Last updated: 2 September 2026
Fire Vault ("FireVault", "we", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you use our fire safety compliance management platform (the "Service"). We operate in accordance with the UK General Data Protection Regulation (UK GDPR), the Privacy and Electronic Communications Regulations (PECR), and the Data Protection Act 2018.
We process your personal data under the following lawful bases:
We may obtain business contact information from publicly available sources for legitimate business and B2B marketing purposes where lawful. Possible sources include:
Public availability does not automatically mean the information can be used for every purpose. We assess the applicable PECR and UK GDPR requirements before using contact information for direct marketing. We do not claim that an email address being publicly available automatically constitutes consent or gives us permission to market to you.
Where we process personal data obtained from a source other than the individual (e.g. from Companies House or a company website), we provide the following information as required by UK GDPR Article 14:
This Privacy Policy itself provides the Article 14 transparency information. Where we first communicate with you by email, this privacy information is linked in the email footer.
We may conduct business-to-business marketing by email, telephone, and other lawful business communications. We only use each communication method where the applicable legal requirements are satisfied.
Different rules apply to corporate subscribers, sole traders, and individuals. Corporate subscribers (limited companies, LLPs, etc.) can generally receive unsolicited B2B marketing emails under PECR without prior consent. However, sole traders, individuals, and certain partnerships are treated as individuals under PECR and must not receive unsolicited marketing emails without consent. We do not state that all B2B contacts can automatically be marketed to.
Every contact in our system is classified for marketing eligibility (Eligible, Manual Review, or Blocked) before being included in any campaign. Only contacts marked as "Marketing Eligible" may receive marketing communications. This classification is enforced server-side and cannot be overridden by individual sales agents.
Individuals have the right to object to the processing of their personal data for direct marketing purposes. If you object to direct marketing, we will stop using your personal data for direct marketing.
To object, you can:
We treat any clear objection as a permanent direct-marketing suppression request. Examples include "stop emailing me", "remove me", "do not contact me", "unsubscribe", "take me off your list", "no further marketing", and "I don't want these emails". Our sales agents cannot override a marketing objection.
When you opt out of marketing, we retain limited information necessary to ensure you are not contacted again. This suppression information may be retained even after other marketing information is removed. We never delete the suppression record simply because a contact has been removed from the marketing database — this prevents accidental re-contact.
Our marketing emails always:
We never state that an email address being publicly available automatically constitutes consent, and we never claim that you have consented to receive marketing emails unless you have explicitly done so.
We do not sell your personal data. We may share data with third-party service providers who support our platform operations, all of whom are bound by data processing agreements and UK GDPR compliance obligations.
Categories of processors may include: hosting providers, database providers, email delivery providers, payment providers, analytics providers, and professional advisers. The full processor list is maintained in our compliance configuration and is available on request.
We may disclose data where required by law or to comply with regulatory authorities including fire and rescue services.
We primarily store data on servers located within the United Kingdom. Where any processor transfers data outside the UK, appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses are in place. We do not claim international transfers that we do not make.
We retain personal data only for as long as necessary for the purposes set out in this policy:
We implement appropriate technical and organisational security measures to protect your personal data, including:
No system can guarantee absolute security. We do not claim that your data is 100% secure, but we take our security obligations seriously and continuously review and improve our measures.
Under UK GDPR, you have the following rights:
Some rights are subject to legal conditions and exemptions. To exercise any of these rights, contact us using the details in Section 17 below.
We use essential cookies to operate the platform and optional analytics cookies to understand how the Service is used. A cookie consent banner is displayed to all visitors, allowing you to accept or reject non-essential cookies. You can change your cookie preferences at any time.
We do not use marketing cookies or third-party advertising cookies on the platform. For details, see our Cookie Policy in the Legal Centre.
FireVault is a B2B fire safety compliance platform and is not intended for use by children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at info@fire-vault.co.uk.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data protection rights have been infringed. We encourage you to contact us first so we can address your concerns, but you are not required to do so.
Effective date: 2 September 2026
Last updated: 2 September 2026
Version: 1.0
Previous versions of this Privacy Policy are retained internally for audit purposes. When this policy is updated, the version number, effective date, and last updated date are changed via the administrator compliance configuration.
Fire Vault · Online Business. · https://fire-vault.co.uk