Skip to content

D+B Facades UK Ltd, Privacy Policy

General Data Protection Regulation, UK GDPR

1. Scope and responsible entity

This policy governs all personal data processed by D+B Facades UK Ltd (Company No. 4165486, registered at The Packway, Larkhill, Salisbury, Wiltshire, SP4 8PY) through:

  • Website (www.dbfacades.com)
  • Project management systems
  • Client/supplier communications
  • Job applicant portals

1.2 Our Data Protection Officer

Name: TBC
Email: mail@dbfacades.com
Phone: 01980 654230

2. Data collection categories

Data TypeExamplesCollection Method
Client DataContact details, project specifications, payment infoContracts, emails, site visits
Supplier DataCompany contacts, certifications, performance recordsVendor onboarding, audits
Employee DataCVs, payroll, training recordsHR systems
Technical DataIPs, cookies, access logsWebsite analytics

3. Lawful Processing Bases (GDPR Article 6)

3.1 Contractual Necessity

  • Processing client orders
  • Managing subcontractor agreements

3.2 Legal Obligations

  • HMRC tax reporting
  • Construction safety compliance

3.3 Legitimate Interests

  • Client account management
  • Fraud prevention

3.4 Consent

  • Marketing newsletters
  • Cookie tracking

4. Special Category Data (GDPR Article 9)

  • Health data (site accident reports)
  • Biometric data (site access systems)

Legal basis: Occupational health/safety obligations

5. Data Sharing & Transfers

5.1 Recipients

  • Architects/engineers (project collaboration)
  • Material suppliers (order fulfilment)
  • Cloud providers (AWS/Microsoft 365)

5.2 International Transfers

  • EU → UK: Adequacy Decision applies
  • UK → [Third Country]: SCCs with risk assessments

6. Retention Schedule

Data CategoryRetention PeriodRationale
Client contracts7 years post-completionLimitation Act 1980
Job applications (unsuccessful)12 monthsRecruitment cycles
Site safety logs40 yearsRIDDOR regulations

7. Security Measures

  • Physical: Secure document storage, access logs
  • Technical: EN 50600-certified data centers, TLS 1.3 encryption
  • Organisational: Staff training, confidentiality agreements

8. Data Subject Rights

8.1 Request Channels

8.2 Response Timeline

  • 30 days standard (extendable for complex requests)

9. Cookies & Tracking Technologies

9.1 Essential

  • Session cookies (login continuity)
  • Load-balancing cookies

9.2 Analytical

  • Google Analytics (IP anonymization enabled)

9.3 Control Options

  • Cookie preference center at first visit
  • Browser-level opt-out instructions provided

10. Updates & Compliance

  • Annual review cycle + ad-hoc updates for legal changes
  • Version history maintained at [URL]

Complaints: UK ICO: https://ico.org.uk/concerns

Back To Top