• Home
  • Door Supervisors
  • Private Security
  • Commercial Security
  • Security Guarding
  • Key-holding
  • Event Security
  • More
    • Home
    • Door Supervisors
    • Private Security
    • Commercial Security
    • Security Guarding
    • Key-holding
    • Event Security

  • Home
  • Door Supervisors
  • Private Security
  • Commercial Security
  • Security Guarding
  • Key-holding
  • Event Security

Privacy Policy

 

PRIVACY POLICY

Carlin Security Services Ltd

Document Reference: CSS-PP-001 | Version 1.0

Effective Date: 29 April 2026 | Next Review Due: 29 April 2027


================================================================


ABOUT THIS POLICY

Carlin Security Services Ltd ("we", "us", "our") is committed to protecting and respecting the privacy of every visitor, client and applicant who uses our website or contacts us through it. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and the rights you have over your information under UK data protection law.


================================================================


1. WHO WE ARE

Carlin Security Services Ltd is a private security company based in Heanor, Derbyshire, providing static guarding, door supervision, mobile patrols, event security, key-holding and alarm response, and private/residential security services across the East Midlands.

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the "data controller" of the personal data we collect about you through our website.


Our Details:

- Company: Carlin Security Services Ltd

- Registered Office: 1-2 Basford House, Derby Road, Heanor, Derbyshire, DE75 7QL

- Website: www.carlinsecurityservicesltd.co.uk

- Email: accounts@carlinsecurityservicesltd.co.uk

- Telephone: 07707 875356


2. SCOPE OF THIS POLICY

This Privacy Policy applies to personal data we collect:

- When you visit www.carlinsecurityservicesltd.co.uk

- When you complete a contact, quote or enquiry form on our website

- When you email, telephone or otherwise communicate with us as a result of using our website

- When you apply for a role with us via our website

- When you sign up to receive marketing communications from us


It does not apply to third-party websites that we may link to. We are not responsible for the privacy practices of those websites and recommend you read their own privacy notices.


3. PERSONAL DATA WE COLLECT

Personal data means any information about an individual from which that person can be identified. We may collect, use, store and transfer the following 

categories of personal data about you:

- Identity Data: First name, last name, title, job title, company name

- Contact Data: email address, telephone numbers

- Enquiry Data: Details of services requested, site information, security requirements

- Technical Data: IP address, browser type and version, device type, operating system, time zone

- Usage Data: Pages visited, time on site, click paths, referring URL, search terms

- Marketing Data: Your preferences in receiving marketing from us, 


Special Category Data

We do not routinely collect any "special category" personal data through the website (such as data about racial or ethnic origin, religious beliefs, health, sexual orientation, or trade union membership). We also do not collect criminal conviction information through the website. Where this information is needed (for example, as part of vetting under BS 7858:2019 for security personnel), it is collected separately under our Recruitment & Vetting policies, not via the website.


Children's Data

Our website and services are not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe that a child has provided us with personal data, please contact us and we will take steps to delete it.


4. HOW WE COLLECT YOUR PERSONAL DATA


We use different methods to collect data from and about you, including through:

- Direct interactions — you provide data when you fill in a form on our website, request a quotation, sign up to our newsletter, apply for a job, or contact us by email or phone.

- Automated technologies — as you interact with our website, we may automatically collect Technical Data and Usage Data using cookies, server logs and similar technologies (see Section 8 — Cookies).

- Third parties — we may receive personal data about you from analytics providers (e.g. Google), advertising networks, search information providers, and publicly available sources such as Companies House.


5. HOW WE USE YOUR PERSONAL DATA AND LAWFUL BASIS


Under UK GDPR, we will only use your personal data when the law allows us to. Most commonly we rely on the following lawful bases:

- Performance of a contract with you, or to take steps before entering into a contract

- Compliance with a legal or regulatory obligation

- Our legitimate interests (or those of a third party), provided your interests and fundamental rights do not override those interests

- Your consent, in specific cases such as non-essential cookies and marketing communications

The purposes for which we use your data, and the lawful basis we rely on, are as follows:

- Responding to enquiries / providing quotations: Identity, Contact and Enquiry Data — Legitimate interests (responding to a request you have made) / Steps prior to entering a contract

- Delivering security services and managing the contract: Identity, Contact, Enquiry and Financial Data — Performance of a contract

- Operating, maintaining and securing the website: Technical and Usage Data — Legitimate interests (running our business, network and information security)

- Analytics and improving the website: Technical and Usage Data — Consent (where required for non-essential cookies)

- Sending marketing communications: Identity, Contact and Marketing Data — Consent / Legitimate interests (existing B2B clients — soft opt-in)

- Recruitment and assessing applications: Identity, Contact and Recruitment Data — Legitimate interests / Steps prior to entering a contract / Legal obligation (right-to-work)

- Complying with legal/regulatory obligations (SIA, HMRC, etc.): All categories as relevant — Legal obligation

- Preventing fraud, protecting our rights, defending claims: All categories as relevant — Legitimate interests / Legal obligation

If you would like further information on the specific legitimate interests we rely on for any particular activity, please contact us using the details in Section 14.


6. MARKETING COMMUNICATIONS


We may send you marketing communications about our security services where you have either:

- Provided your consent (for example, by ticking an opt-in box on our website); or

- Are an existing business client and we are contacting you about similar services to those we have already provided (the "soft opt-in" under PECR — the Privacy and Electronic Communications Regulations).

You can ask us to stop sending you marketing messages at any time by:

- Clicking the "unsubscribe" link at the foot of any marketing email

- Replying to a message asking us to stop

- Emailing INFO@carlinsecurityservicesltd.co.uk with the subject line "Unsubscribe"

Where you opt out of receiving marketing messages, this will not apply to personal data provided to us as a result of a service purchase, contract administration or other non-marketing communications.


7. WHO WE SHARE YOUR DATA WITH


We treat all personal data as confidential. We will only share your personal data with the following categories of recipient, where it is lawful and necessary to do so:

- Service providers acting as processors who provide IT, hosting, email, CRM, accounting and analytics services

- Professional advisers including lawyers, accountants, auditors and insurers, where reasonably necessary

- Subcontracted security personnel or partner security firms, where required to deliver the services you have requested (under written agreements that include data protection terms)

- Regulators and law enforcement, including the Information Commissioner's Office (ICO), Security Industry Authority (SIA), HMRC, courts, and police, where we are required to do so by law


We require all third parties to respect the security of your personal data and to treat it in accordance with the law. Our processors are only permitted to process your personal data for specified purposes and in accordance with our written instructions.


8. COOKIES AND SIMILAR TECHNOLOGIES


Our website uses cookies and similar technologies. A cookie is a small text file placed on your device that allows the website to recognise you and remember things about your visit.

Categories of Cookies We Use:

- Strictly Necessary — Essential for the website to function (e.g. session, security, load balancing). Consent: Not required (exempt under PECR).

- Performance / Analytics — Help us understand how visitors use the site so we can improve it (e.g. Google Analytics). Consent: Opt-in required.

- Functional — Remember your preferences (e.g. language, region, accessibility settings). Consent: Opt-in required.

- Marketing / Targeting — Used by us or third parties to deliver relevant adverts and measure campaign effectiveness. Consent: Opt-in required.

Managing Your Cookie Preferences

When you first visit our website, you will see a cookie banner. You can accept all cookies, reject non-essential cookies, or choose specific categories. You can withdraw or change your consent at any time using the cookie settings link in the website footer.

You can also block or delete cookies through your browser settings. Please note that if you disable strictly necessary cookies, parts of our website may not function correctly.

Third-Party Cookies

Some cookies are set by third parties (for example, Google Analytics). These third parties have their own privacy policies, and we recommend you review them. We do not control the use of these cookies and cannot access them, as they are governed by the privacy policies of the relevant third party.


9. INTERNATIONAL TRANSFERS


We are a UK-based business and your personal data is primarily stored and processed within the United Kingdom and the European Economic Area (EEA).

Some of our service providers (for example, certain analytics or email tools) may process personal data outside the UK/EEA. Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection by using one or more of the following safeguards:

- Transferring to countries that have been deemed to provide an adequate level of protection by the UK government

- Using specific contracts approved for use in the UK (such as the International Data Transfer Agreement or Standard Contractual Clauses with the UK Addendum)

- Relying on other lawful transfer mechanisms recognised under UK GDPR

If you would like more information about the safeguards used, please contact us.


10. HOW WE PROTECT YOUR PERSONAL DATA


We have put in place appropriate technical and organisational security measures to prevent your personal data from being accidentally lost, used, altered, disclosed, or accessed in an unauthorised way. These measures include:

- Restricting access to personal data to staff and contractors who have a genuine business need to know it

- Requiring those individuals to be subject to a duty of confidentiality

- Using secure passwords, multi-factor authentication, and role-based access controls

- Encrypting personal data in transit (via TLS/HTTPS) and, where appropriate, at rest

- Regularly reviewing our information security practices and provider arrangements

- Maintaining a documented incident response process aligned with our wider Data Protection Policy (CSS-DP-001)

We have procedures to deal with any suspected personal data breach and will notify you and any applicable regulator (such as the ICO) of a breach where we are legally required to do so, normally within 72 hours of becoming aware of it.


11. HOW LONG WE KEEP YOUR PERSONAL DATA



We will only retain your personal data for as long as is necessary to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements.

To determine the appropriate retention period, we consider the amount, nature and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for processing, and applicable legal requirements.

Our Retention Periods:

- Website enquiries that do not lead to a contract: Up to 24 months from last contact, then deleted

- Client contract data and related correspondence: Duration of contract + 6 years (limitation period)

- Financial and accounting records: 6 years from end of relevant financial year (HMRC)

- Marketing data (where you have consented): Until you unsubscribe + up to 6 months for suppression list

- Unsuccessful job applications: 12 months from decision (with consent), then deleted

- Website server logs: Up to 12 months for security and diagnostic purposes

- Cookie consent records: Up to 12 months from consent given/refused

In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.


12. YOUR RIGHTS UNDER UK GDPR


Under data protection law, you have a number of rights in relation to your personal data:

- Right to be informed — To be told clearly how your personal data is collected and used. This Privacy Policy is part of how we meet that right.

- Right of access — To request a copy of the personal data we hold about you (a Subject Access Request).

- Right to rectification — To have inaccurate or incomplete personal data corrected without undue delay.

- Right to erasure — To request deletion of your personal data in certain circumstances (the "right to be forgotten").

- Right to restriction — To request that we limit how we use your personal data while a query is being resolved.

- Right to data portability — To receive certain personal data in a structured, commonly used, machine-readable format.

- Right to object — To object to processing based on legitimate interests, or to direct marketing at any time.

- Rights regarding automated decisions — Not to be subject to a decision based solely on automated processing that produces a legal or similarly significant effect.

- Right to withdraw consent — Where we rely on consent, you can withdraw it at any time without affecting prior lawful processing.

- Right to complain — To lodge a complaint with the Information Commissioner's Office (ICO).

How to Exercise Your Rights

You can exercise any of these rights free of charge by contacting us using the details in Section 14. We may need to ask you for information to confirm your identity before responding.

We will respond to your request within one month. In some cases, where requests are complex or numerous, we may extend this period by up to a further two months and will notify you within the first month if we need to do so.

If you are not satisfied with our response, or believe that we are processing your personal data unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at any time. We would, however, appreciate the chance to deal with your concerns first, so please do contact us in the first instance.


13. INFORMATION FOR JOB APPLICANTS


If you apply for a role with Carlin Security Services Ltd via our website or in response to an advert, the personal data you provide will be used for the purposes of progressing your application and to fulfil legal or regulatory requirements.

- We will not share any of the information you provide during the recruitment process with any third parties for marketing purposes.

- Information will be held within our HR/recruitment systems and accessed only by those involved in the recruitment process.

- If you are unsuccessful, we will retain your application data for up to 12 months in case a similar role becomes available, after which it will be securely deleted (unless you withdraw consent earlier).

- If you are successful, your information will become part of your employee file and processed in accordance with our internal HR and Data Protection policies.

Where roles require SIA licensing, we will also process your SIA licence number, references, employment history and right-to-work documentation in line with BS 7858:2019 vetting standards. Further information will be provided in a separate Recruitment Privacy Notice at the relevant stage.


14. CONTACT US AND DATA PROTECTION QUERIES


If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact us using the details below. The Managing Director is the named lead for data protection within Carlin Security Services Ltd.

- Data Protection Lead: Bradley Carlin, Managing Director

- Postal address: Carlin Security Services Ltd, 1-2 Basford House, Derby Road, Heanor, Derbyshire, DE75 7QL

- Email: INFO@carlinsecurityservicesltd.co.uk

- Telephone: 07707 875356


15. CHANGES TO THIS PRIVACY POLICY


We keep this Privacy Policy under regular review. We will post any updates on this page and, where the changes are significant, we will provide a more prominent notice (for example, by email or a banner on the website).

Where we make material changes that affect how we process your personal data based on consent, we will seek fresh consent where required.

- Version: 1.0

- Effective Date: 29 April 2026

- Next Review Due: 29 April 2027

16. GLOSSARY

- UK GDPR: The United Kingdom General Data Protection Regulation.

- DPA 2018: The Data Protection Act 2018.

- PECR: The Privacy and Electronic Communications (EC Directive) Regulations 2003, as amended.

- Personal Data: Any information relating to an identified or identifiable living individual.

- Processing: Any operation performed on personal data — collection, storage, use, disclosure, deletion, etc.

- Data Controller: The organisation that decides why and how personal data is processed (Carlin Security Services Ltd).

- Data Processor: A third party that processes personal data on behalf of the data controller, under written instructions.

- ICO: The Information Commissioner's Office — the UK's independent data protection regulator.

================================================================

Approved and issued by:

Carlin Security Services Ltd

29 April 2026

================================================================

Copyright © 2026 Carlin Security Services LTD - All Rights Reserved.

  • Privacy Policy

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept