Self Storage Sutton Privacy Policy
This Privacy Policy explains how Self Storage Sutton collects, uses, stores, and protects personal data relating to our customers and prospective customers. It applies to all Self Storage Sutton customers and enquirers in the surrounding area who use our services, visit our premises, or interact with us through any communication channel.
Who we are and scope of this policy
Self Storage Sutton is a provider of self storage services to individual and business customers. In the course of providing these services, we act as a data controller for the personal data you provide to us. This Privacy Policy covers all processing activities where we determine the purposes and means of processing your personal data in connection with our storage services and related activities.
Types of personal data we collect
We may collect and process the following categories of personal data, depending on how you interact with us and which services you use:
Identification and contact details, such as your name, postal address, billing address, contact address, and any other contact details you choose to provide.
Account and contract information, such as storage unit number, contract start and end dates, payment terms, services selected, communications relating to your bookings or contracts, and correspondence history.
Payment and transaction data, such as payment method details and records of payments made and amounts due. Where payments are processed by third party payment providers, we receive only limited information necessary to reconcile and manage your account.
Verification and security information, such as copies or details of identity documents where required for fraud prevention or legal compliance, vehicle registration numbers for site access, and access control data relating to use of our premises.
Technical and usage data, such as information about your interactions with our website or online tools, including pages visited, dates and times of access, and general device and browser information collected through standard logging technologies.
Communication data, including information you provide when you contact us in person, by post, or through other channels, and any notes we make in relation to your enquiries or requests.
How we collect your personal data
We collect personal data directly from you when you enquire about our services, request a quote, sign a storage agreement, make a payment, or contact us with questions or feedback. We also collect data generated through your use of our services and facilities, such as access logs to our storage premises and records of your interactions with us.
In some cases, we may obtain personal data from third parties, for example where a business customer provides contact details for an authorised user, or where a payment provider confirms that a payment has been made. Where we receive personal data from third parties, we process it only for the purposes described in this Privacy Policy.
Lawful bases for processing
We process your personal data only where we have a lawful basis under the UK General Data Protection Regulation and related data protection laws. Depending on the context, we rely on one or more of the following lawful bases:
Performance of a contract. We process personal data where it is necessary to enter into or perform a contract with you, including to set up and administer your storage agreement, manage payments, and provide customer support.
Compliance with legal obligations. We process personal data where necessary to comply with legal and regulatory requirements, such as tax and accounting rules, fraud prevention laws, and obligations to retain certain records.
Legitimate interests. We may process your personal data where it is necessary for our legitimate business interests or those of a third party, provided that your interests and fundamental rights do not override those interests. Our legitimate interests include managing and improving our services and facilities, ensuring the security of our premises, maintaining accurate records, and communicating with existing customers about service updates and relevant information.
Consent. In limited circumstances, we may rely on your consent, for example, for certain types of optional marketing communications. Where we rely on consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Purposes for which we use personal data
We use your personal data for the following purposes:
To provide and manage self storage services, including setting up your account, allocating storage units, administering access, and handling queries and complaints.
To process payments, issue invoices, handle refunds where applicable, and maintain accurate financial records.
To maintain the safety and security of our premises, customers, and staff, including through access control mechanisms and site management processes.
To comply with legal and regulatory obligations, including tax and accounting requirements, and to respond to lawful requests from public authorities.
To communicate with you about your contract, including service updates, changes to our terms, maintenance notices, and important safety or operational information.
To improve our services, facilities, and customer experience, including monitoring usage, responding to feedback, and conducting internal analysis.
Where permitted, to send you information about services that may be of interest to you, and to manage your communication preferences.
Data retention
We keep your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet any legal, accounting, or reporting requirements.
As a general rule, we retain contract and account records for a period required under applicable law after your contract ends, to enable us to respond to any questions or disputes and to comply with our legal obligations. Payment and invoicing records are retained in line with statutory retention periods for financial and tax documentation.
Access control and security information is kept for a period that enables us to investigate incidents and maintain site security, after which it is deleted or anonymised. Technical and usage data may be retained for a shorter period, unless it forms part of our legal or contractual records.
When personal data is no longer required for any of the purposes described in this Privacy Policy, we will securely delete or anonymise it in accordance with our data retention procedures.
Data processors and third parties
We may share your personal data with carefully selected third party service providers acting as data processors on our behalf. These providers only process your personal data in accordance with our instructions and for the purposes described in this Privacy Policy, and they are subject to contractual obligations to protect your data.
Such processors may include providers of payment processing services, customer relationship management tools, secure data storage and backup services, and professional advisers such as accountants where needed to support our business operations.
We may also share your personal data with other third parties where required by law, for example with public authorities, law enforcement agencies, or regulators, or where it is necessary to establish, exercise, or defend legal claims.
We do not sell your personal data to third parties.
International transfers
Where our service providers or their systems are located outside the United Kingdom or the European Economic Area, we take appropriate measures to ensure that any international transfers of personal data are carried out in compliance with applicable data protection laws. This may include relying on adequacy regulations, or implementing standard contractual clauses or other appropriate safeguards approved by relevant authorities.
Security of your personal data
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or damage. These measures include access controls, secure storage, and internal policies designed to ensure that personal data is handled only by staff who need it for their role and who are subject to confidentiality obligations.
While we use reasonable efforts to protect your personal data, no system can be guaranteed to be completely secure. You are also responsible for taking reasonable steps to protect your own information, for example by keeping your account details and any access codes secure.
Your data protection rights
Under data protection laws, you have a number of rights in relation to your personal data, subject to certain conditions and exceptions. These rights include:
The right of access. You have the right to obtain confirmation as to whether we process your personal data and, if so, to receive a copy of that data together with certain information about how it is used.
The right to rectification. You have the right to ask us to correct or complete any inaccurate or incomplete personal data we hold about you.
The right to erasure. In certain circumstances, you have the right to request the deletion of your personal data. This right is not absolute and may not apply where we are required or permitted to retain the data for legal or legitimate business reasons.
The right to restrict processing. You may request that we restrict the processing of your personal data in certain situations, for example while we verify the accuracy of the data or consider an objection you have raised.
The right to object. You have the right to object to processing that is based on our legitimate interests, including profiling related to those interests. We will stop processing your personal data unless we can demonstrate compelling legitimate grounds which override your interests, rights, and freedoms, or where processing is required for legal claims.
The right to data portability. Where processing is based on your consent or on a contract and is carried out by automated means, you may have the right to receive your personal data in a structured, commonly used, and machine readable format and to request that it is transmitted to another controller where technically feasible.
The right to withdraw consent. Where we rely on your consent as a lawful basis for processing, you have the right to withdraw that consent at any time.
You also have the right to lodge a complaint with a supervisory authority if you are unhappy with how we handle your personal data. In the United Kingdom, this is generally the Information Commissioner's Office. We encourage you to contact us first so that we can try to resolve any concerns directly.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, in applicable laws, or in how we process personal data. When we make significant changes, we will take appropriate steps to inform you, for example by updating the version available at our premises or through our usual communication channels. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
