our privacy policy

Our commitment to your privacy

This Privacy Statement describes how OneSpirit Interfaith Foundation (“OneSpirit”, “we”, “us”) collects and uses personal information, and the steps we take to protect it.

We process personal information in accordance with UK data protection law, including UK GDPR, the Data Protection Act 2018, PECR and relevant amendments introduced by the Data (Use and Access) Act 2025 (DUAA).

Privacy Principles

We use the following principles to guide how we handle personal information:

  • We will always communicate clearly about what personal information we collect and how we use it.
  • We will respect your privacy and only collect and use personal information that we genuinely need.
  • We will use your personal information to deliver and improve our charitable services, and to communicate with you in ways you expect.
  • We will protect your personal information and keep it secure.
  • We will never sell your personal information.
  • We will only share your personal information when it is necessary and with trusted partners who help us deliver our work.

Who we are and how to contact us

OneSpirit Interfaith Foundation is the ‘data controller’ for the personal information we hold. If you have any questions about this statement or how we use your information, please contact us:

What personal information do we collect?

The personal information we collect depends on how you engage with OneSpirit (for example, requesting information, applying for a programme, becoming a student, joining the Register of OneSpirit Interfaith Ministers (ROSIM), donating, or attending an event).

Information you share with us

  • Your contact details (such as name, email address, telephone number and postal address).
  • Programme applications and enrolment information.
  • Payment information needed to process fees or donations (processed securely via our payment providers).
  • Your communication preferences.
  • Any messages you send us (for example enquiries or feedback).
  • Information you choose to share about support needs or accessibility requirements.
  • Where relevant and with appropriate safeguards, information you choose to share about your spiritual/religious background (which may be special category data).

Information from your online interactions

  • Information about how you use our websites (for example, pages viewed, links clicked and technical identifiers such as IP address).
  • Cookie preferences and related information where cookies are used (see ‘Cookies’ below).

Cookies

Cookies are small text files that are stored on your device when you use a website. We use cookies to make our website work, to remember your preferences, and (where you agree) to help us understand how our website is used so we can improve it.

Where required, we will ask for your consent before placing non-essential cookies or using similar technologies. Some cookies may be used without consent where an exemption applies (for example, where the cookie is strictly necessary to provide a service you have requested, and where permitted under PECR as amended).

You can manage cookies through your browser settings and, where available, our cookie settings tool.

Email Communications

When we send you emails, we may use standard industry technologies (such as pixels) to understand whether an email has been opened and which links are clicked. This helps us improve our communications and keep them relevant.

Social Media

If you engage with us on social media, the relevant platform will also process your personal information. Your relationship with those platforms is governed by their own privacy policies. We may receive aggregated statistics from social media providers to help us understand engagement with our content.

How we use your personal information

We use personal information for the purposes below. In each case we also identify a ‘lawful basis’ under UK GDPR for doing so:

  • To respond to enquiries and provide information you request (legitimate interests).
  • To manage applications, enrolment and course delivery (contract).
  • To provide pastoral, accessibility and learning support where requested (contract and/or consent; explicit consent where special category data is involved).
  • To process payments, donations and maintain financial records (contract and legal obligation).
  • To send essential service communications (contract and/or legitimate interests).
  • To send newsletters, updates and fundraising communications (consent or, where permitted, the charity ‘soft opt-in’ under PECR; you can opt out at any time).
  • To meet legal, regulatory and safeguarding obligations (legal obligation, legitimate interests and/or recognised legitimate interests where applicable).
  • To protect the security of our systems and prevent misuse (legitimate interests).

How can you change the way we contact you?

You can change your communication preferences at any time. Each marketing email includes an unsubscribe link, and you can also contact us at admin@interfaithfoundation.org. If you ask us to stop marketing, we will do so.

However, we may still need to send service messages that are necessary to deliver a programme you are enrolled on or to meet legal obligations.

What personal information do we share with third parties?

We may share personal information with trusted third parties where this is necessary to provide our services and run the organisation. This includes:

  • Service providers who help us deliver our work (for example, IT hosting, email platforms, databases and payment processing).
  • Professional advisers (for example, accountants, insurers and legal advisers).
  • Regulators and authorities where we are legally required to do so.

We do not sell your personal information. Where we use service providers (‘processors’), we put appropriate contracts in place to protect your information.

International transfers

Some of our suppliers may process personal information outside the UK. When this happens, we ensure appropriate safeguards are used (such as adequacy decisions or approved contractual safeguards) to protect your personal information.

How long do we keep your personal information?

We will only keep your personal information for as long as necessary for the purposes it was collected, including legal, accounting, regulatory and safeguarding requirements. We regularly review what we hold and delete or anonymise information when it is no longer needed.

Your Controls and Choices

You have rights in relation to your personal information. These include:

  • The right to withdraw consent (where we rely on consent).
  • The right to object to processing, including an absolute right to object to direct marketing.
  • The right to access the personal information we hold about you (a Subject Access Request).
  • The right to correct inaccurate personal information.
  • The right to request deletion of personal information in certain circumstances.
  • The right to restrict processing in certain circumstances.
  • The right to data portability in certain circumstances.
  • Rights in relation to automated decision-making: we do not make significant decisions about you by automated means alone; if that ever changed, safeguards including the right to human review would apply.

To exercise your rights, contact us using the details above. We may ask you for identification and, where necessary, clarification of your request. We will normally respond within one month. Where we require additional information to verify identity or clarify the request, the response time may be paused until that information is received. Details of how long we keep different kinds of information are set out in our Data Protection Policy’s retention schedule, available on request.

If you are unhappy with how we have handled your personal information, you can complain to us: contact our Data Protection Lead (the Executive Director) at admin@interfaithfoundation.org, and we will acknowledge your complaint within 30 days and respond without undue delay. You also have the right to complain to the Information Commissioner’s Office (ICO) at any time — though we would value the opportunity to put things right first.

How do we protect your personal information?

We take appropriate steps to protect personal information from loss, misuse, unauthorised access, disclosure, alteration and destruction. These steps include access controls, staff training, and technical security measures.

Changes to this Privacy Statement

We may update this Privacy Statement from time to time. The latest version will be published on our website and will show the date it was last updated.

 

Last updated: 5 September 2026.