CHARITY TOOLKIT • DATA & PRIVACY

Keep the loan record useful — and no bigger than it needs to be. 🔒

This page is practical guidance for charities testing the Hub. It is not a substitute for the charity's own privacy notice, lawful-basis decision, retention policy or professional data-protection advice.

⚠️ Test-stage storage — not for permanent real case records yet

The charity workflow is currently in public testing. The live service is not yet connected to the permanent production PostgreSQL storage planned for real charity use. Explore the workflow, but do not rely on the Hub as the permanent record for real owner or case information yet.

What the charity tools are designed to store

The authenticated loan workflow is intentionally minimal. It is designed to store the charity account, Chair ID, wheelchair details, dog name, case reference, case status, follow-up date, short case notes and case history needed to run the wheelchair loan.

The Handover sheet's owner/carer name and phone/email are not intended to be sent into the Hub case database. Keep sensitive contact details in the charity's approved system.

Five rules for volunteers

1. Collect less

Only add information needed to manage the wheelchair loan, fitting follow-up, return or repair. Do not paste unrelated medical history, financial details or long personal conversations into case notes.

2. Use the case reference

Use the Hub case reference and Chair ID wherever possible instead of repeating personal information in notes, photos or messages.

3. Explain the purpose

When a charity collects personal information, its own privacy information should clearly explain why the data is used, how long it is kept, who receives it and how people can exercise their rights.

4. Delete when no longer needed

Each charity should set and document a retention period that fits its real purpose. UK data-protection law does not give one universal retention period for wheelchair-loan records.

5. Keep access controlled

Use individual charity accounts, strong passwords and available MFA/passkey protection. Do not share a single login between unrelated volunteers where individual access can be used.

Before using real owner information

Permanent production storage, backup/restore and the charity's own privacy process must be ready before the Hub is relied on for real case records. The charity using the Hub remains responsible for deciding its lawful basis, giving suitable privacy information, handling rights requests, defining retention/deletion rules, managing staff access and deciding whether any health-related information requires additional safeguards.

Do not assume that using authenticated storage alone makes a charity GDPR-compliant.

Suggested charity checklist

Before real personal data is entered, the charity should have: permanent production storage and tested recovery; a named privacy contact; an up-to-date privacy notice covering the Hub workflow; a documented purpose and lawful basis; a retention/deletion rule; a process for access, correction and deletion requests; an access-control policy for volunteers; and a plan for incidents or lost credentials.

Current Hub data-minimisation choices

The inventory is designed to store equipment data and a linked case reference. The case tracker is designed to store the dog name and operational wheelchair-loan information. Owner/carer phone/email from the printable Handover sheet is deliberately kept outside the Hub case record at this stage.

That design keeps the Hub useful for the loan journey while reducing unnecessary personal information.

Official UK guidance

For the charity's actual compliance decisions, use current Information Commissioner's Office guidance on the right to be informed, data minimisation and storage limitation.