D+B Facades UK Ltd, Privacy Policy
General Data Protection Regulation, UK GDPR1. Scope and responsible entity
This policy governs all personal data processed by D+B Facades UK Ltd (Company No. 4165486, registered at The Packway, Larkhill, Salisbury, Wiltshire, SP4 8PY) through:
- Website (www.dbfacades.com)
- Project management systems
- Client/supplier communications
- Job applicant portals
1.2 Our Data Protection Officer
Name: TBC
Email: mail@dbfacades.com
Phone: 01980 654230
2. Data collection categories
| Data Type | Examples | Collection Method |
|---|---|---|
| Client Data | Contact details, project specifications, payment info | Contracts, emails, site visits |
| Supplier Data | Company contacts, certifications, performance records | Vendor onboarding, audits |
| Employee Data | CVs, payroll, training records | HR systems |
| Technical Data | IPs, cookies, access logs | Website analytics |
3. Lawful Processing Bases (GDPR Article 6)
3.1 Contractual Necessity
- Processing client orders
- Managing subcontractor agreements
3.2 Legal Obligations
- HMRC tax reporting
- Construction safety compliance
3.3 Legitimate Interests
- Client account management
- Fraud prevention
3.4 Consent
- Marketing newsletters
- Cookie tracking
4. Special Category Data (GDPR Article 9)
- Health data (site accident reports)
- Biometric data (site access systems)
Legal basis: Occupational health/safety obligations
6. Retention Schedule
| Data Category | Retention Period | Rationale |
|---|---|---|
| Client contracts | 7 years post-completion | Limitation Act 1980 |
| Job applications (unsuccessful) | 12 months | Recruitment cycles |
| Site safety logs | 40 years | RIDDOR regulations |
7. Security Measures
- Physical: Secure document storage, access logs
- Technical: EN 50600-certified data centers, TLS 1.3 encryption
- Organisational: Staff training, confidentiality agreements
8. Data Subject Rights
8.1 Request Channels
- Online portal www.dbfacades.com / mail@dbfacades.com
- Postal: The Packway, Larkhill, Salisbury, Wiltshire. SP4 8PY marked "Data Protection"
8.2 Response Timeline
- 30 days standard (extendable for complex requests)
10. Updates & Compliance
- Annual review cycle + ad-hoc updates for legal changes
- Version history maintained at [URL]
Complaints: UK ICO: https://ico.org.uk/concerns
