Privacy Notice
Version 2.1 IMSPOL36
Date Adopted: 14/08/2026
- About this notice
Fleetville Security Ltd (“Fleetville”, “we”, “us”, “our”) is committed to protecting the privacy of everyone whose personal data we handle. This notice explains what personal data we collect, why we collect it, the legal basis on which we process it, who we share it with, how long we keep it, and the rights available to you.
This notice is issued in accordance with Articles 13 and 14 of the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018 (“DPA 2018”).
Who this notice applies to
This notice applies to:
- Visitors to our website at fleetvillesecurity.co.uk
- Clients, prospective clients and their staff or representatives
- Job applicants and candidates
- Employees, workers, security officers and contractors engaged by us
- Suppliers, subcontractors and their personnel
- Individuals captured by CCTV, body-worn video or access control systems operated by us
- Individuals who contact us by any means, including our 24/7 control room
Where you are engaged by us as an employee or worker, more detailed information about the processing of your personal data is provided in our Employee and Worker Privacy Notice, which is issued to you separately and supplements this notice.
Controller and processor roles
Fleetville acts as data controller for personal data relating to our own employees, workers, job applicants, suppliers, and the business contacts of our clients, and for data we collect through our website and our own security systems.
Where we deliver security services at a client’s premises using systems specified, owned or directed by that client (for example client-owned CCTV, client visitor books or client access control systems), Fleetville generally acts as data processor on that client’s behalf. In those circumstances the client is the controller and their own privacy notice will apply. The relevant terms are set out in the written processing agreement between us and that client, as required by Article 28 UK GDPR.
Provision of Personal Data
Is the provision of personal data statutory or contractual?
The provision of certain personal data is primarily contractual and, in some circumstances, required to meet legal and regulatory obligations.
Personal data is required to:
- Enter into and perform contracts with customers, suppliers, or business partners.
- Process orders, manage accounts, and deliver goods and services.
- Verify identity and prevent fraud.
- Comply with applicable legal, regulatory, accounting, and tax obligations.
What are the consequences of not providing personal data?
If you choose not to provide the personal data we request:
- We may be unable to enter into a contract with you.
- We may be unable to fulfil orders, supply goods, or provide services.
- We may be unable to conduct necessary verification, compliance, or fraud prevention checks.
- As a result, our services may be delayed, restricted, or declined.
Where personal data is requested for optional purposes, such as marketing communications, providing this data is not mandatory. You may withdraw your consent at any time without affecting your ability to receive goods or services from us.
- Who we are and how to contact us
Fleetville Security Ltd Registered in England and Wales, company number 11180605 Registered office: Kemp House, 152–160 City Road, London, EC1V 2NX
Operational address: Suite 110W, Sterling House Langston Road, Loughton IG10 3TS Telephone: 0203 5000 718 General enquiries: control@fleetvillesecuity.co.uk
ICO registration number: ZA351687
Data protection contact
| Name | Rashid Khan |
| Position | Data Protection Manager |
| info@fleetvillesecurity.co.uk | |
| Postal address | Data Protection Manager, Fleetville Security Ltd, Kemp House, 152–160 City Road, London, EC1V 2NX |
All requests to exercise your rights, and all questions or complaints about how we handle personal data, should be directed to the contact above.
- The personal data we collect
The categories of personal data we process depend on your relationship with us.
3.1 Website visitors
- Information you submit through enquiry, contact or careers forms, including name, employer, job title, email address and telephone number
- The content of your enquiry and any subsequent correspondence
- Technical data including IP address, browser type and version, device type, operating system, referring page, and pages viewed
- Cookie and analytics data, as described in section 11
3.2 Clients, prospective clients and their representatives
- Name, job title, employer, business address, business email and telephone number
- Site details, access arrangements, assignment instructions and site-specific contacts
- Contract, order, invoicing, payment and account records
- Correspondence, meeting notes, complaints and service records
- Incident reports, patrol records and daily occurrence book entries generated in the course of delivering services, which may include personal data about your staff or visitors
3.3 Job applicants, employees, workers and contractors
- Name, address, date of birth, gender, contact details and emergency contact details
- National Insurance number, right to work documentation, passport, visa and immigration status
- SIA licence number, status, sector and expiry, and other qualifications, certifications and training records
- Employment history, education history, references and gaps in employment
- Screening and vetting results obtained in accordance with BS 7858 (security screening) and, where applicable, BS 102000
- Financial probity information obtained from credit reference agencies (see section 5)
- Criminal record information, including basic DBS disclosures and declarations of unspent convictions
- Bank account details, salary, tax code, pension and payroll records
- Working time, shift, rota, attendance, absence and holiday records, including data generated by workforce management systems
- Occupational health information, sickness absence records, health questionnaires and reasonable adjustment records
- Disciplinary, grievance, performance and capability records
- Photographs and images used for identification passes, and body-worn or vehicle camera footage where applicable
- Location data where a worker is using a company device, lone worker device or monitored patrol system while on duty
3.4 Suppliers and subcontractors
- Contact details of your personnel, contract and payment records, insurance, accreditation and compliance documentation, and records relating to due diligence and vetting
3.5 Individuals captured by our security systems
- CCTV images, body-worn video and audio footage, access control and visitor records, and alarm and incident data, where these systems are operated by Fleetville as controller
- Special category and criminal offence data
Some of the data we process is subject to additional protection under the UK GDPR.
Special category data (Article 9) includes data concerning health, and may include data revealing racial or ethnic origin, religious beliefs or trade union membership. We process this data only where we have both an Article 6 lawful basis and an Article 9 condition, which will ordinarily be:
- Article 9(2)(b) — obligations in the field of employment, social security and social protection law, in conjunction with Schedule 1, Part 1, paragraph 1 DPA 2018
- Article 9(2)(h) — occupational medicine and assessment of working capacity, in conjunction with Schedule 1, Part 1, paragraph 2 DPA 2018
- Article 9(2)(f) — establishment, exercise or defence of legal claims
Health information collected during recruitment is handled in accordance with section 60 of the Equality Act 2010, which restricts enquiries about health before a job offer is made. Pre-offer health questions are limited to the narrow purposes permitted by that section, and information collected for those purposes is kept separate from, and is not made available to, those making the selection decision.
Criminal offence data (Article 10) is processed only where authorised by law. Our conditions are ordinarily:
- Schedule 1, Part 2, paragraph 12 DPA 2018 — preventing or detecting unlawful acts
- Schedule 1, Part 2, paragraph 18 DPA 2018 — safeguarding of children and of individuals at risk
- Schedule 1, Part 1, paragraph 1 DPA 2018 — employment purposes
We maintain an Appropriate Policy Document as required by Schedule 1, Part 4 DPA 2018. A copy is available on request from our Data Protection Manager.
- Credit Reference and Affordability Checks
To help us assess applications, prevent fraud, and meet our legal and regulatory obligations, we may obtain information about you from credit reference agencies (CRAs).
We obtain this information via Creditsafe, which uses its data partner TransUnion to supply consumer credit and identity data.
- Creditsafe Business Solutions Limited is authorised and regulated by the Financial Conduct Authority FCA Firm Reference Number: 742313
- TransUnion International UK Limited is authorised and regulated by the Financial Conduct Authority FCA Firm Reference Number: 737740
The information we receive may include data relating to your identity, credit commitments, payment history, and public record information. This data is used solely for legitimate business purposes, including creditworthiness assessment, identity verification, and fraud prevention, in accordance with applicable data protection laws.
Further information about how Creditsafe and TransUnion process your personal data can be found in their respective privacy notices:
- Creditsafe Transparency Notice: https://www.creditsafe.com/gb/en/legal/transparency-notice-customer-supplier.html
- TransUnion Bureau Privacy Notice: https://www.transunion.co.uk/legal/privacy-centre/pc-bureau
How this applies at Fleetville
The principal reason we obtain consumer credit and identity information is pre-employment screening. As an SIA Approved Contractor, we are required to screen personnel to the standard set out in BS 7858, which includes verification of identity, address history and financial probity. We may also use identity and credit information to verify the identity of individuals connected with prospective clients or suppliers and to assess credit risk where we are asked to provide services on account terms.
Where a check is carried out for screening or identity verification purposes rather than in connection with an application for credit, the search is recorded on your credit file in a way that is visible to you but is not shared with lenders and does not affect your credit score. We will confirm the nature of the search to you before it is carried out.
We will always tell you before we obtain information about you from a CRA, and where the check relates to employment we will obtain the necessary information and declarations from you directly.
CRAs are separate controllers in their own right in respect of the data they hold. They give more detail about how they use personal data, and about your rights in relation to that data, in the Credit Reference Agency Information Notice (CRAIN), available at https://www.transunion.co.uk/crain.
If you believe information held about you by a CRA is inaccurate, you may raise this with us or directly with the CRA concerned.
- Why we process your personal data, and our lawful basis
We will only process your personal data where we have a lawful basis under Article 6 UK GDPR.
| Purpose | Lawful basis |
| Responding to enquiries made through our website, by telephone or by email | Legitimate interests; steps prior to entering a contract |
| Providing security services and managing client accounts | Performance of a contract; legitimate interests |
| Invoicing, payment processing, credit control and debt recovery | Performance of a contract; legal obligation; legitimate interests |
| Recruitment, selection and interviewing | Steps prior to entering a contract; legitimate interests |
| Pre-employment screening and vetting under BS 7858, including identity, address, employment history and financial probity checks | Legal obligation; legitimate interests; Article 9(2)(b) and Article 10 conditions where applicable |
| Verifying right to work in the UK | Legal obligation (Immigration, Asylum and Nationality Act 2006) |
| Verifying SIA licensing and maintaining ACS approval | Legal obligation (Private Security Industry Act 2001); legitimate interests |
| Administering employment, payroll, pension and statutory deductions | Performance of a contract; legal obligation |
| Rostering, deployment, time and attendance, and shift management | Performance of a contract; legitimate interests |
| Managing sickness absence, occupational health and reasonable adjustments | Legal obligation; Article 9(2)(b) and 9(2)(h) conditions |
| Health and safety, lone worker safety and welfare monitoring | Legal obligation; vital interests; legitimate interests |
| Operating CCTV, body-worn video and access control | Legitimate interests; legal obligation |
| Investigating incidents, crime, complaints, grievances and disciplinary matters | Legitimate interests; legal obligation; Article 9(2)(f) and Schedule 1 Part 2 para 12 DPA 2018 |
| Fraud prevention and identity verification | Legitimate interests; legal obligation |
| Meeting audit, certification and accreditation requirements (ISO 9001, SIA ACS, SSIP and equivalent) | Legitimate interests; legal obligation |
| Maintaining records for tax, accounting and statutory reporting | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests; legal obligation; Article 9(2)(f) |
| Improving our website and services | Legitimate interests; consent for non-essential cookies |
| Business-to-business marketing to corporate contacts | Legitimate interests |
Where we rely on consent, we will make that clear at the point of collection, and you may withdraw your consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
- Our legitimate interests
Where we rely on legitimate interests as our lawful basis, our legitimate interests include:
- Operating, administering and developing our business
- Fulfilling our contractual obligations to clients, employees and workers
- Ensuring the security and integrity of our systems, premises, personnel and data
- Preventing, detecting and investigating fraud, crime and unlawful acts
- Verifying the identity, suitability, integrity and probity of personnel deployed to client sites
- Supporting audit, certification, accreditation and compliance activities
- Protecting the confidentiality and integrity of data supplied to us by third parties, including data supplied by Creditsafe and TransUnion
- Protecting the safety and welfare of our personnel and of members of the public
- Establishing, exercising and defending legal claims
- Understanding and improving the services we offer
These interests are balanced against the rights and freedoms of individuals, with appropriate safeguards in place. We carry out and document a Legitimate Interests Assessment where the processing is not obvious or is likely to have a significant effect on you. You may request a summary of the relevant assessment by contacting our Data Protection Manager, and you have the right to object to processing based on legitimate interests as set out in section 13.
- Where we obtain your personal data
We obtain personal data directly from you, and also from the following sources:
- Credit reference agencies, including Creditsafe and its data partner TransUnion
- Previous employers, educational institutions and referees
- The Security Industry Authority and other licensing and awarding bodies
- The Disclosure and Barring Service and equivalent bodies
- HM Revenue & Customs and the Home Office
- Recruitment agencies, job boards and background screening providers
- Occupational health providers
- Our clients, where you are a contact or representative of a client organisation
- Publicly available sources, including Companies House, professional networking sites and public registers
- Our own security, workforce management and access control systems
- Automated decision-making and profiling
We may use automated systems and tools to support certain business processes, such as risk assessment, fraud prevention, affordability checks, identity verification, screening and record management.
These tools may analyse personal data using predefined criteria or rules to generate indicators, scores, or recommendations. However, we do not make decisions that have a legal or similarly significant effect on individuals based solely on automated processing. Any such decisions are subject to meaningful human review.
The use of these tools may influence the speed or level of review applied to an application or request, but individuals will not be subject to automatic rejection or adverse decisions without human involvement.
In practical terms, this means that where a screening check, credit reference or identity verification returns an adverse or inconclusive result, that result is referred to a member of our team who reviews the underlying information, considers any explanation or evidence you provide, and makes the decision. No application is refused, and no engagement is terminated, on the basis of an automated output alone.
If you believe a decision has been taken about you by automated means, you have the right to request human intervention, to express your point of view, and to contest the decision, by contacting our Data Protection Manager.
- Who we share your personal data with
We do not sell your personal data, and we do not share it with third parties for their own marketing or advertising purposes.
We may share personal data with:
- Credit reference agencies and screening providers, including Creditsafe and TransUnion
- The Security Industry Authority and other regulatory and licensing bodies
- The Disclosure and Barring Service and equivalent bodies
- Previous employers and referees, for the purpose of obtaining or providing references
- Clients, where necessary to confirm the identity, licensing status and screening status of personnel deployed to their sites, and to deliver contracted services
- Occupational health providers and medical professionals
- Payroll, pension, accounting and banking providers
- IT, hosting, communications, workforce management and software providers acting as our processors
- Insurers, brokers, legal advisers, auditors and certification bodies
- Law enforcement agencies, courts, regulators and government departments, where we are required or permitted by law to do so
- A prospective purchaser in connection with a sale, merger or reorganisation of our business, subject to appropriate confidentiality undertakings
Where a third party acts as our processor, we put in place a written contract meeting the requirements of Article 28 UK GDPR, and we require them to process personal data only on our documented instructions and to apply appropriate technical and organisational security measures.
Where a third party acts as a separate controller, they will process your data in accordance with their own privacy notice, which we encourage you to read.
- Cookies and website analytics
Our website uses cookies and similar technologies. Cookies are small files placed on your device that allow a website to function correctly and to collect information about how it is used.
We use:
- Strictly necessary cookies, which are required for the website to function and which do not require your consent
- Analytics and performance cookies, which help us understand how visitors use our site
- Functional cookies, which remember your preferences
Non-essential cookies are set only with your consent, obtained through the cookie banner displayed when you first visit the site. You may withdraw or change your consent at any time through the cookie preferences link on our website, or by adjusting your browser settings.
Further detail about the specific cookies we use, their purpose and their duration is set out in our Cookie Policy at https://fleetvillesecurity.co.uk/cookie-policy/.
- Marketing
We may send information about our services to business contacts at organisations that are existing or prospective clients, relying on our legitimate interests or, where required, on your consent. Every marketing communication we send includes a means of opting out, and you may ask us to stop sending marketing at any time by contacting us using the details in section 2.
We do not use the personal data of job applicants, employees or workers for marketing purposes.
- Your rights
You have the following rights in relation to your personal data. Some of these rights apply only in particular circumstances.
Right of access — You have the right to be told whether we process personal data about you and, if we do, to receive a copy of that data together with information about how it is used.
Right to rectification — You have the right to have inaccurate personal data corrected and incomplete personal data completed.
Right to erasure — You have the right to ask us to delete personal data where there is no continuing reason for us to hold it. This right does not apply where we are required to retain the data by law or where we need it to establish, exercise or defend legal claims.
Right to restrict processing — You have the right to request that we limit how we use your personal data in certain circumstances, for example while we investigate a dispute about its accuracy or about our grounds for processing it. Where processing is restricted, we will continue to store the data but will not otherwise use it without your consent, except in limited circumstances.
Right to data portability — You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to request that we transfer it to another organisation where technically feasible. This right applies to data you have provided to us which we process by automated means on the basis of consent or of a contract with you.
Right to object — You have the right to object to processing based on our legitimate interests. Where you do so, we will stop processing unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or we need the data for legal claims. You have an absolute right to object to processing for direct marketing purposes.
Rights relating to automated decision-making — You have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you, and to request human intervention, express your point of view and contest such a decision. See section 9.
Right to withdraw consent — Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Right to complain — See section 17.
How to exercise your rights
Please contact our Data Protection Manager using the details in section 2. We will respond within one month of receiving your request, though we may extend this by up to a further two months where a request is complex or where we have received a number of requests from you. If we extend the time limit, we will tell you within one month and explain why.
There is normally no charge. We may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive.
We may need to verify your identity before responding, in order to ensure that personal data is not disclosed to anyone who has no right to receive it.
- Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, regulatory, accounting, contractual and reporting requirements.
Where records are relevant to actual or anticipated legal proceedings, a regulatory investigation or an insurance claim, we will retain them until the matter is concluded and any applicable limitation period has expired.
Our full retention schedule forms part of our Integrated Management System and is available on request.
At the end of the retention period, records are securely deleted or destroyed, or anonymised so that they
- Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage, in accordance with Article 32 UK GDPR. These measures include:
- Access controls, unique user accounts and role-based permissions
- Encryption of data in transit and, where appropriate, at rest
- Secure hosting and backup arrangements
- Multi-factor authentication on business-critical systems
- Screening and vetting of personnel who have access to personal data
- Confidentiality obligations in contracts of employment and supply
- Data protection and information security training for personnel
- Documented procedures for the reporting, containment and investigation of security incidents
- Regular review of security measures as part of our Integrated Management System
The transmission of information over the internet is not completely secure. While we take all reasonable steps to protect your data, we cannot guarantee the security of data transmitted to our website, and any transmission is at your own risk.
- International transfers
We primarily store and process personal data within the United Kingdom.
Where personal data is transferred outside the UK, whether by us or by a supplier acting on our behalf, we ensure that an appropriate transfer mechanism is in place under Chapter V UK GDPR. This will be one of the following:
- The country or territory is covered by UK adequacy regulations
- The International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, is in place
- Another lawful safeguard or exception applies
Where we rely on a contractual safeguard, we carry out a transfer risk assessment and apply any additional measures identified as necessary.
You may request further information about our international transfers, and a copy of the safeguards we rely on, by contacting our Data Protection Manager.
- Data breaches
We maintain a documented personal data breach procedure. Where a personal data breach occurs, we will assess the risk to affected individuals and, where the breach is likely to result in a risk to their rights and freedoms, report it to the Information Commissioner’s Office without undue delay and in any event within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk, we will also inform the affected individuals without undue delay.
Where we act as processor for a client, we will notify that client without undue delay on becoming aware of a breach affecting their data.
- Your right to complain
If you are unhappy with how we have handled your personal data, please contact our Data Protection Manager in the first instance so that we have the opportunity to put things right.
You also have the right to complain to the supervisory authority:
Information Commissioner’s Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Telephone: 0303 123 1113 Website: https://ico.org.uk/make-a-complaint/
Making a complaint to the ICO does not affect any other legal remedy available to you.
- Third-party links
Our website contains links to other websites. We are not responsible for the content, functionality or privacy practices of those websites. If you follow a link, we encourage you to read the privacy notice of the site you visit before providing any personal data.
- Changes to this notice
We review this notice at least annually and update it whenever our processing activities change. The version number and effective date at the top of this notice indicate when it was last updated.
Where changes are material, we will take reasonable steps to bring them to your attention. We recommend that you review this notice periodically.