1. Who we are
Blackhawk Protective Services ("Blackhawk", "we", "us" or "our") provides physical and electronic security services, including security guarding, mobile security, keyholding and alarm response, CCTV-related services, access control, intruder alarm solutions and CCTV/NVR equipment.
For personal information that we decide how and why to use, Blackhawk Protective Services is the data controller. You can contact us about privacy matters using:
Email: info@blackhawkprotectiveservices.co.uk
Telephone: 0203 916 5086
Address: 71–75 Shelton Street, London, WC2H 9JQ
2. What this policy covers
This policy explains how we handle personal information when you visit our website, contact us, request a quotation, enquire about or purchase equipment, become a customer, supplier or business contact, interact with our personnel, or receive services from us.
It also explains the position where Blackhawk supplies, installs, configures, maintains or supports CCTV and other security systems for customers. In many of those situations the customer, rather than Blackhawk, decides the purpose for which footage or access records are collected and will therefore normally be the controller for that information.
3. Personal information we may collect
Depending on your relationship with us, we may collect and use the following categories of personal information:
- Identity and contact details, such as name, job title, company, postal address, email address and telephone number.
- Enquiry and quotation information, including the services, products, premises, risks or operational requirements you ask us to consider.
- Customer and contract information, including service instructions, authorised contacts, billing details, order history and correspondence.
- Site and access information, such as authorised contact lists, access procedures, keyholding instructions, alarm or entry procedures and information required to perform agreed security duties.
- Incident and operational records, including security reports, attendance records, event details, observations, timestamps and actions taken.
- Technical information relating to electronic security systems, such as device details, system configuration, network information, NVR/camera information and support records.
- Website and device information, which may include IP address, browser type, device type, pages requested, timestamps, referring page and server/security logs.
- Marketing preferences and records of whether you have asked to receive or stop receiving communications.
- Supplier and professional-contact information needed to manage our commercial relationships.
We do not seek to collect more information than is reasonably necessary for the purpose concerned.
4. Information relating to incidents and alleged unlawful activity
Security work can occasionally involve information about suspected or alleged criminal activity, threats, trespass, theft, damage or other incidents. We only process this type of information where it is relevant to the security service, incident response, legal obligations, protection of people or property, insurance or legal claims, and where UK data protection law permits that processing.
Where criminal-offence information is processed, we apply additional care and safeguards appropriate to the circumstances and limit access to those who need the information for a legitimate purpose.
5. How we collect personal information
We may collect information directly from you when you complete our website enquiry form, email or telephone us, request a quotation, place an equipment enquiry, enter into a contract, provide site instructions or communicate with our team.
We may also receive information from an organisation you work for, a property owner or managing agent, an authorised representative, a security-system provider, a supplier, an insurer, emergency services, law-enforcement bodies or other parties involved in an incident or security arrangement where there is a lawful reason to receive it.
Technical information may be generated automatically by our website, hosting environment and security systems when you interact with our online services.
6. Why we use personal information and our lawful bases
| Purpose | Typical lawful basis |
|---|---|
| Responding to enquiries and preparing quotations | Steps requested before entering a contract and/or our legitimate interests in responding to business enquiries. |
| Providing contracted security services or supplying equipment | Performance of a contract, or legitimate interests where the contract is with your organisation rather than you personally. |
| Managing site instructions, keyholding contacts, access arrangements and operational communications | Contract and legitimate interests in safely and effectively delivering the agreed service. |
| Managing incidents, investigating events, protecting people/property and maintaining service records | Legitimate interests, legal obligations, protection of legal rights and, where applicable, other conditions permitted by data protection law. |
| Accounts, invoices, tax records and financial administration | Contract and compliance with legal obligations. |
| Maintaining the security and availability of our website, systems and communications | Legitimate interests in protecting our business, customers and information systems. |
| Managing suppliers, contractors and professional advisers | Contract and legitimate interests in operating our business. |
| Sending relevant business-to-business service information | Legitimate interests and, where required by the Privacy and Electronic Communications Regulations, consent or another permitted basis. |
| Establishing, exercising or defending legal claims | Legitimate interests and applicable legal conditions for relevant categories of data. |
Where we rely on legitimate interests, we consider whether our use of the information is necessary and balanced against the rights and reasonable expectations of the people concerned.
7. CCTV, NVRs and customer security systems
Blackhawk may supply, install, configure, maintain or support CCTV cameras, NVRs, access control and other electronic security systems for customers. The party that determines why a system is used and what it records will normally be the data controller for the personal information captured by that system.
If a customer operates its own CCTV system, requests footage, sets retention periods or determines who may access recordings, that customer will usually be responsible for providing appropriate signage and privacy information, establishing a lawful basis, handling data-subject requests and ensuring that the system is used lawfully.
Where Blackhawk accesses customer footage or system data solely to install, maintain, troubleshoot, monitor or otherwise provide a service on the customer's instructions, Blackhawk may act as a processor. In those circumstances we process the information only for the agreed service, apply appropriate security controls and follow the customer's documented instructions except where law requires otherwise.
Where Blackhawk itself determines the purpose of CCTV or another surveillance activity, we will act as controller for that processing and will apply the requirements of UK data protection law, including necessity, proportionality, transparency, access control and appropriate retention.
8. Website enquiries
When you submit our enquiry form, the information you provide is used to respond to your request and to assess the services or equipment that may be suitable. The form is transmitted to us by email. Depending on the hosting, mail and security services in use, technical logs may also record information about the submission for delivery, reliability and security purposes.
Please do not send passwords, alarm codes, door-entry credentials or other highly sensitive security credentials through the general website enquiry form. Where those details are genuinely required for service delivery, we will arrange an appropriate method for exchanging them.
9. Cookies and similar technologies
Our website may use cookies or similar technologies that are necessary for WordPress functionality, security, session management and user preferences. If optional analytics, embedded media, advertising or other non-essential technologies are used, we will handle them in accordance with applicable consent requirements under UK privacy and electronic communications law.
You can also control cookies through your browser settings. Blocking some necessary cookies may affect the way parts of the website function.
10. Who we may share information with
We do not sell personal information. We may share information only where reasonably necessary with:
- Hosting, email, IT, communications, cybersecurity and website-service providers.
- Security personnel, vetted contractors, engineers, monitoring or response providers involved in delivering an agreed service.
- Manufacturers, distributors and technical-support providers where needed to supply, configure or support equipment.
- Accountants, insurers, solicitors and other professional advisers.
- Payment, banking or financial-service providers where relevant to a transaction.
- Property owners, managing agents, customers or authorised representatives where required for the agreed service.
- Police, emergency services, regulators, courts, public authorities or other bodies where disclosure is required or permitted by law or is necessary to protect rights, people or property.
- A purchaser, investor or adviser in connection with a genuine business reorganisation, sale or acquisition, subject to appropriate confidentiality and data-protection safeguards.
Service providers handling information for us are expected to protect it and use it only for authorised purposes.
11. International transfers
Some technology, hosting, communications or equipment-support providers may process information outside the United Kingdom. Where personal information is transferred internationally, we take reasonable steps to ensure that an appropriate transfer mechanism and safeguards are in place, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses, or another lawful mechanism.
12. How long we keep information
We keep personal information only for as long as it is reasonably needed for the purpose for which it was collected, including contractual, operational, insurance, tax, regulatory and legal-claim requirements. Typical periods may include:
- General enquiries and unsuccessful quotations: usually up to 24 months after the last meaningful contact, unless there is a reason to keep the information longer.
- Customer contracts, invoices and core transaction records: generally for up to 6 years after the relevant relationship or accounting period where required for tax, contractual or legal purposes.
- Operational and incident records: for a period proportionate to the service, seriousness of the incident, contractual requirements and possible legal or insurance claims.
- Technical support and system records: for the life of the support relationship and a reasonable period afterwards.
- Marketing preferences and suppression records: for as long as necessary to respect your communication choices.
- CCTV for which Blackhawk is the controller: retained for a proportionate period based on the purpose of the system, with footage connected to an incident retained longer where necessary for investigation, insurance or legal proceedings.
Where we act as processor for a customer's CCTV or other security system, retention is governed by the customer's instructions and the applicable service agreement.
13. Security of personal information
We use technical and organisational measures appropriate to the nature of the information and the risks involved. These may include access controls, authentication, device and account security, restricted administrative access, secure configuration, logging, backups, secure communications, confidentiality obligations and procedures for managing incidents.
No internet or electronic system can be guaranteed to be completely secure. We therefore continually consider security in proportion to the information being handled and the services being provided.
14. Your UK data protection rights
Depending on the circumstances, UK data protection law may give you the right to:
- Ask whether we process your personal information and obtain a copy of it.
- Ask us to correct inaccurate or incomplete information.
- Ask us to erase information in circumstances where the right to erasure applies.
- Ask us to restrict the way we use information in certain circumstances.
- Object to processing based on legitimate interests, including objection to direct marketing.
- Receive certain information in a portable format where the right to data portability applies.
- Withdraw consent at any time where processing is based on consent, without affecting earlier lawful processing.
- Raise concerns about decisions based solely on automated processing where the relevant legal protections apply.
These rights are not absolute and exemptions may apply, particularly where information is needed for security, legal claims, the rights of other people or compliance with law. We may need to verify your identity before acting on a request.
15. Direct marketing
We may send relevant information about Blackhawk services to business contacts where permitted by law and where our legitimate interests are not overridden by your rights. Where consent is required, we will rely on consent. You can opt out of marketing at any time by using an unsubscribe facility where provided or by contacting us at info@blackhawkprotectiveservices.co.uk.
We may retain a minimal suppression record after an opt-out so that we can honour your preference in the future.
16. Children
Our website and commercial security services are not directed at children. We do not knowingly use the website to solicit personal information from children. Information about children may occasionally arise in connection with a security incident or customer-controlled CCTV system; where that occurs, it is handled with additional care and only where relevant and lawful.
17. Links and third-party services
Our website may link to third-party websites or services. Those organisations are responsible for their own privacy practices. We recommend reviewing their privacy information before providing personal information to them.
18. Complaints and the Information Commissioner's Office
If you have a concern about how Blackhawk has handled your personal information, please contact us first so we can investigate. You also have the right to complain to the UK Information Commissioner's Office (ICO), the independent regulator for data protection in the United Kingdom. Information about raising a concern is available from the ICO at ico.org.uk.
19. Changes to this policy
We may update this Privacy Policy when our services, technology, suppliers or legal obligations change. The current version will be published on this page and the "Last updated" date will be revised when material changes are made.
20. Contact us about privacy
For privacy questions, requests or concerns, contact Blackhawk Protective Services at info@blackhawkprotectiveservices.co.uk, telephone 0203 916 5086, or write to 71–75 Shelton Street, London, WC2H 9JQ.
