Privacy by design

Collect less. Explain more. Restrict access.

Applicants should understand what HIF collects, why it is needed, who can see it, how long it remains and how to ask for access, correction or deletion.

Data minimisation

Information grows only when the process requires it.

Identity documents and sensitive checks should not be collected during an initial application merely because they may be useful later.

01

Initial application

What
Contact details, general location, background, role responses and optional accessibility request.
Why
Assess eligibility and suitability and support an accessible process.
02

Later-stage checks

What
References, relevant credentials, registrations, police or child-safety checks where required.
Why
Verify only what is necessary for the role before onboarding.
03

Volunteer record

What
Agreement, induction, role, supervision, training, approved outputs and service history.
Why
Manage the volunteer relationship safely and accurately.
Your controls

Your information should not become a dead end.

View and correct

See core profile and application information and request corrections.

Enabled after production authentication

Download my data

Receive a usable copy of information linked to your account.

Enabled after production authentication

Delete my account

Request deletion subject to lawful or safety-related retention needs.

Enabled after production authentication

Withdraw consent

Leave talent pools and disable optional communications without affecting prior lawful processing.

Enabled after production authentication
Security and access

Sensitive data should have smaller audiences.

Separate records

Accessibility, safeguarding and complaint records are separated from routine assessment data.

Least privilege

Administrators receive only the permissions required for their current responsibility.

Secure storage

Encryption, access logs, restricted exports, backups and breach-response procedures are required.

Auditable decisions

Access, changes, exports, AI-supported recommendations and retention actions are logged.

Recommended retention schedule

Keep only what still has a purpose.

Final periods require legal, safeguarding and insurance review.

RecordRecommended periodAction
Incomplete application90 days after last activityRemind, then delete or anonymise
Unsuccessful application12 months unless consent says otherwiseDelete direct identifiers; retain de-identified analytics
Talent community12 months, renewed by consentPrompt for renewal or delete
Successful volunteer recordRole duration + legal/policy periodReview and securely delete at expiry
Safeguarding or complaint recordSeparate policy based on risk and lawRestricted review; never routine deletion
AI and your application

Every AI-supported recommendation must be visible and reviewable.

If AI assists with summarising, missing-information checks or evidence mapping, the administrator must be able to see the source, criterion, uncertainty and human correction. HIF must keep an automated-decision register even though AI does not make final decisions.

Read the AI controls