Privacy Policy - Westhendon Storage

Westhendon Storage is committed to protecting the privacy and personal data of all customers in the area where our services are provided. This Privacy Policy explains how we collect, use, store, share, and protect personal information in accordance with the UK GDPR and the Data Protection Act 2018. It applies to all Westhendon Storage customers in area, including individuals and businesses who use our storage services, make enquiries, visit our premises, or otherwise interact with us.

1. Who We Are

For the purposes of data protection law, Westhendon Storage is the data controller of the personal information described in this policy. This means we decide how and why your personal data is processed. We take our responsibilities seriously and aim to handle all information lawfully, fairly, transparently, and securely.

2. Information We Collect

We may collect and process different types of personal data depending on how you use our services. This may include:

  • Identity information such as your name, date of birth, and proof of identity where needed.
  • Contact information such as address, email address, and telephone number.
  • Account and contract details including service preferences, storage unit allocation, and billing records.
  • Payment information such as payment method details and transaction history, although we do not usually store full card details where payment processors handle that securely.
  • Access and security information such as entry logs, CCTV images, and records of site access where applicable.
  • Communications including enquiries, complaints, service requests, and correspondence.
  • Technical information such as device or browser data if you interact with any digital systems we use.

We do not intentionally collect special category data unless it is required by law or you choose to provide it in the course of a specific matter. If such information is received, it will be handled with extra care and only where a lawful basis applies.

3. How We Use Your Personal Data

We use personal data for the following purposes:

  • To provide storage services and manage customer accounts.
  • To verify identity and maintain security at our premises.
  • To process payments, invoices, and refunds where applicable.
  • To communicate with you about your account, bookings, and service matters.
  • To comply with legal and regulatory obligations.
  • To prevent fraud, misuse, and unlawful activity.
  • To protect our property, our customers, and our staff.
  • To resolve disputes, enforce agreements, and establish or defend legal claims.

We only use your personal information where it is necessary and proportionate to do so. Our approach is based on the principle of data minimisation, meaning we collect only what we need and keep it only for as long as required.

4. Lawful Basis for Processing

Under GDPR, we must have a lawful basis for processing personal data. Westhendon Storage relies on the following bases where appropriate:

Contract

We process personal data when it is necessary to enter into or perform a contract with you. This includes managing your storage agreement, account setup, billing, and related service delivery.

Legal Obligation

We may process information to comply with legal duties, such as tax, accounting, fraud prevention, record-keeping, and other obligations imposed by law.

Legitimate Interests

We may process data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. These interests include site security, customer protection, business administration, service improvement, and the prevention of unauthorised access or misuse.

Consent

In limited situations, we may rely on your consent, for example where optional marketing or certain non-essential communications are involved. Where consent is used, you may withdraw it at any time.

Vital Interests

In rare cases, we may process personal data where necessary to protect someone’s vital interests, such as in an emergency involving health or safety.

5. Sharing Your Personal Data

We may share personal data with trusted third parties known as processors or, in some cases, independent controllers. We only share information when necessary for legitimate business purposes, legal compliance, or service delivery.

Examples of processors and other recipients may include:

  • Payment processors who handle secure payment transactions.
  • IT and hosting providers who support our record systems, security tools, and communications.
  • Security service providers who assist with monitoring, alarms, or CCTV management.
  • Professional advisers such as accountants, auditors, insurers, and legal advisers.
  • Authorities and regulators where disclosure is required by law or necessary to protect rights, safety, or property.

When we use processors, they are required to act only on our instructions, protect your information, and maintain appropriate security measures. We do not sell personal data.

6. Data Retention

We retain personal data only for as long as it is necessary for the purposes for which it was collected, and no longer than required by law. The retention period may depend on the type of information and the reason it is held.

  • Customer and contract records may be kept for the duration of the relationship and for a reasonable period after it ends.
  • Financial and tax records are generally retained for periods required by accounting and tax law.
  • Security records such as access logs or CCTV may be kept for shorter periods unless needed for an investigation or legal claim.
  • Correspondence and complaints may be retained as needed to manage the issue and maintain business records.

When data is no longer needed, it is securely deleted, anonymised, or otherwise disposed of in a safe and appropriate manner.

7. Data Security

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, disclosure, or destruction. These measures may include access controls, secure storage, staff training, and procedures for handling information securely. While we work hard to protect data, no system can be guaranteed to be completely secure. We therefore encourage customers to take care when sharing personal information with us or others.

8. International Transfers

Where any service provider processes data outside the United Kingdom, we will take steps to ensure appropriate safeguards are in place. This may include using approved contractual protections or transferring data only to countries recognised as providing an adequate level of protection.

9. Your Rights

Under data protection law, you have a number of rights in relation to your personal data. These rights are not absolute and may be subject to legal conditions or exemptions.

  • Right of access – you may request a copy of the personal data we hold about you.
  • Right to rectification – you may ask us to correct inaccurate or incomplete information.
  • Right to erasure – in certain circumstances, you may ask us to delete your data.
  • Right to restrict processing – you may request that we limit how your data is used in certain situations.
  • Right to object – you may object to processing based on legitimate interests or direct marketing.
  • Right to data portability – where applicable, you may request your data in a structured, commonly used format.
  • Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.

If you exercise any of these rights, we may need to verify your identity before responding. We aim to respond within the time limits required by law.

10. Automated Decision-Making

Westhendon Storage does not rely on solely automated decision-making that produces legal or similarly significant effects about customers. If this changes in the future, we will update this policy and explain the relevant safeguards.

11. Children’s Data

Our services are intended primarily for adults. We do not knowingly collect personal data from children unless it is provided lawfully by a parent, guardian, or authorised representative in connection with our services. Where children’s data is processed, it will be treated with particular sensitivity.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data protection practices. Any revised version will apply from the date it is issued. We encourage customers to review this policy periodically so they remain informed about how their personal data is handled.

13. How We Respect Your Privacy

We believe privacy should be built into every stage of our operations. That is why we aim to keep personal data accurate, limited, secure, and used only for clear and lawful purposes. Our commitment is to be transparent, accountable, and respectful in all our handling of customer information. For all Westhendon Storage customers in area, this policy sets out the standards we follow when processing personal data and the protections you can expect from us.

West Hendon Storage

GDPR-compliant privacy policy for Westhendon Storage covering data collection, lawful bases, retention, processors, user rights, and security.

Get a Quote

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.