GDPR Compliance
Legal

GDPR Compliance

Last updated: April 2025

Scope Fire Protection Ltd is fully committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines our approach to data protection, your rights as a data subject, and how we uphold our obligations as a data controller.

1. Our Commitment

At Scope Fire Protection Ltd, we understand that protecting personal data is not just a legal obligation — it is a fundamental part of building trust with our clients, partners, and employees. We are committed to handling all personal data responsibly, transparently, and securely.

Our approach to GDPR compliance is ongoing. We regularly review our data handling practices, update our processes as legislation evolves, and train our staff to ensure personal data is always treated with the utmost care.

2. Data Controller

Scope Fire Protection Ltd acts as the data controller for personal data collected in connection with our services and website. As data controller, we determine the purposes and means of processing your personal data.

Scope Fire Protection Ltd

2 Saxon Park, Saxon Way East, Corby, NN18 9EY
info@scopefireprotection.co.uk
01536 601960

3. The Seven Principles of UK GDPR

We process all personal data in accordance with the seven key principles of the UK GDPR:

Lawfulness, Fairness and Transparency

We process data only where we have a lawful basis to do so, and we are always open about how and why we use personal data.

Purpose Limitation

Personal data is collected for specific, explicit, and legitimate purposes and is not processed in ways incompatible with those purposes.

Data Minimisation

We only collect personal data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.

Accuracy

We take reasonable steps to ensure personal data is accurate and kept up to date, and we rectify or delete inaccurate data promptly.

Storage Limitation

Personal data is retained only for as long as necessary and in accordance with our data retention schedules.

Integrity and Confidentiality

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction.

Accountability

We take responsibility for complying with UK GDPR and can demonstrate our compliance through documented policies and procedures.

4. Lawful Bases for Processing

We rely on the following lawful bases when processing personal data:

  • Contract: Processing is necessary to perform a contract we have with you, or to take steps at your request before entering into a contract.
  • Legal obligation: Processing is necessary to comply with a legal or regulatory obligation (e.g., health and safety records, accounting requirements).
  • Legitimate interests: Processing is necessary for our legitimate business interests, provided your rights do not override those interests.
  • Consent: Where you have given clear and freely given consent for us to process your personal data for a specific purpose (e.g., marketing communications).

We never sell personal data to third parties, and we do not use it for automated decision-making or profiling.

5. Your Rights Under UK GDPR

As a data subject, you have the following rights. You can exercise these at any time by contacting us using the details below:

Right of Access

Request a copy of the personal data we hold about you (Subject Access Request).

Right to Rectification

Ask us to correct inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data where it is no longer necessary.

Right to Restriction

Ask us to restrict processing of your data in certain circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format where applicable.

Right to Object

Object to processing based on legitimate interests or for direct marketing.

Right to Withdraw Consent

Withdraw consent at any time where processing is based on consent.

Right to Complain

Lodge a complaint with the ICO at ico.org.uk if you believe your rights have been infringed.

We will respond to all requests within 30 days. We will never charge a fee for exercising your rights, unless requests are manifestly unfounded or excessive.

6. Data Security

We implement appropriate technical and organisational measures to protect personal data, including:

  • Secure access controls and password policies
  • Encryption of data in transit and at rest where appropriate
  • Regular staff training on data protection
  • Documented data handling and incident response procedures
  • Regular review of our security practices

7. Data Breaches

In the event of a personal data breach that is likely to result in a risk to individuals, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware, as required by UK GDPR. Where the breach is likely to result in a high risk to individuals, we will also notify affected data subjects without undue delay.

We maintain an internal register of all data breaches, regardless of whether they require notification.

8. Third Parties and Data Processors

We may share personal data with third-party service providers (data processors) who act on our behalf, including IT service providers and sub-contractors. All data processors are subject to appropriate data processing agreements and are required to handle data securely and in compliance with UK GDPR.

We do not transfer personal data outside the United Kingdom without appropriate safeguards in place.

9. Data Retention

We retain personal data only for as long as is necessary for the purposes for which it was collected, or as required by law. Our standard retention periods are:

  • Client and contract records: 7 years after contract end
  • Enquiry and marketing data: 2 years from last contact
  • Employee records: as required by employment law
  • Health and safety records: as required by relevant legislation

10. Related Policies

This page should be read alongside our other policies:

11. Contact Our Data Protection Contact

For any queries, concerns, or requests relating to your personal data, please contact us:

Scope Fire Protection Ltd — Data Protection Enquiries

2 Saxon Park, Saxon Way East, Corby, NN18 9EY
info@scopefireprotection.co.uk
01536 601960

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.