Privacy & Personal Information Policy

Operated by Mental Health Support Community Limited (Company No. 16674444) · Last updated: 16 June 2026

UK GDPR compliant • Community-first • Transparency & Safety

Policy Purpose

The Mental Health Support Community Limited (MHSC Ltd, Company No. 16674444) is committed to protecting the privacy and personal information of its members and volunteers. This policy outlines the standards and procedures for collecting, using, storing, and sharing personal information to ensure compliance with legal and ethical guidelines.

Data Controller & ICO Registration

  • Data Controller: Mental Health Support Community Limited (MHSC Ltd), Company No. 16674444.
  • UK ICO Registration: ZB980446 (Information Commissioner’s Office).
  • Register entry: Search our entry on the ICO public register at ico.org.uk/register using the reference above.
  • Data protection contact: privacy@mentalhealthsupportcommunity.org.

Scope

This policy applies to all members, volunteers, and any other individuals interacting with MHSC’s platforms, services, and resources. It covers all personal information collected, stored, and processed by MHSC Ltd, whether electronically or physically.

Key Principles

🔎

Transparency

Clear communication on how personal data is collected, used, and stored.

Consent

Personal information is collected with informed consent, except where required by law.

📦

Minimal Collection

Only the information necessary for MHSC operations is collected.

🔐

Confidentiality

Data is protected from unauthorised access or disclosure.

🧭

Accountability

MHSC Ltd takes full responsibility for compliance.

⚖️

Legal Compliance

We comply with UK law and GDPR obligations.

Lawful Basis for Processing

  • Consent – when members or volunteers voluntarily provide information (e.g., registration, surveys, feedback). Where we rely on consent, you have the right to withdraw it at any time by contacting privacy@mentalhealthsupportcommunity.org. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
  • Legitimate Interests – to maintain platform security, prevent misuse, ensure community safety, and improve services.
  • Legal Obligation – where required to comply with applicable laws or regulations.

Definitions

  • Personal Information: Any data that identifies or can reasonably be used to identify an individual, such as names, email addresses, IP addresses, Discord usernames, Discord IDs, or demographic details.
  • Sensitive Information: Includes, but is not limited to, health data, financial information, or details related to racial or ethnic origin, religion, or sexual orientation.
  • Data Processor: A third-party organisation that processes personal data on behalf of MHSC Ltd under a data processing agreement or equivalent safeguard.

Collection of Personal Information

MHSC Ltd collects personal data to:

  • Facilitate registration and participation in community activities.
  • Enable communication between members and volunteers.
  • Provide tailored support and resources.
  • Monitor platform activity for security and safety purposes.

Methods of Collection

  • Registration forms (e.g., Discord and the Volunteer Portal).
  • Volunteer Portal submissions may include Discord identifiers such as Discord Username and Discord ID to link accounts, manage access, and support safeguarding, moderation, volunteer management, and platform security.
  • Voluntary submissions, such as surveys or feedback forms.
  • System-generated data, such as IP addresses and activity logs.
  • Discord bot interactions, where member data is accessed transiently through Discord’s API to perform bot functions as described in the Discord Bots section below.

Use of Personal Information

  • Operational Purposes: Managing accounts, communications, and access.
  • Community Safety: Monitoring activity to prevent rule violations, abuse, or misuse.
  • Improvement of Services: Analytics to develop and enhance MHSC services.
  • Legal Compliance: Complying with UK law and GDPR obligations.

Prohibited Uses

  • MHSC Ltd will never sell personal data.
  • Personal data will not be shared externally without explicit consent, except where legally required.
  • Personal data will never be used to train machine learning or artificial intelligence models.

Cookies

MHSC’s website uses cookies — small text files placed on your device — to support the operation and security of our platform. We use the following categories of cookies:

  • Essential cookies: Required for the website to function correctly, including session management, login authentication, and security tokens (e.g., WordPress login cookies, nonces). These cannot be disabled.
  • Functional cookies: Used to remember your preferences and improve your experience, such as language settings or consent choices.
  • Analytics cookies: Where analytics tools are in use, these help us understand how visitors interact with our website so we can improve it. No personally identifiable information is collected through analytics.

You can control cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of the site. By continuing to use our website, you consent to our use of cookies as described above.

Third-Party Data Processors

MHSC Ltd uses the following third-party platforms as data processors. Each operates under their own privacy policy and terms of service, which we encourage you to review:

  • Discord Inc. — Primary community platform. Discord Privacy Policy
  • BotGhost — Platform used to host and operate MHSC Core bot functionality. BotGhost Privacy Policy
  • Dyno — Platform powering MHSC Security bot moderation features. Dyno Privacy Policy
  • Google — Used for productivity, email, and related services.
  • SupportCandy — Website support ticket system (WordPress plugin). Data remains within MHSC’s own WordPress environment.

MHSC’s internal automation workflows are operated on a self-managed private VPS under MHSC’s direct control and do not involve any third-party data processors.

Support Tickets (SupportCandy)

When you contact us through our website support system (powered by SupportCandy), we collect the personal information you provide, such as your name, email address, and the content of your message or ticket. This information is used solely to respond to your enquiries and to manage and resolve support requests.

  • Storage: Ticket data is stored within MHSC’s systems (WordPress database) and is accessible only to authorised volunteers.
  • Retention: Ticket data is retained for up to 12 months after resolution, unless a longer period is legally required or you request earlier deletion where applicable.
  • Sensitivity: Please avoid submitting medical details or other highly sensitive personal information in tickets. If sensitive information is necessary, we will handle it in line with this policy.

Data Retention Schedule

MHSC Ltd retains personal data only for as long as necessary for the purpose for which it was collected, or as required by law. The following schedule summarises our key retention periods:

Data Type Retention Period Notes
Website support ticket data 12 months after resolution Stored in WordPress database, accessible to authorised volunteers only
Moderation and security records (banned users) Indefinitely while ban is active Reviewed periodically for continued necessity
Volunteer portal data Duration of volunteering + 12 months Securely deleted or anonymised after retention period
IP address logs (volunteer security checks) 12 months Used solely for alternative account detection and security
Discord bot data (member objects, message content) Not retained — processed transiently Accessed at point of function execution only; not stored outside Discord
Activity logs (system-generated) Up to 6 months Used for security monitoring and platform integrity

Moderation and Security Data Checks

Overview

MHSC Ltd maintains internal security measures and moderation tools, including an internal moderation check system that stores limited personal data (e.g., Discord ID, IP address, region) to protect our community.

When we retain limited data
  • Permanently banned users for safety or misconduct reasons.
  • Previously banned volunteers.
  • Applicants for moderator or elevated access roles.

These records are stored securely and are only accessible to the Director or authorised individuals for the sole purpose of detecting alternative accounts or preventing re-entry following serious policy breaches.

Users who are checked but not flagged are not retained in this system. Records are reviewed periodically for relevance and necessity.

This process is not automated. No profiling or decision-making occurs without human review.

Storage and Security

  • Access Control: Only authorised personnel can access personal information, based on their roles and responsibilities.
  • Encryption: Data stored within MHSC’s systems is protected using industry-standard security practices.
  • Retention: Personal information will be retained only as long as necessary for operational or legal purposes, as set out in our Data Retention Schedule above. After this period, data will be securely deleted or anonymised.

International Data Transfers

MHSC Ltd uses third-party platforms (e.g., Discord, Google, BotGhost) that may operate outside the UK/EU. Where data is transferred internationally, MHSC Ltd ensures appropriate safeguards (e.g., Standard Contractual Clauses) are in place to protect it in line with UK GDPR. MHSC’s internal automation workflows are hosted on a self-managed private VPS under MHSC’s direct control and do not involve international data transfers.

Use of Discord

MHSC primarily operates on Discord, which is a third-party platform owned and managed by Discord Inc. While MHSC applies its own privacy and data protection standards within our community, we do not control Discord’s systems, security, or data handling practices. Members and volunteers should review Discord’s Privacy Policy and Terms of Service for details on how Discord processes their personal information.

Discord Bots

MHSC Ltd operates several custom Discord bots within our community server to support moderation, member management, and community operations. These bots may access member data available through Discord’s API, including Discord usernames, Discord IDs, display names, join dates, and server presence, solely to perform their designated functions.

Our Bots

  • MHSC Core — Community management and support bot built on BotGhost’s platform and integrated with internal automation workflows hosted on MHSC’s private VPS. Accesses member and message data transiently to detect and route support requests, manage roles, and automate community operations. No member or message data is stored outside of Discord.
  • MHSC Security — Server moderation and security bot powered by Dyno. Accesses member and message data for automated moderation, spam detection, content filtering, and action logging within Discord.
  • MHSC Greeter Bot — Welcome bot used exclusively by our greeter team volunteers via a designated slash command. Accesses member data at the point of command execution solely to generate a personalised welcome message. No data is retained beyond command execution.

Data Handling

  • Bot data access is limited to what is strictly necessary for each bot’s designated function.
  • No member data retrieved by MHSC bots is stored outside of Discord beyond what is explicitly described above.
  • Message content accessed by MHSC bots is processed transiently and is not stored, logged, or used for any purpose other than the immediate function being performed.
  • No bot data is used to train machine learning or artificial intelligence models.
  • All bots operate in full compliance with Discord’s Developer Policy and Terms of Service.
  • Bot operations are covered by MHSC’s ICO registration (ZB980446).
  • To request deletion of any data held in relation to bot activity, contact privacy@mentalhealthsupportcommunity.org.

Sharing of Personal Information

  • Internal Use: Within MHSC, to facilitate operations (e.g., volunteers coordinating support efforts).
  • With Consent: When the individual provides explicit consent for a specific purpose.
  • Legal Obligations: When required to comply with legal processes or protect the safety of individuals.
  • Data Processors: With trusted third-party platforms listed in the Third-Party Data Processors section above, solely for the purposes described in this policy.

Volunteer-Specific Guidelines

Core Guidelines
  • Volunteers must not collect or request sensitive personal information from members, including real names, home addresses, phone numbers, financial details, or medical history.
  • Volunteers must use MHSC’s designated systems and platforms for communication and data handling.
  • Adhere to confidentiality policies outlined in the Volunteer Policy.
  • Maintain confidentiality of information shared in restricted volunteer areas (Support Channels, Moderator Channels, HR systems). Breaches may result in disciplinary action, including removal from role.
  • Do not provide support via direct messages (DMs). All support must take place in designated MHSC platforms such as Support Chats or Tickets to ensure safety and accountability.
  • Do not contact emergency services or external authorities on behalf of members. Instead, signpost individuals to professional or emergency resources.
  • Misuse of personal information may result in removal from role and reporting to relevant authorities.
  • Information disclosed as part of leave requests or the Reasonable Adjustments Program will be treated confidentially and only used to evaluate and support such requests.
Volunteer IP Information Collection

For roles with elevated access (e.g. HR and Senior Volunteers), MHSC Ltd may collect IP addresses to detect and prevent alternative account use and strengthen security within volunteer systems. This data is never used for location tracking and may be avoided using a VPN if preferred.

Age Restrictions

MHSC’s platforms are not directed to children under the age of 13 (or under 16 in certain jurisdictions, in line with Discord’s age requirements). We do not knowingly collect or store data from individuals below these age thresholds.

Volunteering Eligibility

  1. Volunteers must be at least 16 years old at the time of application, unless a legacy exception has been approved by HR.
  2. Volunteers under 18 are prohibited from providing support on sensitive topics, including sexual content, rape/assault, and substance misuse.

Member Privacy Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Access: Request access to your personal information held by MHSC.
  • Correction: Request corrections to inaccurate or incomplete personal information.
  • Deletion: Request the deletion of your personal information, subject to operational or legal requirements.
  • Restriction: Request that we restrict the processing of your personal data in certain circumstances.
  • Portability: Request a copy of your personal data in a structured, machine-readable format where applicable.
  • Objection: Object to processing based on legitimate interests where you feel your rights override those interests.
  • Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Enquiries: Submit questions or concerns about MHSC’s handling of personal information.

To exercise any of these rights, contact privacy@mentalhealthsupportcommunity.org. We will respond within one calendar month in line with UK GDPR requirements.

Data Breach Response

  • MHSC will promptly investigate the breach and assess its scope and impact.
  • Where required, breaches will be reported to the ICO within 72 hours of becoming aware of them, in line with UK GDPR obligations.
  • Affected individuals will be notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
  • Corrective actions will be taken to prevent future breaches.

Complaints and Feedback

If you have concerns about how MHSC handles your personal information, you may contact privacy@mentalhealthsupportcommunity.org.

If unresolved, escalate concerns to the UK Information Commissioner’s Office (ICO) at ico.org.uk or to your local supervisory authority if outside the UK.

Policy Review

This policy will be reviewed annually or as required to ensure compliance with evolving legal and operational standards. The date of the most recent review is shown at the top of this page.

Acknowledgment

By interacting with MHSC’s platforms or services, individuals acknowledge their understanding of and agreement with this policy. Volunteers will also sign an acknowledgment form during onboarding to confirm their commitment to privacy and data protection standards.

Community Platforms Access

Volunteers may be required to register accounts on MHSC’s Volunteer Portal and related platforms using their own email address and secure password. Accounts must be kept personal and not shared. Certain volunteer roles must enable Multi-factor Authentication (MFA) to further protect access to sensitive areas. Platform usage may be monitored for compliance with MHSC policies and to maintain system security.

Confidentiality in Volunteer Roles

Volunteers must maintain confidentiality regarding any information shared in restricted areas such as Support Channels, Moderator Channels, Senior Volunteer spaces, and HR communications. Sharing or disclosing this information outside designated spaces without authorisation is prohibited and may result in removal from the volunteer role.

This includes, but is not limited to: real names, home or business addresses, phone numbers, national identification numbers, and payment or financial information. Volunteers must also avoid requesting specific towns, postcodes, or other location identifiers beyond general region information (e.g., country or county).

Volunteers must adhere to MHSC’s Boundaries and Ethics guidelines when handling any personal information, refraining from offering advice beyond their scope, avoiding dual relationships that may compromise objectivity, and keeping all sensitive discussions within designated MHSC channels.