Facilities Management

Company Policies
Privacy Policy
Last updated: 5 May 2025
Orion Facilities Management Ltd is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, share, and protect your personal information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and relevant industry standards.
1. Our Commitment to Data Protection
We are committed to:
-
Ensuring full compliance with UK GDPR and the Data Protection Act 2018
-
Processing personal data fairly, lawfully, and transparently
-
Using data only for specific, legitimate purposes
-
Minimising the amount of data collected
-
Keeping data accurate and up to date
-
Retaining data only as long as necessary
-
Respecting individuals’ rights and freedoms
-
Securing personal data through appropriate technical and organisational measures
-
Appointing a Data Protection Officer to ensure accountability and handle enquiries
2. What Data We Collect
We may collect and process the following categories of personal data to fulfil our services or comply with legal obligations:
1. For Clients and Enquiries
-
Name, email, phone number, company name, job title
-
Service requirements and site addresses
-
Payment and invoice information
-
Additional information provided voluntarily or required by law
2. For Staff, Officers, and Subcontractors
-
Identification (e.g., passport, SIA licence)
-
Contact details, emergency contacts
-
Right-to-work documents
-
Bank/payment details
-
Work history and training records
-
Additional information provided voluntarily or required by law
3. For Website Visitors
-
IP address, browser type, device information
-
Data collected via cookies (with consent)
-
Additional information provided voluntarily or required by law
3. How We Use Your Information
We process your personal data for the following purposes:
-
Delivering contracted services (e.g., guarding, cleaning, training)
-
Managing recruitment, employment, or subcontracting relationships
-
Processing payments and invoicing
-
Providing online training, certification, and support
-
Meeting legal, regulatory, or accreditation obligations
-
Communicating service updates, offers, or marketing (where consent is given)
4. Lawful Basis for Processing
We may only process data when we have a lawful reason to do so:
-
Consent – You have given clear consent for a specific purpose
-
Contract – Processing is necessary for a service contract or employment agreement
-
Legal obligation – Required to meet legal or regulatory duties
-
Vital interests – To protect life in emergencies
-
Legitimate interests – Necessary for our business, provided your rights are not overridden
5. Your Rights as a Data Subject
You have the right to:
-
Access – Request a copy of your personal data
-
Rectify – Correct inaccurate or incomplete data
-
Erasure – Request deletion of data ("right to be forgotten") in certain circumstances
-
Restrict processing – Ask us to limit how we use your data
-
Data portability – Transfer your data to another service provider
-
Object – Object to processing, especially for direct marketing
-
Withdraw consent – Where processing is based on consent
-
Complain – If you are not satisfied with our response, you may contact/lodge a complaint with the ICO
To exercise any of these rights, contact us via the details in section 11 first.
6. Data Security
We have implemented strong security measures including:
-
Encryption of data at rest and in transit
-
Password-protected systems
-
Role-based access control
-
Secure cloud storage with backup
-
Staff confidentiality agreements and training
-
Regular audits and policy reviews
7. Data Retention
We keep personal data only as long as necessary:
-
Client and operational data – Up to 6 years after final service
-
Employment/subcontractor records – 6 years after termination
-
Training records – Up to 3 years from completion
-
Website data – As per cookie settings and analytics retention
Longer retention may apply where legally required.
8. International Transfers
If your data is transferred outside the UK or EEA, we ensure it is protected through:
-
Adequate safeguards such as Standard Contractual Clauses (SCCs)
-
Contracts with data processors ensuring GDPR-compliant standards
-
Transfers only to countries with appropriate legal protections
9. Sharing of Data
We may share your data with:
-
Clients or partners for operational delivery
-
Vetting, payroll, training, or IT service providers
-
Accreditation or legal compliance bodies
-
Law enforcement, courts, or regulatory agencies where legally required
-
Buyers or sellers in the event of a business acquisition
We never sell your personal data.
10. Website, Cookies, and Third-Party Links
We use cookies to enhance user experience and analyse site traffic. You can manage cookie preferences via your browser settings.
Our website may contain links to third-party websites. We are not responsible for their privacy practices. Please check their policies before submitting data.
11. Complaints and Contact Information
If you have any questions, concerns, or wish to exercise your rights, please contact:
Data Protection Officer
Orion Facilities Management Ltd
806 High Road, Leyton, Greater London. E10 6AE
email: alam@orionfm.co.uk , enquiries@orionfm.co.uk
Phone number: +44 20 3679 1298
If you are not satisfied with our response, you may contact:
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
casework@ico.org.uk
www.ico.org.uk
12. Updates to This Policy
We may update this Privacy Policy from time to time. The latest version will always be published on our website with the effective date clearly displayed.