Privacy Policy and Data Protection Notice
Effective date: 1 August 2026
Organisation: Phronesis Fire Engineering Limited (Company No. 17296109)
Jurisdiction: United Kingdom
Phronesis Fire Engineering is committed to protecting personal data and handling it fairly, lawfully and transparently in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018 and, where applicable, the Privacy and Electronic Communications Regulations.
This notice explains what personal data we collect through this website and in the course of business enquiries, how that data is used, the legal bases we rely on, how long information is kept, and the rights available to individuals.
1. Who controls your personal data
Phronesis Fire Engineering Limited is the data controller for personal data collected through this website and through related business communications.
Contact for privacy matters:
Email:privacy@phronesisfire.co.uk
Postal address: 203 West Street, Fareham, Hampshire, PO16 0EN
Telephone: +44 (0)20 4622 9994
2. What this notice covers
This notice applies to personal data collected when individuals:
Visit the website.
Submit an enquiry by email, contact form or other website feature.
Request information about services.
Discuss a possible appointment, collaboration or referral.
Otherwise communicate with Phronesis Fire Engineering in connection with its services.
This notice does not apply to third-party websites linked from this site. Those websites have their own terms and privacy notices.
3. Categories of personal data collected
3.1 Website and technical data
IP address
Browser type and version
Device type
Operating system
Referral source
Pages viewed, dates, times and duration of visits
Basic cookie or analytics data, where used
3.2 Enquiry and correspondence data
Name
Employer or organisation name
Job title
Email address and telephone number
Postal address, if provided
Contents of emails, forms, messages and attachments
Records of meetings, calls and correspondence
3.3 Client and professional relationship data
Where a matter progresses beyond an initial enquiry, personal data may also include:
Contact and billing details
Project-related correspondence
Details needed to prepare proposals, appointments or invoices
Due diligence information reasonably required for professional and legal compliance
We do not intentionally collect special category personal data through the website. Individuals should avoid sending unnecessary sensitive personal information unless specifically requested and securely required for a defined purpose.
4. How personal data is collected
Personal data may be collected:
Directly from individuals when they contact the business.
Automatically through normal website operation, server logs and similar technical means.
From publicly available professional sources, such as company websites or professional networking profiles, where this is relevant to a business enquiry or potential collaboration.
From clients, project teams or professional contacts where a legitimate business reason exists.
5. Purposes of processing and legal bases
| Purpose of processing | Typical personal data | Lawful basis relied on |
|---|---|---|
| Operating, maintaining and securing the website | Technical and usage data | Legitimate interests in running a secure and effective website |
| Responding to enquiries and requests | Contact details, correspondence, attachments | Legitimate interests in responding to business enquiries; steps prior to entering into a contract where requested |
| Preparing proposals, appointments and delivering services | Contact, project and billing data | Performance of a contract; steps prior to entering into a contract |
| Managing client and professional relationships | Contact details, correspondence, meeting notes | Legitimate interests in operating and developing the business; performance of a contract where applicable |
| Complying with legal, accounting, regulatory and professional obligations | Identity, contact, billing and engagement records | Compliance with a legal obligation |
| Establishing, exercising or defending legal claims | Relevant correspondence and records | Legitimate interests; compliance with a legal obligation where applicable |
We do not currently send marketing newsletters or electronic marketing messages. If we introduce such features, we will obtain consent where required and update this notice before doing so. Where consent is relied upon, it may be withdrawn at any time; withdrawal will not affect the lawfulness of processing carried out before withdrawal.
6. Legitimate interests
Where processing is based on legitimate interests, those interests include:
Operating a professional fire engineering consultancy efficiently and responsibly.
Responding to requests and maintaining professional communications.
Improving website functionality, resilience and user experience.
Keeping business records, managing risk and protecting legal rights.
Developing professional networks and business opportunities in a proportionate way.
These interests are balanced against the rights and freedoms of the individuals concerned.
7. Cookies and similar technologies8. Who personal data may be shared with
Our website uses only strictly necessary cookies and technologies for basic site operation and security. Further information is available in our Cookie Policy, which explains the specific cookies used and how to manage preferences. If non-essential cookies or tools are introduced, consent will be obtained before they are set where required.
8. Who personal data may be shared with
Personal data may be shared, where reasonably necessary, with:
Website hosting and IT support providers.
Email, productivity and cloud storage providers.
Accountants, insurers, legal advisers and other professional advisers.
Software providers used for CRM, analytics or document management.
Regulators, courts, law enforcement or public authorities where disclosure is legally required or reasonably necessary.
Carefully selected collaborators, associates or subcontractors involved in delivering services, subject to appropriate confidentiality and data protection controls.
Personal data will not be sold.
9. International transfers
Some service providers may process or store personal data outside the UK. Where personal data is transferred internationally, appropriate safeguards will be used, which may include a UK adequacy regulation, the UK International Data Transfer Agreement, or another lawful transfer mechanism recognised under UK data protection law. Individuals may request further information about relevant safeguards.
10. Data retention
Personal data is kept only for as long as reasonably necessary for the purposes for which it was collected, including satisfying legal, regulatory, insurance, accounting and professional record-keeping requirements.
Our retention periods are:
| Category | Retention period |
|---|---|
| Enquiries that do not proceed | Up to 24 months after the last meaningful contact |
| Client and project records (general) | 12 years from completion of the engagement or final invoice |
| Client and project records (higher-risk buildings / golden thread work) | 15 years from completion, in line with Building Safety Act obligations |
| Financial and accounting records | 6 years after the relevant tax year, per HMRC requirements |
| Website technical and server logs | Up to 12 months |
| Correspondence connected to disputes | Until conclusion of the matter and any applicable limitation period has expired |
Longer retention may apply where records are required for legal proceedings, regulatory investigation, insurance claims or the Building Safety Act "golden thread" for higher-risk buildings. Retention periods are reviewed periodically and this notice will be updated accordingly.
11. Data security
Appropriate technical and organisational measures are used to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include access controls and password management, device and account security, encrypted services where appropriate, backup and recovery arrangements, need-to-know restrictions, and supplier selection with security in mind. No internet-based transmission or storage system can be guaranteed to be completely secure, but reasonable and proportionate safeguards are used.
In the event of a personal data breach likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office as required by law and, where necessary, affected individuals.
12. Individual rights
Under UK data protection law, individuals may have the right to:
Be informed about how personal data is used.
Request access to their personal data.
Request correction of inaccurate or incomplete data.
Request erasure of personal data in some circumstances.
Request restriction of processing in some circumstances.
Object to processing based on legitimate interests in some circumstances.
Request data portability in some circumstances.
Withdraw consent where processing is based on consent.
Object to direct marketing at any time.
Raise a complaint with the Information Commissioner's Office.
These rights are not absolute and may be subject to legal exemptions. Requests should be sent using the contact details in this notice; reasonable steps will be taken to verify identity before responding.
13. Complaints
Concerns about the handling of personal data should be raised first with Phronesis Fire Engineering using the contact details above. Individuals also have the right to complain to the Information Commissioner's Office:
Information Commissioner's Office — https://ico.org.uk — Telephone: 0303 123 1113
14. Children
This website and services are directed at business, professional and organisational users and are not intended for children. If it becomes apparent that personal data has been collected from a child without appropriate authority, steps will be taken to delete that information.
15. Automated decision-making
No solely automated decision-making or profiling producing legal or similarly significant effects is carried out through this website. If this changes, this notice will be updated accordingly.
16. Third-party links
The website may contain links to third-party websites. Phronesis Fire Engineering is not responsible for the privacy practices of third parties; users should read the relevant privacy notices on those websites.
17. Changes to this notice
This notice may be updated from time to time to reflect legal, technical or business changes. The latest version will always be available on the website with its effective date clearly shown. Where changes are material, appropriate steps will be taken to bring them to the attention of affected individuals.