Storage Heston Privacy Policy
This Privacy Policy explains how Storage Heston collects, uses, stores and protects personal data relating to our customers and prospective customers in our service area. It also explains the lawful bases on which we process personal data and describes the rights you have under the UK General Data Protection Regulation and the Data Protection Act.
This Privacy Policy applies to all individuals who use or enquire about Storage Heston services, including self-storage, associated services, and related customer support, regardless of how they contact us or interact with us.
Data Controller
Storage Heston is the controller of the personal data described in this Privacy Policy. As controller, we determine the purposes and means of processing your personal data and are responsible for ensuring that any processing is carried out in accordance with applicable data protection laws.
Personal Data We Collect
We collect and process different types of personal data depending on how you interact with us and which services you use. The categories of data we may collect include:
Identification data, such as full name, title, date of birth and government issued identification details when required for verification and security.
Contact details, such as address, billing address, and any alternative contact details you choose to provide.
Account and contract data, such as customer reference numbers, contract start and end dates, unit numbers, services purchased, payment status, and communication preferences.
Payment and transaction data, such as payment method, payment history and invoices. We do not store full card details when payment is processed by an external payment processor.
Communications, such as emails, letters, written forms, and notes of conversations with our staff related to your enquiries, bookings, or complaints.
Security and access data, which may include records of access to our site, such as keypad or access token usage times, and in some areas may include closed circuit television images for security and safety purposes.
Website and technical data, such as basic device and browser data, pages visited, and interactions with online forms. This may be collected using cookies or similar technologies where permitted by law and your browser settings.
How We Collect Your Data
We collect personal data in the following ways:
Directly from you, when you contact us by phone, in person, through our website, or by any other means to make an enquiry, obtain a quote, or enter into a storage agreement.
During the performance of your contract with us, when you make payments, request changes to your service, or interact with our staff for customer support.
From third parties, where this is necessary to verify identity, payment information, or for fraud prevention and debt recovery, in accordance with the law.
Automatically, when you access our premises or use our online services, including access control systems and website usage data, subject to applicable legal requirements and your rights.
Lawful Bases For Processing
We only process your personal data where we have a lawful basis to do so. Depending on the circumstances, we may rely on the following lawful bases:
Contract: We process personal data when it is necessary to enter into or perform a contract with you, for example to provide storage services, manage your account, handle payments, or respond to your requests relating to your agreement.
Legal obligation: We process personal data when it is necessary to comply with legal obligations, such as tax and accounting rules, anti money laundering requirements, and health and safety regulations.
Legitimate interests: We process personal data based on our legitimate interests, provided that such interests are not overridden by your rights and freedoms. These interests may include securing our premises, preventing fraud or misuse, managing our business operations, improving our services, and communicating with existing customers about relevant service information.
Consent: In limited circumstances, we may rely on your consent, for example for certain marketing communications or optional cookies. Where we rely on consent, you have the right to withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
How We Use Your Personal Data
We use your personal data for the following purposes:
To provide and manage storage and related services, including setting up new accounts, administering contracts, responding to enquiries, managing access to storage units, and resolving issues.
To process payments and maintain accurate financial records, including handling direct debits or other payment methods, issuing invoices, and managing debt collection where necessary.
To maintain the security and integrity of our premises and services, including using access control systems and, where in place, closed circuit television for crime prevention and safety.
To communicate with you about your contract, billing, service changes, access information, notices, and other operational matters.
To carry out internal reporting, service monitoring, quality assurance, and business administration.
To comply with applicable laws, regulations, and requests from competent authorities, including law enforcement and regulatory bodies, where we are legally obliged to do so.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements.
In general, personal data relating to your contract and account will be retained for the duration of your agreement with us and for a reasonable period thereafter, typically up to several years, to comply with legal obligations, resolve disputes, and enforce our agreements.
Security, access and closed circuit television data, where collected, is retained for a shorter period, unless longer retention is required in connection with an investigation or legal claim.
When personal data is no longer needed, we will delete it or anonymise it in a secure manner, in accordance with our data retention policies.
Data Processors And Third Parties
We may share your personal data with carefully selected third parties who act as our processors. These processors may provide services such as payment processing, accounting, customer relationship management, information technology support, security systems, or document storage.
Where we use processors, they are only permitted to process your personal data on our instructions, must implement appropriate technical and organisational measures to protect it, and are bound by contractual obligations that reflect applicable data protection law.
We may also share personal data with other third parties where we are required or permitted to do so by law, such as government bodies, regulators, law enforcement agencies, or professional advisers like accountants or legal counsel, where this is necessary for compliance, the protection of our legal rights, or the establishment, exercise or defence of legal claims.
If we were to undertake a reorganisation, sale, or transfer of all or part of our business, personal data may be transferred to the new owner or relevant third parties as part of that process, in accordance with data protection law.
International Transfers
Where personal data is transferred outside the United Kingdom or European Economic Area, we will ensure that appropriate safeguards are in place to protect it, such as using standard contractual clauses or transfers to countries that have been recognised as providing an adequate level of data protection.
Your Data Protection Rights
Under data protection law, you have a number of rights in relation to your personal data. These rights may be subject to certain conditions and legal exemptions. Your rights include:
Right of access: You have the right to request confirmation of whether we process your personal data and, if so, to obtain a copy of that data and information about how we process it.
Right to rectification: You have the right to request correction of inaccurate personal data and completion of incomplete data.
Right to erasure: In certain circumstances, you have the right to request deletion of your personal data, for example where it is no longer necessary for the purposes for which it was collected or where you withdraw consent and there is no other lawful basis for processing.
Right to restriction of processing: You have the right to request that we restrict the processing of your personal data in certain circumstances, such as while we review a challenge to its accuracy or our legitimate interests.
Right to data portability: Where the legal basis is consent or contract and processing is carried out by automated means, you may have the right to receive your personal data in a structured, commonly used and machine readable format and to transmit it to another controller.
Right to object: You have the right to object to processing based on our legitimate interests, including profiling, on grounds relating to your particular situation. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is required for legal claims.
Right to withdraw consent: Where we rely on consent as the lawful basis, you have the right to withdraw that consent at any time.
How To Exercise Your Rights
If you wish to exercise any of your data protection rights or have any questions about this Privacy Policy or how we handle your personal data, you can contact us using the contact details provided on our website or in your contract documentation. We may need to verify your identity before responding to your request, and we aim to respond within the time limits set by law.
You also have the right to lodge a complaint with the relevant supervisory authority if you believe that your data protection rights have been infringed. Further information on how to do this can be obtained directly from the supervisory authority.
Updates To This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. Any changes will be made available in the latest version of this Privacy Policy, and any material changes may be communicated to you by appropriate means.
This Privacy Policy applies to all Storage Heston customers and prospective customers in our area and is intended to provide transparent and accessible information about how we handle personal data in connection with our services.




