This website is operated by Muirhouse Housing Association. We, Muirhouse HA, take your privacy seriously and we ask that you read this policy carefully, as it contains important information on:
- The personal information we collect about you when you access our website;
- what we do with that personal information; and
- who that personal information might be shared with.
We are the controller of the personal information that we collect from you on our website, which means that we are legally responsible for how we collect, hold and use your personal information. It also means that we are required to comply with data protection laws when collecting, holding and using your personal information.
We have appointed a Data Protection Officer (DPO), Daradjeet Jagpal, who ensures that we comply with data protection laws. If you have any questions about this policy or how we hold or use your personal information, please contact the DPO by: e-mail at email@example.com; telephone on 07308 014 844; or writing to: The Data Protection Officer, Muirhouse Housing Association Limited, 11 Muirhouse Medway, Edinburgh, EH4 4RW.
You can also contact us by: e-mail at firstname.lastname@example.org; telephone on 0131 336 5282; or writing to: Muirhouse Housing Association Limited, 11 Muirhouse Medway, Edinburgh, EH4 4RW.
Your attention is particularly drawn to section 2 of this policy, which confirms that you consent to your personal information and sensitive personal information being held and used by us as described in section 1 of this policy.
What personal information do we collect about you and why?
Our website is a place for you to find out more about us, your neighbourhood and the services available to you.
When you visit our website, we collect personal information about you when you:
- apply for housing with us;
- pay your rent;
- report a repair;
- apply to make alterations or improvements to your home, sublet, take in a lodger, assign your tenancy or keep a pet;
- request an adaptation to your home;
- notify us of any changes to your tenancy, including adding a joint tenant and changes to household members;
- inform us of changes to your contact details;
- complete a survey, including new tenant survey and satisfaction with repairs survey;
- provide us with notice to end your tenancy;
- apply for a garden waste permit;
- express an interest in getting involved as a tenant, owner or Board member;
- make a complaint, report anti-social behaviour, notify us of estate management issues or otherwise provide your comments on the standard of service that you have received from us;
- complete and submit a “contact us” form;
- complete and submit an “information request” form to us; and
- log in to your account via the “My Home” area of our website.
We use such personal information to:
- provide you with the information and services that you have requested from us;
- communicate with you, including in response to any of your enquiries or requests;
- improve our services and respond to changing needs;
- carry out repairs to your property;
- handle and resolve complaints made by / against you;
- keep the personal information that we hold about you and members of your household accurate and up-to-date; and
- arrange an appointment with our staff.
We may not be able to provide the above services to you if you do not provide us with sufficient personal information to allow us to do so.
What is our legal basis for holding and using your personal information?
Data protection laws require us to have a legal reason for collecting, holding and using your personal information.
Our legal reasons for holding and using your personal information are:
- Performance and management of any agreement between us;
- legal and regulatory obligations which apply to us as a registered social landlord;
- protection of your vital interests; and
- our legitimate interests – while you have a legitimate interest in the protection of your personal information, we also have an overriding legitimate interest in handling and using your personal information, including sharing it with our service providers (listed in section 3 of this policy), for the purposes described in section 1 of this policy.
In some circumstances, we may rely on your consent as the legal reason. By providing us with your personal information and sensitive personal information (relating to your health, racial or ethnic origin, religious or other beliefs or sexual orientation) and the personal information and sensitive personal information of other members of your household via our website, you:
- consent to it being used by us as described in section 1 of this policy; and
- confirm that you have informed the other members of your household of 12 years old and above of the content of this policy and they have provided their consent to their personal information and sensitive personal information being used by us as described in section 1 of this policy.
You and the other members of your household have the right to withdraw your consent to us holding and using your and their personal information and sensitive personal information by contacting us. Once you / they have withdrawn your / their consent, we will no longer use your / their personal information and sensitive personal information for the purpose(s) set out in section 1 of this policy, which you originally agreed to, unless we have another legal reason for doing so.
Who do we share your personal information with?
We may share your personal information with the following organisations for the purposes described in section 1 of this policy:
- Our contractors to undertake repairs, works and maintenance;
- our IT service providers, including the providers of our document management and housing management systems;
- organisations providing benefits advice and support;
- local and other public authorities for housing management and regulatory purposes; and
- Police Scotland and the local authority anti-social behaviour department in relation to complaints involving anti-social or other criminal behaviour.
How long do we keep your personal information?
We will only keep your personal information for as long as we need to for the purposes described in section 1 of this policy, including to meet any legal, accounting, reporting or regulatory requirements. More information is contained in our Data Retention Policy, which is available here: [INSERT LINK]
How do we keep your personal information secure?
The security of your personal information is important to us and we use technical and organisational measures to safeguard your personal information.
However, while we will use reasonable efforts to safeguard your personal information, the use of the Internet is not entirely secure and, for this reason, we cannot guarantee the security of any personal information that is transferred by or to you via the Internet. If you have any concerns about the security of your personal information, please contact our DPO for more information.
What if you provide us with personal information about somebody else?
We understand that there may be situations where you provide us with personal information about somebody else. In those situations, you confirm that:
- The other individual has consented to you acting for them and to your use of their personal information;
- you have informed the other individual of our identity and the contents of this policy, including the purposes for which we will use that individual’s personal information described in section 1 of this policy; and
- The other individual has explicitly consented to our use of that individual’s personal information for the purposes described in section 1 of this policy.
This policy will apply to our collection, handling and use of the other individual’s personal information in the same way that it applies to your personal information.
Where is your personal information stored?
Our servers are located in the United Kingdom and the information that we collect directly from you will be stored in these servers.
Some of the organisations we share your personal information with (listed in section 3 of this policy) may be based or may make use of data storage facilities that are located outside the United Kingdom. Their handling and use of your personal information will involve us and / or them transferring it outside the United Kingdom. When we and / or they do this, we will ensure similar protection is afforded to it by:
- Only transferring it or permitting its transfer to countries that have been deemed to provide an adequate level of protection for personal information under data protection laws; or
- using specific contracts with such organisations, which are approved for use in the United Kingdom, and which give your personal information the same protection it has in the United Kingdom after it is transferred.
Please contact our DPO for further information on the specific mechanism used by us when transferring your personal information outside the United Kingdom.
What rights do you have in relation to your personal information that we collect, hold and use?
It is important that the personal information that we collect, hold and use about you is accurate and current. Please keep us informed of any changes by contacting our DPO. Under certain circumstances, the law gives you the right to request:
- A copy of your personal information and to check that we are holding and using it in accordance with legal requirements.
- Correction of any incomplete or inaccurate personal information that we hold and use about you.
- Deletion of your personal information where there is no good reason for us continuing to hold and use it. You also have the right to ask us to do this where you object to us holding and using your personal information (details below).
- Temporarily suspend the use of your personal information, for example, if you want us to check that it is correct or the reason for processing it.
- The transfer of your personal information to another organisation.
You can also object to us holding and using your personal information where our legal basis is a legitimate interest (either our legitimate interests or those of a third party).
Please contact our DPO if you wish to make any of the above requests. When you make a request, we may ask you for specific information to help us confirm your identity for security reasons. You will not need to pay a fee when you make any of the above requests, but we may charge a reasonable fee or refuse to comply if your request for access is clearly unfounded or excessive.
Feedback and complaints
We welcome your feedback on how we hold and use your personal information, and this can be sent to our DPO.
You have the right to make a complaint to the Information Commissioner, the UK regulator for data protection, about how we hold and use your personal information. The Information Commissioner’s website is https://ico.org.uk/ and complaints can be made here.
If you would like to receive this policy in alternative format, for example, audio, large print or braille, please contact our DPO.
Updates to this policy
We may update this policy at any time, and you should check our website occasionally to ensure you are aware of the most recent version that will apply each time you access our website.
Last updated: 6 May 2021