Privacy Policy
Aspeera CIO
Last updated: 1 September 2026
Aspeera CIO is a registered charity supporting Eastern European communities across Worcestershire and the West Midlands. We provide mental health support, social support, immigration advice and gambling harm support.
This policy explains what personal information we collect about you, why we collect it, how we keep it safe, how long we keep it and what you can ask us to do about it. It covers our website at aspeera.org, including the Polish and Ukrainian versions, the enquiry forms we run on Facebook and Instagram, and the information you give us when you contact us or use one of our services.
We have written it in plain English, and under each section there is a short summary in italics. If anything is still unclear after reading it, please ask us. We would rather explain it than have you wonder.
Our main principles
1. We ask for what we need, not for everything
We collect the information a service actually requires, and no more.
2. We keep it safe
Your information is held securely and seen only by the people who need it to help you.
3. We do not sell your data
Not to anyone, ever, for any price.
4. We do not use your case against you
What you tell us in the course of getting help is used to help you, not to market to you.
5. We keep it only as long as we should
When the reason for holding something ends, we delete it or make it anonymous.
1. Who we are
Aspeera CIO (“we”, “us”, “our”) is the data controller for the information described in this policy. That means we are the organisation responsible for deciding how your personal information is used and for keeping it safe.
-
Registered charity number: 1210749
-
Registered address: The Kiln, 2 Copenhagen Street, Worcester WR1 2HB, United Kingdom
-
Email: help@aspeera.org
-
ICO registration number: ZC104050
-
Person responsible for data protection queries: Tomasz Jarecki
In plain language: this is who we are and where to find us if you want to ask about your information.
2. Why we are allowed to hold your personal data
Data protection law requires us to have a lawful reason for holding your information. Different parts of our work rely on different reasons.
Contract
Where we agree to act for you on an immigration matter, we need your information to do the work you are paying us for, including preparing and submitting your application.
Legal obligation
Some records we are required to keep by law, or under the rules of the Immigration Advice Authority, the body that regulates immigration advice in the United Kingdom and under whose accreditation our immigration service operates.
Legitimate interests
Running the charity involves some ordinary activities that need personal data: responding to an enquiry, keeping a record of advice given so that a colleague can pick up your case, understanding in aggregate which services are most needed, and reporting numbers to the funders who pay for the work. Where we rely on this reason, we have considered whether it would be unfair to you, and we will stop if you object and there is no overriding reason to continue.
Consent
Some things happen only if you say yes. Referring you to another organisation is the main example. You can withdraw consent at any time.
In plain language: sometimes we hold your data because you hired us, sometimes because the law makes us, sometimes because running a charity requires it, and sometimes because you said we could.
3. Sensitive information
Some of what we handle is treated as more sensitive under data protection law. Depending on the service, this can include information about your health, including mental health, information relating to gambling harm, and information about your immigration status and history.
We collect this information only where it is necessary to provide the service you have asked for. Where we do, we rely on your explicit consent, or on the substantial public interest condition relating to the provision of confidential counselling, advice and support services, set out in Schedule 1 of the Data Protection Act 2018.
You decide how much you tell us. If you would rather talk something through before putting it in writing, contact us and we will explain what we actually need for your case and what we do not.
In plain language: some of what you share with us is very personal. We only ask for it when the service genuinely requires it, and how much you say is your choice.
4. How we collect your information
-
When you complete the contact form on our website
-
When you complete one of our enquiry forms on Facebook or Instagram
-
When you email us, call us or message us on social media
-
When you become a client of one of our services and give us documents and details relating to your case
-
When another organisation refers you to us with your consent
-
When you visit our website, through cookies and similar technologies, described in section 8
-
When you visit our office by appointment. Our office is in a rented building, and any security measures in the shared parts of that building are operated by the landlord, not by us.
In plain language: mostly you tell us directly. A little comes from your browser when you visit the site.
5. What information we collect
When you get in touch
-
Your name, email address and telephone number
-
The language you would prefer us to use
-
Whatever you choose to tell us about the matter you need help with
If you become a client
-
Information relevant to your case, which may include your immigration status and history, correspondence with the Home Office, family and household circumstances, employment and financial information, and copies of identity or supporting documents
-
A record of the advice we gave you and the work we did
Automatically, when you visit our website
-
Pages viewed, time on the site, and the page or advert that brought you to us
-
Device and browser type, and approximate location derived from your IP address
-
Cookie data, described in section 8
In plain language: what you type in, plus the documents your case needs, plus some basic technical information about your visit.
6. How we use your information
What we use it for
What that involves
Handling payments
Answering your enquiry
Providing our services
Improving what we do
Reporting to funders
Safeguarding
Meeting our regulatory obligations
Understanding, in aggregate, which services are most needed and how people find us
Reporting numbers and outcomes in a form that does not identify you individually
Acting where we have a serious concern about the safety of a person, including a child or an adult at risk
Keeping the case records required of us by the Immigration Advice Authority as an accredited immigration advice provider
Recording that a payment has been made. If you ask, a member of our team can talk you through the payment page, but we never ask for or write down your card details
Contacting you by phone, email or messaging to arrange a consultation or answer a question
Assessing your situation, preparing applications and correspondence, and recording the advice we gave
We do not sell your personal information. We do not use your case information to advertise to you, and we do not build advertising audiences from the people we have helped.
In plain language: we use your details to help you, to keep the records our regulator requires, and to count how many people we support. Nothing about your case feeds our advertising
7. Enquiry forms on Facebook and Instagram
We advertise our services on Facebook and Instagram. Some of those adverts include an enquiry form that opens inside the app, so that you can send us your contact details without leaving it.
When you complete one of those forms, Meta Platforms Ireland Limited processes it first and then passes us the details you confirmed. Meta's own handling of your information is governed by Meta's privacy policy, which we do not control. Once the details reach us, this policy applies, and we use them only to contact you about the enquiry you made.
In plain language: if you fill in our form inside Facebook or Instagram, Meta handles it first and then sends it to us. From that moment it is covered by this page.
8. Cookies and similar technologies
A cookie is a small file placed on your device when you visit a website. It cannot damage your device. Some cookies are needed for a website to function; others tell us, in numbers only, how the site is being used.
Essential cookies
Our website is built on Wix, which sets a number of cookies that are necessary for the site to work at all. These handle security, protection against attacks, and remembering your session while you move between pages.
Cookie
Duration
Fraud detection on requests
Session
svSession, wixSession
Security, stability and core site function
12 months
SSR-caching
Page rendering performance
24 hours
bSession
Measuring system performance
24 hours
TS*
server-session-bind, client-session-bind
Attack detection
Session
Protecting the site's internal connections
Session
fedops.logger.sessionId
Recording site errors so they can be fixed
12 months
These cannot be switched off, because without them the site does not work.
Advertising and measurement
We use the Meta pixel, which is a piece of code from Facebook and Instagram. It tells us whether our adverts are reaching people who go on to look at our services, and it lets us show information about our work to people in our area.
Cookie
_fbp
_fbc
Set by
Meta
Meta
Purpose
Measuring advert performance and showing relevant adverts
Recording which advert brought you to the site
Duration
3 months
3 months
Turning cookies off
You can restrict, block or delete cookies through your browser settings, and you can manage advertising preferences in your Facebook and Instagram account settings. Blocking non-essential cookies will not stop you using the site or contacting us.
In plain language: some small files are needed for the site to work. Others tell us whether our adverts are reaching the right people. You can switch the second kind off and everything will still work.
9. Who we share your information with
We share personal information only where it is necessary.
-
Government bodies, where you have asked us to act for you. Principally the Home Office and UK Visas and Immigration.
-
The Immigration Advice Authority and our auditors, where required for the oversight of regulated immigration advice.
-
Service providers who process information on our behalf, and only on our instructions. These are our website platform (Wix), our email provider, Localgiving Ltd, which processes payments made to us, and Meta Platforms Ireland Limited in respect of the enquiry forms and advertising described above.
-
Other organisations, where you have consented to a referral.
-
Where the law requires it, or where there is a serious and immediate risk to someone's safety.
We do not sell your personal information and we do not pass it to anyone for their own marketing.
In plain language: we share your information with the offices your case needs, with our regulator, and with the companies that run our website, email and payments. Otherwise it stays with us.
10. Information held outside the United Kingdom
Some of the providers we use operate internationally, which means your information may be stored on servers outside the UK. Where that happens, we rely on the safeguards permitted under UK data protection law, so that your information receives the same protection as it would here.
In plain language: a few of the companies that run our website and email are based abroad. The rules protecting your information travel with it.
11. How long we keep your information
Type of information
Enquiries that do not become cases
Immigration case records
Support and counselling records
Financial and accounting records
Website and advertising data
How long we keep it
12 months from your last contact with us
6 years from the closure of your file
6 years from our last contact with you
6 years plus the current financial year
26 months
Why
So we can respond and follow up
Required by the Immigration Advice Authority and to answer any complaint
Continuity of support and professional obligations
Charity and tax law
Understanding how people find and use the site
When a retention period ends, we delete the information or make it anonymous so that it no longer identifies you.
In plain language: we keep things for as long as our regulator and the law require, and then we get rid of them.
12. How we keep your information safe
We take appropriate technical and organisational measures to protect your information. Access to case records is limited to the members of our team who need them. We use secure email and storage, our website runs over an encrypted connection, and our team is trained in confidentiality.
No system can be completely secure. If a breach occurs that is likely to result in a risk to your rights, we will report it to the Information Commissioner's Office within 72 hours and will tell you where the law requires it.
In plain language: only the people helping you can see your file, everything is encrypted, and if something goes wrong we will say so.
13. Your rights
Under UK data protection law you have the right to:
-
Be informed about how we use your information, which is what this page is for
-
Access a copy of the information we hold about you
-
Have inaccurate information corrected
-
Ask us to delete information, where we are not required to keep it
-
Ask us to restrict how we use your information
-
Receive your information in a portable format
-
Object to certain uses, including any direct marketing
-
Withdraw consent at any time, where we relied on your consent
To exercise any of these rights, email help@aspeera.org with the word GDPR in the subject line, so that it reaches the right person quickly. We will respond within one month. There is no charge, and asking will never affect the service you receive from us.
Because case files are confidential, we will ask you to confirm your identity before we release information or make changes.
In plain language: you can ask us what we hold, ask us to fix it or delete it, and ask for a copy. Just email us and put GDPR in the subject. We will check it is really you, then deal with it within a month.
14. Children
Our services are provided to adults. Where we support a family, information about a child may form part of a case, and we handle it with the same care as any other sensitive information. We do not knowingly collect information directly from children through our website.
In plain language: we work with adults. Where a child is part of a family case, their details are treated with the same care as everything else.
15. Complaints
If you are unhappy with how we have handled your information, please tell us first at help@aspeera.org and we will try to put it right.
You also have the right to complain to the Information Commissioner's Office, the UK regulator for data protection, at ico.org.uk/concerns or on 0303 123 1113.
In plain language: come to us first, but you can always go to the regulator.
16. Changes to this policy
We may update this policy as our services or the law change. The date at the top shows when it was last revised. Where a change materially affects how we use your information, we will make that clear on the website.
17. How to contact us
Email: help@aspeera.org (please write GDPR in the subject line for data protection queries)
Post: Aspeera CIO, The Kiln, 2 Copenhagen Street, Worcester WR1 2HB, United Kingdom
We hope this has answered your questions. If it has not, please get in touch and we will explain.
This policy is written to address the requirements of the UK General Data Protection Regulation and the Data Protection Act 2018. It has not been reviewed by a solicitor and does not constitute legal advice.
