1. Who we are and how to contact us
Lewis Griffiths t/a Pembrokeshire Security is a sole-trader security-services business. Pembrokeshire Security Services and PSS are brand references to the same business. For processing where we determine the purposes and means, Lewis Griffiths t/a Pembrokeshire Security is the data controller.
Correspondence / service address: Barnhill Farm, The Ridgeway, Lamphey, Pembrokeshire, SA71 5PB, United Kingdom. Email: PembrokeshireSecurity@gmail.com. Telephone: 01646 833212.
Our Information Commissioner's Office (ICO) registration number is ZC256541.
This policy explains our handling of personal data under UK data-protection law. Where we act on a client's documented instructions as a processor, the client's privacy information and our agreed processing arrangements also apply.
2. Who this policy covers
This policy covers prospective and existing clients and their representatives; suppliers; contractors and subcontractors; personnel and job applicants; website visitors and enquirers; and people whose information appears in security, assignment or incident records, including visitors, witnesses and other individuals involved in an incident.
The information we handle depends on the relationship, service, role and circumstances. Not every category described below applies to every individual.
3. Personal data we may collect
We collect only information relevant and proportionate to a lawful purpose. Depending on the circumstances, this may include:
Where legitimately required, records may include special-category data, such as health information, or criminal-offence-related information. We process such information only where necessary, with an applicable lawful basis and the additional legal conditions, safeguards and documentation required by law. An operational need alone does not authorise this processing.
- Identity, contact and business details, including names, business roles, correspondence addresses, email addresses and telephone numbers.
- Enquiry, quotation, contract and correspondence information; invoice, payment and accounting records relevant to our business relationship.
- Operational attendance, site, shift, assignment and activity records; incident reports, witness details and accounts, escalation and follow-up records.
- Personnel identity and right-to-work information; employment history and references where relevant; SIA licence details; qualifications, training, availability and deployment records.
- Limited website technical information necessary to deliver and secure the website, such as connection and request information processed by hosting and communications services.
4. Where information comes from
We receive information directly from individuals through discussions, emails, telephone calls, correspondence, applications and service activity. The website enquiry form is currently inactive and does not send or save the details entered into it.
Where appropriate and lawful, information may also come from clients, employers and referees, approved subcontractors, public registers and regulators, and other lawful sources. We consider the relevance, reliability and permitted use of information obtained indirectly and provide privacy information where required.
5. How we use personal data
We use relevant personal data for the following purposes, where applicable:
- Responding to enquiries, preparing quotations, arranging contracts and maintaining client relationships.
- Planning mobilisation, allocating personnel, briefing assignments and delivering agreed security services.
- Client communications, attendance and service reporting, and maintaining factual operational and incident records.
- Recruitment, personnel administration, right-to-work and role-appropriate SIA licence checks, training and deployment management.
- Handling complaints, investigating incidents and concerns, and supporting proportionate follow-up action.
- Invoicing, payment administration, accounting and tax obligations.
- Insurance administration, obtaining professional advice and establishing, exercising or defending legal claims.
- Protecting people, premises, information and business systems, and meeting applicable legal and regulatory requirements.
6. Our lawful bases
We identify an appropriate lawful basis for each purpose. Contract applies where processing is necessary to enter into or perform a contract with the individual. It does not automatically cover every employee or representative of a business client; relevant legitimate interests or legal obligations may apply instead.
Legal obligation applies where processing is necessary to comply with applicable duties, such as employment, licensing, accounting, tax or other regulatory requirements.
Legitimate interests may support business-to-business enquiries and communications, staffing and service coordination, maintaining reliable records, protecting people and property, preventing or investigating misconduct, securing systems, administering our business and handling claims. We assess necessity and balance these interests against individuals' rights, freedoms and reasonable expectations.
Consent is used only where it is appropriate, freely given, specific and informed. Where we rely on consent, it may be withdrawn; this does not affect the lawfulness of processing before withdrawal.
Special-category information requires a separate condition under Article 9 of the UK GDPR. Criminal-offence data requires an appropriate Article 10 authorisation and applicable UK legal condition. Where required, we maintain an appropriate policy document and related safeguards. We do not treat ordinary legitimate interests or a contract as sufficient on their own for these categories.
7. Security-industry and operational records
Operational records may document attendance, assignment activity, access-related events, incidents, witness accounts, escalation and actions taken. We aim to record information factually, accurately and proportionately, distinguishing observations from allegations, opinions and information supplied by others.
Personnel should avoid unnecessary sensitive detail, speculation or irrelevant personal information. Access and disclosure are limited to those with a legitimate need. Records may be corrected or supplemented where appropriate while preserving an accurate audit trail.
8. Personnel information and SIA licence verification
We verify SIA licence status where required for the role and use relevant personnel information for lawful employment, licensing and deployment purposes.
The information required depends on the role, legal requirements and assignment. Personnel information is handled on a need-to-know basis and is not shared with clients in greater detail than is justified. Additional conditions and safeguards apply where processing involves special-category or criminal-offence information.
10. Incidents, emergencies and law enforcement
Incident information may be used to protect people and property, manage an emergency, investigate concerns, support insurance or legal claims, and meet lawful requests or duties. We may provide relevant records to clients, emergency services, police or other competent authorities where necessary and lawful.
Disclosure is assessed in context, including urgency, legal authority, necessity and the rights of affected individuals. We do not routinely release entire records without considering relevance and proportionality. Lawful exemptions may restrict disclosure to an individual where, for example, doing so would prejudice an investigation or another person's rights.
11. CCTV and client-operated systems
PSS provides appropriately licensed personnel to support client-owned or client-operated CCTV and control-room functions, subject to contract requirements. This is personnel support, not a PSS-owned or operated monitoring centre.
Controller and processor roles depend on the actual arrangements. A client is normally the controller where it determines the purposes and means of CCTV processing. PSS may act as a processor under the client's documented instructions; separate controller responsibilities may arise for records we determine are necessary for our own lawful purposes.
The relevant client should provide information about its CCTV use and how individuals can exercise rights. We assist with requests and security obligations as required by law and the agreed processing arrangements, rather than assuming authority to release client footage independently.
12. How long we keep information
Personal data is kept only for as long as justified by its purpose and applicable legal, contractual, insurance, accounting and regulatory requirements. We use documented retention criteria and schedules appropriate to the categories of records and review continued need.
Relevant factors include the duration of the relationship or assignment, the sensitivity and usefulness of the information, obligations to retain records, applicable claim periods, ongoing disputes or investigations and client processing instructions. Where justified, a legal hold may suspend routine deletion. Information is securely deleted, returned or anonymised when it is no longer required, as appropriate to the record and our role.
13. Protecting personal data
We use proportionate organisational and technical measures appropriate to the information and risks. These include restricting access to authorised people, confidentiality requirements, appropriate handling and sharing practices, secure storage and communications, personnel awareness, and incident-management procedures.
Providers and processing arrangements are considered with regard to security and confidentiality. No system can guarantee absolute security; suspected data breaches are assessed and addressed, including notifying the ICO and affected individuals where legally required.
14. International transfers
Some IT or communications providers may process information outside the United Kingdom. Where this involves a restricted transfer, we use an appropriate UK transfer mechanism and safeguards as required, such as applicable adequacy arrangements or approved contractual safeguards, with the required risk assessment and additional measures where necessary.
You may contact us for information about safeguards relevant to your data, subject to lawful confidentiality and security restrictions.
16. Your data-protection rights
Subject to the applicable conditions, you may request access to your personal data, rectification of inaccuracies, erasure, restriction of processing, or portability. You may withdraw consent where it is used. Rights depend on the lawful basis and circumstances; lawful exemptions may apply, including protection of others' rights or relevant investigation and legal-claim requirements.
Right to object: where we rely on legitimate interests, you may object on grounds relating to your particular situation. We will stop that processing unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or it is necessary for legal claims. You may object to processing for direct marketing at any time, including related profiling.
To exercise a right, contact PembrokeshireSecurity@gmail.com or write to our correspondence address. We may request proportionate information to verify identity or clarify a request and will respond within the applicable statutory time limits. Where we process client-controlled information, we may refer the request to the controller and assist as required.
17. Data-protection complaints
If you are concerned about our handling of personal data, make a data-protection complaint by emailing PembrokeshireSecurity@gmail.com or writing to Lewis Griffiths t/a Pembrokeshire Security, Barnhill Farm, The Ridgeway, Lamphey, Pembrokeshire, SA71 5PB, United Kingdom. Please describe the concern and provide sufficient information for us to understand and respond; do not send unnecessary sensitive information.
We will acknowledge a data-protection complaint within 30 days of receipt. We will investigate without undue delay, take appropriate steps in response and keep you informed about progress and the outcome. We may ask for information reasonably needed to clarify or investigate the complaint.
You can also complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint/. Our complaints process does not replace or restrict your statutory rights, including the right to complain to the ICO or seek a judicial remedy.
18. Automated decision-making
We do not make decisions through this website based solely on automated processing that produce legal or similarly significant effects on individuals. If this changes, we will provide the required information, identify a lawful basis and put applicable safeguards in place before doing so.
19. Changes to this policy
We may update this policy to reflect changes to our services, processing or legal requirements. The dated version on this page identifies the current website policy. Where required, we will bring material changes to affected individuals' attention through an appropriate communication method.
