Legal

Privacy Policy

Last updated: 2 September 2026

Fire Vault ("FireVault", "we", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you use our fire safety compliance management platform (the "Service"). We operate in accordance with the UK General Data Protection Regulation (UK GDPR), the Privacy and Electronic Communications Regulations (PECR), and the Data Protection Act 2018.

1. Data We Collect

Account Data

  • Name, email address, and role within your organisation
  • Company name and contact details
  • Authentication credentials (securely hashed)

Compliance Data

  • Premises information including addresses and responsible persons
  • Inspection records, checklists, and evidence (photos, signatures, GPS data)
  • Fire risk assessments and associated documents
  • Training records and certification details
  • Audit trail logs including timestamps and user actions

Sales & CRM Data

  • Business contact information (name, job title, business email, business telephone)
  • Communication history (calls, emails, messages)
  • Marketing preferences and objection status
  • Lead source and provenance information

2. How We Use Your Data

  • To provide and maintain the fire safety compliance platform
  • To schedule and track inspections, actions, and training
  • To generate compliance reports and audit trails
  • To send notifications about upcoming checks, overdue items, and expiring certificates
  • To comply with legal obligations under the Regulatory Reform (Fire Safety) Order 2005
  • To conduct legitimate B2B marketing in accordance with PECR and UK GDPR

3. Legal Basis for Processing

We process your personal data under the following lawful bases:

  • Contract: Processing necessary to deliver the Service under our terms of service
  • Legal Obligation: Compliance with fire safety and data protection legislation
  • Legitimate Interests: Platform security, audit logging, service improvement, and B2B marketing to corporate subscribers where permitted under PECR. Where we rely on legitimate interests, we have conducted a balancing assessment to ensure your rights and interests are not overridden. You have the right to object to processing based on legitimate interests (see Section 7).

4. Publicly Available Business Information

We may obtain business contact information from publicly available sources for legitimate business and B2B marketing purposes where lawful. Possible sources include:

  • Companies House
  • Company websites
  • Public business directories
  • Google/business listings
  • Other publicly accessible business sources
  • Business enquiries and referrals
  • Direct contact by the business

Public availability does not automatically mean the information can be used for every purpose. We assess the applicable PECR and UK GDPR requirements before using contact information for direct marketing. We do not claim that an email address being publicly available automatically constitutes consent or gives us permission to market to you.

5. Indirect Collection (UK GDPR Article 14)

Where we process personal data obtained from a source other than the individual (e.g. from Companies House or a company website), we provide the following information as required by UK GDPR Article 14:

  • Categories of personal data: Name, job title, business email, business telephone number, company name
  • Purposes: B2B marketing of fire safety compliance products and services
  • Lawful basis: Legitimate interests (for corporate subscribers under PECR)
  • Source: Publicly available business sources (recorded per contact — see Section 4)
  • Your rights: See Section 10 below, including the right to object to direct marketing

This Privacy Policy itself provides the Article 14 transparency information. Where we first communicate with you by email, this privacy information is linked in the email footer.

6. Direct Marketing

We may conduct business-to-business marketing by email, telephone, and other lawful business communications. We only use each communication method where the applicable legal requirements are satisfied.

Different rules apply to corporate subscribers, sole traders, and individuals. Corporate subscribers (limited companies, LLPs, etc.) can generally receive unsolicited B2B marketing emails under PECR without prior consent. However, sole traders, individuals, and certain partnerships are treated as individuals under PECR and must not receive unsolicited marketing emails without consent. We do not state that all B2B contacts can automatically be marketed to.

Every contact in our system is classified for marketing eligibility (Eligible, Manual Review, or Blocked) before being included in any campaign. Only contacts marked as "Marketing Eligible" may receive marketing communications. This classification is enforced server-side and cannot be overridden by individual sales agents.

7. Right to Object

Individuals have the right to object to the processing of their personal data for direct marketing purposes. If you object to direct marketing, we will stop using your personal data for direct marketing.

To object, you can:

  • Reply "unsubscribe" to any marketing email
  • Click the unsubscribe link in any marketing email
  • Contact us at info@fire-vault.co.uk

We treat any clear objection as a permanent direct-marketing suppression request. Examples include "stop emailing me", "remove me", "do not contact me", "unsubscribe", "take me off your list", "no further marketing", and "I don't want these emails". Our sales agents cannot override a marketing objection.

8. Marketing Suppression

When you opt out of marketing, we retain limited information necessary to ensure you are not contacted again. This suppression information may be retained even after other marketing information is removed. We never delete the suppression record simply because a contact has been removed from the marketing database — this prevents accidental re-contact.

9. Email Marketing

Our marketing emails always:

  • Identify FireVault as the sender (including our legal entity name and contact details)
  • Provide appropriate contact information
  • Provide an opt-out mechanism (reply "unsubscribe" or one-click unsubscribe)
  • Link to this Privacy Policy
  • Respect marketing objections and suppression status

We never state that an email address being publicly available automatically constitutes consent, and we never claim that you have consented to receive marketing emails unless you have explicitly done so.

10. Data Sharing

We do not sell your personal data. We may share data with third-party service providers who support our platform operations, all of whom are bound by data processing agreements and UK GDPR compliance obligations.

Categories of processors may include: hosting providers, database providers, email delivery providers, payment providers, analytics providers, and professional advisers. The full processor list is maintained in our compliance configuration and is available on request.

We may disclose data where required by law or to comply with regulatory authorities including fire and rescue services.

11. International Transfers

We primarily store data on servers located within the United Kingdom. Where any processor transfers data outside the UK, appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses are in place. We do not claim international transfers that we do not make.

12. Data Retention

We retain personal data only for as long as necessary for the purposes set out in this policy:

  • Marketing contacts: Retained for the duration of the business relationship plus a reasonable period thereafter
  • Suppression records: Permanent — retained to prevent accidental re-contact
  • Customer accounts: Duration of subscription plus 6 years
  • Sales records: Duration of the business relationship plus 6 years
  • Fire risk assessment records: Duration of subscription plus a minimum of 6 years, in accordance with fire safety record-keeping requirements
  • Uploaded documents: Duration of subscription plus 6 years
  • Audit records: Retained permanently while the account is active
  • Support communications: Duration of subscription plus 2 years

13. Security

We implement appropriate technical and organisational security measures to protect your personal data, including:

  • Access controls and role-based access permissions
  • Secure authentication and session management
  • Encryption of data in transit (TLS 1.2+) and at rest
  • Immutable audit logging of all platform actions
  • Secure hosting on UK-based infrastructure
  • Regular security reviews and monitoring

No system can guarantee absolute security. We do not claim that your data is 100% secure, but we take our security obligations seriously and continuously review and improve our measures.

14. Your Rights

Under UK GDPR, you have the following rights:

  • Right to be informed: This Privacy Policy
  • Right of access: Request a copy of your personal data
  • Right to rectification: Correct inaccurate or incomplete data
  • Right to erasure: Request deletion of your personal data where applicable
  • Right to restrict processing: Limit how we use your data
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing for direct marketing or legitimate interests
  • Rights relating to automated decision-making: Where applicable

Some rights are subject to legal conditions and exemptions. To exercise any of these rights, contact us using the details in Section 17 below.

15. Cookies

We use essential cookies to operate the platform and optional analytics cookies to understand how the Service is used. A cookie consent banner is displayed to all visitors, allowing you to accept or reject non-essential cookies. You can change your cookie preferences at any time.

  • Essential cookies: Required for the platform to function (authentication, security)
  • Analytics cookies: Help us understand how the Service is used (optional, opt-in)

We do not use marketing cookies or third-party advertising cookies on the platform. For details, see our Cookie Policy in the Legal Centre.

16. Children

FireVault is a B2B fire safety compliance platform and is not intended for use by children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.

17. Complaints

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at info@fire-vault.co.uk.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data protection rights have been infringed. We encourage you to contact us first so we can address your concerns, but you are not required to do so.

18. Policy Version Control

Effective date: 2 September 2026
Last updated: 2 September 2026
Version: 1.0

Previous versions of this Privacy Policy are retained internally for audit purposes. When this policy is updated, the version number, effective date, and last updated date are changed via the administrator compliance configuration.

Fire Vault · Online Business. · https://fire-vault.co.uk