OFFICE FOR REPAIR

                 [oFR]

systems and spatial 
design studio


OFFICE FOR REPAIR

                [OFR]

systems and spatial 
design studio
OFR Privacy Notice
Last updated: July 2026
Version: 1.0

This notice explains how Office for Repair (OFR) collects, uses, stores and protects your personal information, and the rights you have over it. It covers everyone whose data we hold: people who apply to work with us or join our network, the clients, funders and partners we work with, our suppliers and collaborators, the people who take part in our research and community work, people who come to our events, our team, and people who contact us or visit our website.

We may update this notice from time to time. When we do, we will change the date at the top and, where the change is significant, let affected people know.

This is version 1.0. The current version will always be on our website (ofr.works).
WHO WE ARE
Office for Repair is a not-for-profit Community Interest Company registered in England (company number 14326015, registered office Studio 133, Canalot Studios, Kensal Road, London, England, W10 5BN). For the purposes of data protection law, OFR is the data controller for the personal information covered by this notice, and is responsible for it.

You can reach us at hello@ofr.works.
THE INFORMATION WE COLLECT
We collect different information depending on your relationship with us.

People who visit our website. We use SimpleAnalytics, a privacy-first, cookieless analytics tool, to understand how our website (ofr.works) is used. It collects limited, largely anonymised information such as a shortened IP address, the pages viewed, the site you came from, your country, and your browser and device type. It does not set cookies and does not track you across other websites, so our website does not need a cookie banner for this. Our legal basis is our legitimate interest in improving our website. You can opt out by turning on Do Not Track in your browser.

People who email us. Your email address and whatever you choose to tell us. We keep that correspondence only as long as we need it to deal with your query and any follow-up.

People who take part in our research, engagement and community work. Depending on the project, this may include your name, age, profession, pronouns, your relationship to the place being studied, contact details, and the views and experiences you share with us through surveys, interviews, workshops and time spent together. We sometimes record this work in writing, photographs, audio or film, and where we do we obtain your consent first, on the same basis described under events below.

People who attend our events. Name, contact details, the languages you speak, and any accessibility, dietary or other requirements you tell us about. We ask about accessibility needs and languages so we can cater to you properly and make our events as inclusive as possible.

Clients, funders and project partners. Name, job title, organisation, postal address, phone number and email address, along with the information we need to agree and deliver a project and to meet our reporting obligations.

Suppliers, freelancers and collaborators. Name, job title, pronouns, contact details, and the information we need for due diligence, contracts and payments.

Our team. For the people who work at OFR we hold contact details, home address, emergency contact details, employment and education history, and the payment and tax information we need to employ you and meet our legal obligations.

People who apply to work with us or join our network. Your name, pronouns, email address and phone number; the languages you speak; your profession, qualifications, experience and software skills; the OFR principles and work strands you align with; a short written statement; links to your CV or profile and to examples of your work, and the contents of those links when we open them; your invoicing status; your eligibility to work in the UK if you provide it; your location, availability and preferred working arrangements; any rate or income expectations you share; and your responses to our consent questions.

Our social media. We share our work on social media, including Instagram and LinkedIn. If you interact with us there, those platforms process your data under their own privacy policies, which we would encourage you to read. We sometimes use the platforms' own analytics to understand how our posts are seen.

How we receive your information. We collect it directly from you (by email, phone, social media, a form, a procurement process, or at an event); from publicly available sources (such as Companies House, a website or a public social media profile); and from service providers (such as analytics providers, if we use them).
Special and sensitive information
Some information needs extra care under data protection law, including information about your health, racial or ethnic origin, religious or philosophical beliefs, sexual orientation or political opinions, and information about criminal records.

We do not usually ask for this. Where we do, it is because:

  • We are running an event and need to know about health, access or dietary requirements so we can include you properly.
  • We want our engagement and community work to represent people fairly, and may ask about ethnicity, beliefs or lived experience for that reason.
  • We work in settings, such as schools, where background checks are required. Our team members hold up-to-date DBS certificates, and we ask suppliers or partners to provide one where they will be working with children or vulnerable adults. DBS information is criminal offence data, which we handle with particular care and keep only as long as we need it to confirm suitability.

People sometimes also choose to share sensitive personal experiences with us during research, engagement or community work, which can reveal this kind of information.

Some of our engagement and community work involves children and young people. We treat their information with particular care and work through schools, guardians or partner organisations where appropriate.

Where we hold sensitive information, we do so with your consent, and we keep a record of that consent. If you would rather not share it, we will adapt the event or project to include you as fully as we can. We treat this information with particular care and, wherever possible, anonymise it before using or sharing it.

When we work with displaced people and other communities in vulnerable situations, our baseline is to hold as little identifiable information as possible. We do not photograph or film individuals in any identifiable way, we avoid holding identifying details, and we encourage people to use aliases. We adapt our consent process to each context, including using spoken rather than written consent where that helps, so that people can genuinely understand and agree to what we are asking of them.
WHY WE USE YOUR INFORMATION
Delivering our projects and services. To agree, run and report on our work with clients, funders and partners. Our legal basis is performing our contract with you, or our legitimate interest in delivering and reporting on our projects.

Recruitment and our network. To consider you for openings and for freelance, part-time or project-based work, and to keep you in our network so we can contact you when something relevant comes up. Our legal basis is your consent, given through the form. If you have given separate permission, we may pass your details to trusted partners and collaborators when a brief fits; our legal basis for that is your separate consent.

Research, engagement and community work. To understand people's needs, experiences and relationships to place, to inform our projects, and to contribute to the wider field. Our legal basis is your consent.

Running events. To organise and host events and to look after the people who attend. Our legal basis is your consent, or our legitimate interest in running the event.

Employing our team. To manage our working relationship, pay you, look after your wellbeing and safety, and meet our legal obligations as an employer. Our legal basis is performing our contract with you and meeting our legal obligations.

Business administration. To manage our relationships with suppliers and collaborators, process payments, keep proper records, and meet our financial and legal obligations. Our legal basis is performing our contracts and meeting our legal obligations.

Keeping in touch. To share updates relevant to an existing relationship and invitations to our and others' events. Our legal basis is our legitimate interest in staying in contact with the people we work with.
Photography and film
We always ask for your consent before photographing or filming you at an event or during our engagement and community work, and you are free to say no.

If you agree and later change your mind, even after we have published the material, email us at hello@ofr.works and we will do our best to remove it from our own channels. Please be aware that once material is in the public domain, or has been published by our clients or partners, we cannot control or guarantee its removal from those places.
HOW LONG WE STORE YOUR INFORMATION
We keep personal data only as long as we need it for the purpose we collected it, and we review it periodically. As a general guide:

  • Applications for a specific advertised position: 12 months after that recruitment closes, unless you also join the network.
  • Network applications: 24 months. Before that ends, we will ask whether you would like to stay. If you do not confirm, or ask us to remove you sooner, we will delete your details.
  • Client, funder, supplier and contract records: six years after the project ends, to meet our legal, tax and accounting obligations and in case of any dispute.
  • Financial records: six years, as required by HMRC and company law.
  • Research and engagement data: for the life of the project. We keep identifiable information to a minimum and delete it as soon as it is no longer needed; data that has been anonymised is no longer personal data and may be kept indefinitely for research or statistical purposes.
  • Team records: for the length of your employment and for six years afterwards.

If you withdraw your consent and we are not legally required to keep the data, we will delete it.
WHO WE SHARE IT WITH
We do not sell your data, and we do not share it publicly or with our clients without your explicit consent. Where research or engagement data forms part of our work and we do not have consent to attribute it, we anonymise it before sharing.

We share personal data only with:

  • People within OFR involved in the relevant work.
  • Partners and collaborators, where you have given consent (for network members) or where they are delivering a project with us.
  • Service providers who run our systems on our instructions, including Airtable, Google Workspace, Xero, and Anna.
  • Professional advisers such as accountants, lawyers and insurers, where needed to run OFR properly.
  • Funders and public bodies, where a funder or the law requires us to report.

We sometimes facilitate events for other organisations. In those cases your data is controlled by that organisation and shared with us, and we use it in line with their privacy notice.
DATA STORAGE
Most of the data we process is held in the UK and the EEA. Some of our service providers, including Airtable and Google, are based in the United States, so your information may be transferred to and stored outside the UK. Where data is transferred outside the UK, we rely on approved safeguards (such as the UK-approved Standard Contractual Clauses with the UK Addendum, or an International Data Transfer Agreement) so that it receives an equivalent level of protection.
YOUR RIGHTS
Under UK data protection law you have the right to:

  • Ask for a copy of the personal information we hold about you, and to be told where we got it, who we share it with, and the safeguards we use for any international sharing.
  • Ask us to correct information that is wrong or incomplete.
  • Ask us to delete your information.
  • Ask us to restrict or object to how we use it.
  • Ask us to transfer your information to you or another organisation.
  • Withdraw your consent at any time, where consent is our basis.
  • Not be subject to a decision made solely by automated means (we do not do this; see below).
  • Be told about any data breach that is likely to put your rights at serious risk.

To exercise any of these, email us at hello@ofr.works. You can ask verbally or in writing. We will respond within one month, unless your request is particularly complex. There is no charge, though we may apply a reasonable fee or decline if a request is clearly unfounded or excessive, and we will tell you if so. We may ask you to confirm your identity before we release information.
SOFTWARE AND AUTOMATION
We use software tools, including AI-assisted tools, to help us organise, sort and process the information we hold, so we can work efficiently. These tools support our team; they do not act on their own.

We will never use them to make decisions about you, to contact you automatically, or to share your data outside OFR. Any decision that affects you is made by a person, and your information stays within OFR unless you have given consent for it to be shared, or the law requires it. This applies to all the information we hold, not only to job applications.
THINGS WE DON'T DO
To be clear about our limits, OFR does not:

  • Buy or sell marketing or contact lists.
  • Enter into data-sharing agreements that let other organisations use your data for their own purposes.
  • Send postal marketing.
  • Use "soft opt-in", meaning you will not receive marketing from us unless you have specifically agreed to it.
KEEPING YOUR DATA SECURE
We choose our tools and service providers carefully and review their privacy and security practices before we use them. We limit access to personal data to the people who need it, and we brief our team on keeping their accounts, devices and any fieldwork data secure.

If a data breach happens that is likely to put your rights and freedoms at risk, we will assess it and, where appropriate, tell the people affected and the relevant authorities without undue delay, and within 72 hours of becoming aware of it where feasible. Where the law requires it, we will report the breach to the Information Commissioner's Office and follow their guidance.
HOW TO COMPLAIN
If you are unhappy with how we have handled your information, please contact us first at hello@ofr.works so we can try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator:

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
0303 123 1113
ico.org.uk