Customer, Supplier and Website Privacy Notice
Reference: BWF-DP-001 | Version: 2.1 | Effective: 31 August 2026 | Review: 31 August 2027 | Classification: Public
Controller
Black & White Facilities Limited is the data controller for the processing described in this notice.
Contact: operations@blackandwhitefacilities.co.uk, 0191 833 0040, Collingwood Buildings, 38 Collingwood Street, Newcastle upon Tyne, NE1 1JF. Company number 17377351.
Information and sources
We may process customer, site-contact, supplier, subcontractor and worker contact details; enquiries, quotations, work orders, contracts, invoices and communications; property, access and emergency information; job notes, photographs, video, test results, signatures and completion evidence; supplier insurance, qualifications and payment information; and website form, security, cookie and analytics information where enabled.
Information may come directly from an individual, their organisation, a customer, landlord, managing agent, facilities manager, contractor, insurer, public register, site activity or the systems used to operate and secure our services.
Purposes and lawful bases
We use information to answer enquiries, take pre-contract steps, plan and deliver services, manage access and safety, evidence work, administer variations and warranties, invoice, maintain accounts, prevent fraud, approve suppliers, operate and secure systems, comply with law and establish or defend claims.
Our lawful basis depends on the purpose and may be contract or pre-contract steps, legal obligation, legitimate interests, vital interests in an emergency or consent where consent is required and genuinely optional.
Site evidence
Proportionate photographs and records may be created for diagnosis, quotation, safety, progress, quality, certification, warranty, dispute and authorised customer reporting. We avoid unnecessary capture of people, private possessions, documents and screens. Marketing use of an identifiable site requires separate appropriate permission.
Sharing and suppliers
We share only what is necessary with authorised workers and subcontractors, customers and contract participants, insurers and professional advisers, finance and debt-recovery services, technology and workflow providers, and authorities where lawful. Processors are subject to appropriate terms and security review.
International transfers
We do not intentionally make a restricted transfer outside the UK without a lawful mechanism, appropriate safeguards and proportionate assessment.
Retention and security
Records are retained according to contract, tax, accounting, safety, certification, insurance, limitation, warranty and dispute needs and then securely disposed of. We apply proportionate authentication, access control, device and software management, secure services, backup, restricted sharing and incident response.
Rights requests
Depending on the circumstances, individuals may request access, correction, erasure, restriction, objection or portability, withdraw consent and ask about qualifying automated decisions. Rights requests should be sent to operations@blackandwhitefacilities.co.uk. Identity may be verified proportionately. Responses are normally provided within one calendar month, subject to lawful extension, clarification and exemption.
Data-protection complaints
A data-protection complaint may be made electronically to operations@blackandwhitefacilities.co.uk or by post to the controller address above. Please identify that the message is a data-protection complaint and explain the personal information, event or practice concerned and the outcome sought.
We acknowledge a data-protection complaint within 30 days, take appropriate steps to investigate it, keep the complainant informed where the investigation continues and communicate the outcome without undue delay. Complaint handling does not restrict the right to raise the matter with the Information Commissioner's Office.
Individuals may also complain to the Information Commissioner's Office through https://ico.org.uk.
Cookies and marketing
Non-essential cookies or similar technologies are used only after valid consent where required. Marketing identifies the sender and provides an easy opt-out. Service messages needed for an enquiry, job, safety matter, invoice or contract are not optional marketing.
Processing summary and retention criteria
Scroll the table horizontally to read all columns. Use the arrow keys when the table is focused.
| Activity | Typical information | Main basis | Retention approach |
|---|---|---|---|
| Enquiries, tenders and mobilisation | identities, contacts, sites, requirements, questionnaires and correspondence | pre-contract steps and legitimate interests | unsuccessful opportunities are removed when no longer reasonably required, subject to audit, dispute and suppression needs |
| Contract delivery | orders, authorised contacts, access, assets, instructions, service reports, photographs, variations and completion | contract and legitimate interests | throughout delivery and afterwards for warranty, limitation, insurance, audit and claims requirements |
| Safety, security and compliance | hazard, incident, competence, access, permit and certification information | legal obligation, legitimate interests and vital interests in an emergency | according to applicable statutory, customer, insurance and claims requirements |
| Finance and supplier administration | invoices, transactions, payment and due-diligence records | contract, legal obligation and legitimate interests | for statutory tax/accounting periods and while a payment, audit or dispute remains live |
| Website, communications and security | forms, IP/device data, logs, preferences and consent evidence | legitimate interests, legal obligation and consent for optional tracking | only for the justified security, operational or consent-evidence period |
| Business contact marketing | professional contact and preference records | legitimate interests or consent as applicable | until objection, withdrawal or loss of relevance; limited suppression evidence may remain |
Exact periods are maintained in the controlled retention schedule. A legal hold, incident, complaint, insurer requirement or live claim may extend a period. Records are reviewed and securely erased or anonymised when the reason for retention ends.
Special-category information, vulnerable people and criminal data
Health, disability, vulnerability or safeguarding information is processed only where necessary for safety, an adjustment, protection of a person or a legal duty, and with an applicable additional condition. Criminal-offence information is not routinely requested; where a regulated role, safeguarding need or legal claim requires it, access and legal authority receive specific review.
Automated decisions and profiling
We do not currently use solely automated decisions producing legal or similarly significant effects for customers or suppliers. Routine triage, spam filtering, security alerts or workflow routing does not remove accountable human decision-making. Material future use will receive an impact assessment and updated notice before deployment.
Whether information must be supplied
Information necessary for a tender, contract, safe access, statutory record, supplier approval or payment must be provided if the relevant activity is to proceed. Optional direct marketing and non-essential tracking can be refused without affecting contracted facilities services.
Changes
This notice is reviewed when processing or law changes and at least annually.
Approved by David Swaddle, Company Director and Data Protection Lead, on 31 August 2026.