StopSO UK – Privacy Policy


Last updated: Jan 2026

Version: May 2026
Owner: Chair
Approved by: Needs to be Board of Trustees
Review frequency: Annually (or sooner if required)


StopSO UK – Privacy Notice

StopSO UK is committed to protecting your privacy and handling your personal information lawfully, fairly and securely.

This Privacy Notice explains how we collect, use, store and share your personal data when you interact with StopSO UK, including via our website.


1) Who we are

StopSO UK is a UK registered charity.

For the purposes of data protection law, StopSO UK is the data controller of the personal data we hold.

Contact (data protection): admin@stopso.org.uk


2) The kind of information we collect

Depending on how you contact us, we may collect and process personal information including:

a) Contact and identity information

  • name

  • email address

  • telephone number

  • postal address (where relevant)

b) Referral and enquiry information

StopSO UK receives referrals and enquiries from:

  • individuals who may have sexually harmed, or may be at risk of causing sexual harm, and/or

  • survivors of sexual offending and violence, and/or

  • family members, partners or professionals seeking support or signposting.

Referral/enquiry information may include highly sensitive details and is stored in our CRM.

c) Special category (sensitive) information

Due to the nature of StopSO UK’s work, information we receive may include special category personal data, such as:

  • information about health or therapy needs

  • information about trauma

  • information concerning sexual behaviour or sexual orientation

We may also receive information relating to criminal offences or allegations.

d) Donations, training and financial information

If you donate to us or pay for training/events, we may collect information such as:

  • payment confirmations and transaction references

  • Gift Aid information (where applicable)

  • accounting records required for financial compliance

Payments may be processed via PayPal and recorded in QuickBooks.

e) Website and communications data

We may collect limited technical data about how you use our website (such as cookies or analytics), and we may retain records of emails or messages you send us.


3) How we use your information

We use personal data to:

  • respond to enquiries and referrals

  • manage and administer referrals and signposting appropriately

  • administer training or events

  • process donations and maintain financial records

  • improve and manage how we operate as a charity

  • manage complaints and concerns

  • meet legal and regulatory obligations

  • protect the safety of individuals where necessary (including safeguarding/risk management)


4) Our lawful basis for processing

We process personal data under UK GDPR using one or more lawful bases, depending on the context:

  • Legitimate interests (for example, handling enquiries/referrals and running the charity effectively and safely)

  • Contract (for example, where you book training or services)

  • Legal obligation (for example, accounting and record-keeping requirements, Gift Aid where applicable)

  • Consent (for example, if you opt in to receive newsletters or marketing communications)

Where we process special category data, we apply an additional lawful condition under UK GDPR and use appropriate safeguards.


5) Where we store your information

We store and manage personal data using secure systems, including:

  • a CRM for referral and enquiry management

  • Microsoft OneDrive / Microsoft 365 for document storage

  • email systems used by StopSO UK

  • finance and payment systems (including PayPal and QuickBooks)

We restrict access to authorised personnel only, on a need-to-know basis.


6) Who we share your information with

We do not sell your personal data.

We may share your information where necessary with:

  • trusted IT and service providers (such as cloud storage and software providers)

  • payment processors (for example PayPal)

  • professional advisers (such as legal or accounting support)

  • regulators, law enforcement, or statutory bodies where required by law

  • other parties where necessary to protect individuals or manage serious risk

We only share information where it is lawful, necessary and proportionate.


7) Therapy provided by StopSO UK members

StopSO UK operates as a network charity and does not generally provide therapy directly.

If you engage in therapy with a StopSO member, that member is responsible for:

  • their own privacy information

  • their own clinical records

  • professional and regulatory compliance

StopSO UK will normally hold only the administrative information needed to manage referrals and signposting.


8) How long we keep your information

We keep your personal data only as long as necessary for the purpose it was collected, including legal and regulatory requirements.

Examples may include:

  • donation and accounting records: typically retained for 8 years

  • training records: typically retained for a limited period (e.g. 8 years)

  • Safeguarding queries: typically retained for 25 years 

  • newsletter subscriptions: until you unsubscribe

  • referral/enquiry records: retained in line with our internal retention schedule and risk-based governance requirements


9) Your rights

You have rights under data protection law, including the right to:

  • request access to your personal data (a Subject Access Request)

  • request correction of inaccurate information

  • request deletion of your information (in certain circumstances)

  • object to or restrict our processing (in certain circumstances)

  • withdraw consent at any time (where consent is the lawful basis)

  • complain to the Information Commissioner’s Office (ICO)

To exercise your rights, contact: admin@stopso.org.uk


10) Subject Access Requests (SARs)

You can request a copy of the personal information StopSO UK holds about you by emailing admin@stopso.org.uk.

We will normally respond within one month. We may ask for proof of identity before providing information, especially where the data is sensitive.


11) Security

We take appropriate technical and organisational steps to protect personal data, including access controls and secure systems.

You can also help protect your information by ensuring your devices and passwords are kept secure.


12) International transfers

Some of our service providers may process or store data outside the UK. Where this happens, we take steps to ensure appropriate safeguards are in place.


Our website may include links to third-party websites. We are not responsible for the privacy practices of those websites. Please check their privacy notices before submitting personal data.


14) Changes to this Privacy Notice

We may update this Privacy Notice from time to time. Please check this page occasionally to ensure you are aware of any changes.



This site uses cookies that enable us to make improvements, provide relevant content, and for analytics purposes. For more details, see our Cookie Policy. By clicking Accept, you consent to our use of cookies.