If someone is in immediate danger, call 999.Safeguarding and urgent help

Data Processing Agreement policy

PUCIC’s operational requirements for processing personal data with service providers and on behalf of other organisations.

Published for the limited information launchReview: every 12 months or sooner where UK law requires

Purpose and legal status

Phoenix Utd CIC is an active Community Interest Company, company number 11027177. Its registered office is Office 1 Izabella House, 24–26 Regent Place, Birmingham, B1 3NJ. References to “PUCIC”, “we”, “us” and “our” in these documents mean Phoenix Utd CIC.

This public Data Processing Agreement policy sets the minimum operational terms PUCIC expects when it acts as a processor for another organisation or appoints a processor to handle personal data. It is not a substitute for a signed, transaction-specific data processing agreement.

Processing instructions and confidentiality

Personal data must be processed only on documented instructions, unless law requires otherwise. People authorised to process data must be subject to confidentiality duties and receive appropriate training. Processing purposes, categories, duration, data subjects and instructions must be specified in the relevant signed schedule.

Security and sub-processors

ProviderRole in the PUCIC serviceCurrent or planned use
ManusWebsite hosting, application infrastructure and analyticsWebsite operation and aggregated site measurement
Microsoft 365Organisational emailMicrosoft 365 is not used for the initial attachment-free referral workflow.
MailchimpNewsletter processorEmail-only double-opt-in newsletter when activated
Google MapsVisitor-requested map serviceMap panel is loaded only after a visitor requests it
CloudflareWeb-security and delivery servicesWhere enabled for PUCIC web delivery

Processors must use appropriate technical and organisational measures, restrict access, assist with security assessment and obtain written authorisation before appointing a new sub-processor where required. PUCIC must be told of material sub-processor changes in sufficient time to assess them.

Rights requests, incidents and assistance

Processors must promptly support PUCIC with data-subject rights requests, impact assessments, audits and relevant regulatory enquiries. A personal-data incident must be reported to PUCIC without undue delay, with enough information for PUCIC to assess the incident and meet its own obligations.

Return, deletion and audit

At the end of a service, personal data must be returned or deleted as agreed, unless retention is required by law. For PUCIC secure referrals, the approved period is 24 months before deletion. The initial workflow is attachment-free: it removes the encrypted referral record and its audit trail after the retention period. Any unexpected historic attachment record blocks automated deletion for documented manual physical-deletion review. Relevant compliance records must be available for reasonable audit.

Need to raise a policy question?

For policy and accessibility questions, contact Policy@pucic.co.uk. For personal-data and privacy questions, contact DPO@pucic.co.uk.