Privacy Policy
Westminster Digital Bridge CIC. Last updated: June 2026.
We care about your privacy and we want to be clear about how we look after your information. This policy explains, in plain language, what information we collect, why we collect it, and the rights you have. If anything here is unclear, please contact us - we are happy to explain.
1. Who We Are
Westminster Digital Bridge CIC is a Community Interest Company based in Westminster, London. We support residents with digital confidence, online safety and access to essential digital services.
- Company Number: 17262108 (a private company limited by guarantee, registered in England and Wales)
- Registered office: 124-128 City Road, London, EC1V 2NX
- ICO Registration Number: ZC172553
- Who is responsible for your data: Westminster Digital Bridge CIC is the “data controller” for the information you give us. Our data protection contact is Ahmed Abdou, Director.
- How to reach us: contact@westminsterdigitalbridge.org.uk, or the contact form on our website
2. What Information We Collect
We only collect the information we need to support you or respond to your enquiry. Depending on how you contact us, this may include:
- Your name
- Your email address
- Your phone number
- A short description of the support you need
- Organisation details, if you are referring someone or contacting us as a partner
- The name and contact details of a resident, if you are referring them on their behalf
- Any access needs or support needs you choose to tell us about
- If you book a private 1:1 session: your booking details (date, time, selected service)
- Payment information: we receive payment confirmation details (such as transaction ID and status) from our payment provider - we do not store your card details
About sensitive information. Some of what you may tell us - for example an access need, a disability, or a health-related reason you would like support - counts as “special category” information under data protection law. We treat this information with extra care. We explain the legal basis for handling it in Section 4.
3. How We Use Your Information
We use your information to:
- Contact you about your enquiry
- Provide digital confidence and online safety support
- Manage referrals from partners and professionals
- Arrange meetings or follow-up conversations
- Keep basic internal records of the support we provide
- Improve our services
- Process bookings and payments for optional private 1:1 training sessions
We do not use your information for marketing unless you give us clear, separate permission. We do not make any decisions about you using automated systems or profiling.
4. Our Legal Basis for Using Your Data
Under UK GDPR we must have a lawful basis for using your information. We rely on the following:
- Legitimate interests - to respond to your enquiry, provide the support you have asked for, and manage referrals and partnership conversations. Our legitimate interest is running a community service that helps residents build digital confidence, in a way you would reasonably expect when you contact us.
- Contract - when you book and pay for a private 1:1 session, we process your information to deliver the service you have purchased.
- Consent - only for things that are genuinely optional, such as sending you updates or marketing. You can withdraw this consent at any time, and it will not affect the support we provide.
- Legal obligation - where the law requires us to act, for example certain safeguarding or record-keeping duties.
For sensitive (special category) information - such as access needs, disability or health-related support needs - we also rely on an additional condition under Article 9 of the UK GDPR: handling this information is necessary for reasons of substantial public interest, specifically to provide support to people with a particular disability or medical condition (Data Protection Act 2018, Schedule 1). We keep an Appropriate Policy Document that explains how we protect this information, available on request.
5. When Someone Refers You to Us
If a partner organisation, professional or carer refers you to our service, we will have received some of your information from them rather than directly from you. In that case:
- The information will usually be your name, contact details and a short description of why support was suggested.
- We will have received it from the person or organisation making the referral.
- We will let you know we hold your information within a reasonable time, and no later than one month, unless contacting you would be impossible or involve disproportionate effort.
- You have the same rights over this information as if you had given it to us yourself (see Section 9).
6. How We Store and Protect Your Data
We take the security of your information seriously. Your information is:
- Stored in a secure database located in the UK or the European Union
- Protected in transit and at rest using encryption (HTTPS and database encryption)
- Accessed only by authorised people, through a password-protected system with individual logins
- Backed up securely so it is not lost, with backups kept private and deleted on the same schedule as the original data
- Never shared without your permission, except where safeguarding or the law requires it (see Section 7)
For private 1:1 sessions:
- Payment card details are handled securely by our payment provider
- We only receive payment confirmation metadata
- We never store your card number or bank details
7. Who We Share Your Data With
We do not sell or trade your personal information, ever. We only share it when:
- You ask us to, or agree to it
- It is necessary to arrange the support you have requested
- A safeguarding concern means we need to act to protect you or someone else - in which case we may share information with local authority adult safeguarding teams, health services or, in an emergency, the emergency services
- We are legally required to do so, for example by a regulator or court
- You book a private 1:1 session - in which case our payment provider processes your card details securely on our behalf. We do not receive or store your full card information.
8. Where Your Data Is Held (International Transfers)
The personal information you give us (such as form submissions) is stored in a secure database hosted in the UK or the European Union.
Our public web pages are delivered through a global content network so the site loads quickly, but those pages do not contain your personal information - they only serve the public content of the website.
If our payment provider or another processor transfers data outside the UK/EU, this is done using approved safeguards such as: UK adequacy regulations; International Data Transfer Agreements (IDTAs); Standard Contractual Clauses (SCCs). We assess these transfers to ensure your data remains protected.
9. Your Rights
Under UK GDPR you have the right to:
- Be informed about how we use your data (this policy)
- Access the personal data we hold about you
- Correct information that is wrong or incomplete
- Ask us to delete your data
- Restrict how we use your data
- Object to how we use your data
- Request a copy of your data to reuse elsewhere (data portability)
- Withdraw consent at any time, where we relied on your consent
To exercise any of these rights, contact us using the details in Section 1. We will respond within one month. There is normally no charge.
10. How Long We Keep Your Data
We keep your information only for as long as we need it:
- General enquiries and support records - kept for up to 12 months after our last contact with you, then securely deleted.
- Booking records: up to 12 months
- Payment metadata: kept only as required for accounting or legal obligations
- Safeguarding records - where we have acted on a safeguarding concern, we keep the relevant records for longer where we are legally or professionally required to do so.
- Anything we must keep by law - retained for the period the law requires, then securely deleted.
11. Cookies and Analytics
We have deliberately built this website to respect your privacy:
- We use privacy-friendly, cookieless analytics that count visits without identifying you or tracking you across the web.
- We do not use advertising cookies or tracking pixels.
- We do not show a cookie consent banner because we do not set the kind of cookies that require one. The only cookie we use is a strictly necessary login cookie, and only for staff signing in to manage the site - never for visitors.
12. Children’s Information
Our service is designed for adults, and our eligibility is for people aged 18 and over. We do not knowingly collect personal information from children. Please note that, separately, the minimum age at which a child can give their own consent online under UK law is 13.
13. Complaints
If you have a concern about how we handle your information, please contact us first - we will do our best to put things right.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator:
- Website: ico.org.uk
- Helpline: 0303 123 1113
14. Changes to This Policy
We may update this policy from time to time to reflect changes in our services or the law. The latest version will always be available on our website, with the “last updated” date at the top.
15. How to Contact Us
If you have any questions, concerns or requests about your data, please contact us:
- Email: contact@westminsterdigitalbridge.org.uk
- Registered office: Westminster Digital Bridge CIC, 124-128 City Road, London, EC1V 2NX