1.
Purpose
This policy explains how we collect, use, and store personal data; how we protect personal data and ensure compliance with data protection laws; and your rights as a data subject and how to exercise them
2.
Scope
This policy applies to:
- All clients, employees, contractors, suppliers, and website visitors
- All personal data processed by EPD Engineering Solutions Limited, whether in electronic, paper, or other forms
3.
Definitions
- Personal Data — Any information relating to an identifiable individual
- Processing — Any action performed on personal data, including storage, sharing, and analysis
- Data Controller — EPD Engineering Solutions Limited, responsible for deciding how personal data is used
- Data Subject — Any individual whose data we process
4.
Our Data Protection Commitment
We adhere to the seven UK GDPR principles:
1
Lawfulness, fairness & transparency
2
Purpose limitation
3
Data minimisation
4
Accuracy
5
Storage limitation
6
Integrity & confidentiality
7
Accountability
5.
Types of Data We Collect
5.1 client & project data
- Contact details, company information, and project specifications
- Engineering reports, feasibility studies, CAD models, and FEA results
5.2 employee & contractor data
- Payroll and HR records
- Emergency contacts, qualifications, and training records
5.3 Supplier & Third-Party Partner Data
- Contact details, contracts, and service agreements
5.4 Website Visitors
- IP addresses, browsing activity, and cookie preferences (via analytics tools)
6.
How We Use Personal Data
We adhere to the seven UK GDPR principles:
purpose
examples
lawful basis
Delivering engineering services
Project management, analysis, reporting
Contract
Supplier & contractor management
Project management, analysis, reporting
Legitimate interest
HR & payroll processing
Employee records, pensions, payments
Legal obligation
Marketing & updates
Email communications, newsletters
Consent
Legal & compliance
Tax, invoicing, insurance, audits
Legal obligation
8.
Data Security
We implement strict technical and organisational measures to protect personal data:
- Secure, encrypted cloud storage for engineering reports and client files
- Access controls and strong password policies for internal systems
- Multi-factor authentication where appropriate
- Regular security audits and off-site data backups
10.
International Data Transfers
Where personal data is transferred outside the UK, we ensure appropriate safeguards, including:
- UK-approved Standard Contractual Clauses (SCCs)
- Transfers to countries deemed adequate by the ICO
11.
Data Retention
We adhere to the seven UK GDPR principles:
Data Type
retention period
Client project files
7 years after completion
Engineering reports
7 years after completion
Employee HR records
6 years after employment
Supplier contracts
6 years after expiry
Marketing data
Until consent withdrawn
After these periods, data will be securely deleted or anonymised.
12.
Your Data Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Request corrections to inaccurate data
- Request deletion (“right to be forgotten”)
- Restrict or object to processing
- Request data portability
- Withdraw marketing consent at any time
To exercise these rights, email us at matthew@epdengineeringsolutions.com.
13.
Your Data Rights
In the event of a suspected data breach, we will:
- Contain and investigate immediately
- Notify the Data Protection Lead
- Assess potential impact and risks
- Report to the ICO within 72 hours if required
- Inform affected individuals where necessary
14.
Third Party Platforms
We carefully select and review third-party platforms used to store or process data (e.g., Microsoft 365, Dropbox, cloud-based project systems) to ensure they comply with UK GDPR.
15.
Contact Information
data protection lead
EPD Engineering Solutions Limited
Phone: +44 7554 592744
If you believe we’ve mishandled your data, you can also contact the Information Commissioner’s Office (ICO): ico.org.uk
15.
Policy Review
This policy will be reviewed annually or sooner if there are significant changes to legislation, company operations, or data processing practices.