Practical local support, close to home07508 390070
Your information matters

Local Family Links privacy notice

Version: 1.0 — approved for publication before real-client intake
Approval date: 21 September 2026
Effective date: the date this notice is published

Who we are

Local Family Links Ltd, trading as Local Family Links, is the controller of the personal information described in this notice.

Information we may use

Depending on the service, we may use:

We may receive information directly from you, from a trusted person or formal representative, from our own observations during agreed services, or from another organisation where you have authorised this or the law permits it. We record the source where it matters.

Why and how we use it

We use necessary information to respond to enquiries, assess whether our service is suitable, agree and deliver services, arrange appointments and visits, communicate with you and authorised people, keep an accurate service record, manage safety, administer agreed charges, meet specific legal duties, handle complaints/claims, secure our systems and recover from incidents.

Our lawful bases are:

Health and other sensitive information

Some information about health, disability, cognition or medication is special-category information. We first need an Article 6 lawful basis for the purpose described above. Separately, for routine support planning where no other documented condition applies, our Article 9 condition is your explicit consent. We will explain the information, purpose and any sharing separately and record your specific, informed choice. You may withdraw consent. Withdrawal applies to future use and does not make earlier lawful processing unlawful. We may need to pause or stop affected work if we cannot provide it safely without the necessary information.

In an exceptional emergency or safeguarding situation, another legal condition may permit necessary use or disclosure. We will identify and document that condition before relying on it; we do not treat a family relationship as consent on a client's behalf.

Trusted people and sharing

We do not treat a family relationship as automatic authority. We record who you authorise, what we may share, for what purpose and for how long. We share only what is necessary. You may change or withdraw ordinary authority at any time. We may retain a minimal record of disclosures already made.

Formal attorneys or deputies must provide suitable evidence of their role and scope. We may share without ordinary authority only where the law permits or requires it, such as a properly assessed emergency or safeguarding situation.

If you give us another person's contact details, please tell them that we will use those details for the agreed contact purpose and direct them to this notice.

Who receives information

Access is limited to authorised LFL personnel who need it. Current hosting and technical processors include Supabase and Google Cloud. We may also disclose information to professional advisers, regulators, emergency services or other organisations where necessary and lawful.

Google Drive, Twilio/SMS, Stripe LIVE and outbound provider email are currently disabled for live client processing. If these services are activated later, we will review the processing and update this notice before using them.

Some processors or subprocessors may process information outside the UK. Their contractual terms include applicable UK transfer safeguards. We maintain and review a processor/subprocessor register and assess material changes.

How long we keep information

We keep information only while it is needed for the stated purpose, an active complaint/claim/safeguarding matter, or a documented legal obligation. Our initial business policy is normally 12 months for enquiries that do not proceed and six years after service closure for the core client and visit record. Different periods apply to short-lived working files, security logs, finance records and incidents. These are business-policy periods, not claims that the law always requires retention for that length. We periodically review necessity and obtain professional confirmation where finance, safeguarding or potential claims require it.

Encrypted backups are retained on an approximately 35-day rolling cycle. When live information is validly erased, it is placed beyond normal operational use in backups and expires through that cycle. If a backup is restored, the erasure instruction is reapplied before operational use.

Your rights

Depending on the processing, you may ask us to:

You can make a request verbally or in writing. We may ask for proportionate proof of identity or a representative's authority. We normally respond without undue delay and within one calendar month. Some rights are not absolute; if we cannot fully comply, we will explain why and tell you how to complain.

Contact [email protected] or write to the registered office above. We will use a verified, secure delivery method for sensitive responses.

Security and automated decisions

We use named access, multi-factor authentication, encryption, audit controls, monitoring and encrypted backups. No system is risk-free, so we also maintain incident and recovery procedures.

We do not use your information for solely automated decisions with legal or similarly significant effects, and we do not use client information for direct marketing under this notice.

Complaints

Please contact us first so that we can try to resolve a concern. You also have the right to complain to the Information Commissioner's Office: https://ico.org.uk/make-a-complaint/.

Changes to this notice

We will review this notice at least annually and before a material new use or provider is introduced. We will bring material changes to affected people's attention where appropriate.

Privacy contact
Privacy Lead (Owner/Administrator)
[email protected]
07508 390070