Privacy Policy - Pondersend Storage
Pondersend Storage is committed to protecting the privacy and personal data of its customers. This Privacy Policy explains how we collect, use, store, share, and protect personal data in connection with our storage services. It applies to all Pondersend Storage customers in area, including individuals and business account holders who use our facilities, manage bookings, or otherwise interact with our services.
1. Who We Are
Pondersend Storage acts as a data controller for the personal data we collect and process in the course of providing storage services. This means we determine the purposes and means of processing personal data in line with applicable data protection laws, including the GDPR.
We are committed to processing personal data in a lawful, fair, and transparent manner. We only collect data that is necessary for legitimate service-related purposes and retain it only for as long as needed.
2. Personal Data We Collect
We may collect the following categories of personal data:
- Identification data such as name, date of birth, and customer reference numbers.
- Contact data such as postal address, email address, and telephone number.
- Account and booking data such as storage unit details, rental dates, payment records, and service preferences.
- Financial data such as payment method details, billing history, and transaction confirmations.
- Security and access data such as entry logs, key or code usage records, and CCTV-related information where applicable.
- Correspondence data such as messages, complaints, claims, and other communications relating to our services.
We generally collect personal data directly from customers when they complete forms, make bookings, enter into agreements, contact us, or make payments. We may also receive data from authorised representatives, payment providers, or other service partners where necessary to provide our services.
We do not intentionally collect special category data unless it is required by law or provided voluntarily and lawfully by the customer.
3. How We Use Personal Data
We use personal data to deliver and manage our storage services and to meet our legal and operational responsibilities. This may include:
- creating and administering customer accounts;
- processing bookings, payments, and renewals;
- verifying identity and preventing fraud;
- maintaining facility security and access controls;
- responding to enquiries, complaints, and service requests;
- meeting accounting, tax, and record-keeping obligations;
- protecting our rights, property, customers, and staff;
- improving our services and operational processes.
We only process personal data for specific, explicit, and legitimate purposes. We do not use customer data in ways that are incompatible with those purposes.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis to process personal data. Pondersend Storage relies on the following bases, depending on the context:
Contract
We process data where it is necessary to enter into or perform a storage agreement with the customer. This includes managing your storage unit, billing, providing access, and fulfilling service obligations.
Legal obligation
We process certain data to comply with laws and regulations, including tax, accounting, fraud prevention, and regulatory requirements.
Legitimate interests
We may process data where it is necessary for our legitimate business interests, provided these interests are not overridden by the rights and freedoms of the customer. Examples include site security, incident management, service improvement, and protecting against misuse.
Consent
Where we rely on consent, we will make it clear what the consent relates to and how it may be withdrawn. Consent may be used for optional communications or other limited purposes where required by law.
We do not depend on consent where another lawful basis is more appropriate.
5. Data Retention
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, and reporting obligations. Retention periods vary depending on the type of information and the reason for processing.
For example, customer account records, billing information, and contractual documents may be retained for the duration of the service relationship and for a further period after the relationship ends, where required by law or needed to resolve disputes. Security records may also be retained for a limited period to support incident investigation and site protection.
When personal data is no longer required, we will securely delete, anonymise, or archive it in accordance with our retention practices.
6. Sharing and Processors
We may share personal data with trusted third parties where necessary to operate our business and provide services. These third parties act as processors or independent controllers, depending on the context.
Processors may include:
- payment service providers that handle transactions;
- IT and cloud service providers that store or support our systems;
- security and monitoring providers that assist with facility protection;
- administrative and professional advisors who support business operations;
- maintenance and facility management contractors where access is required for service delivery.
Where processors handle personal data on our behalf, they are required to act only on our instructions, apply appropriate security measures, and comply with GDPR requirements through written agreements or equivalent safeguards.
We may also disclose personal data if required by law, court order, or lawful request from public authorities, or where necessary to protect our legal rights or prevent harm.
7. Data Security
We use technical and organisational measures designed to protect personal data against accidental loss, unlawful access, misuse, alteration, or disclosure. These measures may include access restrictions, secure systems, staff confidentiality obligations, and monitoring of sensitive operational areas.
While we strive to safeguard all personal data, no method of transmission or storage is entirely risk-free. We therefore maintain security practices proportionate to the nature of the data and the risks involved.
8. User Rights
Customers have rights under GDPR in relation to their personal data. Subject to legal limitations, these rights may include:
- Right of access - to request confirmation of whether we process your data and to obtain a copy of it;
- Right to rectification - to request correction of inaccurate or incomplete data;
- Right to erasure - to request deletion of data in certain circumstances;
- Right to restriction - to request limited use of your data in certain cases;
- Right to data portability - to receive certain data in a structured, commonly used format;
- Right to object - to object to processing based on legitimate interests or direct marketing;
- Right to withdraw consent - where processing is based on consent, without affecting prior lawful processing.
We may need to verify your identity before responding to a request. If a request is refused or limited, we will explain the reasons where permitted by law.
Customers also have the right to lodge a complaint with their local data protection authority if they believe their rights have been infringed.
9. International Transfers
If personal data is transferred outside the European Economic Area, we will ensure appropriate safeguards are in place as required by GDPR. These may include standard contractual clauses or other lawful transfer mechanisms.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service arrangements. Any updated version will apply from the date it is made effective. Customers are encouraged to review the policy periodically to remain informed about how their data is handled.
11. Summary of Key Principles
Pondersend Storage processes personal data in a manner that is lawful, limited, and proportionate. We collect only what is needed to provide storage services, we rely on clear lawful bases for processing, we retain data only as long as necessary, and we use processors under proper safeguards. Customers may exercise GDPR rights to control and understand how their personal data is used.
This Privacy Policy applies to all Pondersend Storage customers in area.