Pathways – Data Protection Policy
Version Information
Version: 1.0
Last updated: April 2026
Applies to: Pathways app users, website users, partner agencies, staff and contractors.
1. Purpose of this Policy
Pathways is committed to protecting the privacy and personal data of individuals who use the Pathways platform, particularly survivors of domestic abuse. This policy explains how personal data is collected, used, stored, shared, and protected in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data Controller
Pathways acts as the Data Controller for personal data processed through the Pathways app and website. Organisation: Pathways Email: support@path-ways.co.uk Website: www.path-ways.co.uk
3. Personal Data We Process
This includes identification and contact data, referral information, and special category data such as information relating to domestic abuse, safeguarding concerns, health or wellbeing, and information relating to children or family circumstances.
4. How Personal Data Is Collected
Personal data is collected directly from individuals, from partner agencies making referrals, through use of the Pathways app and website, and through secure communications linked to referrals.
5. Lawful Basis for Processing
Pathways processes personal data under Articles 6(1)(c), 6(1)(e), and 6(1)(f) of UK GDPR, and special category data under Articles 9(2)(g) and 9(2)(h).
6. How We Use Personal Data
Personal data is used to enable rapid referrals, reduce retraumatisation, support multi-agency collaboration, ensure safeguarding, and maintain the safe operation of the Pathways platform.
7. Data Sharing
Personal data is shared only where necessary with legal service providers, partner agencies, and statutory bodies, and is subject to appropriate safeguards and access controls.
8. Data Security
Pathways uses secure systems, restricted access controls, and appropriate technical and organisational measures to protect personal data. 9. Data Retention Personal data is retained only for as long as necessary to meet legal, safeguarding, and operational requirements and is securely deleted or anonymised when no longer required.
10. Individual Rights
Individuals have the right to access, rectify, restrict, or erase their personal data where applicable, and to lodge a complaint with the Information Commissioner’s Office (ICO).
11. Data Breaches
Any actual or suspected data breach is investigated promptly and reported to the ICO within 72 hours where required.
12. Review of this Policy
This policy is reviewed regularly to ensure it remains accurate, compliant, and effective