Storage Petersham Privacy Policy
This Privacy Policy explains how Storage Petersham collects, uses, discloses and protects personal data relating to customers and prospective customers in the Storage Petersham service area. It also sets out your rights under the UK General Data Protection Regulation and related data protection laws. By using our storage services or otherwise providing your personal data to us, you acknowledge that you have read and understood this Privacy Policy.
Scope and Data Controller
This Privacy Policy applies to all Storage Petersham customers and prospective customers in our operating area, including individuals and representatives of business clients who use or enquire about our storage services. Storage Petersham is the controller of the personal data described in this Privacy Policy, meaning that we decide how and why your personal data is processed.
Personal Data We Collect
We collect only the personal data that is necessary to provide and manage our storage services, operate our business, and comply with our legal obligations. The types of personal data we may collect include:
Identification and contact details: name, postal address, billing address, contact address, and any other contact information you choose to provide.
Account and contract information: customer account details, unit number, contract start and end dates, service history, correspondence relating to enquiries, bookings, renewals, and complaints.
Payment and billing information: payment method details such as partial card information or other transaction identifiers processed via our payment processors, invoices, payment status, and records of payments made or due. We do not store full payment card details when processed via third party payment providers.
Usage and communication data: information about your use of our services, records of communications with you including enquiries, service requests, feedback, and internal notes relating to the management of your account.
Security and access information: records relating to access to storage units or premises, such as access control logs, visit dates and times, and security incident records where relevant.
Technical data: where you visit our online pages or digital tools, we may collect technical information such as device type, browser type and version, and basic usage statistics. This is used to administer and improve our online services.
How We Collect Your Personal Data
We collect personal data directly from you when you contact us, make an enquiry, request a quote, sign a contract, access our premises, make a payment, or communicate with us by any channel. We may also generate personal data as part of operating and administering your account, including billing and security records.
In some cases, we may receive personal data about you from third parties, for example where a business client lists you as a contact, or from payment providers who confirm payment status. We will only obtain such data where it is lawful and necessary to provide our services or manage our relationship with you.
Lawful Basis for Processing
We process your personal data only when we have a lawful basis under the UK General Data Protection Regulation and related data protection legislation. Depending on the circumstances, our lawful bases include:
Contract: processing that is necessary to enter into or perform a contract with you, including creating and managing your account, providing access to storage units, processing payments, and communicating with you about your contract and services.
Legal obligation: processing that is necessary to comply with our legal or regulatory obligations, including tax and accounting requirements, record keeping obligations, and responding to lawful requests from public authorities.
Legitimate interests: processing that is necessary for our legitimate business interests or those of a third party, provided that your interests and fundamental rights do not override those interests. This includes maintaining security at our premises, preventing and investigating fraud or misuse of services, managing customer relationships, and improving our services.
Consent: where required by law, we may rely on your consent, for example for certain optional communications or marketing. When we rely on consent, you have the right to withdraw your consent at any time.
How We Use Your Personal Data
We may use your personal data for the following purposes:
To provide, manage, and administer storage services and related offerings.
To set up and manage customer accounts and contracts, including handling bookings, renewals, and terminations.
To process payments, issue invoices, manage arrears, and maintain accurate financial records.
To communicate with you about your account, service updates, changes to terms, access arrangements, and customer support requests.
To maintain security at our premises, protect our property and the property of our customers, prevent unauthorised access, and investigate security incidents.
To comply with legal, regulatory, and tax obligations and to respond to lawful requests from authorities or regulators.
To manage business operations, including internal reporting, service improvement, and quality assurance.
Data Sharing and Processors
We do not sell your personal data. We may share your personal data with carefully selected third parties where this is necessary for the purposes outlined in this Privacy Policy and in accordance with data protection law. These third parties may act as processors, processing personal data on our behalf and under our instructions.
Typical categories of recipients and processors may include:
IT service providers who host, operate, or support our systems, including storage management systems, customer relationship tools, and data backup services.
Payment service providers and banks who process payments, handle card transactions, and support financial reconciliation.
Professional advisers such as accountants, auditors, and legal advisers where necessary for the management of our business and to obtain professional advice.
Security service providers who support access control, security monitoring, or incident investigation, where required for the protection of our premises and customers.
Public authorities or regulators where we are legally required to do so, or where disclosure is necessary to protect our rights or the rights of others.
Whenever we use processors, we ensure that appropriate contracts and safeguards are in place requiring them to protect your personal data, use it only in accordance with our instructions and applicable law, and implement suitable security measures.
International Transfers
Where we transfer personal data outside the United Kingdom or European Economic Area, we will ensure that appropriate safeguards are in place to protect your personal data, such as adequacy decisions or standard contractual clauses, in accordance with data protection law.
Data Retention
We retain your personal data only for as long as necessary for the purposes for which it was collected, and to comply with our legal and contractual obligations. In determining retention periods, we consider the nature of the data, the purpose of processing, legal and regulatory requirements, and our legitimate business needs.
In general, we will keep core contract and billing records for a period required by tax and accounting law after your contract or relationship with us ends. Security and access records are retained for a shorter period, unless required for the investigation of an incident, legal claim, or dispute. When personal data is no longer needed, we will securely delete or anonymise it.
Security of Your Personal Data
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, unlawful processing, accidental loss, destruction, or damage. These measures may include access controls, secure storage, encryption or pseudonymisation where appropriate, and regular review of our security practices. While we strive to protect your personal data, no system can be completely secure, and you should take care to keep your own access credentials safe.
Your Data Protection Rights
Under the UK General Data Protection Regulation and related laws, you have certain rights in relation to the personal data we hold about you. Subject to legal conditions and exemptions, these rights include:
Right of access: you have the right to request confirmation as to whether we process your personal data and to receive a copy of that data, along with information about how it is used.
Right to rectification: you have the right to request that we correct or complete personal data that is inaccurate or incomplete.
Right to erasure: in certain circumstances, you have the right to request that we delete your personal data, for example where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent and there is no other lawful basis for processing.
Right to restriction of processing: you have the right to request that we restrict the processing of your personal data in certain situations, such as while we verify the accuracy of data or assess an objection you have raised.
Right to object: where we rely on legitimate interests to process your personal data, you have the right to object to that processing on grounds relating to your particular situation. We will stop processing unless we can demonstrate compelling legitimate grounds or where processing is required for legal claims.
Right to data portability: in some cases, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine readable format and to request that we transmit it to another controller, where this is technically feasible and based on consent or contract.
Right to withdraw consent: where we rely on your consent to process personal data, you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
You also have the right to lodge a complaint with a data protection supervisory authority if you believe your data protection rights have been infringed. We encourage you to contact us first so we can address your concerns.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or how we process personal data. Any changes will take effect when the updated Privacy Policy is made available. We recommend that you review this Privacy Policy periodically to stay informed about how we protect your personal data.




