Privacy Policy and Data Protection Notice

Effective date: 1 August 2026
Organisation: Phronesis Fire Engineering Limited (Company No. 17296109) 
Jurisdiction: United Kingdom

Phronesis Fire Engineering is committed to protecting personal data and handling it fairly, lawfully and transparently in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018 and, where applicable, the Privacy and Electronic Communications Regulations.

This notice explains what personal data we collect through this website and in the course of business enquiries, how that data is used, the legal bases we rely on, how long information is kept, and the rights available to individuals.

1. Who controls your personal data

Phronesis Fire Engineering Limited is the data controller for personal data collected through this website and through related business communications.

Contact for privacy matters:

Email:privacy@phronesisfire.co.uk

Postal address: 203 West Street, Fareham, Hampshire, PO16 0EN

Telephone: +44 (0)20 4622 9994

2. What this notice covers

This notice applies to personal data collected when individuals:

  • Visit the website.

  • Submit an enquiry by email, contact form or other website feature.

  • Request information about services.

  • Discuss a possible appointment, collaboration or referral.

  • Otherwise communicate with Phronesis Fire Engineering in connection with its services.

This notice does not apply to third-party websites linked from this site. Those websites have their own terms and privacy notices.

3. Categories of personal data collected

3.1 Website and technical data

  • IP address

  • Browser type and version

  • Device type

  • Operating system

  • Referral source

  • Pages viewed, dates, times and duration of visits

  • Basic cookie or analytics data, where used

3.2 Enquiry and correspondence data

  • Name

  • Employer or organisation name

  • Job title

  • Email address and telephone number

  • Postal address, if provided

  • Contents of emails, forms, messages and attachments

  • Records of meetings, calls and correspondence

3.3 Client and professional relationship data

Where a matter progresses beyond an initial enquiry, personal data may also include:

  • Contact and billing details

  • Project-related correspondence

  • Details needed to prepare proposals, appointments or invoices

  • Due diligence information reasonably required for professional and legal compliance

We do not intentionally collect special category personal data through the website. Individuals should avoid sending unnecessary sensitive personal information unless specifically requested and securely required for a defined purpose.

4. How personal data is collected

Personal data may be collected:

  • Directly from individuals when they contact the business.

  • Automatically through normal website operation, server logs and similar technical means.

  • From publicly available professional sources, such as company websites or professional networking profiles, where this is relevant to a business enquiry or potential collaboration.

  • From clients, project teams or professional contacts where a legitimate business reason exists.

5. Purposes of processing and legal bases

Purpose of processing Typical personal data Lawful basis relied on
Operating, maintaining and securing the website Technical and usage data Legitimate interests in running a secure and effective website
Responding to enquiries and requests Contact details, correspondence, attachments Legitimate interests in responding to business enquiries; steps prior to entering into a contract where requested
Preparing proposals, appointments and delivering services Contact, project and billing data Performance of a contract; steps prior to entering into a contract
Managing client and professional relationships Contact details, correspondence, meeting notes Legitimate interests in operating and developing the business; performance of a contract where applicable
Complying with legal, accounting, regulatory and professional obligations Identity, contact, billing and engagement records Compliance with a legal obligation
Establishing, exercising or defending legal claims Relevant correspondence and records Legitimate interests; compliance with a legal obligation where applicable

We do not currently send marketing newsletters or electronic marketing messages. If we introduce such features, we will obtain consent where required and update this notice before doing so. Where consent is relied upon, it may be withdrawn at any time; withdrawal will not affect the lawfulness of processing carried out before withdrawal.

6. Legitimate interests

Where processing is based on legitimate interests, those interests include:

  • Operating a professional fire engineering consultancy efficiently and responsibly.

  • Responding to requests and maintaining professional communications.

  • Improving website functionality, resilience and user experience.

  • Keeping business records, managing risk and protecting legal rights.

  • Developing professional networks and business opportunities in a proportionate way.

These interests are balanced against the rights and freedoms of the individuals concerned.

7. Cookies and similar technologies8. Who personal data may be shared with

Our website uses only strictly necessary cookies and technologies for basic site operation and security. Further information is available in our Cookie Policy, which explains the specific cookies used and how to manage preferences. If non-essential cookies or tools are introduced, consent will be obtained before they are set where required.

8. Who personal data may be shared with

Personal data may be shared, where reasonably necessary, with:

  • Website hosting and IT support providers.

  • Email, productivity and cloud storage providers.

  • Accountants, insurers, legal advisers and other professional advisers.

  • Software providers used for CRM, analytics or document management.

  • Regulators, courts, law enforcement or public authorities where disclosure is legally required or reasonably necessary.

  • Carefully selected collaborators, associates or subcontractors involved in delivering services, subject to appropriate confidentiality and data protection controls.

Personal data will not be sold.

9. International transfers

Some service providers may process or store personal data outside the UK. Where personal data is transferred internationally, appropriate safeguards will be used, which may include a UK adequacy regulation, the UK International Data Transfer Agreement, or another lawful transfer mechanism recognised under UK data protection law. Individuals may request further information about relevant safeguards.

10. Data retention

Personal data is kept only for as long as reasonably necessary for the purposes for which it was collected, including satisfying legal, regulatory, insurance, accounting and professional record-keeping requirements.

Our retention periods are:

Category Retention period
Enquiries that do not proceed Up to 24 months after the last meaningful contact
Client and project records (general) 12 years from completion of the engagement or final invoice
Client and project records (higher-risk buildings / golden thread work) 15 years from completion, in line with Building Safety Act obligations
Financial and accounting records 6 years after the relevant tax year, per HMRC requirements
Website technical and server logs Up to 12 months
Correspondence connected to disputes Until conclusion of the matter and any applicable limitation period has expired

Longer retention may apply where records are required for legal proceedings, regulatory investigation, insurance claims or the Building Safety Act "golden thread" for higher-risk buildings. Retention periods are reviewed periodically and this notice will be updated accordingly.

11. Data security

Appropriate technical and organisational measures are used to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include access controls and password management, device and account security, encrypted services where appropriate, backup and recovery arrangements, need-to-know restrictions, and supplier selection with security in mind. No internet-based transmission or storage system can be guaranteed to be completely secure, but reasonable and proportionate safeguards are used.

In the event of a personal data breach likely to result in a risk to individuals' rights and freedoms, we will notify the Information Commissioner's Office as required by law and, where necessary, affected individuals.

12. Individual rights

Under UK data protection law, individuals may have the right to:

  1. Be informed about how personal data is used.

  2. Request access to their personal data.

  3. Request correction of inaccurate or incomplete data.

  4. Request erasure of personal data in some circumstances.

  5. Request restriction of processing in some circumstances.

  6. Object to processing based on legitimate interests in some circumstances.

  7. Request data portability in some circumstances.

  8. Withdraw consent where processing is based on consent.

  9. Object to direct marketing at any time.

  10. Raise a complaint with the Information Commissioner's Office.

These rights are not absolute and may be subject to legal exemptions. Requests should be sent using the contact details in this notice; reasonable steps will be taken to verify identity before responding.

13. Complaints

Concerns about the handling of personal data should be raised first with Phronesis Fire Engineering using the contact details above. Individuals also have the right to complain to the Information Commissioner's Office:

Information Commissioner's Office — https://ico.org.uk — Telephone: 0303 123 1113

14. Children

This website and services are directed at business, professional and organisational users and are not intended for children. If it becomes apparent that personal data has been collected from a child without appropriate authority, steps will be taken to delete that information.

15. Automated decision-making

No solely automated decision-making or profiling producing legal or similarly significant effects is carried out through this website. If this changes, this notice will be updated accordingly.

16. Third-party links

The website may contain links to third-party websites. Phronesis Fire Engineering is not responsible for the privacy practices of third parties; users should read the relevant privacy notices on those websites.

17. Changes to this notice

This notice may be updated from time to time to reflect legal, technical or business changes. The latest version will always be available on the website with its effective date clearly shown. Where changes are material, appropriate steps will be taken to bring them to the attention of affected individuals.