Data Protection Policy
Your privacy and data security are fundamental to how we operate.
Data Security
How we protect your information
Community Connect is committed to protecting all personal data with industry-leading security practices. We implement multiple layers of protection including:
- Encryption: All data is encrypted both in transit (using SSL/TLS) and at rest using advanced encryption standards.
- Access Controls: Strict role-based access controls ensure only authorised personnel can view sensitive data.
- Regular Audits: We conduct regular security audits and penetration testing to identify and address vulnerabilities.
- Secure Infrastructure: Data is stored on secure, GDPR-compliant cloud infrastructure with automatic backups.
- Staff Training: All team members receive regular data protection and privacy training.
Platform Infrastructure & Compliance
Built on trusted, certified infrastructure
Community Connect is built on a platform, which prioritises robust data security, compliance and is SOC 2 Type II compliant and ISO 27001 certified, adhering to international standards for information security management. We are committed to GDPR compliance, ensuring that all data processing activities meet stringent privacy regulations.Data is stored on servers located in the UK, and all vendors involved in data processing are bound by strict data processing agreements. The platform provides app-level security controls, including Row-Level Security (RLS), Field-Level Security (FLS), and Role-Based Access Control (RBAC) to manage data access. All API keys and secrets are stored securely and encrypted.
Data Sharing & Consent
Your control over your information
We never share your data without explicit consent. Your personal information is kept confidential and is only shared in the following circumstances:
- With Your Permission: When you explicitly consent to share your data with a service provider as part of a referral.
- Service Delivery: Only the minimum information necessary to deliver the service is shared with relevant organisations.
- Legal Requirements: Where legally required by law, we will comply with data disclosure requests.
Your Rights:
- • You can withdraw consent at any time by contacting us
- • You have the right to know what data we hold about you
- • You can request correction of inaccurate data
- • You can request deletion of your data (subject to legal requirements)
Privacy Best Practices
GDPR and industry standards compliance
Community Connect complies with the UK General Data Protection Regulation (GDPR) and follows international data protection best practices:
- Transparency: We are clear about what data we collect and how it's used.
- Purpose Limitation: Data is only used for the purposes you've consented to.
- Data Minimisation: We only collect data that is necessary and relevant.
- Accuracy: We maintain accurate, complete, and up-to-date data.
- Storage Limitation: Data is retained only for as long as necessary.
- Integrity & Confidentiality: Strong technical and organisational measures protect data from misuse.
What Data We Collect
Only what's necessary for our service
We only collect personal data that is necessary to deliver our services:
For Service Users:
- • Name and contact information
- • Age group
- • Location
- • Service preferences
For Professional Referrals:
- • Client details (with consent)
- • Referrer information
- • Reason for referral
- • Urgency level
Your Rights & Contact
If you have questions about how your data is handled, wish to exercise your rights, or have concerns about your data protection, please contact us:
Data Protection Officer
Contact us via the footer email address with the subject "Data Protection Query"
Response Time
We aim to respond to all data protection requests within 30 days in accordance with GDPR requirements.
This Data Protection Policy was last updated on April 7, 2026