TLS Security Consultancy A division of Tameside Lock Services
Privacy Notice
For customers, prospective customers and people connected with residential physical-security assessment services.
1. Who this notice applies to
This Privacy Notice explains how TLS Security Consultancy handles personal information when you enquire about, book or receive a residential physical-security assessment, or otherwise communicate with us about that service. TLS Security Consultancy is the customer-facing name for the assessment service operated as part of Tameside Lock Services.
For these activities, Paul Campbell trading as Tameside Lock Services / TLS Security Consultancy is the data controller. This means we decide why and how personal information is used.
2. Information we may collect
Depending on the enquiry or assessment, we may collect the following categories of information:
- Identity and contact information - such as your name, telephone number, email address and correspondence address where relevant.
- Booking and contract information - including the service booked, assessment reference, appointment details, agreed fee, authority to commission the assessment, access restrictions and cancellation/early-performance records.
- Property and assessment information - including the address assessed, property type, agreed scope, observations, risk ratings, recommendations, field notes and report content.
- Security-sensitive evidence - including photographs of doors, windows, boundaries, locks, CCTV/alarm equipment or other relevant features where reasonably necessary to evidence findings.
- Communications - including emails, messages, call notes and information you provide when asking questions, changing a booking, making a complaint or exercising a data-protection right.
- Payment and accounting information - such as invoice/payment status, transaction references and records needed for bookkeeping or tax purposes. We do not need to retain full payment-card details where a bank or payment provider processes them.
- Information provided by another person - for example where a property owner, landlord, managing agent or authorised representative arranges an assessment on your behalf.
3. Why we use your information and our lawful bases
We must have a lawful basis whenever we use personal information. The basis depends on the purpose. The main purposes for this service are set out below.
| Purpose | Typical information | Lawful basis |
|---|---|---|
| Respond to an enquiry, provide a quote or take steps you ask us to take before booking. | Contact details, property/service details, correspondence. | Contract - necessary to take steps at your request before entering into a contract. |
| Book, arrange and perform the assessment and prepare/deliver the report. | Identity/contact, booking, property, scope, assessment records, relevant photographs. | Contract - necessary to provide the service you booked. |
| Take payment, issue records and meet tax/accounting requirements. | Payment status, invoices, transaction and accounting records. | Contract and legal obligation, depending on the record and purpose. |
| Maintain proportionate records, handle complaints, protect legal rights and deal with insurers/advisers where necessary. | Contract, report, assessment evidence, correspondence, complaint/claim records. | Legitimate interests - managing the service, demonstrating what was assessed, handling complaints, establishing/defending legal rights and managing insurance. |
| Protect customers, our systems and security-sensitive assessment information. | Access/security logs where available, assessment records, incident information. | Legitimate interests - keeping information secure, preventing misuse and protecting customers and the business. |
| Send direct marketing about our own services, if we decide to do so. | Name and electronic contact details, marketing preference. | Consent where required, or legitimate interests only where the law (including PECR) permits. You can opt out at any time. |
4. Special-category or criminal-offence information
We do not normally need special-category personal information (for example health information) or criminal-offence information to provide a residential security assessment. If you voluntarily provide information of this type because it is genuinely relevant to safe access, an incident, a complaint or a legal matter, we will minimise what we record and only use it where an appropriate legal basis and additional condition applies. Please avoid sending unnecessary information about named suspects, victims, medical matters or other people.
5. Photographs and security-sensitive property information
Assessment photographs are taken only where reasonably useful for documenting the condition observed, supporting a finding, preparing the report or maintaining an appropriate record of the service. The assessment authorisation can restrict photography or identify areas that must not be photographed.
We do not use assessment photographs, customer reports or identifiable property-security information for advertising, social media, training examples or promotional case studies without separate permission or another clear lawful basis. Where examples are used, we will prefer anonymised material that does not identify the customer or property.
6. Where information comes from
Most information comes directly from you. We may also receive relevant information from a person acting with authority for the property, such as an owner, landlord, managing agent or family member, or from a professional adviser coordinating the assessment. Where information is obtained from another source, we will provide privacy information where required and be clear about the source where reasonably possible.
7. Who we may share information with
We do not sell personal information. We may share limited information where reasonably necessary with:
- IT, email, website, document-storage or other service providers that process information for us;
- banks, payment providers, bookkeepers, accountants or tax advisers where relevant;
- professional indemnity/public-liability insurers, insurance brokers, solicitors or other professional advisers where a complaint, claim, risk issue or coverage question requires it;
- specialist contractors or advisers, but only where you ask us to make a referral or sharing is otherwise necessary and lawful;
- law enforcement, regulators, courts, tribunals or public authorities where disclosure is required or permitted by law;
- a recipient you authorise, such as an insurer, landlord, managing agent or contractor receiving your report.
Where another organisation processes personal information on our behalf, we will use appropriate arrangements intended to protect the information and limit use to the relevant service.
8. International transfers
Some technology or service providers may process information outside the UK. If personal information is transferred internationally, we will use a transfer mechanism or safeguard required by UK data-protection law where one is needed, such as UK adequacy regulations or approved contractual safeguards. You can contact us if you want more information about safeguards relevant to a particular transfer.
9. How we protect information
Security-assessment records can reveal vulnerabilities and therefore require careful handling. We use proportionate technical and organisational measures appropriate to the risk, including restricting access to people who need it for the service, using access controls on devices/accounts, minimising unnecessary copies, and taking care when transferring or sharing reports and photographs.
No storage or transmission method can remove every risk. If we become aware of a personal-data breach, we will assess it and take the steps required by data-protection law, including notification to affected people or the Information Commissioner where the legal thresholds are met.
10. How long we keep information
We do not keep personal information indefinitely. Our working retention schedule is designed to balance legal/accounting needs and the need to evidence professional work against the sensitivity of property-security information.
| Record | Normal retention | Reason / notes |
|---|---|---|
| Enquiries that do not become a booking | Normally 12 months after last meaningful contact. | Allows reasonable follow-up and handling of questions; then delete/anonymise unless another reason applies. |
| Booking, contract, invoice/payment and core business records | Normally 6 years after completion / relevant accounting period. | Supports tax/accounting records, contract administration and legal/insurance needs. |
| Final report, field assessment record and selected evidence photographs supporting findings | Normally 6 years after report delivery. | May be required to demonstrate what was observed/recommended and to manage complaints, insurance or legal claims. Access should remain restricted because the material is security-sensitive. |
| Duplicate, accidental or unnecessary raw photographs not needed for the report/record | Normally deleted within 90 days after report delivery. | Reduces unnecessary retention of security-sensitive imagery. |
| Complaints, disputes, insurance matters or legal claims | For the duration of the matter and normally up to 6 years after closure where still necessary. | Allows the matter to be investigated, resolved and evidenced. |
| Marketing preferences / suppression record | Until consent is withdrawn or marketing stops; a minimal suppression record may be kept longer. | Helps ensure we do not contact someone who has opted out. |
We may keep a record for longer where necessary because of an ongoing complaint, legal claim, insurer requirement, regulatory request or other legal obligation. We will review retention if our insurer, accountant or legal adviser identifies a different justified period. When information is no longer needed, we will delete it securely or anonymise it where appropriate.
11. Your data-protection rights
Depending on the circumstances and the lawful basis being used, you may have rights to:
- ask for confirmation that we process your personal information and obtain a copy of it (access);
- ask us to correct inaccurate or incomplete information (rectification);
- ask us to delete information in certain circumstances (erasure);
- ask us to restrict how information is used in certain circumstances (restriction);
- receive certain information you provided to us in a portable format where the legal conditions are met (data portability);
- object to processing based on legitimate interests in certain circumstances;
- withdraw consent at any time where consent is the lawful basis. Withdrawal does not make earlier processing unlawful.
These rights are not absolute and exemptions or other legal reasons may mean we cannot comply with a request in full. We may need information to confirm your identity before acting on a request. We will respond within the applicable statutory timeframe.
12. How to make a privacy request or complaint
For an access, correction, deletion, objection or other privacy request, or if you believe we have handled your information incorrectly, contact us at tamesidelockservices@gmail.com or by the phone/postal details in this notice. Please give enough information for us to identify the relevant enquiry or assessment.
If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (ICO), the UK data-protection regulator. Information about making a data-protection complaint is available at www.ico.org.uk. The ICO helpline is 0303 123 1113.
13. Direct marketing
Service messages about an enquiry, booking, appointment, report, payment, safety issue or existing contract are not treated as marketing merely because they are sent electronically. If we send promotional emails, texts, direct messages or similar marketing, we will do so only where the law allows and will provide a simple way to opt out. We will keep a minimal suppression record where necessary to honour an opt-out.
14. Website, social media and cookies
If you contact us through the website or a social-media platform, that platform may also process information under its own privacy terms. We are responsible for our own use of information once we receive it. Where our website uses cookies or similar technologies, cookie information should be provided separately; non-essential cookies or tracking technologies will only be used in accordance with applicable consent requirements.
This website does not currently use analytics, advertising cookies, account registration or a server-side contact-form database. The email routes open your usual email application; the site itself does not store the message.
15. Children and incidental information about other people
The assessment service is intended to be booked by adults. We do not intentionally collect information from children as customers. Assessment photographs should normally avoid identifiable people altogether. If information about another person is incidentally provided or captured, we will minimise and remove it where it is not relevant to the assessment.
16. Automated decision-making
We do not make decisions about customers using solely automated processing that produces legal or similarly significant effects. Risk ratings and recommendations in a security assessment are subject to human professional judgment.
17. Changes to this Privacy Notice
We may update this notice where our services, technology, storage arrangements, suppliers or legal requirements change. The version supplied or made available at the time will show its issue date. Material changes affecting current customers will be communicated where required.
18. Version control
- Document
- TLS Security Consultancy Privacy Notice
- Version
- v1.0
- Issue date
- 18 August 2026
- Review trigger
- Change in storage/technology providers, retention schedule, marketing activity, service scope, insurer requirements or relevant data-protection/PECR law.
- Next routine review
- 12 months from issue, or sooner if a review trigger occurs.
