Skip to main content
m
mycasework.org
Statutory Compliance Notice

Privacy Policy

Last Updated: 3 September 2026 • Version 1.0 (Draft)

1. Who We Are & Key Data Roles

mycasework.org is a specialized casework management utility built for elected representatives across the United Kingdom (Members of Parliament, Members of Devolved Parliaments and Assemblies, and Local Authority Councillors).

Data Controller: The individual Elected Representative (or their statutory office) who receives your inquiry and determines why and how your personal data is processed to advocate on your behalf.

Data Processor: mycasework.org operates solely as a data processor on documented instructions from the representative, providing secure database infrastructure, email delivery, and triage tooling.

2. Personal Data We Collect

When you contact your elected representative via a public intake form, email, or advice surgery, the following data may be processed:

  • Contact Identification: Your full name, email address, phone number (optional), and UK postcode (used strictly to verify residence within the representative's constituency or electoral ward under GDPR Article 5(1)(c) data minimisation).
  • Third-Party Advocacy Details: If someone contacts the representative on your behalf (e.g. an adult child, carer, or advocate), their name and relationship to you are captured alongside your consent.
  • Case Narrative & History: The description of your inquiry, correspondence timeline, agency responses, and supporting evidence.
  • Special Category Data: Inquiries frequently involve sensitive personal matters, including physical or mental health conditions, social care requirements, housing distress, financial vulnerability, or immigration status.

3. Lawful Bases for Processing

Processing is conducted strictly under statutory conditions recognized by UK data protection law:

  • UK GDPR Article 6(1)(e) (Public Task): Processing is necessary for the performance of a task carried out in the public interest, specifically the constitutional function of elected representatives assisting their constituents.
  • UK GDPR Article 9(2)(g) & DPA 2018 Schedule 1 Part 2 Paragraph 23: Specifically authorizes elected representatives to process special category data (such as health, welfare, or safeguarding data) without requiring explicit formal consent when responding to requests from individuals.

4. Data Residency & Sub-processors

We strictly partition where constituent data is stored and processed:

Infrastructure LayerResidency RegionDetails
Database (Firestore) & FilesLondon, UK (europe-west2)All constituent records, cases, and documents stored strictly in the UK.
Compute & Web RenderingNetherlands / EEA (europe-west4)Stateless, in-memory compute under UK/EU GDPR adequacy regulations.

See our complete register of authorised sub-processors in our Sub-processors Directory.

5. Security Safeguards & Privacy Silos

  • Strict Role Silos: Casework is isolated to an individual RepresentativeRole. No other representative or administrative user in the organisation can view your casework.
  • Dual-Hatter Protection: Representatives holding dual offices (e.g. an MP who is also a Councillor) have completely segregated database partitions for each office.
  • In-Memory AI Redaction: When AI assistance is used to categorize inquiries, personal identifiers (names, postcodes, contact details) are masked in-memory before model dispatch. Foundation models never train on your casework.
  • Cryptographic Audit Trail: Every access, edit, and forwarding action is recorded in an immutable SHA-256 hash-chained audit log.

6. Data Retention & Scheduled Erasure

Constituent casework is retained only as long as necessary to resolve inquiries and meet statutory accountability obligations. When a representative leaves office, data is retained for a maximum 12-month handover window before scheduled purging. When an individual constituent requests erasure, records undergo a 30-day soft-delete grace window followed by automated irreversible hard deletion across database and storage systems.

7. Your Statutory Rights

Under UK GDPR, you have the right to request access to your data (Subject Access Request), request rectification of inaccurate records, request erasure, or object to processing under Article 21. When an Article 21 objection is registered, the system places a hard restriction on the case, halting automated triage and multi-agency forwarding.

To exercise your rights, contact your elected representative directly or submit an inquiry through their public contact page. If you believe your data has been handled unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).