Privacy Policy - Hoxton Storage
This Privacy Policy explains how Hoxton Storage collects, uses, stores, shares, and protects personal data in connection with the storage services it provides. It applies to all Hoxton Storage customers in area, including prospective customers, current customers, former customers, authorised users, and any individuals who interact with us in relation to our services. We are committed to handling personal data in a lawful, fair, transparent, and secure manner in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Hoxton Storage is a storage service provider that processes personal data for the purposes of managing storage accounts, providing access to storage units, administering payments, maintaining security, and meeting legal and operational requirements. For the purposes of data protection law, Hoxton Storage is the data controller in relation to the personal data described in this policy.
2. Personal Data We Collect
We collect and process only the personal data necessary to operate our services effectively and responsibly. The categories of data we may collect include:
- Identity details, such as name, date of birth, and proof of identity where required.
- Contact details, such as postal address, email address, and telephone number.
- Account and contract information, including storage unit details, account references, service history, and agreement records.
- Payment information, such as billing details, transaction records, and payment status. We do not keep card details unless necessary through secure payment systems.
- Access and security data, such as entry logs, CCTV footage, incident reports, and records of site access.
- Correspondence, including communications with our staff by email, phone, or written messages.
- Technical data, such as IP addresses or device information where collected through digital systems used to support security or service administration.
We do not intentionally collect special category data unless it is necessary for a specific legal reason or is provided by you in the course of a complaint, claim, or other lawful interaction.
3. How We Use Personal Data
We use personal data only where there is a lawful basis to do so. Typical uses include:
- setting up and managing customer accounts;
- verifying identity and preventing fraud;
- providing access to storage units and related services;
- processing payments, deposits, refunds, and account administration;
- communicating service updates, notices, and account information;
- ensuring site safety, security, and operational control;
- dealing with disputes, claims, and complaints;
- meeting tax, accounting, and legal obligations;
- improving our services, systems, and customer experience;
- protecting the rights, property, and safety of Hoxton Storage, our customers, and visitors.
4. Lawful Basis for Processing
Under UK GDPR, we must have a lawful basis for each type of processing. Depending on the situation, we rely on one or more of the following:
Performance of a Contract
We process personal data when it is necessary to enter into or perform a storage agreement with you. This includes managing bookings, access, billing, and account administration.
Legal Obligation
We process certain information to comply with legal requirements, such as tax, accounting, fraud prevention, and lawful requests from regulators or law enforcement.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include security monitoring, preventing misuse, maintaining records, improving services, and handling claims.
Consent
In limited cases, we may rely on your consent, for example where specific optional communications or services are offered. Where consent is used, you may withdraw it at any time.
5. Sharing and Processors
We may share personal data with carefully selected third parties that act as processors on our behalf. These parties only process data under our instructions and are required to keep it secure and confidential. Processors may include:
- payment service providers;
- IT, cloud storage, and software providers;
- security and CCTV monitoring providers;
- accounting and audit service providers;
- customer communication and record-management providers;
- professional advisers, including legal advisers, where necessary.
We may also disclose personal data to third parties where required by law, to enforce our agreement, to protect vital interests, or to respond to lawful requests from public authorities. We do not sell personal data.
6. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Retention periods vary depending on the type of data and the purpose of processing.
As a general principle:
- customer account and contract records are retained for the duration of the relationship and for a reasonable period afterwards;
- payment and accounting records are retained for the period required by tax and financial law;
- security logs and access records are kept only as long as necessary for security and incident management;
- complaints, disputes, and legal claim records are retained for as long as required to resolve and defend the matter.
When personal data is no longer needed, we securely delete, anonymise, or destroy it.
7. Security of Personal Data
We use appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction. These measures may include access controls, encryption, secure systems, staff training, and restricted permissions. While no system is completely secure, we regularly review our safeguards and seek to maintain a high standard of protection.
8. Your Rights
Under data protection law, you have a number of rights in relation to your personal data. These rights may be subject to legal limits or exemptions, but we will always respond properly and fairly. Your rights include:
- Right of access – to request confirmation of whether we process your data and to obtain a copy.
- Right to rectification – to ask us to correct inaccurate or incomplete data.
- Right to erasure – to request deletion of data in certain circumstances.
- Right to restriction – to ask us to limit processing in certain cases.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to data portability – to request transfer of data you provided to us in a structured, commonly used format, where applicable.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) if you believe your data protection rights have been infringed.
9. Children’s Data
Our services are directed to adults and business users. We do not knowingly collect personal data from children except where it is incidentally included in records connected to an adult customer and only where necessary for legitimate business or legal purposes.
10. International Transfers
If any of our processors or service providers store or access data outside the United Kingdom, we take steps to ensure an appropriate level of protection is in place, such as approved contractual safeguards or adequacy arrangements, in accordance with applicable law.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service arrangements. Any revised version will apply from the date it is published or otherwise communicated. We encourage customers to review this policy periodically.
12. How We Apply This Policy
This policy applies to all personal data processed by Hoxton Storage in relation to our storage services, whether collected directly from you, generated through account administration, or obtained through lawful third-party sources. By using our services, entering into an agreement with us, or interacting with our staff or systems, you acknowledge that your personal data will be processed in accordance with this policy and applicable data protection law.
Hoxton Storage is committed to respecting privacy and to handling personal information with care, transparency, and accountability. We aim to ensure that all processing is necessary, proportionate, and secure, and that your rights are protected at every stage.