Legal and privacy

Privacy notice

Clear information about what TIFA Life collects through this website, why we need it, who may receive it and the choices available to you.

Last updated:

Controller
TIFA Life Ltd

Company
15145866

ICO registration
ZC131131

1. Who controls your information

TIFA Life Ltd is registered in England and Wales under company number 15145866. Our registered office is Unit 23, The Courtyard South Court, Woodlands, Bradley Stoke, Bristol, BS32 4NH. Our ICO registration is ZC131131.

For website enquiries, referrals, recruitment and the supported-accommodation records we create, TIFA Life will normally be a data controller. For activities carried out solely on a Local Authority's documented instructions, the relevant contract or data-sharing agreement sets out the parties' roles.

Our data-protection contact can be reached at hello@tifa.co.uk, by telephone on 01792 677275, or at the registered office above.

2. Who and what this covers

This notice covers visitors to life.tifa.co.uk; people who contact us or request a callback; Local Authority staff and other professionals making a referral; young people named in a referral; and applicants using our website careers form.

Young people who move into a TIFA placement, staff who join TIFA and users of TIFA Connect receive more specific privacy information about the operational records relevant to them. This website notice supplements, rather than replaces, those notices.

Where a professional gives us information about a young person, we obtain the information from that professional and the relevant Local Authority records. We expect the referring organisation to make the young person aware of the proposed sharing. We also provide appropriate privacy information directly when the placement proceeds, unless a documented legal exception applies.

3. Information we collect

Website visitors and enquiries

Contact details, organisation, enquiry type, message, callback preference, source page, IP address, device/browser information and basic security logs. Vercel Web Analytics provides aggregate page and event information without third-party tracking cookies or persistent cross-site identifiers.

Referrers and young people

Referrer name, role, Local Authority and contact details; the young person's initials, date of birth, gender, care status, urgency, location and accommodation needs; presenting circumstances, risks, restrictions, health and medication information, cultural and communication needs, missing or exploitation concerns, and the availability of statutory plans and assessments.

This can include special-category information about health, ethnicity, religion or sexual orientation, and information relating to alleged or proven offences. We ask for only what is necessary to assess whether an offer can be made safely.

Job applicants

Identity and contact details, preferred role and location, work history, qualifications, availability, CV, right-to-work status, references, Social Care Wales status, DBS status and other information you choose to provide. Please do not upload identity documents or a DBS certificate through the website form; originals are checked later through the controlled recruitment process.

4. Why we use it and our lawful bases

PurposeUK GDPR basis
Answer enquiries, callbacks and professional communicationsArticle 6(1)(f): our legitimate interest in operating and improving our services.
Assess and mobilise a referral safelyArticle 6(1)(f): legitimate interests in assessing suitability and delivering safe supported accommodation; Article 6(1)(c) where a specific legal obligation applies.
Health, social-care and safeguarding informationArticle 9(2)(h) with DPA 2018 Schedule 1 Part 1 paragraph 2 for health or social care; and, where necessary, Article 9(2)(g) with Schedule 1 Part 2 paragraph 18 for safeguarding children or people at risk.
Recruit and vet staffArticle 6(1)(b) for steps before employment; 6(1)(c) for legal obligations; and 6(1)(f) for fair recruitment and workforce planning. Additional DPA 2018 conditions apply to special-category and criminal-offence data.
Protect the site and understand aggregate useArticle 6(1)(f): security, abuse prevention, reliability and service improvement.

Consent is used only where it is genuinely optional, for example permission to check a DBS Update Service record or to retain an unsuccessful application in a future-opportunities pool. You may withdraw that consent at any time.

5. Who we share it with

Access inside TIFA is limited by role and need. Depending on the purpose, information may be shared with the placing Local Authority and relevant statutory professionals; safeguarding or emergency services where necessary; referees and lawful vetting bodies; and professional advisers, insurers or regulators.

Our website suppliers include Vercel for hosting, functions and privacy-focused aggregate analytics; Resend for delivery of referral, callback and contact emails; Supabase for the recruitment application workflow; and hCaptcha on recruitment pages for bot prevention when enabled. They process information under their contracts and security terms. We do not sell personal information or disclose referral information to advertising networks.

6. International transfers

Our website functions are configured to run in London, but internet infrastructure and some suppliers operate globally. Resend, Vercel, Supabase and hCaptcha may process or support information from the United States or other countries.

Where information is transferred outside the UK, we require an appropriate UK transfer mechanism, such as UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework where applicable, the International Data Transfer Agreement, or the UK Addendum to approved standard contractual clauses. Contact us if you would like more information about the safeguard relevant to a particular supplier.

7. How long we keep it

  • General website enquiries and callback records: normally up to 24 months after the last meaningful contact.
  • Referrals that do not proceed: normally 12 months after the decision, unless a safeguarding, dispute or legal reason requires longer.
  • Referrals that become placements: transferred into the operational record and retained under TIFA's safeguarding and contract retention schedule, normally at least seven years after the placement ends and longer where law, contract or an active concern requires it.
  • Unsuccessful recruitment applications: normally six months after the decision; up to 12 months where you agree to future-opportunity retention.
  • Security logs: normally up to 30 days. Aggregate analytics is not tied to a named person; Vercel's temporary visitor identification expires after 24 hours.

We may keep a minimal suppression, legal-claim or audit record for longer where necessary. Records are securely deleted or irreversibly anonymised when the retention purpose ends.

8. Automated tools and human decisions

We may use approved tools to check form completeness, detect abuse or help summarise and organise applications or reports. TIFA does not make a placement decision, safeguarding decision or recruitment rejection solely by automated means. A suitably authorised person reviews the source information and remains accountable for the decision.

If an automated tool materially assists the handling of your recruitment application, you may ask for an explanation or a fresh human review by contacting us.

9. Your rights

Depending on the lawful basis and circumstances, you may ask for access, correction, erasure, restriction or portability of your information, or withdraw consent. You may also challenge a decision and complain about how information has been handled.

Your right to object

You have the right to object to processing based on legitimate interests. Tell us what you object to and why. We will stop unless we can demonstrate compelling legitimate grounds or need the information for legal claims.

Email hello@tifa.co.uk. We may ask for proportionate proof of identity. We respond without undue delay and normally within one month.

If you remain unhappy, you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or call 0303 123 1113.

10. Security and contact

We use role-based access, multi-factor authentication where available, encrypted connections, controlled supplier access, logging and staff confidentiality requirements. No internet service can promise absolute security, so concerns should be reported promptly.

Contact: hello@tifa.co.uk · 01792 677275 · Unit 23, The Courtyard South Court, Woodlands, Bradley Stoke, Bristol, BS32 4NH.

We review this notice when our services, suppliers or law change. The current version and date will always appear on this page.

Urgent placement? Speak to the senior on-call team.

01792 677275 · answered 24/7