GDPR Data Protection Policy
Keeping information relevant, controlled, secure and used only for a proper business or legal reason.
Core compliance
A data protection policy for lawful, transparent, limited and secure handling of client, supplier, subcontractor, employee and project information.
Process
Process personal data lawfully, fairly and transparently
Process personal data lawfully, fairly and transparently
Collect
Collect only necessary information for defined purposes
Collect only necessary information for defined purposes
Protect
Protect paper, email, device and cloud records with proportionate safeguards
Protect paper, email, device and cloud records with proportionate safeguards
Handle
Handle rights requests, data sharing and breach concerns responsibly
Handle rights requests, data sharing and breach concerns responsibly
StatusApproved / signed
Approval date08 May 2026
ReviewAnnual / earlier after significant change
OwnerDirector
Website summary available
Controlled PDF download linked.
Controlled PDF download linked.