1. Welcome to Stream Foundation's Privacy Notice
Stream Foundation respects your privacy and is committed to protecting your personal data.
This Privacy Notice explains how we collect, use, store and share personal data through our website and in connection with our governance, research-related activities, events, funding activities, communications and general administration.
It should be read together with any more specific privacy information we may provide for a particular activity or interaction. This Privacy Notice supplements that information and is not intended to override it.
This Privacy Notice is intended to apply to our activities in the UK and the US. Depending on where you are located, additional rights may apply under local law.
In most cases covered by this Privacy Notice, Stream Foundation is the controller of the personal data described below.
2. Who we are and how to contact us
Stream Foundation is a company limited by guarantee in England and Wales (company number 16963638) and a registered charity in England and Wales (charity number 1218141).
Our registered office is:
7-9 Rathbone Street
London
W1T 1LY
United Kingdom
If you have any questions about this Privacy Notice or about how we use personal data, please contact us at:
contact@stream-foundation.com
We are registered with the Information Commissioner's Office under reference ZC144789.
3. Whose personal data we process
We may process personal data about:
- people who visit our website
- people who contact us
- people who sign up to receive updates from us
- people who register interest in, attend, speak at, or otherwise participate in our events
- trustees and prospective trustees
- people involved in trustee training
- research partners and other professional contacts
- people involved in invited funding requests, reviews, grant administration and reporting
- reviewers, advisers and assessors
- suppliers, consultants and service provider contacts
- people who make privacy requests, complaints or objections
The Foundation usually receives aggregated, anonymised or summary research outputs rather than personal data about research participants. Research partners, universities, think tanks and other organisations carrying out research will usually be responsible for providing participant-facing privacy information where they collect personal data.
Our website and activities are not directed at children, and we do not knowingly collect personal data from children.
4. What personal data we collect
Depending on your relationship with us, we may collect and use the following categories of personal data.
Category of personal data | Examples |
|---|
Identity and contact data | Name, email address, telephone number, postal address, organisation or employer, job title or role |
Communications data | Correspondence with us, enquiry content, attachments and documents you send to us, meeting notes, and records of responses, outcomes and follow-up actions |
Subscription and preference data | Records of your request to receive updates, communication preferences, consent records, unsubscribe records, and suppression records used to respect your opt-out choices |
Event data | Event registration details, attendance status and preferences, guest list information, speaker or panel participation details, biographies and profile information, travel information where relevant, accessibility requirements where relevant, dietary requirements where relevant, photographs, audio or video recordings where relevant, and post-event follow-up records |
Trustee and governance data | Appointment records, declarations of interest, board papers and minutes, attendance and training records, trustee correspondence, expense records, signatures, biographies and photographs, bank details for expenses where relevant, and statutory or governance records |
Funding and grant administration data | Named organisational contacts, CVs, biographies and professional background information, employment or publication history where relevant, project descriptions and application materials, budgets and finance contact details, reviewer comments and assessment notes, conflict declarations, payment details, and monitoring or reporting information |
Due diligence and compliance data | Conflict of interest information, governance and integrity check findings, reputational check results, sanctions screening results, anti-fraud screening records, and internal assessment notes linked to those checks |
Technical and website usage data | IP address, browser type, device type, operating system, technical log data, date and time of access, pages viewed, referring URL or source, cookie identifiers and similar online identifiers, and analytics data where analytics tools are enabled |
Rights request and complaint data | Details of your request, objection or complaint, identity verification information where necessary, correspondence and internal handling records, and response or outcome records |
Aggregated and anonymised information
We may also receive or create aggregated, anonymised or summary information. This does not identify an individual and is not personal data. If it is combined with personal data in a way that means an individual could be identified, we will treat it as personal data.
Special category data
We do not expect to process large amounts of special category data. However, we may occasionally collect limited sensitive information where relevant to a particular activity, for example accessibility or dietary requirements for an event, or other information you choose to provide so that we can make arrangements you have requested.
5. How we collect your personal data
We collect personal data in the following ways:
5.1 Directly from you
For example when you:
- contact us
- sign up for updates
- register interest in an event
- attend or speak at an event
- act as a trustee or prospective trustee
- take part in trustee training
- submit or support an invited funding request
- make a privacy request or complaint
5.2 From your organisation or another person acting on its behalf
For example where:
- your organisation nominates you as a contact
- a trustee, research partner, applicant, reviewer or adviser introduces you to us
- a colleague provides your details as part of a project, event or grant process
5.3 From public sources
For example:
- professional profiles
- organisation websites
- published biographies
- public registers
- public sanctions or regulatory sources where proportionate checks are carried out
5.4 Automatically through our website
When you use our website, we may automatically collect limited technical and usage information through server logs, cookies and similar technologies.
6. How we use your personal data and our lawful bases
We only use personal data where we have a lawful basis to do so.
Purpose | Personal data used | Lawful basis |
|---|
Responding to enquiries and managing communications | Identity and contact data, communications data | Legitimate interests - to administer the Foundation and respond to communications |
Sending Foundation updates | Identity and contact data, subscription and preference data | Consent. We may also retain limited suppression information where necessary to respect opt-out preferences |
Organising and running events | Identity and contact data, event data, communications data | Legitimate interests - to organise and administer Foundation events |
Managing speaker, panel and contributor participation | Identity and contact data, event data, biographies, photos, communications data | Legitimate interests - to organise, run and communicate about Foundation events and activities |
Appointing and administering trustees and trustee training | Identity and contact data, trustee and governance data, communications data | Legal obligation where we need to keep records and comply with charity, company or other legal requirements, and legitimate interests to ensure good governance and proper administration of the Foundation |
Identifying, engaging and managing research partners and professional contacts | Identity and contact data, communications data, professional background information | Legitimate interests - to carry out the Foundation's research and public education activities |
Assessing and administering invited funding requests and grants | Identity and contact data, funding and grant administration data, communications data, due diligence and compliance data | Legitimate interests - to assess and administer the Foundation's funding activities; legal obligation where accounting, audit, regulatory or governance requirements apply; contract where we enter into an agreement directly with an individual |
Carrying out proportionate due diligence, conflict and compliance checks | Identity and contact data, due diligence and compliance data, communications data | Legitimate interests - to protect the Foundation and ensure its activities are properly governed; legal obligation where a particular check is required by law or regulatory expectation |
Managing suppliers and service providers | Identity and contact data, communications data, contract and payment information, due diligence and compliance data | Legitimate interests - to operate the Foundation effectively; contract; legal obligation where financial, tax, accounting or audit requirements apply |
Operating, securing and improving our website | Technical and website usage data | Legitimate interests - to operate, secure and improve our website; consent where non-essential cookies or analytics tools are used |
Handling privacy requests, complaints and legal matters | Identity and contact data, rights request and complaint data, communications data | Legal obligation where data protection laws require us to respond to requests; legitimate interests to manage complaints and protect the Foundation's legal position |
Updates and communications preferences
If you sign up to receive updates from us, we will use your details to send you Foundation-related communications such as research publication alerts, event announcements and occasional news.
You can unsubscribe at any time by using the unsubscribe link in our emails or by contacting us.
We do not sell personal data and do not share your personal data with third parties for their own direct marketing purposes.
Sensitive information for events and similar activities
Where we collect accessibility or dietary information, or similar information that may reveal health or other sensitive details, we will only do so where relevant and lawful, usually because you have chosen to provide it to us so that we can make arrangements you have requested and, where required, with your explicit consent.
7. Research and participant data
The Foundation funds and supports research, but usually receives aggregated, anonymised or summary outputs rather than personal data about research participants.
In most cases, research partners, universities, think tanks and other organisations carrying out research will be responsible for informing participants how their personal data is used.
If a specific research project requires the Foundation to process participant-level personal data, we will ensure appropriate safeguards are in place and that participants are provided with specific privacy information at that time.
8. Who we share personal data with
We may share personal data where necessary with:
- trustees and authorised Foundation personnel
- service providers who help us operate the website, events, communications, storage, administration or payments
- research partners, reviewers, advisers or professional contacts where relevant to a Foundation activity
- venues, event organisers, travel providers or production partners where relevant to an event
- professional advisers, including legal, audit, compliance or other specialist advisers
- regulators, law enforcement bodies, courts or other authorities where we are required or permitted to do so
- providers of administrative, technical, legal, finance or event support used by the Foundation, including support made available by affiliated organisations where necessary
The Foundation operates independently but receives donated support, facilities, and services from Stream Group Holdings and its affiliated entities. When Stream staff provide this support (for example, providing legal, finance, engineering, or event coordination assistance), they act under the direction of the Foundation.
We require service providers and support providers who process personal data for us to protect it and use it only for appropriate purposes.
9. International transfers
Some of our service providers, professional contacts or support personnel may be located outside the UK, including in the United States.
Where personal data is transferred outside the UK, we will take steps to make sure it is protected in line with applicable data protection laws. These steps may include using adequacy regulations, standard contractual clauses, or other lawful transfer mechanisms.
10. How we keep personal data secure
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
These measures may include access controls, restricted permissions, logical separation of Foundation data within shared systems, secure storage, and appropriate governance over service providers and support arrangements.
We limit access to personal data to people and organisations that need it for an appropriate Foundation purpose.
No system is completely secure, but we take proportionate steps to protect the personal data we hold.
11. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the relevant purpose, including to meet legal, accounting, tax, audit, governance, regulatory or reporting requirements, and to establish, exercise or defend legal claims.
Where appropriate, we aim to align retention periods with the wider retention framework used across Stream entities, while applying it appropriately to the Foundation's own activities.
In summary:
- enquiry and professional contact records are usually kept for a limited period after our last substantive interaction
- update subscription data is kept until you unsubscribe or withdraw consent, with limited suppression data kept afterwards so we can respect your opt-out
- event records are usually kept for a limited period after the event, unless they need to be kept longer for finance, complaints, recordings or governance purposes
- trustee, governance, grant, contract, finance and compliance records may be kept for longer, where required for legal, regulatory, audit or governance purposes
- privacy requests and complaint records may also be kept for a reasonable period to demonstrate compliance and manage legal risk
Some records may need to be kept for significantly longer, or in limited cases permanently, where required for statutory, constitutional, governance, audit or legal reasons.
12. What happens if you do not provide personal data
You do not have to provide personal data to us in every case.
However, if you do not provide information we reasonably need, we may be unable to:
- respond to your enquiry
- send you updates you have asked for
- register you for an event or make appropriate arrangements
- consider a funding request or manage a grant
- appoint or administer you as a trustee
- process expenses or payments
- comply with legal or governance obligations
13. Automated decision making
We do not expect to make decisions about individuals based solely on automated processing in the activities covered by this Privacy Notice.
If that changes for a particular activity, we will update this Privacy Notice or provide additional privacy information where appropriate.
14. Third-party links
Our website may include links to third-party websites or resources.
If you follow a link to a third-party website, that website will have its own privacy information and practices. We are not responsible for those third-party privacy practices.
15. Cookies
Our website may use cookies and similar technologies.
We expect to use:
- strictly necessary cookies required for the operation, security and basic functionality of the website
- analytics cookies to help us understand website usage and improve the website
We do not intend to use marketing or retargeting cookies unless this changes in future.
Where non-essential cookies are used, we will ask for your consent before placing them on your device.
If you disable or refuse cookies, some parts of the website may not function properly.
More information about the cookies used on our website, including their purposes and retention periods, will be set out in our Cookie Notice.
16. Your rights relating to your personal data
Depending on the circumstances and the laws that apply, you may have rights to:
- request access to your personal data
- request correction of inaccurate or incomplete personal data
- request deletion of your personal data
- request restriction of processing
- object to processing based on legitimate interests
- withdraw consent where we rely on consent
- request portability of certain personal data
- complain to a regulator
These rights are not absolute and may not apply in all cases.
How to exercise your rights
To exercise your rights, please contact us using the details in section 2.
We may ask you for information to help us confirm your identity before responding to your request.
You will not usually have to pay a fee to exercise your rights, although we may be entitled to charge a reasonable fee or refuse to act on a request if the law allows us to do so, for example if a request is manifestly unfounded or excessive.
We will respond without undue delay and, in most cases, within the timeframe required by applicable law. This will often be within one month of receiving your request. Where the law allows, we may take longer for complex requests or where you have made multiple requests, but if that happens we will let you know.
Complaints
If you have a concern about how we use your personal data, please contact us first so that we can try to resolve it.
If you are not satisfied with our response, or you believe our use of your personal data does not comply with applicable law, you also have the right to complain to the Information Commissioner's Office, or another relevant regulator where applicable.
17. Where another organisation is responsible for your personal data
In some cases, another organisation may be responsible for personal data connected with a particular activity.
For example, where a research partner, university, think tank or other organisation collects personal data from research participants for its own research activity, that organisation will usually be responsible for providing participant-facing privacy information.
If another organisation is acting as controller for a particular activity, its privacy information will also apply.
18. Changes to this Privacy Notice
This Privacy Notice is version Privacy Notice: 2026_1 and was last updated on 9th June 2026.
We may update this Privacy Notice from time to time. We will post any changes to this Privacy Notice on this page.
If we make material changes, we will take appropriate steps to let people know, for example by updating this page or providing additional notice where appropriate.