This GDPR Policy sets out how FireVault Ltd complies with its obligations as a Data Controller and Data Processor under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Our Role
FireVault acts as a Data Processor on behalf of our customers (Data Controllers) for the compliance data entered into the platform. We also act as a Data Controller for account and billing information.
2. Data Processing Principles
We adhere to the seven principles of UK GDPR:
- Lawfulness, fairness, and transparency: All processing has a lawful basis and is transparent to data subjects
- Purpose limitation: Data is collected for specified, explicit fire safety compliance purposes only
- Data minimisation: We only collect data necessary for compliance management
- Accuracy: Data is kept accurate and up to date
- Storage limitation: Data is retained only as long as legally required
- Integrity and confidentiality: Data is secured against unauthorised access
- Accountability: We demonstrate compliance through audit trails and documentation
3. Data Subject Rights
We facilitate the following rights for all data subjects whose information is processed through our platform:
- Right of Access (Article 15): Data subjects can request a copy of their personal data
- Right to Rectification (Article 16): Inaccurate data can be corrected
- Right to Erasure (Article 17): Data subjects can request deletion, subject to legal retention obligations
- Right to Restriction (Article 18): Processing can be restricted in certain circumstances
- Right to Data Portability (Article 20): Data can be exported in a structured, machine-readable format
- Right to Object (Article 21): Data subjects can object to processing based on legitimate interests
4. Lawful Basis for Processing
- Article 6(1)(b): Performance of a contract — providing the compliance platform service
- Article 6(1)(c): Legal obligation — fire safety record-keeping under RRO 2005
- Article 6(1)(f): Legitimate interests — platform security, audit logging, fraud prevention
5. Special Category Data
FireVault does not knowingly process special category data (Article 9). If health or disability information is relevant to fire evacuation planning (e.g. PEEPs — Personal Emergency Evacuation Plans), this is processed under Article 9(2)(b) for reasons of substantial public interest, specifically health and safety. Such data is stored securely and access is restricted.
6. International Data Transfers
All personal data is stored and processed within the United Kingdom. We do not transfer personal data outside the UK. If this position changes, we will update this policy and ensure appropriate safeguards (e.g. International Data Transfer Agreements) are in place.
7. Data Breach Procedure
In the event of a personal data breach, FireVault will:
- Assess the breach and take immediate steps to contain it
- Notify the ICO within 72 hours where the breach is likely to result in a risk to data subjects
- Notify affected data subjects without undue delay where there is a high risk
- Document all breaches and remedial actions taken
8. Data Protection by Design
FireVault implements data protection by design and by default (Article 25):
- Role-based access control — users only access data relevant to their role
- Immutable audit trails — all data changes are permanently logged
- Encrypted data transmission and storage
- Regular security reviews and penetration testing
9. Data Retention
Compliance data is retained for the subscription duration plus six years to meet fire safety legal requirements. Upon account closure, customers can export all data before scheduled deletion. Audit trail records are retained for the legal maximum period.
10. Contact
For GDPR enquiries, data subject requests, or to report a data breach, contact our Data Protection Officer at info@fire-vault.co.uk.
You may also complain to the Information Commissioner's Office at ico.org.uk or by calling 0303 123 1113.