Legal
Privacy Policy
What personal data we hold, why we hold it, how long we keep it, and the rights you have over it. It also sets out our position on CCTV footage, which is not ours.
We are a small company that installs security systems in people’s homes. Our clients tell us where their doors are, when the house is empty, and which windows are weak. We treat that as some of the most sensitive information a person can hand over, and we collect as little of it as the work allows.
1. Who is responsible for your data
FlexiScan Security is the data controller for the personal data described in this policy. Our data protection registration details, registered company details and the name of the person responsible for data protection are provided on request and appear on our contracts and formal correspondence. They are not published here, for the reasons given in our Terms of Use.
We have not appointed a statutory Data Protection Officer, as we are not required to. Responsibility sits with a named member of our team, and that name is given to you when you become a client.
To reach us about anything in this policy, use the enquiry form on this website. Please do not include personal data in that first message — describe what you need in general terms and we will move the conversation to a secure channel.
2. CCTV footage recorded by your system
This is the single most common misunderstanding about a company like ours, so it is stated first and in full.
FlexiScan is not the data controller for your CCTV footage, and has no access to it.
Where we design, supply, install or maintain a CCTV system at your property, the recording equipment and the storage media belong to you and remain at your premises or in a storage account under your sole control. We do not hold copies of your footage, we do not stream it, we do not retain remote viewing credentials after handover, and we have no technical means of retrieving recorded images once an installation is complete.
In UK data protection terms, you determine the purposes and means of that processing and you are therefore the data controller for the images your system records. FlexiScan is not a controller and is not a processor in respect of that footage.
We cannot act on a data subject access request, an erasure request or any other request under the UK GDPR or the Data Protection Act 2018 relating to CCTV images. We have nothing to search and no lawful basis on which to obtain the material from you. Any such request must be made to the operator of the system. If a request reaches us in error we will not forward the substance of it, and will simply explain that we are not the controller.
The same applies to doorbell cameras, standalone recorders, network video recorders and any cloud storage account you hold with a manufacturer. Where a manufacturer’s cloud service is involved, your agreement is with that manufacturer and their privacy policy governs it; we are not a party to it.
What you are responsible for. As the operator of a domestic CCTV system you must consider whether your cameras capture anything beyond the boundary of your own property — a pavement, a shared drive, a neighbour’s garden or window. If they do, UK data protection law applies to you directly, and you must be able to respond to a request from someone who appears in the footage. We will tell you during the survey where this is likely to arise, will angle and mask cameras to reduce it wherever the design allows, and will explain what the Information Commissioner’s Office expects of domestic operators. That advice is given as part of the installation; it does not make us responsible for how the system is used afterwards.
During commissioning we may briefly view a live image to confirm a camera is aimed and focused correctly. We do not record it, and we do not retain it.
3. The personal data we hold
We hold different things about different people. In every case we hold the minimum the work requires.
Enquirers. Whatever you choose to put in the enquiry form, and the email address your message arrives from. Nothing else — the form does not ask for a name, a number or an address. The web server keeps a standard access log for about 30 days, described in our Cookie Policy.
Clients and prospective clients. Name; contact details; the address of the property; the survey findings and system design; the equipment installed and its configuration; service, maintenance and fault history; correspondence with us; and billing records. Where you have asked for monitoring or a response service, the keyholder details and passwords needed to operate it.
Cyber security clients. The domains, accounts and aliases we have been asked to configure or protect, and the technical records that go with them.
Suppliers and partners. Business contact details and the records of what was ordered or delivered.
Job applicants. We are not currently recruiting, and unsolicited applications are deleted immediately and irrecoverably rather than held on file. See our Careers page.
Special category data. We do not ask for it and do not want it. Occasionally a client volunteers something relevant to the design — for example that a household member has a mobility need affecting where a keypad should go. We record only the practical requirement, not the reason for it.
4. Information about how your property is protected
Drawings, device schedules, camera positions, codes, credentials, network details and anything we noted as a weakness during a survey are treated as a class of their own. They are held on a need-to-know basis within a deliberately small team, kept apart from routine correspondence, never used in marketing, never used as a case study, and never disclosed to anyone outside the company except where genuinely necessary to deliver a service you have asked for, or where the law requires it.
This is also why we keep our client list short. A long list is a long list of properties whose weaknesses one company holds in detail.
5. Why we use it, and our lawful bases
To answer an enquiry and prepare a quotation. Steps taken at your request before entering a contract, and our legitimate interest in responding to people who approach us.
To survey, design, supply, install, maintain and repair a system. Performance of our contract with you.
To arrange monitoring or a response service on your behalf. Performance of our contract with you.
To invoice, keep accounts and meet tax obligations. Legal obligation.
To hold service and warranty history, and to handle complaints, claims and insurance matters. Our legitimate interest in running the company properly and being able to defend a claim.
To keep our own systems and premises secure. Our legitimate interest in protecting the company and its clients.
To send occasional information about our services to existing clients. Our legitimate interest, subject at all times to the rules in our Marketing Preferences and to your right to object, which we will always honour.
Where we rely on a legitimate interest we have considered whether it is outweighed by your rights and freedoms, and have concluded it is not. You may ask us to explain that assessment.
6. Who we share it with
We do not sell personal data, we do not trade it, and we do not share it for anyone else’s marketing. It is shared only in these circumstances:
- Alarm receiving and response providers — where you have asked for monitoring or a keyholding response, the provider needs the site address, the keyholder details and the operating instructions. These providers are accredited, contracted to us, and bound by written terms covering confidentiality and data protection. We remain responsible to you for the service.
- Equipment manufacturers — for a warranty claim or a technical escalation, limited to what is needed to resolve it.
- Our accountant and professional advisers — billing and statutory records, and legal advice where needed.
- Providers of the business software we use — email, accounting and backup, acting as processors under written terms.
- Law enforcement, a regulator or a court — where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims. We will resist any request that is not properly made, and where we are lawfully able to tell you about it, we will.
Every processor we use is engaged under a written contract meeting the requirements of Article 28 of the UK GDPR.
7. Transfers outside the UK
We keep personal data in the UK wherever we can. Some of the business software we rely on stores data in the European Economic Area, which the UK recognises as providing an adequate level of protection.
Where a transfer to a country without a UK adequacy decision is unavoidable, we put in place the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional safeguards a transfer risk assessment identifies. Information about how a particular property is protected is not transferred outside the UK at all.
8. How long we keep it
| Record | Kept for |
|---|---|
| Enquiries that do not lead to a quotation | 6 months |
| Quotations not accepted | 12 months |
| Contracts, surveys, designs and service history | The life of the system, then 7 years |
| Codes, credentials and access details | Deleted when the system is decommissioned or the contract ends |
| Accounting and tax records | 7 years, as required by law |
| Complaint records | 7 years from resolution |
| Marketing suppression records | Indefinitely — so that we do not contact you again |
| Unsolicited job applications | Not retained; deleted on receipt |
The long retention on contracts and service history exists because a security system installed today may still be in service in fifteen years, and because warranty, insurance and liability questions can arise long after the work is finished. Records are securely destroyed at the end of the period.
9. How we protect it
Access is limited to those who need it to do the work. Devices are encrypted and passphrase-protected, accounts are protected by multi-factor authentication, backups are encrypted, and sensitive material is kept separately from routine correspondence. Paper survey notes are transcribed and destroyed.
We use secure channels for anything sensitive and will ask you to move away from ordinary email when a discussion turns to detail about your property. Email is not a secure medium, which is why our enquiry form asks you not to put personal data in it.
No measure is perfect. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and will tell you directly without undue delay where the risk is high.
10. Your rights
Under the UK GDPR you have the right to:
- be told how your data is used — this document;
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected;
- ask us to delete data where there is no good reason for us to keep it;
- ask us to restrict how we use it while a question about it is resolved;
- object to processing carried out on the basis of a legitimate interest;
- object to direct marketing at any time, which is an absolute right;
- receive data you gave us in a portable electronic format, or have it sent to another provider, where processing is based on consent or a contract and is carried out by automated means;
- withdraw consent at any time, where we relied on consent.
There is no charge. We respond within one month, and will tell you if we need longer because a request is complex. We will ask you to verify your identity before releasing anything — in a business like ours, releasing security information to the wrong person is the worst thing we could do.
Two limits worth stating plainly. A request for erasure cannot extend to records we must keep for tax, or to records we need to defend a legal claim. And a request about CCTV footage cannot be met by us at all, for the reasons in section 2 — it must go to the operator of the system.
11. Cookies and this website
This website sets no cookies and uses no analytics, no advertising technology and no tracking of any kind, and we do not attempt to identify anyone who visits. The web server keeps a standard access log for about 30 days, described in our Cookie Policy. Every request the site makes — its typefaces included — is served from its own domain; there are no third-party requests at all. Our Cookie Policy explains this in full.
12. Automated decision-making
We do not carry out profiling and we do not make decisions about you by automated means. Every design, quotation and decision is made by a person.
13. Children
Our services are sold to adults and this website is not directed at children. We do not knowingly collect personal data from anyone under 18. Where a household includes children, we do not record anything about them beyond what a system design unavoidably requires.
14. Changes to this policy
We may update this policy. The version published here is the one that applies. Where a change materially affects how we use your data, we will tell existing clients directly rather than relying on you to notice.
15. Complaints
If you are unhappy with how we have handled your personal data, please raise it with us first through our contact form, marked for the attention of the person responsible for data protection.
You may also complain to the Information Commissioner’s Office, the UK supervisory authority for data protection, at ico.org.uk. We would ask you to give us the chance to put things right first, but you are not obliged to.
Questions about this document should be raised through our contact form. Please do not include personal data in your message.