Privacy Policy - Gipsyhill Storage

This Privacy Policy explains how Gipsyhill Storage collects, uses, stores, shares, and protects personal data in connection with the provision of storage services. It applies to all Gipsyhill Storage customers in the area, including prospective customers, account holders, authorised users, and any other individuals whose personal data we process in the course of operating our business. We are committed to handling personal data in a lawful, fair, transparent, and secure manner in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

By using our services or providing us with your information, you acknowledge that we may process personal data as described in this policy. This policy is intended to be clear and practical, while reflecting the rights and protections granted to individuals under applicable data protection laws.

1. Data We Collect

We collect only the data that is necessary for operating our storage services, managing customer relationships, protecting our premises, and meeting legal and regulatory obligations. The types of information we may collect include:

  • Identity data: name, date of birth, and identification information used to verify identity.
  • Contact data: postal address, email address, telephone number, and billing address.
  • Account and contract data: customer reference numbers, tenancy or storage agreement details, service preferences, and communications related to your account.
  • Payment data: payment status, transaction records, and limited payment information necessary to process fees and maintain accounts.
  • Access and security data: records of access to premises, entry logs, CCTV recordings where used, alarm event records, and incident reports.
  • Correspondence data: messages, complaints, queries, and other communications sent to us or received from us.
  • Usage and operational data: information relating to the occupation, use, and management of storage units and related services.

We generally do not seek to collect special category data. If such information is provided to us inadvertently, we will only process it where a lawful basis applies and where it is necessary for a legitimate purpose or legal obligation.

2. How We Collect Personal Data

We may collect personal data directly from you when you complete forms, enter into an agreement, communicate with us, make payments, or otherwise interact with our services. We may also receive data from third parties where necessary, such as identity verification providers, payment service providers, insurers, legal advisers, debt recovery agents, or public authorities. In some cases, personal data may be captured automatically through security systems, access controls, and CCTV, where these are used to protect people, property, and the integrity of our premises.

3. How We Use Personal Data

We use personal data for the following purposes:

  • to open and manage customer accounts;
  • to provide storage services and administer agreements;
  • to verify identity and carry out fraud prevention checks;
  • to process payments, refunds, and account adjustments;
  • to communicate about service updates, notices, and account matters;
  • to protect our customers, staff, property, and facilities;
  • to investigate incidents, breaches, or misuse of storage facilities;
  • to comply with legal, regulatory, tax, accounting, and insurance requirements;
  • to handle disputes, complaints, and claims;
  • to maintain business records and improve service operations.

We will not use personal data for purposes that are incompatible with the reasons it was collected unless we have a valid legal basis and, where required, notify you of the new purpose.

4. Lawful Basis for Processing

We process personal data only where we have a lawful basis under UK GDPR. Depending on the context, we rely on the following bases:

Contract

We process personal data where it is necessary to enter into or perform a storage agreement, manage your account, provide services, and fulfill related obligations.

Legal Obligation

We may process data to comply with legal duties, including accounting, tax, regulatory, fraud prevention, record-keeping, and lawful requests from public authorities.

Legitimate Interests

We may process personal data where it is necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests. These legitimate interests may include protecting property, preventing loss or misuse, maintaining secure premises, resolving disputes, and improving our services. When we rely on this basis, we assess the impact on individuals and ensure appropriate safeguards are in place.

Consent

Where required, we will rely on your consent, for example in relation to certain optional communications or specific uses of data. You may withdraw consent at any time, although this will not affect processing carried out before withdrawal.

Vital Interests

In exceptional circumstances, we may process data to protect someone’s vital interests, such as in an emergency involving injury or serious risk.

5. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for legal, accounting, insurance, and operational requirements. Retention periods vary depending on the category of data and the reason for processing. For example, account records may be retained for the duration of the customer relationship and for a further period after closure to deal with claims, disputes, or statutory obligations. Security records, such as access logs or CCTV footage, are retained for a limited period unless needed for an investigation or legal process.

When personal data is no longer required, we will delete it securely, anonymise it, or otherwise dispose of it in a safe and appropriate manner. We regularly review retained data to ensure it is not kept longer than necessary.

6. Sharing and Processors

We may share personal data with trusted third parties where necessary for legitimate business purposes, legal compliance, or service delivery. These third parties may act as processors or, in some cases, as independent controllers. We only use third parties that provide adequate safeguards for personal data and we require them to process data securely and in accordance with applicable law.

Examples of processors and recipients may include:

  • payment processing providers;
  • identity verification and fraud prevention services;
  • IT hosting, cloud storage, and software service providers;
  • security and surveillance service providers;
  • professional advisers such as accountants, auditors, insurers, and lawyers;
  • debt recovery or credit management providers;
  • maintenance or facilities contractors where access to limited personal data is necessary;
  • public authorities, regulators, courts, and law enforcement where disclosure is required by law.

Where a processor acts on our behalf, they may only process personal data on our documented instructions and must not use it for their own purposes. We put contractual and technical safeguards in place to ensure personal data remains protected.

7. International Transfers

If personal data is transferred outside the United Kingdom, we will ensure appropriate protections are in place in accordance with applicable data protection laws. This may include the use of standard contractual clauses, adequacy regulations, or other lawful safeguards designed to protect personal data to a standard essentially equivalent to that required in the UK.

8. Data Security

We take appropriate technical and organisational measures to protect personal data from unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, authentication procedures, secure storage, staff training, regular reviews of security practices, and restricted access on a need-to-know basis. While no system is completely immune to risk, we work to maintain a level of security appropriate to the nature of the data we process.

9. Your Rights

Under data protection law, individuals have a number of rights in relation to their personal data. Subject to legal conditions and exemptions, you may have the right to:

  • access your personal data and receive a copy of it;
  • rectify inaccurate or incomplete data;
  • erase your data in certain circumstances;
  • restrict processing in certain situations;
  • object to processing based on legitimate interests or direct marketing;
  • data portability for data provided by you and processed by automated means in certain cases;
  • withdraw consent where processing is based on consent;
  • request information about decisions made solely by automated means, where applicable.

You also have the right to lodge a complaint with the relevant data protection supervisory authority if you believe your rights have been infringed. We encourage you to raise any concern with us first so that we can try to resolve it promptly and fairly.

10. Children’s Data

Our storage services are not directed to children, and we do not knowingly collect personal data from children unless it is necessary in exceptional circumstances, such as where a parent, guardian, or authorised adult is acting on their behalf. Where we become aware that data has been collected unlawfully from a child, we will take appropriate steps to delete or protect it.

11. Automated Decision-Making

We do not عادة rely on fully automated decision-making that produces legal or similarly significant effects on individuals. If this changes, we will ensure that appropriate information is provided and that any required safeguards are implemented.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we do so, we will publish the revised version and, where appropriate, bring material changes to your attention. We encourage customers to review this policy periodically so they remain informed about how their personal data is used.

13. Summary of Our Commitment

Gipsyhill Storage is committed to processing personal data responsibly, transparently, and in line with data protection principles. We collect only what we need, use it for clear and lawful purposes, retain it no longer than necessary, and apply safeguards when working with processors and other third parties. Our aim is to respect privacy while delivering secure and reliable storage services to all customers in the area.

Gipsy Hill Storage

GDPR-compliant privacy policy for Gipsyhill Storage covering data collection, lawful basis, retention, processors, rights, and scope for all local customers.

Get a Quote

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.