1. Purpose
The purpose of this Data Protection Policy is to ensure that Harrison Steel Properties Ltd (“we”, “us”, “our”) complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable data protection laws. We are committed to protecting the rights and freedoms of individuals whose personal data we process as part of our Non-Domestic Energy Performance Certificate (EPC) services.
2. Scope
This policy applies to:
3. Data Protection Principles
We adhere to the following principles:
4. Lawful Bases for Processing
We process personal data under one or more of the following lawful bases:
5. Data Subject Rights
Under the UK GDPR, individuals have the right to:
Requests should be made in writing to our Data Protection Officer.
6. Data Security Measures
We implement appropriate technical and organisational measures to safeguard personal data, including:
7. Data Sharing
We may share personal data with:
We will never sell personal data to third parties.
8. Data Retention
EPC-related personal data will be retained for 15 years in line with EPC validity requirements, unless a longer retention period is required by law.
9. Data Breaches
In the event of a data breach:
10. Responsibilities
The Data Protection Officer (DPO) is responsible for ensuring compliance with this policy, responding to data subject requests, and liaising with the ICO.
11. Contact
Data Protection Officer
Harrison Steel Properties Ltd
Sixty Six, North Quay, Great Yarmouth, Norfolk, United Kingdom, NR30 1HE
Email: info@harrisonsteel.co.uk
ICO Registration Number: ZB640083
12. Review and Updates
This policy will be reviewed annually or sooner if there are significant changes in legislation, our operations, or data processing activities.
The information contained in this website is subject to UK regulatory regime and is therefore intended for consumers based in the UK
Copyright © 2025 Harrison Steel Properties Limited | Company No. 14536625
All Rights Reserved.