We keep this privacy notice under regular review and was last updated on 14 September 2026.

We respect your privacy and is committed to protecting your personal data. This privacy notice will inform you as to how we look after your personal data and tell you about your privacy rights and how the law protects you.

View an easy read version of the Targeted Relationships privacy notice (PDF, 575.5 KB).

Who we are

We collect, use and are responsible for certain personal information about you. When we do so we are regulated under the United Kingdom General Data Protection Regulation (‘UK GDPR’) and the Data Protection Act 2018. We are responsible as ‘data controller’ of that personal information. Our Data Protection Officer is Benjamin Watts.

The Targeted Relationships Service, also known as HERA (Healthy Empowering Relationship Advisory), is designed to enhance the emotional health and wellbeing of young people aged 10 to 18 who have experienced trauma, such as being victims of child sexual exploitation, coercive or abusive relationships, or domestic abuse within the family.

Project Salus CIC delivers the service on our behalf and act as the ‘data processor’ of the personal information collected as part of the Service. Project Salus CIC’s Data Protection Officer is Sarah Townsend.

The personal information we collect and use

Personal information we collect and use

Personal information is collected directly from you, your family and other agencies, when necessary, to understand if and how the service can support you and your needs.

Personal data

From you, we collect:

  • name
  • address
  • date of birth
  • telephone number
  • email address
  • age at referral
  • school details or education status (home schooled, in training, employed or not in employment, education or training - NEET)
  • young carer status
  • care leaver status
  • unaccompanied asylum-seeking status
  • social care status such as Child in Need, Child in Care
  • early help support
  • child protection plan
  • referral reasons
  • support preferences
  • risk factors
  • ongoing assessments
  • support plans.

From your parent or caregiver, we collect:

  • name
  • address
  • telephone number
  • email address.

From the person who is referring you to the service, we collect:

  • name
  • address
  • telephone number
  • email address
  • referrer type.

From other agencies supporting you such as your GP or School, we collect:

  • name
  • address
  • telephone number
  • email address.

Special catagory data

We collect special category data (personal data which is more sensitive and is treated with extra care and protection).

From you, we collect:

  • race or ethnic origin
  • sexual orientation
  • gender identity
  • disability
  • relevant health information
  • religion.

At the end of the service contract, if TUPE conditions apply, personal information of service staff will be shared with the new service provider.

How we use your personal information

Project Salus uses your personal information to:

  • understand risk, needs and protective factors
  • coordinate support
  • monitor progress, outcomes and engagement
  • carry out evaluations to improve service quality
  • share pseudonymised data with the national Mental Health Services Dataset, held by NHS Digital (part of NHS England). You can opt-out of sharing your health records
  • share anonymised statistical data with us for contract and performance monitoring.

We use your anonymised information to:

  • monitor service quality and contract performance
  • produce statistical reports, equality monitoring and anonymised analysis.

Reasons we can collect and use your personal information

When we collect and use your personal data, we rely on the following legal basis:

  • Article 6(1)(e) – Public task: Oversight, service evaluation and reporting.

When we collect or share your special category personal data (such as health information), we rely upon the following legal bases:

  • Article 9(2)(g) – Substantial public interest: Safeguarding children and individuals at risk of harm.
  • Article 9(2)(h) – Health or social care purposes: Providing healthy relationship education and wellbeing support to children and young people aged 10 to 18.

We rely on the ‘health or social care purposes’, ‘equality of opportunity or treatment’, and ‘safeguarding of children and individuals at risk’ conditions in the Data Protection Act 2018 to process your special category data.

We take the following appropriate safeguards in respect of your special category data when relying on the conditions above:

  • we have an Adult Health and Social Care Appropriate Policy Document in place when using your special category data. This policy is retained throughout the time we use your data and for 6 months after we cease to use it
  • we maintain a record of our processing in our ‘Record of Processing Activities’ and record in it any reasons for deviating from the periods in our retention schedule.

How long your personal information will be kept

For personal information collected and held by Project Salus CIC and on the Access Core + Client Caseload Information System, the following retention schedules will be adhered to:

Retention periods for types of data we collect
DataRetention period
CorrespondenceUp to 5 years
All records relating to Children and Young People referred to the Service.Child’s date of birth + 25 years
All records relating to Children and Young People, referred to the Service, who have a Child Protection Plan.Child’s date of birth + 40 years
All records relating to Children and Young People, referred to the Service, who are in our care (Looked after Children).Child’s date of birth + 75 years

If the child/young person dies before the age of 18 records will be retained for 15 years from their date of death.

Data submitted to the National Mental Health Services Dataset (NMHSD) will comply with the relevant data retention periods outlined above.

For anonymised data submitted as part of contractual performance reporting requirements to us, all anonymised service-level performance data will be held for 6 years after the contract end date.

For further information on how Project Salus process your information, see the Project Salus privacy notice.

Who we share your personal information with

We may share information with:

  • partner agencies involved in your support (for example, police, health services, district councils)
  • other organisations where required for safeguarding purposes
  • the Mental Health Services Dataset, held by NHS Digital (part of NHS England). This is a national dataset which draws on patient data to inform and improve research, planning, commissioning and policy making. For more information on how your data is used and protected, please visit the Mental Health Services Dataset. You can opt-out of sharing your health records with the Mental Health Services Dataset
  • our internal teams supporting service oversight.

We will share personal information with law enforcement or other authorities if required by applicable law or in connection with legal proceedings.

We will share personal information with our legal and professional advisers in the event of a dispute, complaint or claim. We rely on Article 9(2)(f) where the processing of special category data is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity.

Your rights

Under the UK GDPR you have a number of rights which you can access free of charge which allow you to:

  • know what we are doing with your information and why we are doing it
  • ask to see what information we hold about you
  • ask us to correct any mistakes in the information we hold about you
  • object to direct marketing
  • make a complaint to the Information Commissioner’s Office.

Depending on our reason for using your information you may also be entitled to:

  • object to how we are using your information
  • ask us to delete information we hold about you
  • have your information transferred electronically to yourself or to another organisation
  • object to decisions being made that significantly affect you
  • stop us using your information in certain ways.

We will always seek to comply with your request. However, we may be required to hold or use your information to comply with legal duties. Your request may delay or prevent us delivering a service to you.

For further information about your rights, including the circumstances in which they apply, see the guidance from the UK Information Commissioner’s Office (ICO) on individuals’ rights under the United Kingdom General Data Protection Regulation.

If you would like to exercise a right, contact the Information Resilience and Transparency Team at data.protection@kent.gov.uk .

Keeping your personal information secure

We have appropriate security measures in place to prevent personal information from being accidentally lost or used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.

We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

Who to contact

Contact the Information Resilience and Transparency Team at data.protection@kent.gov.uk to exercise any of your rights, or if you have a complaint about why your information has been collected, how it has been used or how long we have kept it for.

You can contact our Data Protection Officer, Benjamin Watts, at dpo@kent.gov.uk.

UK GDPR also gives you right to lodge a complaint with Information Commissioner, who may be contacted via the Information Commissioner's website or call 03031 231113.

For further information read our privacy statement.