Privacy Policy for AM Gas & Electrics

This Privacy Policy explains how AM Gas & Electrical Services Ltd (“we”, “us”, “our” or “the Company”) collects, uses, shares and safeguards personal data when you visit our website, request a quotation, make a booking, instruct us to carry out works, or otherwise interact with us. We are committed to handling your personal data lawfully, fairly and transparently in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (“PECR”).

For the purposes of UK data protection law, AM Gas & Electrical Services Ltd is the data controller of your personal data

1. Who We Are and How to Contact Us

Company name: AM Gas & Electrical Services Ltd.

Company number: 14316143 (registered in England and Wales)

Registered office: Enfield, EN3 6FU

Email: [email protected]

Telephone: 020 8058 0867

If you have any questions about this Privacy Policy, wish to exercise any of your rights, or have a concern about how we are handling your personal data, please contact us using the details above. We do not currently have a statutory obligation to appoint a Data Protection Officer; data protection enquiries are handled by the company’s directors.

2. Personal Data We Collect

We collect and process the following categories of personal data:

Identity and contact data: your full name, postal address, email address, telephone numbers (mobile and landline), and, where you are acting on behalf of an organisation, your job title and organisation name.

Property data: the address of the premises to be inspected, property type (house, flat, HMO, commercial), tenure (owner occupier, landlord, tenant, agent), number of bedrooms, number of consumer units and circuits, age of the installation, and any access information you provide.

Booking and transaction data: appointment dates and times, services requested, quotation reference numbers, invoice records, and payment confirmation data. Full card details are processed and stored by our PCI DSS-compliant payment provider — we do not see or retain full card numbers.

Certificate and inspection data: the findings of any Electrical Installation Condition Report or other certificate we issue, including observations, classifications, photographs taken on site, and remedial recommendations.

Communications data: records of correspondence with you, including emails, online enquiry submissions, SMS messages, and brief notes of telephone calls. Telephone calls are not routinely recorded; if recording is introduced in future, a notice will be played at the start of the call.

Technical and usage data: IP address, approximate geographic location derived from IP, browser type and version, operating system, device type, referring URL, pages visited, time spent on pages, and other diagnostic data collected automatically when you use our website.

Marketing and preferences data: your choices regarding marketing communications, the channels you have agreed to be contacted through, and a record of consent or withdrawal.

Finance data: where you apply for finance, limited identity and affordability information necessary to introduce you to Phoenix Financial Consultants Limited, who will then conduct their own credit and affordability assessment with the relevant lender.

We do not knowingly collect special category data (such as data revealing health, ethnicity, religion, sexual orientation, political opinions or biometric data), nor data relating to criminal convictions. Please do not provide such data to us. If you do so, you consent to its limited processing solely for the purpose of responding to your enquiry, after which it will be deleted.

3. How We Collect Your Personal Data

Personal data is collected:

Directly from you, when you complete an online enquiry form, request a quotation, telephone or email us, instruct us to attend a property, or interact with our team during a site visit.

Automatically, through cookies and similar technologies on our website (see clause 8), and from server logs maintained by our hosting provider for security and diagnostic purposes.

From third parties, including: (i) Phoenix Financial Consultants Limited, where you apply for finance; (ii) referring agents, landlords or letting agents who book inspections on behalf of an owner or tenant; (iii) publicly available sources, such as Companies House and the Land Registry, where reasonably necessary to verify identity or property ownership; and (iv) fraud prevention agencies, where appropriate.

4. Why We Use Your Personal Data and Our Lawful Bases

We process personal data for the following purposes, each on the lawful bases set out under Article 6 of the UK GDPR (and, where relevant, Article 9 conditions for any special category data):

Purpose:

• Responding to your enquiry and providing a quotation

• Delivering the services you have booked, including inspection, certification and remedial works

• Taking and processing payment

• Maintaining records required by law, including HMRC obligations and EICR records

• Facilitating finance applications via Phoenix Financial Consultants Limited

• Reporting to competent persons schemes and certification bodies

• Responding to complaints and improving our

• service Sending marketing communications about similar services

• Preventing and detecting fraud, securing our systems, and protecting our property

• Establishing, exercising or defending legal claims.

Lawful Basis:

• Steps taken at your request prior to entering into a contract.

• Performance of a contract with you

• Performance of a contract; legal obligation (HMRC)

• Legal obligation

• Steps taken at your request; legitimate interests

• Legal obligation; legitimate interests.

• Legitimate interests

• Consent (new customers); soft opt-in (existing customers, in accordance with PECR)

• Legitimate interests; legal obligation

Where we rely on legitimate interests, we have carried out a balancing exercise to ensure that our interests are not overridden by your rights and freedoms. You may request further information about this balancing exercise by contacting us.

You may withdraw consent at any time where consent is the lawful basis (for example, in respect of marketing). You may also object to any processing carried out on the basis of legitimate interests, and we will reassess the processing in light of your objection.

5. Marketing Communications

We may send you marketing communications about services similar to those you have previously enquired about or purchased (“soft opt in”), in accordance with PECR. Every marketing communication we send will contain a clear unsubscribe link or instructions for opting out. You can also opt out at any time by emailing us at [email protected].

We do not undertake any marketing-related profiling or automated decision-making that produces legal or similarly significant effects

6. Who We Share Your Personal Data With

We share personal data only with parties who need it to deliver the service or to support our lawful operations. These recipients fall into the following categories:

Our engineers, surveyors and subcontractors, who carry out work at the premises on our behalf under appropriate confidentiality and data-protection obligations.

Phoenix Financial Consultants Limited (FRN: 539195) and lenders on its panel, where you apply for finance under our Introducer Appointed Representative arrangement (FCA Register No. 1031237).

Payment processors and our card-terminal provider, who handle card transactions on our behalf.

IT and software providers, including our website host, customer relationship management system, calendar and booking platform, email provider, document storage, and accounting software.

Accountants, auditors and professional advisers, including legal advisers, under appropriate confidentiality arrangements.

Competent persons schemes and certification bodies (such as NICEIC, NAPIT or equivalent), to whom we are required to report or provide records as a condition of our memberships.

Insurers and brokers, in connection with claims, public liability cover, or professional indemnity matters.

Regulators, law-enforcement agencies and government bodies, where we are required to disclose information by law, including HMRC, local housing authorities (in respect of landlord EICR submissions) and the Information Commissioner’s Office.

Successors in title, in the event of a sale, merger or reorganisation of our business, in which case personal data may be transferred to the acquiring entity subject to equivalent data protection obligations.

We do not sell your personal data, and we do not share it with any third party for their own marketing purposes without your express consent

7. International Transfers

We are based in the United Kingdom and the majority of our personal data processing takes place in the UK or the European Economic Area. Some of our IT and software suppliers may, however, host or process data outside the UK and the EEA. Where transfers take place to a country not covered by UK adequacy regulations, we ensure that appropriate safeguards are in place — typically the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supplemented where necessary by additional technical measures such as encryption.

You may request a copy of the safeguards we apply to a particular transfer by contacting us

8. Cookies and Similar Technologies

Our website uses cookies and similar technologies to function correctly, remember your preferences, and analyse how visitors use the site. The categories of cookie we use are:

Strictly necessary cookies — required for the website to function (for example, session and security cookies). These cannot be disabled.

Analytics cookies — help us understand how visitors interact with the site, typically through Google Analytics or an equivalent. Used only with your consent.

Functional cookies — remember choices such as form data or preferred display settings. Used only with your consent.

You can manage your cookie preferences through the consent banner displayed on first visit, or by clearing or blocking cookies through your browser settings. Disabling certain cookies may affect site functionality. A more detailed list of the cookies we set, their purpose and their lifespan, is available within the cookie banner’s preference panel

9. How Long We Keep Your Personal Data

We retain personal data only for as long as is necessary for the purposes described in this Privacy Policy, and in accordance with our internal retention schedule. Typical retention periods are:

Enquiry data (where no booking is made): twelve (12) months from last contact.

Quotation records: two (2) years from issue.

Booking and contract records: six (6) years from the end of the contract, in accordance with HMRC requirements and the Limitation Act 1980.

EICR certificates and inspection records: a minimum of six (6) years and, where relevant for landlord compliance, until superseded by a later certificate.

Accounting and tax records: six (6) years plus the current f inancial year.

Marketing preferences and consent records: until withdrawn, or three (3) years from last engagement, whichever is sooner.

Website analytics: typically twenty-six (26) months.

CCTV at our premises (if any): thirty (30) days, save where required for an investigation.

After these periods we either delete or anonymise the data so that it can no longer be associated with you

10. Your Rights Under UK Data Protection Law

You have the following rights in respect of your personal data:

Right to be informed — to know how we collect and use your data (this Privacy Policy).

Right of access — to obtain a copy of the personal data we hold about you (a “subject access request”).

Right to rectification — to have inaccurate or incomplete data corrected.

Right to erasure — to have your data deleted in certain circumstances (“the right to be forgotten”).

Right to restriction — to limit our processing of your data in certain circumstances.

Right to object — to processing carried out on the basis of legitimate interests, or to direct marketing.

Right to data portability — to receive your data in a structured, commonly used, machine-readable format and to have it transmitted to another controller.

Right to withdraw consent — at any time, where consent is the lawful basis.
Rights in relation to automated decision-making and profiling — we do not currently carry out any solely automated decision-making that produces legal or similarly significant effects, but you have the right not to be subject to such decisions if introduced in future.

To exercise any of these rights, please contact us using the details in clause 1. We may need to verify your identity before responding. We will respond within one calendar month, although this period may be extended by up to two further months for complex or numerous requests, in which case we will notify you within the first month and explain the reason for the extension. Exercising these rights is normally free of charge, although we reserve the right to charge a reasonable fee, or refuse the request, where it is manifestly unfounded or excessive

11. Security of Your Personal Data

We apply appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include, where appropriate: access controls and role-based permissions; encryption of data in transit (TLS) and at rest; secure password policies and multi-factor authentication; regular software patching and antivirus protection; secure backups; written contracts with our processors imposing equivalent obligations; staff training on data protection and confidentiality; and confidentiality clauses in employment and engineer contracts.

No transmission over the internet, and no storage system, is entirely secure. We cannot therefore guarantee absolute security of personal data, but we do take all reasonable steps to safeguard it.

12. Personal Data Breaches

In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

a. notify the Information Commissioner’s Office within seventy-two (72) hours of becoming aware of the breach, where required to do so under Article 33 UK GDPR; and

b. where the breach is likely to result in a high risk to your rights and freedoms, notify you directly without undue delay, in accordance with Article 34 UK GDPR.

13. Children’s Data

Our services are directed at adults (homeowners, landlords, tenants and businesses), and we do not knowingly collect personal data from children under sixteen (16) years of age. If you believe a child has provided us with personal data, please contact us so that we can delete it

14. Third-Party Links

Our website may contain links to third-party websites, including those of our finance partner, suppliers and accreditation bodies. We are not responsible for the privacy practices of those websites, and we encourage you to read their privacy policies before providing personal data.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other operational factors. The current version will always be published on our website with the “Last updated” date shown at the top. Where the changes are material, we will draw them to your attention by appropriate means, which may include an email notification or a prominent notice on our website

16. Complaints and the Information Commissioner’s Office

If you have a concern about how we handle your personal data, please contact us first so that we can try to resolve it. You retain the right at all times to lodge a complaint with the Information Commissioner’s Office, the UK’s data protection regulator:

Website: ico.org.uk

Helpline: 0303 123 1113

Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

© AM Gas & Electrical Services Ltd. All rights reserved