Privacy Policy - Self Storage Bromley
This Privacy Policy explains how Self Storage Bromley collects, uses, stores, shares, and protects personal data in connection with storage services provided to customers in the Bromley area. It applies to all Self Storage Bromley customers in area, including prospective customers, active account holders, former customers, and any person who communicates with us about our services.
We are committed to handling personal data in accordance with the UK GDPR and the Data Protection Act 2018. This policy is intended to help you understand what information we process, why we process it, how long we keep it, who may receive it, and what rights you have over your data.
1. Personal Data We Collect
We collect only the information needed to provide secure and reliable storage services, comply with our legal obligations, and manage our business operations. The type of data we collect depends on how you use our services.
Information you provide directly
- Identity details such as your name, date of birth, and signature.
- Contact details such as billing address, email address, and telephone number.
- Account and booking information such as your chosen storage unit, access dates, payment plan, and agreement details.
- Payment information needed to process invoices, fees, and deposits.
- Correspondence including messages, complaints, and service requests.
- Verification documents where required for identity checks, fraud prevention, or compliance purposes.
Information we collect automatically
- Access records such as entry logs, gate activity, and security system events.
- Technical data including device information, IP address, and browser details if you interact with our digital services.
- Security footage from CCTV where such systems are in operation for safety, security, and crime prevention.
We do not collect more data than necessary, and we aim to ensure that all information is relevant, limited, and accurate.
2. How We Use Personal Data
We use personal data for the following purposes:
- to set up and manage customer accounts;
- to provide storage services and administer access to storage units;
- to process payments, invoices, and refunds;
- to communicate about bookings, renewals, service updates, or account issues;
- to ensure site safety, security, and loss prevention;
- to comply with legal, tax, accounting, and regulatory obligations;
- to investigate complaints, disputes, or suspected misuse of services;
- to improve our services, systems, and customer experience;
- to establish, exercise, or defend legal claims where necessary.
We only use personal data in ways that are consistent with the purpose for which it was collected, unless we reasonably need to use it for another compatible purpose or we have a lawful basis to do so.
3. Lawful Basis for Processing
Under data protection law, we must have a lawful basis for processing personal data. Depending on the specific activity, we rely on one or more of the following:
Contract
We process data when it is necessary to enter into or perform a contract with you. This includes managing your storage agreement, billing, customer support, and access control linked to your service.
Legal obligation
We may process data to comply with laws and regulations, including accounting, taxation, fraud prevention, and record-keeping obligations.
Legitimate interests
We may process data where it is necessary for our legitimate interests and where your rights do not override those interests. Examples include preventing theft or misuse, maintaining site security, improving our operations, and responding to customer enquiries. When relying on legitimate interests, we assess the impact on individuals and ensure appropriate safeguards are in place.
Consent
In limited situations, we may rely on your consent, for example where you have explicitly agreed to receive certain types of marketing communication or where consent is otherwise required by law. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Vital interests and public task
These bases are generally unlikely to apply to routine storage services, but we may use them in exceptional circumstances if necessary to protect someone’s life or comply with a public duty.
4. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, including for legal, accounting, insurance, and dispute resolution purposes. Retention periods vary depending on the type of data and the reason for processing.
- Customer account records are typically kept for the duration of the storage agreement and for a reasonable period after it ends.
- Financial and transaction records are kept for the period required by applicable tax and accounting laws.
- Security records such as access logs and CCTV footage are retained for limited periods unless needed longer for investigation, security incidents, or legal claims.
- Correspondence and complaints may be retained while the issue is active and for a suitable period afterwards to demonstrate how it was handled.
When personal data is no longer required, we will securely delete, anonymise, or archive it in accordance with our retention practices. We do not keep data indefinitely without a legitimate reason.
5. Sharing Personal Data and Processors
We may share personal data with trusted third parties that help us operate our services. These third parties act as processors when they process data on our behalf and under our instructions. We require processors to handle personal data securely, confidentially, and only for agreed purposes.
Examples of processors and service providers
- Payment service providers used to process card or bank-related transactions.
- IT and cloud service providers that host systems, store records, or support communications.
- Security providers involved in CCTV, alarm monitoring, or site protection services.
- Professional advisers such as accountants, auditors, insurers, or legal advisers where necessary.
- Maintenance and service contractors when access is required to support site operations.
We may also disclose data to law enforcement, regulators, courts, or other authorities where required by law or where disclosure is necessary to protect our rights, customers, staff, property, or the public.
We do not sell personal data. Where data is transferred outside the UK, we will take appropriate safeguards to ensure it is protected to an adequate standard.
6. Data Security
We use appropriate technical and organisational measures to protect personal data from unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, secure storage, staff training, and monitoring of systems and premises.
Although no system can be guaranteed to be completely secure, we take data protection seriously and regularly review our safeguards to reduce risk. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will act in line with legal reporting and notification requirements.
7. Your Rights
Under data protection law, you have certain rights regarding your personal data. These rights may be subject to conditions or exemptions, but we will always respond carefully and fairly to any request.
- Right of access – you may ask for a copy of the personal data we hold about you.
- Right to rectification – you may ask us to correct inaccurate or incomplete data.
- Right to erasure – you may request deletion of your data in certain circumstances.
- Right to restriction – you may ask us to limit how we use your data in specific situations.
- Right to data portability – you may request a copy of certain information in a reusable format.
- Right to object – you may object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
If you exercise one of these rights, we may need to verify your identity before responding. We aim to respond within the time limits required by law.
8. Marketing Preferences
We may send service-related messages that are necessary for your account or storage arrangement. These are not marketing communications. If we send marketing messages, we will do so only where permitted by law and, where required, with your consent.
You can object to marketing at any time. If you do so, we will stop sending such communications as soon as reasonably practicable.
9. Children’s Data
Our storage services are not directed to children, and we do not knowingly collect personal data from children except where it is necessary in connection with a lawful customer relationship or legal requirement. If we become aware that data has been collected inappropriately, we will take appropriate steps to delete or safeguard it.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, regulation, our services, or our internal practices. Any updated version will apply from the date it is published or otherwise communicated. We encourage customers to review the policy periodically so they remain informed about how their personal data is handled.
11. Summary of Our Commitment
Self Storage Bromley is committed to processing personal data lawfully, fairly, and transparently. We collect only what we need, use it for clear and legitimate purposes, retain it for limited periods, and share it only with trusted processors or where required by law. We respect your rights and aim to handle all personal data with care, accountability, and integrity.
Last updated: This policy is effective for customers in the Bromley area and applies to all services provided by Self Storage Bromley.