Privacy Notice
Introduction
LEGS is committed to protecting your personal information and being transparent about the data we hold. We only collect personal data when there is a clear reason for doing so and will always explain why it is needed. We respect your right to privacy at all times.
If you have any questions about this notice or how we use your personal data, please contact us at info@legs.org.uk.
Who we are
LEGS, registered charity no. 1177659, is the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and responsible for how your personal information is used and safeguarded.
What information we collect and how
We may collect personal data from you in the following ways:
1. Through our website
-
You may submit your contact details to sign up for our newsletter.
-
Our website uses cookies – small text files stored on your device – to help us improve functionality, understand user behaviour, and enhance your experience.
-
We do not use cookies to collect personally identifiable information without your explicit consent.
-
Users may refuse to supply personal information; however, this may limit participation in some website features. ​
By using our website, you agree to this policy. If you do not agree, please discontinue use. Continued use after changes are posted will indicate acceptance.
2. Through assessment and screening processes
We collect and process personal data under the legal bases of legitimate interests, consent, and contractual necessity. Information we may collect includes:
-
Your name, address, contact details, date of birth, and gender
-
Marital status, next of kin, and emergency contact information
-
Payment and donation records
-
Health information provided by you or third parties (e.g. GP, referrer)
-
Outcome measures and progress within our programmes
-
Accessibility needs or disability-related information for reasonable adjustments
-
Marketing and communication preferences
-
Visual images (e.g. video recordings of assessments or sessions)
We seek explicit consent for the collection and processing of special category data (such as health information), in accordance with UK GDPR. This data is retained for eight years following your final engagement with LEGS.
In the unlikely event of a data breach, we will notify affected individuals and the Information Commissioner’s Office (ICO) within 72 hours, where required.
3. Through email or social media
Messages, emails, social media comments (e.g. Facebook, Instagram), and other correspondence may be stored and occasionally quoted in newsletters or promotional materials but only in anonymised form, unless permission has been explicitly granted.
Links to other websites
Our website may include links to other external websites. We are not responsible for the privacy policies or practices of other sites. Users are encouraged to read the privacy notice of any external website they visit.
How we use your personal information
We use your personal information to:
-
Deliver and tailor our services
-
Monitor outcomes and improve our programmes
-
Communicate updates, news, and opportunities (with your consent)
-
Process payments and donations
-
Respond to your queries or feedback
-
Comply with legal obligations
​​
We do not sell, rent, or share your data with third parties for marketing purposes.
Legal basis for processing
Under the UK GDPR, we rely on the following legal bases:
-
Consent – for marketing communications or processing sensitive data
-
Contractual necessity – to provide services you've requested
-
Legitimate interests – to improve our programmes, respond to queries, and ensure safe operations
​​
Security
We have implemented appropriate technical and organisational measures to protect your data from loss, misuse, unauthorised access, disclosure, alteration, or destruction.
Your rights
You have the right to:
-
Request access to the personal information we hold about you
-
Ask for inaccurate or incomplete data to be corrected
-
Withdraw consent at any time (where we rely on consent)
-
Object to or restrict how your data is processed
-
Request that your data be deleted in certain circumstances
-
Lodge a complaint with the Information Commissioner’s Office (ICO): www.ico.org.uk
To exercise any of these rights, please contact info@legs.org.uk.
You may unsubscribe from any marketing communications at any time by contacting us or clicking the ‘unsubscribe’ link in our emails.
Changes to this notice
We regularly review this privacy notice to ensure it remains accurate and up to date. Updates will be published on our website: www.legs.org.uk
​
