Privacy Policy - Coombe Storage
Last updated: [Insert Date]
This Privacy Policy explains how Coombe Storage collects, uses, stores, shares, and protects personal data. It applies to all Coombe Storage customers in the area, including prospective customers, current customers, former customers, and any individuals who interact with us in relation to storage services, billing, administration, security, or customer support.
We are committed to handling personal data lawfully, fairly, and transparently in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Coombe Storage provides storage-related services to customers in the local area. For the purposes of data protection law, Coombe Storage is the data controller for the personal data described in this policy, meaning we decide how and why your personal data is used.
2. What Personal Data We Collect
We only collect personal data that is necessary for providing our services, managing our relationship with you, maintaining security, and meeting legal obligations. Depending on how you interact with us, we may collect the following categories of personal data:
- Identity data: name, title, date of birth, and proof of identity where required.
- Contact data: address, email address, telephone number, and postal details.
- Account and contract data: customer records, tenancy or storage agreement details, payment status, service history, and communication preferences.
- Financial data: billing details, payment records, and transaction information. We do not usually store full card details if payment is processed by a third-party payment provider.
- Access and security data: entry records, CCTV images, vehicle registration details, site access logs, and alarm or incident records where applicable.
- Communication data: enquiries, complaints, correspondence, call notes, and feedback.
- Technical data: device information, IP address, browser information, and cookies or similar technologies where used on our systems.
We do not intentionally collect special category data unless it is required for a specific lawful reason, such as an emergency, legal claim, or where you choose to provide it and we have a valid legal basis to process it.
3. How We Collect Your Data
We may collect personal data directly from you when you:
- register for or use our storage services;
- complete forms or make enquiries;
- enter into an agreement with us;
- make payments or request invoices;
- contact us by phone, email, post, or in person;
- visit our premises where access logs or CCTV are in operation.
We may also receive data from third parties, such as payment processors, identity verification providers, insurance-related partners, debt recovery providers, legal advisers, or public authorities where relevant and lawful.
4. Why We Use Your Data
We use personal data for the following purposes:
- to provide storage services and manage customer accounts;
- to verify identity and prevent fraud;
- to process payments and manage invoices;
- to communicate with you about your account, service updates, or site matters;
- to ensure the security of our premises, staff, customers, and property;
- to investigate complaints, incidents, or disputes;
- to comply with legal and regulatory obligations;
- to establish, exercise, or defend legal claims.
We will only use your personal data for the purposes for which it was collected, unless we reasonably consider that we need to use it for another compatible purpose and the law allows us to do so.
5. Lawful Basis for Processing
Under data protection law, we must have a lawful basis to process your personal data. Depending on the context, Coombe Storage relies on one or more of the following lawful bases:
Contract
We process personal data where it is necessary to enter into or perform a contract with you, such as providing storage services, managing your account, taking payment, and delivering customer support.
Legal Obligation
We process personal data where necessary to comply with legal obligations, such as accounting, tax, regulatory, fraud prevention, record keeping, or responding to lawful requests from authorities.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided your rights and interests do not override those interests. This may include protecting our premises, preventing misuse of services, maintaining records, improving operations, and handling disputes.
Consent
Where required, we will rely on your consent, for example for certain optional marketing communications or non-essential technologies. You may withdraw consent at any time where processing is based on consent.
6. Sharing Your Data and Processors
We may share personal data with trusted third parties when necessary for our business operations or legal compliance. These parties may act as processors or as independent controllers depending on the service provided.
Examples of processors and service providers include:
- IT and hosting providers that store or manage our systems and data;
- payment service providers that handle transactions securely;
- security providers that support CCTV, alarm monitoring, or access control systems;
- accounting and administration providers that assist with invoicing, bookkeeping, and record management;
- legal and professional advisers who help with disputes, compliance, or contractual matters;
- debt recovery or credit management providers where unpaid balances need to be recovered lawfully;
- identity verification or anti-fraud providers where checks are required.
We require all processors to keep personal data secure, use it only for the services we instruct them to provide, and comply with data protection law. We do not sell your personal data.
7. International Transfers
If any processor or service provider stores or accesses personal data outside the United Kingdom, we will ensure appropriate safeguards are in place. These may include adequacy regulations, standard contractual clauses, or other lawful transfer mechanisms designed to protect your data.
8. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, and to meet legal, accounting, tax, security, and contractual requirements.
Retention periods vary depending on the type of data and our legal obligations. In general:
- Customer and contract records are retained for the duration of the relationship and for a period after it ends.
- Financial records are retained for the period required by accounting and tax law.
- Security records such as access logs and CCTV are retained for a shorter period unless needed for an investigation, incident, or legal claim.
- Correspondence and complaints are retained long enough to manage the matter and maintain appropriate records.
When personal data is no longer required, it is securely deleted, anonymised, or otherwise disposed of in a safe manner.
9. Data Security
We take appropriate technical and organisational measures to protect personal data from loss, misuse, unauthorised access, alteration, or disclosure. These measures may include restricted access, secure systems, staff training, password protection, physical security controls, and supplier oversight.
No system is completely secure, but we work to reduce risks and maintain a level of protection appropriate to the nature of the data we hold.
10. Your Rights
Under data protection law, you have certain rights in relation to your personal data. These rights may be subject to legal limitations and exemptions. They include the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete information;
- Erase your data in certain circumstances;
- Restrict processing in certain situations;
- Object to processing based on legitimate interests or direct marketing;
- Data portability for information you have provided to us, where applicable;
- Withdraw consent where processing is based on consent;
- Complain to the Information Commissioner’s Office if you believe your data has been handled unlawfully.
To help protect your privacy, we may need to verify your identity before responding to a request. We aim to respond to valid requests within the timeframes required by law.
11. Marketing Communications
Where permitted, we may send you limited marketing or service-related communications. You may opt out of marketing at any time. Service messages that are necessary for your account or storage arrangement are not marketing and may still be sent when needed.
12. Cookies and Similar Technologies
If we use cookies or similar technologies on any digital systems, they may be used for basic functionality, security, analytics, or preference management. Where consent is required, we will seek it before using non-essential technologies. You can manage cookie settings through your browser or device controls where applicable.
13. Children’s Data
Our services are intended for adults and business users. We do not knowingly collect personal data from children except where necessary and lawful, such as in relation to emergency contacts or lawful representatives.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or operational practices. Any updated version will apply from the date it is published or otherwise communicated.
15. Summary of Your Privacy Protection
In summary, Coombe Storage uses personal data only where we have a lawful basis, keeps it only for as long as needed, shares it only with trusted processors or where legally required, and respects your rights under data protection law. This policy is designed to ensure that all Coombe Storage customers in the area understand how their personal data is handled in a fair, secure, and transparent way.
We value your trust and are committed to maintaining a high standard of privacy and data protection in everything we do.