PRIVACY NOTICE
Customers, prospective customers, site contacts, keyholders and service users
Effective from: August 2026
This Privacy Notice explains how Stag Systems Ltd collects, uses, shares and protects personal information when we provide quotations, install, maintain, monitor or support fire, security, CCTV, access control and related systems. It also explains your rights under UK data protection law.
This notice primarily applies where Stag Systems Ltd acts as the data controller. Where we access or handle information contained within a customer-controlled system solely on that customer’s instructions, such as CCTV footage, access logs or user records during support, the customer will normally be the controller and Stag Systems Ltd will normally act as a processor on its behalf.
1. WHO WE ARE
Stag Systems Ltd is the data controller for the personal information described in this notice where we determine why and how that information is used.
Stag Systems Ltd, Unit D15 Heritage Business Park, Heritage Way, Gosport, Hampshire PO12 4BG. Company number 12139429.
Privacy enquiries and data protection requests can be sent to info@stagsystems.co.uk or to the postal address above.
2. PERSONAL INFORMATION WE MAY COLLECT
Depending on the services you use and your relationship with us, we may collect:
identity and contact information, including names, job titles, company details, postal addresses, email addresses and telephone numbers;
site and property information needed to survey, design, install, maintain or support a system;
quotation, order, contract, maintenance, service, warranty, invoice and payment information;
keyholder and emergency contact details supplied for alarm monitoring or response;
system information, including equipment details, serial numbers, configuration information, event histories, fault records, service records and maintenance results;
alarm, signalling and monitoring information, including activations, test signals, response information and communications with an alarm receiving centre where applicable;
access control or CCTV information where it is necessary for us to commission, maintain, investigate a fault or provide remote support;
telephone calls, emails, correspondence, complaints and records of instructions given to us;
website or online-service information, such as IP address, device and technical information, where our websites or online services collect it; and
marketing preferences and records of whether you have opted out of marketing.
We do not intentionally collect special category information unless it is genuinely necessary for a particular service, legal requirement or safety issue. If this is necessary, we will identify appropriate legal conditions and provide any additional information required.
3. WHERE WE GET PERSONAL INFORMATION FROM
We normally obtain personal information directly from you. We may also receive information from:
your employer, landlord, managing agent, main contractor, consultant or another person authorised to act for the site;
other named keyholders or authorised users;
alarm receiving centres, signalling providers, manufacturers and other service providers involved in your system;
publicly available business sources, such as company websites or Companies House, where appropriate; and
existing system records or another installer where we take over maintenance or support.
If we receive your personal information from another source, we will provide privacy information within the period required by law unless an exemption applies or you already have the information.
4. WHY WE USE PERSONAL INFORMATION AND OUR LAWFUL BASES
We only use personal information where we have a lawful basis. The bases most relevant to our activities are contract, legal obligation and legitimate interests. Consent is used where the law specifically requires it or where it is otherwise the most appropriate basis.
Quotations and contracts
We use personal information to respond to enquiries, carry out surveys, prepare quotations, take steps before entering into a contract and administer contracts.
Lawful basis: Contract and legitimate interests.
Installation and service
We use personal information to plan, install, commission, maintain, repair and support systems.
Lawful basis: Contract and legitimate interests.
Monitoring and response
We use personal information to manage keyholders, alarm events, signalling, alarm receiving centre services and response arrangements.
Lawful basis: Contract and legitimate interests.
Billing and records
We use personal information for invoicing, payment collection, accounting, tax and audit records.
Lawful basis: Contract and legal obligation.
Safety, compliance and certification
We use personal information to meet applicable legal, regulatory, certification, insurance and industry-standard requirements.
Lawful basis: Legal obligation and legitimate interests.
Security and fraud prevention
We use personal information to protect systems, networks, premises, accounts and our business from misuse, fraud or security incidents.
Lawful basis: Legitimate interests and legal obligation.
Claims and disputes
We use personal information to handle complaints, enforce agreements, recover debts and establish, exercise or defend legal claims.
Lawful basis: Legitimate interests and legal obligation.
Service improvement
We use personal information to review faults, service history, recurring issues and operational performance so we can improve our services.
Lawful basis: Legitimate interests.
Marketing
We may use personal information to send relevant information about our own products and services where permitted by data protection and electronic marketing law.
Lawful basis: Legitimate interests and/or consent, as applicable.
I’d use exactly that on Wix. It will read better on desktop and mobile than the table, and nobody has ever complained that a privacy notice was too easy to read.
5. WHOM WE MAY SHARE PERSONAL INFORMATION WITH
We may share personal information where necessary with:
alarm receiving centres, signalling and communications providers, and emergency services where the service requires this;
equipment manufacturers, software, cloud, remote access and technical support providers where necessary to provide or support the system;
subcontractors and specialist engineers working on our behalf;
payment providers, banks, accountants, auditors and debt-recovery providers;
insurers, insurance brokers, solicitors and professional advisers;
certification, accreditation, inspection or regulatory bodies where required for our work or approvals;
law enforcement, courts, regulators, government bodies or other authorities where disclosure is required by law or reasonably necessary to protect rights, safety or security; and
a purchaser, investor or adviser involved in a genuine sale, restructuring or transfer of all, or part, of our business, subject to appropriate confidentiality and data protection safeguards.
We do not sell personal information to advertisers or data brokers.
6. INTERNATIONAL TRANSFERS
Some technology, cloud, manufacturer or communications providers may process information outside the United Kingdom. Where this amounts to a restricted international transfer, we will use a lawful transfer mechanism and appropriate safeguards required by UK data protection law, such as UK adequacy regulations or approved contractual safeguards. Further information about relevant safeguards can be requested from us.
7. HOW LONG WE KEEP PERSONAL INFORMATION
We keep personal information only for as long as it is reasonably required for the purpose for which it was collected, including legal, accounting, warranty, certification, safety and claims requirements. Our usual retention approach is:
Enquiries and unsuccessful quotations
We normally keep enquiry and unsuccessful quotation records for up to 2 years after the last meaningful contact, unless we need them for an ongoing relationship, dispute or legal requirement.
Customer contracts, site and service records
We normally keep customer contracts, site records and service history for the duration of the customer relationship and for up to 7 years afterwards. We may keep them longer where reasonably necessary for an ongoing system, warranty matter, certification issue or legal claim.
Accounting and tax records
We keep accounting and tax records for at least 6 years from the end of the relevant company financial year, or longer where required by tax or company law.
Monitoring, alarm and signalling records
We keep monitoring, alarm and signalling records for as long as needed to provide the monitoring service, investigate events, meet applicable standards and deal with complaints or claims.
Retention periods may also depend on the relevant alarm receiving centre or monitoring platform.
CCTV, access logs and customer system data
Where we access CCTV footage, access-control logs or other customer system data for support purposes, we keep it only for as long as necessary to carry out the support or investigation, unless the customer instructs otherwise or the law requires a longer period.
Where we act as a processor on the customer’s behalf, retention will also be subject to the customer’s instructions and the relevant service arrangement.
Complaints, incidents and legal claims
We keep complaint, incident and legal claim records for as long as necessary to resolve the matter and normally for up to 6 years after closure where records may be required to establish, exercise or defend legal rights.
Marketing records
We keep marketing information until you opt out or we decide it is no longer useful.
If you opt out, we may keep a minimal record of that preference so we can make sure we do not contact you again for marketing purposes.
