Data Controller & Data Protection Officer (DPO)
Fetch Security (“we”, “us”, “our”) is the data controller under the UK GDPR and EU GDPR.
Business Address: Fetch
Fire & Security Ltd,
The
Maidstone Studios,
New
Cut Road,
Maidstone,
Kent,
ME15 8JR
Data Protection Officer (DPO): Paul (Paul@Fetchsecurity.com)
Contact Email:
Paul@Fetchsecurity.com
The Source of Personal Data
We may collect personal data about you from:
- You directly.
- Employers/clients when you apply for a role or are considered for an opportunity.
- Referees (where relevant and permitted).
- Publicly available sources (for example, professional networking sites, business websites, and public records).
- Credit reference agencies (CRAs) where required for consumer credit, identity, or affordability checks.
- Third-party service providers used to support recruitment, screening, and compliance processes.
The types of data we process include:
- Identity & Vetting Data: Name, address, date of birth, SIA licence numbers, 5-year employment/education histories, and criminal record details.
- Contact Data: Email address, telephone numbers.
- Financial & Credit Data: Credit commitments, payment history, financial probity markers, and public record information (e.g., CCJs or bankruptcies) received via credit checks.
- Technical & Usage Data: IP address, browser type, operating system, device details, pages visited, and timestamps.
Provision of Personal Data
To operate as a compliant CSAS, Security, and Steward provider, we must collect and process personal data belonging to our employees, self-employed contractors, sub-contractors, and clients.
The provision of certain personal data is primarily contractual and, in some circumstances, required to meet legal and regulatory obligations. Personal data is required to:
- Enter into and perform contracts with customers, suppliers, or business partners (including employees, self-employed contractors, and sub-contractors).
- Process orders, manage accounts, issue deployment rosters, process payroll, and deliver goods and services.
- Verify identity, verify active SIA licensing, conduct background screening, and prevent fraud.
- Comply with applicable legal, regulatory, policing (CSAS), accounting, and HMRC tax obligations.
What are the consequences of not providing personal data?
If you choose not to provide the personal data we request:
- We may be unable to enter into a contract with you.
- We may be unable to fulfil orders, supply goods, provide physical security services, or legally deploy security personnel to client sites.
- We will be legally and contractually unable to clear employees, self-employed or sub-contractors through the BS 7858 vetting process or submit necessary Non-Police Personnel Vetting applications for CSAS.
- We may be unable to conduct necessary verification, compliance, or fraud prevention checks; and as a result, our services or your engagement may be delayed, restricted, or declined.
Where personal data is requested for optional purposes, such as marketing communications, providing this data is not mandatory, and you may withdraw your consent at any time without affecting your ability to receive goods, services, or contracts from us.
Non-Automated Decision Making and Profiling
We may use automated systems and tools to support certain business processes, such as risk assessment, fraud prevention, affordability checks, identity verification, background vetting, or record management.
These tools may analyse personal data using predefined criteria or rules to generate indicators, scores, or recommendations. However, we do not make decisions that have a legal or similarly significant effect on individuals based
solely on automated processing. Any such decisions (including workforce hiring, deployment, or contract terminations) are subject to meaningful human review by our management team.
The use of these tools may influence the speed or level of review applied to an application or request, but individuals will not be subject to automatic rejection or adverse decisions without human involvement.
Credit Reference and Affordability Checks
To help us assess applications, prevent fraud, and meet our legal and regulatory obligations, we may obtain information about you from credit reference agencies (CRAs).
We obtain this information via Creditsafe, which uses its data partner TransUnion to supply consumer credit and identity data.
- Creditsafe Business Solutions Limited is authorised and regulated by the Financial Conduct Authority (FCA Firm Reference Number: 742313).
- TransUnion International UK Limited is authorised and regulated by the Financial Conduct Authority (FCA Firm Reference Number: 737740).
The information we receive may include data relating to your identity, credit commitments, payment history, and public record information. This data is used solely for legitimate business purposes, including creditworthiness assessment, identity verification, and fraud prevention, in accordance with applicable data protection laws.
Further information about how Creditsafe and TransUnion process your personal data can be found in their respective privacy notices:
- Creditsafe Privacy / Transparency Notice: Transparency Notice | Customers & Suppliers
- TransUnion Bureau Privacy Notice: https://www.transunion.co.uk/legal/privacy-centre/pc-bureau
Lawful Bases & How We Use Data
We rely on: Legitimate Interests (site operation, corporate security, business risk assessment, and fraud prevention); Contract Necessity; and Legal Obligations.
We use this data to run and maintain our website, process background screenings, manage account operations, monitor workforce safety, and comply with all legal, tax, and SIA/CSAS regulatory frameworks.
Data Sharing & International Transfers
We do not sell data. We share data only with necessary hosting/analytics providers (e.g., Google), local police forces (for CSAS vetting workflows), regulated security bodies (the SIA), and credit reference agencies. All data processors
are contractually bound. Where data leaves the UK/EEA, we utilise Standard Contractual Clauses (SCCs) or rely on direct statutory Adequacy Decisions.
Data Retention Period
We keep personal data only for as long as necessary for its purpose and to meet legal or regulatory obligations. Data used for credit reference or affordability checks is retained only for as long as required to complete the vetting
assessment and meet audit standards and is then securely deleted. Vetting files related to BS 7858 and CSAS applications are securely stored for the duration of workforce engagement plus any supplementary years mandated by regulatory
bodies for compliance auditing.
Your Rights & Complaints
Under data protection laws, you can request to access, correct, delete, restrict, or object to the processing of your data, as well as request data portability or withdraw your consent. To exercise these rights, please contact Paul
at Paul@Fetchsecurity.com.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the
UK Information Commissioner’s Office (ICO) or your local EU supervisory authority.
This Privacy Policy was last updated and reviewed on: 21st September 2026