Customer, Supplier and Website Privacy Notice

Reference: BWPS-DP-001 | Version: 2.1 | Effective: 31 August 2026 | Review: 31 August 2027 | Classification: Public

Who is responsible

David George Swaddle trading as Black & White Property Services is the data controller for the processing described in this notice.

Contact: enquiries@blackandwhiteaccess.co.uk, +44 7495 017080, 11 Boyd Street, Newcastle upon Tyne, NE15 8LU.

Information we collect

We may collect names, roles, organisations, contact details, property and site information, access and emergency contacts, enquiries, quotations, orders, invoices, payment administration, correspondence, job notes, photographs, videos, test results, signatures and completion evidence. For suppliers and subcontractors we may also collect insurance, qualifications, compliance and payment information. Website use may create form entries, IP addresses, device/browser information, security logs, cookie preferences and analytics information where enabled.

We avoid collecting sensitive information unless necessary and lawful for safety, accessibility, safeguarding, legal claims or another defined purpose.

Sources

Information may come from you, your employer, a customer, landlord, managing agent, facilities manager, insurer or contractor; from site activity and communications; from public professional or regulatory registers; and from the systems used to operate and secure our services.

Purposes and lawful bases

We use information to respond to enquiries and take pre-contract steps; plan and deliver work; manage access, safety, variations, defects and warranties; invoice and maintain accounts; prevent fraud; select and manage suppliers; operate and secure websites and systems; comply with law; and establish or defend legal claims.

Depending on the purpose, our lawful basis is contract or pre-contract steps, legal obligation, legitimate interests, vital interests in a genuine emergency, or consent where consent is required and genuinely optional. Direct marketing is subject to applicable electronic-marketing rules and an easy opt-out.

Job photographs and site evidence

We may create proportionate images or records of defects, work areas, installations and completed work for diagnosis, quotation, safety, progress, certification, quality, warranty, disputes and authorised customer reporting. We seek to avoid unnecessary images of people, private possessions, documents and screens. Marketing use of an identifiable site requires separate appropriate permission.

Sharing

We share only what is necessary with authorised workers and subcontractors; customers and authorised contract participants; insurers, accountants, legal and debt-recovery advisers; IT, hosting, communication, workflow and payment providers; and authorities where disclosure is lawful or required.

International transfers

We do not intentionally make restricted transfers outside the UK without a lawful transfer mechanism, appropriate safeguards and an assessment of the provider and processing.

Retention

Information is retained according to its purpose and relevant contract, tax, accounting, safety, certification, insurance, limitation, warranty and dispute requirements. Unsuccessful enquiries are kept for a shorter period than contract and safety records. Minimal suppression information may be retained to respect a marketing opt-out.

Security

We use proportionate access control, authentication, device and software management, secure services, backup, restricted sharing, instruction and secure disposal. No system is risk-free, and suspected incidents are contained, assessed and documented.

Your rights

Depending on the circumstances, you may request access, correction, erasure, restriction, objection or portability; withdraw consent; and ask about safeguards for qualifying automated decisions. Requests may be sent to enquiries@blackandwhiteaccess.co.uk. We may verify identity proportionately and normally respond within one calendar month, subject to lawful extension, clarification and exemption.

Complaints

A data-protection complaint may be made electronically to enquiries@blackandwhiteaccess.co.uk or by post to the controller address above. Please identify that the message is a data-protection complaint and explain the personal information, event or practice concerned and the outcome sought.

We acknowledge a data-protection complaint within 30 days, preserve relevant evidence, take appropriate steps to investigate it, keep the complainant informed where the investigation continues and communicate a reasoned outcome without undue delay. Complaint handling does not restrict the right to complain to the Information Commissioner's Office through https://ico.org.uk.

Cookies

Essential technologies may support security and website operation. Non-essential analytics or similar technologies are used only after valid consent where required. The website cookie controls describe the technologies actually enabled and allow optional consent to be withdrawn.

Processing summary and retention criteria

Scroll the table horizontally to read all columns. Use the arrow keys when the table is focused.

ActivityTypical informationMain basisRetention approach
Enquiries and quotationsidentity, contact, property, requested work and correspondencepre-contract steps and legitimate interestsunsuccessful enquiries are removed when no longer reasonably useful, subject to dispute, suppression and security needs
Contract and service deliveryorders, site contacts, instructions, access, job records, photographs, completion and warranty evidencecontract and legitimate interestscontract records are kept through delivery and for the period reasonably required for warranty, limitation, insurance and claims
Safety and compliancehazards, incidents, competence, permits and certificationlegal obligation and legitimate interests; vital interests in an emergencyaccording to the applicable safety, regulatory, insurance and claims requirement
Accounts and taxinvoices, transaction and payment-administration recordscontract and legal obligationfor the statutory accounting and tax period and any live dispute
Suppliersidentity, competence, insurance, compliance, bank and performance recordscontract, legal obligation and legitimate interestswhile approved or engaged and afterwards for audit, tax, limitation and dispute needs
Website and securityform submissions, IP/device data, logs and consent recordslegitimate interests, legal obligation and consent for optional trackingonly for the security, evidential or consent period justified for the technology
Marketingbusiness contact, preference and campaign recordlegitimate interests or consent as applicableuntil opt-out, loss of relevance or withdrawal; limited suppression data may then be retained

Exact periods are maintained in the controlled retention schedule and may differ where law, contract, insurer requirements, an incident, a complaint or a legal hold requires preservation. Data is not retained merely because storage is available.

Special-category information and children

The services are not directed at children. Information about health, disability, vulnerability or safeguarding is collected only where necessary to provide an adjustment, protect a person, manage safety or comply with law, with an appropriate UK GDPR Article 9 condition recorded. Criminal-offence information is not routinely sought and receives additional legal and access controls if a specific need arises.

Automated decisions

We do not currently make solely automated decisions about customers or suppliers that produce legal or similarly significant effects. If this changes, this notice will explain the logic, significance, consequences and available human review before the processing begins.

Required and optional information

Where information is needed to quote, contract, provide safe access, complete regulated records or receive payment, failure to provide it may mean we cannot proceed or may need to suspend affected work. Optional marketing consent and optional cookies may be refused without affecting the core service.

Changes

This notice is reviewed when services, systems, suppliers or law change and at least annually. Material changes are brought to affected people’s attention where appropriate.

Approved by David Swaddle, Owner and Data Protection Lead, on 31 August 2026.