Privacy
- Introduction
Clarion Security Systems Ltd (“the Company”) is committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy explains:
- When and why we collect personal data.
- How we use it.
- The conditions under which we may disclose it to others.
- How we keep it secure.
This Privacy Policy explains how we collect, use, and protect your data. This Privacy Policy applies to all personal data we process, whether collected through our website, during the delivery of services, or through other interactions with our business. By using our services or this website, you acknowledge that you have read and understood this policy. For any questions, please contact info@clarionuk.com.
- Compliance & Responsibilities
This policy applies to all Company staff, contractors, and third-party service providers.
- Data Controller: The Company is the data controller, responsible for handling personal data.
- Data Protection Representative (DPR): Our Managing Director is responsible for day-to-day data protection compliance. A Data Protection Officer (DPO) will be appointed if legally required.
- Individuals providing personal data must ensure accuracy and notify the Company of any updates.
- Lawful Basis for Processing Personal Data
We process personal data under the following legal bases:
- Contractual Necessity: When processing is required to provide a service.
- Legal Obligation: To comply with regulations (e.g., tax, employment, security screening).
- Legitimate Interests: To operate and improve our services securely.
- Consent: We will only use personal data for marketing communications if we have obtained your explicit consent. At present, we do not engage in marketing activities.
- Data Protection Principles
Under UK GDPR, we process personal data based on the following principles:
- Lawfulness, Fairness & Transparency: We ensure clear and lawful processing.
- Purpose Limitation: Data is only used for the purpose it was collected.
- Data Minimisation: We only collect essential data.
- Accuracy: Personal data is kept accurate and up to date.
- Storage Limitation: Data is retained only as long as necessary.
- Security & Confidentiality: Data is protected against unauthorised access.
- What Personal Data We Collect
We may collect and process:
- Clients & Potential Clients: Name, address, email, phone number, keyholder details.
- Employees & Subcontractors: Name, contact details, background screening information (collected under legal obligations).
- System Users (e.g., security system users): Keyholder details, location data, system logs.
- Remote Access & Security System IP Addresses: When our security personnel, customers, or authorized users connect remotely to security systems, we log the external IP address used for authentication and monitoring. These logs are maintained for security and compliance purposes.
- Website Visitors’ IP Addresses: When visitors access our website, their IP addresses may be logged temporarily for security monitoring, fraud prevention, and system diagnostics. These addresses are not linked to specific individuals and are deleted automatically after 60 days. We may use aggregated web analytics data, such as visit duration and page interactions, collected through tools like Google Analytics. This data does not identify individuals.
- How We Use Your Personal Data
We process personal data to:
- Provide security system installation and maintenance.
- Process customer enquiries and contracts.
- Manage security system users and keyholders.
- Meet legal obligations (e.g., regulatory compliance, fraud prevention).
- We process IP addresses to monitor website security, prevent fraud, and improve system performance.
We do not sell or rent personal data to third parties.
- Data Sharing & Third-Party Processors
We may share data with:
- Service Providers: IT support, cloud storage, payment processors.
- Law Enforcement Authorities: Where required by law.
- Subcontractors: For security system installation and maintenance.
We ensure third parties comply with UK GDPR through Data Processing Agreements (DPAs).
- International Data Transfers
If personal data is transferred outside the UK, we ensure:
- Adequacy Decisions (for countries approved by the UK government).
- Standard Contractual Clauses (SCCs) for other countries.
- Data Retention Policy
We retain personal data for the following periods:
- Customer records: Retained for 2 years after contract completion as per NSI Quality Schedule SSQS 101.
- Keyholder & Security System Data (contractual information): Retained for the duration of the contract plus 2 years as per NSI Quality Schedule SSQS 101.
- CCTV footage: Retained for 31 days unless required for investigation.
- Employee & Screening Records: Retained for employment period + 7 years (as per security regulations).
- IP addresses collected for remote system access and diagnostics may be retained as part of contractual service records for the duration of the contract plus 2 years, in line with NSI Quality Schedule SSQS 101, where applicable
- Website visitor IP addresses: Retained temporarily for 60 days.
After the retention period, data is securely deleted or anonymised.
- Data Security
We take steps to protect personal data, including:
- Encryption for stored and transmitted data.
- Access controls to restrict unauthorised access.
- Regular cybersecurity audits.
- Your Rights Under UK GDPR
You have the right to:
- Access your data (Subject Access Request – SAR).
- Correct inaccuracies in your data.
- Request deletion (‘right to be forgotten’), subject to legal requirements.
- Restrict or object to processing under certain conditions.
- Request data portability where applicable.
- Withdraw consent for marketing communications.
- Lodge a complaint with the ICO (www.ico.org.uk) if you believe your data is mismanaged.
To exercise your rights, email info@clarionuk.com. We respond within one month (or up to three months for complex cases). SARs are free, but we may charge a reasonable fee for excessive requests.
- Use of Cookies
If our website uses cookies, we provide a separate Cookie Policy explaining:
- Types of cookies used (essential, analytics, advertising).
- How to manage or disable cookies.
For details, refer to our Cookie Policy: https://clarionuk.com/cookies/
- Third-Party Links
Our website may contain links to third-party sites. We are not responsible for their privacy policies. Always review external privacy policies before providing personal data.
- Updates to This Policy
We review and update this Privacy Policy periodically. Any changes will be posted on our website. Significant changes will be communicated directly where necessary.
For further information, visit the ICO website (www.ico.org.uk).
For questions about this Privacy Policy, contact us at info@clarionuk.com.