Privacy Policy

Introduction AMV Projects Ltd ("we", "us", "our") is committed to protecting the privacy and security of personal data. This Privacy Policy explains how we collect, use, store and share personal data when you interact with our services, our website, or when you otherwise provide data to us. It also describes your rights and how to contact us.

Controller AMV Projects Ltd Registered office: [Insert registered address] Company number: [Insert company number] Data protection lead: [Insert name or job title] Contact: [Insert email address] | [Insert telephone number]

Data we collect We may collect and process the following categories of personal data, depending on the context:

  • Identity and contact information: name, job title, company name, address, telephone number, email address.

  • Service and project information: details of enquiries, briefs, quotations, contracts, site addresses, project schedules, photographs and technical specifications.

  • Financial and transactional data: invoicing details, bank account or payment card information (where provided), billing address and payment history.

  • Communication records: emails, letters, meeting notes, recorded telephone calls (where lawful and notified), and any other correspondence.

  • Technical data: IP address, device and browser information, website usage and analytics, cookies and similar technologies.

  • Employment and HR data: CVs, references, right to work documentation, health or medical information where necessary for site safety, criminal record checks (where required), emergency contact details.

  • Compliance and security: CCTV images and access logs at premises, health & safety incident reports, audit and compliance records.

Sources of personal data

  • Directly from you when you contact us, request a quote, apply for employment, or use our services.

  • From your employer or the organisation you represent.

  • From third parties such as suppliers, contractors, credit reference agencies, referees, background check providers and professional advisers.

  • Automatically when you use our website (see Cookies and similar technologies below).

Purposes and lawful bases for processing We will only process personal data where we have a lawful basis, which may include:

  • Performance of a contract: to provide refurbishment, maintenance, fire safety and fit-out services, to manage projects, to process orders and payments, and to deliver customer support.

  • Legal compliance: to comply with statutory obligations (for example health & safety and tax requirements).

  • Legitimate interests: for our business operations, administration, fraud prevention, network and information security, improving our services and website, and marketing our services (we will balance our interests against your rights).

  • Consent: when we ask for consent (for example some marketing communications or certain cookies), we will process your data only with your consent.

  • Vital interests: where necessary to protect someone’s life or wellbeing.

  • Legal claims: to establish, exercise or defend legal claims.

Cookies and similar technologies Our website uses cookies and similar technologies to improve functionality, analyse performance and personalise content. You will be offered the ability to accept or manage cookies where required. Details of the types of cookies we use and how to manage them are available on our website.

Sharing and disclosure We may share personal data with:

  • Service providers and contractors who support our business (for example IT providers, professional advisers, insurers, transport and logistics providers, subcontractors and security providers).

  • Third parties involved in a project (for example clients, architects, surveyors and other contractors) where necessary to deliver services.

  • Payment processors and banks when handling financial transactions.

  • Government bodies, regulators, law enforcement and other authorities where required by law or to protect our legal rights.

  • Purchasers, potential purchasers or professional advisers in the event of a sale, merger or restructuring of our business.

Whenever we share data we require recipients to protect it appropriately and only process it for specified purposes.

International transfers Some third-party service providers may be based outside the UK. Where personal data is transferred outside the UK or to organisations that do not offer an adequate level of protection, we will put suitable safeguards in place, such as standard contractual clauses, to protect the data.

Data retention We will retain personal data only for as long as is necessary for the purposes for which it was collected, including to fulfil legal, accounting or reporting obligations, resolve disputes and enforce our agreements. Retention periods vary by data type; for example:

  • Contract and project records: typically retained for at least 6 years for tax and contractual purposes.

  • Recruitment records: retained for the duration of recruitment and if unsuccessful, typically kept for up to 12 months unless you request otherwise.

  • CCTV, access logs and health & safety records: retained in line with legal and operational requirements.

Security We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or destruction. These measures include access controls, encryption where