object to the processing of your personal data – if we are processing your personal data under the legitimate interest lawful basis.
- The right to have your personal data rectified – you can request that we correct your personal data if it is incorrect or incomplete.
- The right of portability of your personal data – you can request that some of your personal data is transferred to yourself or to another organisation
- The right to be forgotten – you can request that we delete your personal data.
- The right to have your personal data restricted – you can request that we stop processing your personal data and only store it.
- The right to object to direct marketing – you can object to direct marketing at any point and we will not send you any further marketing communications unless you change your mind.
- The right to request that any automated decisions are reviewed by a human
- The right to withdraw consent – if we are relying on your consent as our lawful basis for processing your personal data, you can withdraw your consent for processing at any time.
- The right to complain about our processing of your personal data – please contact [email protected] so that we can help you. If you wish you can contact the Information Commissioner’s Office on 0303 123 1113 or via their website.
9. Queries
If you have any questions or queries about this Privacy Policy, or if you would like to exercise any of your rights, please contact the Data Controller at the address and contact details below:
- In writing: Data Protection Officer, Tommy’s, Nicholas House, 3 Laurence Pountney Hill, London, EC4R 0BB
- Tel: 0207 398 3400
- Email: [email protected]
Data Protection Officer:
Siân Dawson
Interim Chief Operating Officer
This Privacy Policy was last updated in October 2021.