Effective from 10th September 2026. Last updated 11th March 2024. See “Changes to this notice” at the end for what has changed.

Responsible data practice is at the heart of what we do at Open Data Manchester, and that includes how we look after your data. This notice explains what personal data we collect, why we collect it, how long we keep it and what your rights are under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025.

The short version


  • We collect the information we need to run our events, projects and newsletter, and we try to collect as little as possible.

  • We never sell your data or use it for advertising.

  • Some of our project work involves sensitive information, such as health or lived experience. We will always explain this at the start, and we only collect it with your explicit agreement or where the law specifically allows it.

  • When we analyse research data we remove names first. What we publish or share with funders is anonymised or aggregated so that you can’t be identified.

  • You can ask to see, correct or delete your data, and you can withdraw your consent at any time.

  • If you’re unhappy with how we’ve handled your data, tell us and we’ll put it right if we can. You can also complain to the Information Commissioner’s Office (ICO).

  • Get in touch at office@opendatamanchester.org.uk

Who we are


Open Data Manchester CIC is a community interest company registered in England and Wales, company number 10906273. Our registered office is 52 Kensington Road, Manchester, M21 9NU. Our head office address for correspondence is Holyoake House, Manchester, M60 0AS.

We are the “controller” for the personal data described in this notice, which means we decide how and why it is used. We are not required to appoint a Data Protection Officer, but our Chief Executive has overall responsibility for data protection at Open Data Manchester.

When this notice applies


This notice covers personal data we collect when you:

  • use our website or contact us

  • sign up to our newsletter or one of our mailing lists

  • come to one of our events or workshops, in person or online

  • take part in one of our projects or research activities

Projects we run for other organisations

A lot of our project work is done with or for other organisations, such as local councils, universities and research bodies. Sometimes we are working on their behalf, in which case they are the controller and we are their “processor”. Sometimes we decide jointly how data is used. When that happens, we will give you a project information sheet before you take part, explaining who is responsible for your data, what will be collected and how it will be used. For that project, the information sheet takes priority over this notice where the two differ.

What we collect


What we collect depends on how you interact with us.

If you use our website or contact us

  • Your name, email address and anything you include in your message

  • Technical information such as your IP address and browser type, which our web host records in server logs [confirm with host, and how long logs are kept]

  • Information from cookies (see “Cookies” below)

If you sign up to our newsletter or a mailing list

  • Your name and email address, and organisation and area you are based if given.

  • A record of when and how you gave consent

If you book or attend an event or workshop

  • Your name, email address, and your organisation, area you are based and job role if you give them

  • Any accessibility or dietary requirements you tell us about

  • For online events, your display name and anything you say or share in the chat. If we record a session, we will tell you before recording starts.

If you take part in a project or research activity

  • Your name and contact details, and your organisation and job role where relevant

  • An emergency contact, where this is needed for in-person activities. Please check they are happy for you to share their details with us.

  • Any accessibility, dietary or health needs you tell us about

  • What you tell us about your experiences, which may include lived experience and information about your physical or mental health

  • Photos, audio and video recordings, and transcripts

  • Equality monitoring information, if you choose to give it. This is always optional.

Some of this is “special category” data, which the law gives extra protection. Health information obviously is, but so are dietary needs that reveal a religious or philosophical belief, and accessibility needs that reveal a health condition or disability. We treat all of it with extra care (see “Sensitive information” below).

Almost everything we hold comes directly from you. If a partner organisation passes us your contact details so that we can invite you to take part in a project, the project information sheet will say so.

We only ask for what we need. If we ask for something you’d rather not give, just tell us. Most of it is optional, and where it isn’t we will explain why.

How we use your information, why we’re allowed to, and how long we keep it


The law requires us to have a lawful basis for each thing we do with your data. The table below sets out what we do, the basis we rely on and how long we keep the information.

What we do

Information used

Lawful basis

How long we keep it

Reply to your enquiries

Your contact details and message

Legitimate interests (responding to people who get in touch)

2 years after we were last in contact

Send our newsletter

Name, email address, consent record

Consent

Until you unsubscribe. We then keep your email address on a suppression list so we don’t contact you again by mistake.

Send updates for the communities we support: LCR Data Community of Practice, Data Cooperative Working Group and [Design Justice North]

Name, email address, organisation and area you based – if given, and consent record

Consent

Until you unsubscribe, with a suppression list as above

Organise events and workshops: bookings, reminders and joining details

Name, contact details, organisation and role

Legitimate interests (running events people have signed up for)

[6 months] after the event

Meet accessibility or dietary needs

The needs you tell us about

Explicit consent

Deleted 6 months after the event or project

Record online sessions for note taking

Display name, video, audio, chat

Legitimate interests. We will always tell you before recording starts, and you can keep your camera and microphone off.

Deleted 6 months after the event or project

Record online sessions for public distribution

Display name, video, audio, chat

Legitimate interests. We will always tell you before recording starts, and you can keep your camera and microphone off.

In perpetuity

Run the projects and workshops you take part in

Contact details, emergency contact, what you contribute

Legitimate interests (delivering projects people have signed up to)

2 years after the project ends

Research and analysis

Pseudonymised contributions, which may include lived experience and health information

Legitimate interests. For sensitive information, explicit consent or the research condition (see below).

Pseudonymised data: 2 years after the project ends. Anonymised findings may be published and kept indefinitely.

Equality monitoring

Equality information you choose to give

Legitimate interests. For sensitive information, substantial public interest (equality of opportunity or treatment).

Individual responses deleted 6 months after the project ends. Only aggregated figures are kept.

Keep people safe

Emergency contacts, relevant health or access information

Legitimate interests, including safeguarding. Vital interests in an emergency.

As for the event or project, unless an incident means we need to keep a record for longer

Improve our workshops and training

Feedback, collected anonymously wherever possible

Legitimate interests

12 months

Report to our funders

Anonymised or aggregated information only

No personal data is shared. If a funder requires attendance records for audit, we will tell you when you sign up.

As required by the funding agreement

Promote our work on our website, on social media and in reports

Photos, video, quotes

Consent

Until you ask us to remove it. We can remove what we have published, but we can’t recall copies others have already shared.

Meet our legal obligations, including requests from the police or other authorities

Only what is required

Legal obligation

As long as the law requires

Where we rely on legitimate interests, we have weighed our interests against yours, and you have the right to object.

Sensitive information


We only collect special category information where we need it, and we will always explain why at the time. We rely on:

  • Your explicit consent (Article 9(2)(a) UK GDPR). This covers accessibility, dietary and health needs, and most project work involving lived experience or health. You can withdraw your consent at any time.

  • Archiving, research and statistics (Article 9(2)(j), with the research condition in Schedule 1, Part 1, paragraph 4 of the Data Protection Act 2018). We use this for some research projects, where the research is in the public interest and we have safeguards such as pseudonymisation in place. The project information sheet will say if we are relying on it.

  • Substantial public interest (Article 9(2)(g), with the equality of opportunity or treatment condition in Schedule 1, Part 2, paragraph 8 of the Data Protection Act 2018). We use this for equality monitoring.

  • Vital interests (Article 9(2)(c)). We use this only in an emergency, where someone’s life or health is at risk and they can’t give consent.

Where we rely on the equality of opportunity condition, we have an appropriate policy document explaining how we protect this information. You can ask to see it.

Pseudonymised and anonymised data  


When we analyse what people tell us in projects, we first replace names and other obvious identifiers with codes. This is called pseudonymisation. Pseudonymised data is still personal data, and we protect it in the same way. The key that links codes to names is kept separately, and only the project team can access it.

What we publish, and what we share with funders and partners, is anonymised or aggregated so that individuals can’t be identified. We take particular care with small numbers and with quotes, where the detail of what someone says could reveal who they are. We will check with you before using a quote that could identify you.

AI and automated decision-making


We don’t make decisions about you based solely on automated processing.

We transcribe recordings using noScribe, free, open-source software that runs entirely on our own computers. Recordings aren’t uploaded to a transcription service, and they aren’t used to train anyone’s AI models. noScribe separates out different speakers in a recording, but it doesn’t match voices to named people. A member of our team checks every transcript for accuracy and removes identifying details, and we delete the audio once that’s done.

We don’t use AI notetakers such as Otter.ai. [If someone else’s AI notetaker joins one of our online sessions, we will remove it.]

Some of the other services we use have built-in AI features. We keep these switched off where they would process research data. If we use any other AI tools on personal data, we will say so in the project information sheet.

The services we use and who we share with


We use a small number of services to run our work. They act only on our instructions under contract and can’t use your data for their own purposes.

Service

What we use it for

Where data is held

How transfers outside the UK are protected

Ticket Tailor

Event bookings

UK and EEA

Data transferred to EAA under UK data adequacy

Sender.net

Newsletter and mailing lists

EEA

See Sender.net GDPR compliance

Typeform

Sign-up forms and surveys

US

UK Extension to the EU–US Data Privacy Framework

Zoho

Our workspace: email, documents, spreadsheets and file storage, including interview notes, transcripts and reports and contact records.

EEA

Data transferred to EAA under UK data adequacy

Miro

Online whiteboards, including mapping pseudonymised interview data [and workshop activities]

Board content: European Union (Ireland, with backup in Germany)

Data transferred to EAA under UK data adequacy

Whereby

Most of our online events

EEA

Data transferred to EAA under UK data adequacy

Vimeo

Publishing videos of public workshops

United States

UK Extension to the EU–US Data Privacy Framework

Zoom

Liverpool City Region Data Community of Practice events and some online events a

United States

UK Extension to the EU–US Data Privacy Framework

WebArchitects Co-operative

Our website

United Kingdom 

Not applicable

We sometimes use paper forms at in-person events. These are kept securely, typed up where needed and securely destroyed within 6 months.

We also share personal data:

  • with partner organisations on joint projects, as explained in the project information sheet

  • with the police or other authorities where the law requires it

We never sell your data.

Transfers outside the UK


Some of the services we use store or process data outside the UK. Zoom, Typeform and Vimeo, for example, process data in the United States. Where this happens, we make sure your data is protected by one of the safeguards UK law provides:

The table above shows which applies to each service. If you’d like more detail, just ask.

Children and young people


Our events and projects are generally for adults. If a project involves children or young people, we will provide an information sheet written for them and ask a parent or carer for consent where appropriate.

Cookies


If you visit the Open Data Manchester website:

  • As a visitor no cookies are stored
  • If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Keeping your information secure


We have appropriate technical and organisational measures in place to stop personal information being lost, or being used or accessed without authorisation. Only people who need your information to do their work can access it, and they are bound by a duty of confidentiality.

We have a procedure for dealing with data breaches. We will report breaches to the ICO where the law requires it, and if a breach is likely to put you at high risk, we will tell you directly.

Your rights


Under UK GDPR you have the right to:

  • be told how we use your information, which is what this notice is for

  • see the information we hold about you (a “subject access request”)

  • have mistakes corrected

  • have your information deleted

  • restrict how we use your information

  • object to how we use it, including for direct marketing and wherever we rely on legitimate interests

  • have information you have given us transferred to you or to another organisation

  • withdraw your consent at any time, where we rely on consent

  • not be subject to decisions made solely by automated means that significantly affect you

Some of these rights depend on the lawful basis we are relying on. In limited circumstances the law allows or requires us to keep using your information, and if that applies we will explain why.

Exercising your rights is free. We will respond within one month. If your request is complex, we can extend this by up to two further months, and we will tell you if we need to. We may need to confirm your identity or ask you to clarify your request, and the time limit is paused while we wait. We will carry out reasonable and proportionate searches for your information.

To make a request, email office@opendatamanchester.org.uk or write to us at the address below. You don’t need to use any particular form of words.

The ICO has practical information for the public about your rights and when they apply.

Withdrawing your consent


Where we rely on your consent, you can withdraw it at any time. Use the unsubscribe link in any email from us, or email office@opendatamanchester.org.uk. Withdrawing consent doesn’t affect anything we did before you withdrew it.

Complaints


If you’re unhappy with how we have handled your information, please tell us first. You can complain by email to office@opendatamanchester.org.uk, by post to the address below, or in whatever way suits you, and we will treat it as a complaint.

We will:

  • acknowledge your complaint within 30 days

  • look into it properly

  • tell you the outcome without undue delay

If you’re not satisfied with how we have dealt with your complaint, you can complain to the Information Commissioner’s Office. The ICO will usually expect you to have raised it with us first.

Contact us


Changes to this notice


We review this notice at least once a year, and whenever we change how we use personal data.

Date

What changed

[date]

Rewritten in plainer language. Added a summary; a table setting out the lawful basis and retention period for each use; sections on sensitive information, pseudonymisation, sessions on other organisations’ platforms, AI and transcription, transfers outside the UK, children and young people, and complaints; and a list of the services we use, including Zoho, Miro and Vimeo. Corrected the legal conditions for sensitive information. Stopped using Otter.ai for transcription [and deleted the recordings and transcripts held there]; transcription now takes place on our own computers using noScribe.

10 September 2026

Previous version

This notice is published under a Creative Commons Attribution-ShareAlike 4.0 licence. You’re welcome to adapt it for your own organisation, but make sure it reflects what you actually do.

Contact


To exercise any of your rights, or if you have a complaint about why your information has been collected, how it has been used or how long we have kept it for, please contact office@opendatamanchester.org.uk or write to: Chief Executive at Open Data Manchester CIC , Holyoake House, Manchester M60 0AS.

UK GDPR also gives you right to lodge a complaint with the Information Commissioner who may be contacted via the Information Commissioner’s website or call 03031 231113.

This document was last updated: 10th September 2026.

Newsletter signup

Enter your email address to sign up to the latest news from Open Data Manchester