Effective from 10th September 2026. Last updated 11th March 2024. See “Changes to this notice” at the end for what has changed.
Responsible data practice is at the heart of what we do at Open Data Manchester, and that includes how we look after your data. This notice explains what personal data we collect, why we collect it, how long we keep it and what your rights are under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025.
The short version
-
We collect the information we need to run our events, projects and newsletter, and we try to collect as little as possible.
-
We never sell your data or use it for advertising.
-
Some of our project work involves sensitive information, such as health or lived experience. We will always explain this at the start, and we only collect it with your explicit agreement or where the law specifically allows it.
-
When we analyse research data we remove names first. What we publish or share with funders is anonymised or aggregated so that you can’t be identified.
-
You can ask to see, correct or delete your data, and you can withdraw your consent at any time.
-
If you’re unhappy with how we’ve handled your data, tell us and we’ll put it right if we can. You can also complain to the Information Commissioner’s Office (ICO).
-
Get in touch at office@opendatamanchester.org.uk
Who we are
Open Data Manchester CIC is a community interest company registered in England and Wales, company number 10906273. Our registered office is 52 Kensington Road, Manchester, M21 9NU. Our head office address for correspondence is Holyoake House, Manchester, M60 0AS.
We are the “controller” for the personal data described in this notice, which means we decide how and why it is used. We are not required to appoint a Data Protection Officer, but our Chief Executive has overall responsibility for data protection at Open Data Manchester.
When this notice applies
This notice covers personal data we collect when you:
-
use our website or contact us
-
sign up to our newsletter or one of our mailing lists
-
come to one of our events or workshops, in person or online
-
take part in one of our projects or research activities
Projects we run for other organisations
A lot of our project work is done with or for other organisations, such as local councils, universities and research bodies. Sometimes we are working on their behalf, in which case they are the controller and we are their “processor”. Sometimes we decide jointly how data is used. When that happens, we will give you a project information sheet before you take part, explaining who is responsible for your data, what will be collected and how it will be used. For that project, the information sheet takes priority over this notice where the two differ.
What we collect
What we collect depends on how you interact with us.
If you use our website or contact us
-
Your name, email address and anything you include in your message
-
Technical information such as your IP address and browser type, which our web host records in server logs [confirm with host, and how long logs are kept]
-
Information from cookies (see “Cookies” below)
If you sign up to our newsletter or a mailing list
-
Your name and email address, and organisation and area you are based if given.
-
A record of when and how you gave consent
If you book or attend an event or workshop
-
Your name, email address, and your organisation, area you are based and job role if you give them
-
Any accessibility or dietary requirements you tell us about
-
For online events, your display name and anything you say or share in the chat. If we record a session, we will tell you before recording starts.
If you take part in a project or research activity
-
Your name and contact details, and your organisation and job role where relevant
-
An emergency contact, where this is needed for in-person activities. Please check they are happy for you to share their details with us.
-
Any accessibility, dietary or health needs you tell us about
-
What you tell us about your experiences, which may include lived experience and information about your physical or mental health
-
Photos, audio and video recordings, and transcripts
-
Equality monitoring information, if you choose to give it. This is always optional.
Some of this is “special category” data, which the law gives extra protection. Health information obviously is, but so are dietary needs that reveal a religious or philosophical belief, and accessibility needs that reveal a health condition or disability. We treat all of it with extra care (see “Sensitive information” below).
Almost everything we hold comes directly from you. If a partner organisation passes us your contact details so that we can invite you to take part in a project, the project information sheet will say so.
We only ask for what we need. If we ask for something you’d rather not give, just tell us. Most of it is optional, and where it isn’t we will explain why.
How we use your information, why we’re allowed to, and how long we keep it
The law requires us to have a lawful basis for each thing we do with your data. The table below sets out what we do, the basis we rely on and how long we keep the information.
|
What we do |
Information used |
Lawful basis |
How long we keep it |
|
Reply to your enquiries |
Your contact details and message |
Legitimate interests (responding to people who get in touch) |
2 years after we were last in contact |
|
Send our newsletter |
Name, email address, consent record |
Consent |
Until you unsubscribe. We then keep your email address on a suppression list so we don’t contact you again by mistake. |
|
Send updates for the communities we support: LCR Data Community of Practice, Data Cooperative Working Group and [Design Justice North] |
Name, email address, organisation and area you based – if given, and consent record |
Consent |
Until you unsubscribe, with a suppression list as above |
|
Organise events and workshops: bookings, reminders and joining details |
Name, contact details, organisation and role |
Legitimate interests (running events people have signed up for) |
[6 months] after the event |
|
Meet accessibility or dietary needs |
The needs you tell us about |
Explicit consent |
Deleted 6 months after the event or project |
|
Record online sessions for note taking |
Display name, video, audio, chat |
Legitimate interests. We will always tell you before recording starts, and you can keep your camera and microphone off. |
Deleted 6 months after the event or project |
|
Record online sessions for public distribution |
Display name, video, audio, chat |
Legitimate interests. We will always tell you before recording starts, and you can keep your camera and microphone off. |
In perpetuity |
|
Run the projects and workshops you take part in |
Contact details, emergency contact, what you contribute |
Legitimate interests (delivering projects people have signed up to) |
2 years after the project ends |
|
Research and analysis |
Pseudonymised contributions, which may include lived experience and health information |
Legitimate interests. For sensitive information, explicit consent or the research condition (see below). |
Pseudonymised data: 2 years after the project ends. Anonymised findings may be published and kept indefinitely. |
|
Equality monitoring |
Equality information you choose to give |
Legitimate interests. For sensitive information, substantial public interest (equality of opportunity or treatment). |
Individual responses deleted 6 months after the project ends. Only aggregated figures are kept. |
|
Keep people safe |
Emergency contacts, relevant health or access information |
Legitimate interests, including safeguarding. Vital interests in an emergency. |
As for the event or project, unless an incident means we need to keep a record for longer |
|
Improve our workshops and training |
Feedback, collected anonymously wherever possible |
Legitimate interests |
12 months |
|
Report to our funders |
Anonymised or aggregated information only |
No personal data is shared. If a funder requires attendance records for audit, we will tell you when you sign up. |
As required by the funding agreement |
|
Promote our work on our website, on social media and in reports |
Photos, video, quotes |
Consent |
Until you ask us to remove it. We can remove what we have published, but we can’t recall copies others have already shared. |
|
Meet our legal obligations, including requests from the police or other authorities |
Only what is required |
Legal obligation |
As long as the law requires |
Where we rely on legitimate interests, we have weighed our interests against yours, and you have the right to object.
Sensitive information
We only collect special category information where we need it, and we will always explain why at the time. We rely on:
-
Your explicit consent (Article 9(2)(a) UK GDPR). This covers accessibility, dietary and health needs, and most project work involving lived experience or health. You can withdraw your consent at any time.
-
Archiving, research and statistics (Article 9(2)(j), with the research condition in Schedule 1, Part 1, paragraph 4 of the Data Protection Act 2018). We use this for some research projects, where the research is in the public interest and we have safeguards such as pseudonymisation in place. The project information sheet will say if we are relying on it.
-
Substantial public interest (Article 9(2)(g), with the equality of opportunity or treatment condition in Schedule 1, Part 2, paragraph 8 of the Data Protection Act 2018). We use this for equality monitoring.
-
Vital interests (Article 9(2)(c)). We use this only in an emergency, where someone’s life or health is at risk and they can’t give consent.
Where we rely on the equality of opportunity condition, we have an appropriate policy document explaining how we protect this information. You can ask to see it.
Pseudonymised and anonymised data
When we analyse what people tell us in projects, we first replace names and other obvious identifiers with codes. This is called pseudonymisation. Pseudonymised data is still personal data, and we protect it in the same way. The key that links codes to names is kept separately, and only the project team can access it.
What we publish, and what we share with funders and partners, is anonymised or aggregated so that individuals can’t be identified. We take particular care with small numbers and with quotes, where the detail of what someone says could reveal who they are. We will check with you before using a quote that could identify you.
AI and automated decision-making
We don’t make decisions about you based solely on automated processing.
We transcribe recordings using noScribe, free, open-source software that runs entirely on our own computers. Recordings aren’t uploaded to a transcription service, and they aren’t used to train anyone’s AI models. noScribe separates out different speakers in a recording, but it doesn’t match voices to named people. A member of our team checks every transcript for accuracy and removes identifying details, and we delete the audio once that’s done.
We don’t use AI notetakers such as Otter.ai. [If someone else’s AI notetaker joins one of our online sessions, we will remove it.]
Some of the other services we use have built-in AI features. We keep these switched off where they would process research data. If we use any other AI tools on personal data, we will say so in the project information sheet.
The services we use and who we share with
We use a small number of services to run our work. They act only on our instructions under contract and can’t use your data for their own purposes.
|
Service |
What we use it for |
Where data is held |
How transfers outside the UK are protected |
|
Event bookings |
UK and EEA |
Data transferred to EAA under UK data adequacy |
|
|
Newsletter and mailing lists |
EEA |
See Sender.net GDPR compliance |
|
|
Sign-up forms and surveys |
US |
||
|
Our workspace: email, documents, spreadsheets and file storage, including interview notes, transcripts and reports and contact records. |
EEA |
Data transferred to EAA under UK data adequacy |
|
|
Online whiteboards, including mapping pseudonymised interview data [and workshop activities] |
Board content: European Union (Ireland, with backup in Germany) |
Data transferred to EAA under UK data adequacy |
|
|
Most of our online events |
EEA |
Data transferred to EAA under UK data adequacy |
|
|
Publishing videos of public workshops |
United States |
||
|
Liverpool City Region Data Community of Practice events and some online events a |
United States |
||
|
Our website |
United Kingdom |
Not applicable |
We sometimes use paper forms at in-person events. These are kept securely, typed up where needed and securely destroyed within 6 months.
We also share personal data:
-
with partner organisations on joint projects, as explained in the project information sheet
-
with the police or other authorities where the law requires it
We never sell your data.
Transfers outside the UK
Some of the services we use store or process data outside the UK. Zoom, Typeform and Vimeo, for example, process data in the United States. Where this happens, we make sure your data is protected by one of the safeguards UK law provides:
-
the destination country is covered by UK adequacy regulations
-
the provider is certified under the UK Extension to the EU–US Data Privacy Framework
-
the transfer is covered by the ICO’s International Data Transfer Agreement or Addendum
The table above shows which applies to each service. If you’d like more detail, just ask.
Children and young people
Our events and projects are generally for adults. If a project involves children or young people, we will provide an information sheet written for them and ask a parent or carer for consent where appropriate.
Cookies
If you visit the Open Data Manchester website:
- As a visitor no cookies are stored
- If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Keeping your information secure
We have appropriate technical and organisational measures in place to stop personal information being lost, or being used or accessed without authorisation. Only people who need your information to do their work can access it, and they are bound by a duty of confidentiality.
We have a procedure for dealing with data breaches. We will report breaches to the ICO where the law requires it, and if a breach is likely to put you at high risk, we will tell you directly.
Your rights
Under UK GDPR you have the right to:
-
be told how we use your information, which is what this notice is for
-
see the information we hold about you (a “subject access request”)
-
have mistakes corrected
-
have your information deleted
-
restrict how we use your information
-
object to how we use it, including for direct marketing and wherever we rely on legitimate interests
-
have information you have given us transferred to you or to another organisation
-
withdraw your consent at any time, where we rely on consent
-
not be subject to decisions made solely by automated means that significantly affect you
Some of these rights depend on the lawful basis we are relying on. In limited circumstances the law allows or requires us to keep using your information, and if that applies we will explain why.
Exercising your rights is free. We will respond within one month. If your request is complex, we can extend this by up to two further months, and we will tell you if we need to. We may need to confirm your identity or ask you to clarify your request, and the time limit is paused while we wait. We will carry out reasonable and proportionate searches for your information.
To make a request, email office@opendatamanchester.org.uk or write to us at the address below. You don’t need to use any particular form of words.
The ICO has practical information for the public about your rights and when they apply.
Withdrawing your consent
Where we rely on your consent, you can withdraw it at any time. Use the unsubscribe link in any email from us, or email office@opendatamanchester.org.uk. Withdrawing consent doesn’t affect anything we did before you withdrew it.
Complaints
If you’re unhappy with how we have handled your information, please tell us first. You can complain by email to office@opendatamanchester.org.uk, by post to the address below, or in whatever way suits you, and we will treat it as a complaint.
We will:
-
acknowledge your complaint within 30 days
-
look into it properly
-
tell you the outcome without undue delay
If you’re not satisfied with how we have dealt with your complaint, you can complain to the Information Commissioner’s Office. The ICO will usually expect you to have raised it with us first.
-
Website: ico.org.uk/make-a-complaint
-
Helpline: 0303 123 1113
Contact us
-
Post: Chief Executive, Open Data Manchester CIC, [Holyoake House, Hanover Street, Manchester, M60 0AS]
-
Web: contact form
Changes to this notice
We review this notice at least once a year, and whenever we change how we use personal data.
|
Date |
What changed |
| [date] |
Rewritten in plainer language. Added a summary; a table setting out the lawful basis and retention period for each use; sections on sensitive information, pseudonymisation, sessions on other organisations’ platforms, AI and transcription, transfers outside the UK, children and young people, and complaints; and a list of the services we use, including Zoho, Miro and Vimeo. Corrected the legal conditions for sensitive information. Stopped using Otter.ai for transcription [and deleted the recordings and transcripts held there]; transcription now takes place on our own computers using noScribe. |
|
10 September 2026 |
Previous version |
This notice is published under a Creative Commons Attribution-ShareAlike 4.0 licence. You’re welcome to adapt it for your own organisation, but make sure it reflects what you actually do.
Contact
To exercise any of your rights, or if you have a complaint about why your information has been collected, how it has been used or how long we have kept it for, please contact office@opendatamanchester.org.uk or write to: Chief Executive at Open Data Manchester CIC , Holyoake House, Manchester M60 0AS.
UK GDPR also gives you right to lodge a complaint with the Information Commissioner who may be contacted via the Information Commissioner’s website or call 03031 231113.
This document was last updated: 10th September 2026.
