
Last updated: April 2025
Scope Fire Protection Ltd is fully committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page outlines our approach to data protection, your rights as a data subject, and how we uphold our obligations as a data controller.
At Scope Fire Protection Ltd, we understand that protecting personal data is not just a legal obligation — it is a fundamental part of building trust with our clients, partners, and employees. We are committed to handling all personal data responsibly, transparently, and securely.
Our approach to GDPR compliance is ongoing. We regularly review our data handling practices, update our processes as legislation evolves, and train our staff to ensure personal data is always treated with the utmost care.
Scope Fire Protection Ltd acts as the data controller for personal data collected in connection with our services and website. As data controller, we determine the purposes and means of processing your personal data.
Scope Fire Protection Ltd
We process all personal data in accordance with the seven key principles of the UK GDPR:
Lawfulness, Fairness and Transparency
We process data only where we have a lawful basis to do so, and we are always open about how and why we use personal data.
Purpose Limitation
Personal data is collected for specific, explicit, and legitimate purposes and is not processed in ways incompatible with those purposes.
Data Minimisation
We only collect personal data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
Accuracy
We take reasonable steps to ensure personal data is accurate and kept up to date, and we rectify or delete inaccurate data promptly.
Storage Limitation
Personal data is retained only for as long as necessary and in accordance with our data retention schedules.
Integrity and Confidentiality
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction.
Accountability
We take responsibility for complying with UK GDPR and can demonstrate our compliance through documented policies and procedures.
We rely on the following lawful bases when processing personal data:
We never sell personal data to third parties, and we do not use it for automated decision-making or profiling.
As a data subject, you have the following rights. You can exercise these at any time by contacting us using the details below:
Right of Access
Request a copy of the personal data we hold about you (Subject Access Request).
Right to Rectification
Ask us to correct inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data where it is no longer necessary.
Right to Restriction
Ask us to restrict processing of your data in certain circumstances.
Right to Data Portability
Receive your data in a structured, machine-readable format where applicable.
Right to Object
Object to processing based on legitimate interests or for direct marketing.
Right to Withdraw Consent
Withdraw consent at any time where processing is based on consent.
Right to Complain
Lodge a complaint with the ICO at ico.org.uk if you believe your rights have been infringed.
We will respond to all requests within 30 days. We will never charge a fee for exercising your rights, unless requests are manifestly unfounded or excessive.
We implement appropriate technical and organisational measures to protect personal data, including:
In the event of a personal data breach that is likely to result in a risk to individuals, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware, as required by UK GDPR. Where the breach is likely to result in a high risk to individuals, we will also notify affected data subjects without undue delay.
We maintain an internal register of all data breaches, regardless of whether they require notification.
We may share personal data with third-party service providers (data processors) who act on our behalf, including IT service providers and sub-contractors. All data processors are subject to appropriate data processing agreements and are required to handle data securely and in compliance with UK GDPR.
We do not transfer personal data outside the United Kingdom without appropriate safeguards in place.
We retain personal data only for as long as is necessary for the purposes for which it was collected, or as required by law. Our standard retention periods are:
This page should be read alongside our other policies:
For any queries, concerns, or requests relating to your personal data, please contact us:
Scope Fire Protection Ltd — Data Protection Enquiries
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.