Pathways – Data Protection Policy

Version Information

Version: 1.0
Last updated: April 2026
Applies to: Pathways app users, website users, partner agencies, staff and contractors.

1. Purpose of this Policy

Pathways is committed to protecting the privacy and personal data of individuals who use the Pathways platform, particularly survivors of domestic abuse. This policy explains how personal data is collected, used, stored, shared, and protected in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data Controller

Pathways acts as the Data Controller for personal data processed through the Pathways app and website. Organisation: Pathways Email: support@path-ways.co.uk Website: www.path-ways.co.uk

3. Personal Data We Process

This includes identification and contact data, referral information, and special category data such as information relating to domestic abuse, safeguarding concerns, health or wellbeing, and information relating to children or family circumstances.

4. How Personal Data Is Collected

Personal data is collected directly from individuals, from partner agencies making referrals, through use of the Pathways app and website, and through secure communications linked to referrals.

5. Lawful Basis for Processing

Pathways processes personal data under Articles 6(1)(c), 6(1)(e), and 6(1)(f) of UK GDPR, and special category data under Articles 9(2)(g) and 9(2)(h).

6. How We Use Personal Data

Personal data is used to enable rapid referrals, reduce retraumatisation, support multi-agency collaboration, ensure safeguarding, and maintain the safe operation of the Pathways platform.

7. Data Sharing

Personal data is shared only where necessary with legal service providers, partner agencies, and statutory bodies, and is subject to appropriate safeguards and access controls.

8. Data Security

Pathways uses secure systems, restricted access controls, and appropriate technical and organisational measures to protect personal data. 9. Data Retention Personal data is retained only for as long as necessary to meet legal, safeguarding, and operational requirements and is securely deleted or anonymised when no longer required.

10. Individual Rights

Individuals have the right to access, rectify, restrict, or erase their personal data where applicable, and to lodge a complaint with the Information Commissioner’s Office (ICO).

11. Data Breaches

Any actual or suspected data breach is investigated promptly and reported to the ICO within 72 hours where required.

12. Review of this Policy

This policy is reviewed regularly to ensure it remains accurate, compliant, and effective

Get in Touch

Fill out the form below to get in touch with a member of our team