We inspect doors.

We protect data just as carefully.

Because trust should extend beyond the fire door…

Privacy Policy

Sure Door IOW
Last updated: 26 August 2026

Sure Door IOW takes privacy, confidentiality and responsible information handling seriously.

This Privacy Policy explains how Sure Door IOW collects, uses, stores, protects and shares personal information when providing fire door inspection services or when people use our website.

Our approach follows the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 as amended, the Privacy and Electronic Communications Regulations where applicable, and other relevant UK data protection requirements.

1. Who we are

Sure Door IOW provides independent fire door inspection, condition assessment and reporting services to organisations and property owners, including:

  • schools and educational establishments;

  • care homes and supported living environments;

  • hotels and hospitality businesses;

  • holiday accommodation and short-term lets (Air BnB’s);

  • landlords and managing agents;

  • commercial organisations; and

  • other responsible persons and property operators.

For personal information processed for our own business purposes, Sure Door IOW acts as the data controller.


Trading name: Sure Door IOW
Email: info@suredoor-iow.co.uk

Questions, requests and data protection complaints can be made using these contact details.

2. Our experience with data protection

Sure Door IOW understands that clients need confidence in the way information is handled, particularly within schools, care homes and other environments where confidential information may be present.

The owner of Sure Door IOW has:

  • completed GDPR and data protection training;

  • over 20 years' experience working within school administration;

  • extensive practical experience handling confidential organisational information;

  • experience working within established information-management and data-processing procedures; and

  • an understanding of the particular confidentiality requirements associated with educational and care environments.

This experience informs how Sure Door IOW approaches site access, photography, reporting, document storage, information sharing and client confidentiality.

Information handling forms part of our professional inspection process rather than an administrative afterthought.

3. Information we may collect

Depending upon the service being provided, we may collect or process:

  • customer names;

  • names of client representatives;

  • job titles and organisational roles;

  • organisation names;

  • email addresses;

  • telephone numbers;

  • site and property addresses;

  • site contact details;

  • appointment details;

  • access arrangements;

  • quotation information;

  • contract information;

  • purchase order information;

  • invoices and accounting information;

  • correspondence;

  • fire door identification information;

  • inspection findings;

  • photographs of fire doors and associated building elements;

  • information required to produce inspection reports;

  • records of previous inspections;

  • website enquiry information;

  • IP addresses and basic website technical information; and

  • cookie or analytics information where applicable.

Our approach is based upon data minimisation. We collect information that has a clear purpose in relation to the service being provided.

4. Working with schools

Sure Door IOW recognises that schools operate within a particularly sensitive information environment.

Our inspection activities may take place around pupils, staff records, safeguarding information, medical information, SEND information and other confidential material.

Our inspection process is designed to minimise interaction with this information.

When working within schools:

  • inspection photography focuses on fire doors, frames, ironmongery, glazing, signage and relevant building defects;

  • identifiable pupils are excluded from inspection photographs wherever reasonably practicable;

  • pupil names, work, photographs, timetables and personal records are excluded from inspection images wherever reasonably practicable;

  • inspection notes focus on the physical condition and compliance of the fire door;

  • access to offices, classrooms and restricted areas follows the school's agreed arrangements;

  • information supplied by the school is used only for relevant business and inspection purposes;

  • confidential information encountered during an inspection is treated accordingly;

  • reports are shared with authorised client representatives;

  • client contact information is stored securely; and

  • information access is limited to those who require it for legitimate business purposes.

Where practical, photographs can be framed, cropped or otherwise managed so that inspection evidence concentrates on the fire door rather than surrounding personal information.

Sure Door IOW understands that schools retain their own responsibilities as data controllers. We work within client instructions, site procedures and agreed information-governance arrangements where these apply.

5. Working with care homes and care environments

Care homes and supported living environments can contain information relating to residents, relatives, staff and health or care arrangements.

Some of this information may qualify as special-category personal data under UK data protection legislation.

Sure Door IOW applies enhanced care when inspecting these environments.

Our inspection process focuses on the building and fire door rather than the personal circumstances of individual residents.

Where reasonably practicable:

  • residents are excluded from photographs;

  • resident names are excluded from photographs and reports;

  • medical information is excluded;

  • care plans and other documents are excluded;

  • medication and treatment information is excluded;

  • personal photographs and private information are excluded;

  • inspection records identify doors through suitable door references, room numbers or asset references where available; and

  • only information relevant to the inspection is retained.

Where personal or sensitive information becomes visible incidentally during an inspection, our approach is to minimise its capture and remove unnecessary information from the inspection record wherever practicable.

Any special-category personal information that genuinely requires processing receives an appropriate level of security and confidentiality.

Sure Door IOW works within the care provider's agreed site, confidentiality and information-governance procedures where applicable.

6. Children and vulnerable people

Our services are provided to organisations, responsible persons, property owners and adults responsible for managing buildings.

Fire door inspections focus upon physical assets.

Our working procedures aim to minimise the collection of information relating to children, residents and vulnerable people.

Where individuals happen to be present during an inspection, photography is directed towards the relevant fire door and building elements.

7. Fire door inspection photographs

Photography provides important technical evidence during a fire door inspection.

Photographs may record:

  • the door leaf;

  • frame;

  • gaps;

  • seals;

  • hinges;

  • closers;

  • glazing;

  • ironmongery;

  • signage;

  • damage;

  • apertures;

  • surrounding construction;

  • certification labels; and

  • other matters relevant to the inspection.

These photographs may form part of the inspection record and support the findings presented within the final report.

Inspection photography is undertaken for legitimate professional purposes associated with the commissioned inspection.

Where personal information appears within an image, we consider whether that information contributes to the inspection record. Unnecessary personal information may be cropped, obscured or excluded.

8. Secure storage using Google services

Sure Door IOW uses Google services as its principal digital information-management platform.

Depending upon the type of information involved, these services may include Google Drive, Gmail, Google Docs, Google Sheets and related Google services.

Inspection reports, photographs, customer records, correspondence and associated business information may therefore be held within controlled Google accounts.

Our information-security arrangements include appropriate measures such as:

  • controlled account access;

  • strong account credentials;

  • multi-factor authentication where available;

  • controlled sharing permissions;

  • limiting access according to business need;

  • secure cloud-based document storage;

  • device security;

  • appropriate file organisation;

  • review of shared access;

  • secure deletion where information reaches the end of its retention period; and

  • use of reputable technology services with established data-protection and security arrangements.

Google services may process or store information using infrastructure located outside the United Kingdom.

Where international processing occurs, we rely upon the applicable contractual and international data-transfer safeguards made available through the relevant Google service and UK data protection framework.

9. Our role when working for organisations

Data protection roles can vary according to the service being provided.

For our own:

  • customer administration;

  • accounting;

  • quotations;

  • business correspondence;

  • website;

  • marketing;

  • inspection administration; and

  • legal and insurance records,

Sure Door IOW generally acts as a data controller.

In some circumstances, a school, care provider or other organisation may instruct Sure Door IOW to process limited personal information on its behalf.

Where that arrangement makes Sure Door IOW a data processor, we process that information according to the client's documented instructions and applicable contractual arrangements.

The client organisation remains responsible for determining the purpose and lawful basis for the personal information it controls.

Where appropriate, data-processing requirements can be incorporated into client contracts or service arrangements.

10. Why we use personal information

We may process information to:

  • answer enquiries;

  • provide quotations;

  • arrange inspections;

  • arrange site access;

  • communicate with customers;

  • undertake fire door inspections;

  • record inspection findings;

  • produce reports;

  • provide photographic evidence;

  • maintain appropriate inspection records;

  • answer subsequent questions about an inspection;

  • administer contracts;

  • issue invoices;

  • maintain accounting records;

  • maintain appropriate professional and insurance records;

  • respond to complaints;

  • establish or defend legal claims;

  • maintain website security;

  • manage our business;

  • improve our services; and

  • meet applicable legal and regulatory obligations.

11. Lawful bases for processing

UK data protection law requires personal information to be processed using an appropriate lawful basis.

The basis used depends upon the circumstances.

Contract

We use personal information where processing is required to enter into or perform a contract.

Examples include:

  • providing quotations;

  • arranging inspections;

  • communicating with customers;

  • completing inspections; and

  • delivering reports.

Legitimate interests

We may process information where this supports a legitimate business purpose and the processing remains proportionate to the interests and rights of the individual.

Examples include:

  • maintaining inspection records;

  • communicating with organisational representatives;

  • maintaining service quality;

  • business administration;

  • ensuring information and system security;

  • responding to complaints;

  • maintaining evidence of services provided; and

  • establishing or defending legal claims.

Legal obligation

Information may be processed where applicable legislation requires us to retain, disclose or otherwise process information.

This may include taxation, accounting, regulatory or legal requirements.

Consent

Consent may be used where it represents the appropriate lawful basis, particularly for certain marketing activities or website technologies.

Consent can be withdrawn at any time.

12. Special-category information

Special-category personal information includes information relating to matters such as:

  • health;

  • disability;

  • racial or ethnic origin;

  • religious beliefs;

  • biometric information used for identification; and

  • certain other sensitive personal characteristics.

Fire door inspections generally require very little interaction with this type of information.

Our processes therefore emphasise avoiding unnecessary collection.

Where special-category information genuinely requires processing, Sure Door IOW will ensure that an appropriate UK GDPR Article 6 lawful basis and an appropriate Article 9 condition apply where required.

Enhanced data minimisation and security measures will also be considered.

13. Sharing information

Information may be shared where appropriate with:

  • the customer who commissioned the inspection;

  • authorised representatives of that customer;

  • property owners;

  • responsible persons;

  • managing agents;

  • schools or academy trusts;

  • care providers;

  • landlords;

  • accountants;

  • insurers;

  • professional advisers;

  • IT and cloud-service providers;

  • payment providers;

  • contractors providing authorised services to Sure Door IOW;

  • regulatory authorities;

  • courts; and

  • public authorities where disclosure is lawfully required.

Information sharing is limited to what is reasonably necessary for the relevant purpose.

Sure Door IOW does not sell customer personal information.

14. Google and other service providers

Third-party technology providers help us operate efficiently and securely.

These may include providers of:

  • cloud storage;

  • email;

  • website hosting;

  • online forms;

  • accounting services;

  • payment processing;

  • data backup; and

  • business administration systems.

Google is one of our principal technology providers.

Where a third party processes personal information on our behalf, we select established providers and use appropriate service arrangements.

15. International transfers

Some technology providers operate internationally.

As a result, information may occasionally be processed outside the United Kingdom.

Where UK personal information is transferred internationally, the transfer will be handled using an appropriate mechanism recognised by UK data protection law.

These mechanisms may include:

  • UK adequacy regulations;

  • approved international transfer arrangements;

  • the International Data Transfer Agreement;

  • the UK Addendum to approved Standard Contractual Clauses; or

  • another applicable UK-approved transfer mechanism.

16. Information security

Sure Door IOW uses proportionate technical and organisational measures to protect information.

These measures include, where appropriate:

  • secure cloud storage;

  • password-protected systems;

  • access controls;

  • multi-factor authentication;

  • restricted sharing permissions;

  • secure devices;

  • appropriate backup arrangements;

  • controlled document access;

  • secure deletion;

  • account security;

  • confidentiality procedures; and

  • periodic review of how information is managed.

Particular care is applied to information originating from schools, care environments and other sensitive settings.

17. How long information is retained

Personal information is retained according to its purpose.

Typical retention periods include:

General enquiries

Normally retained for up to 12 months following the last meaningful contact.

Quotations

Normally retained for up to 2 years following the quotation or last meaningful contact.

Fire door inspection reports

Normally retained for up to 6 years following completion of the inspection.

A longer period may apply where the client contract, legal requirements, insurance arrangements, an ongoing claim or professional record requirements make this appropriate.

Inspection photographs and supporting evidence

Normally retained alongside the associated inspection record.

Contracts and significant client correspondence

Normally retained for up to 6 years following completion of the relevant service.

Accounting records

Retained for the period required by applicable UK taxation and accounting requirements.

Marketing information

Retained while it remains relevant or until the individual exercises their applicable rights.

At the end of the appropriate retention period, information is securely deleted, destroyed or anonymised.

18. Website information

When you visit our website, certain technical information may be processed to operate and protect the website.

This can include:

  • IP address;

  • browser information;

  • device information;

  • pages visited;

  • website interaction information; and

  • cookie information.

The website may use essential cookies required for its operation.

Analytics, performance or marketing cookies are managed according to applicable UK cookie and electronic communications requirements.

Further details should be provided through the website's Cookie Policy and cookie preference controls.

19. Marketing

Sure Door IOW may communicate with existing or prospective customers about relevant services where applicable data protection and electronic marketing rules permit this.

Where consent forms the appropriate basis, marketing communications will follow the consent provided.

Individuals can opt out of direct marketing at any time.

A minimal suppression record may be retained following an opt-out so that the preference can continue to be respected.

20. Your rights

Depending upon the circumstances, UK data protection law provides individuals with rights including:

  • the right to be informed;

  • the right of access;

  • the right to rectification;

  • the right to erasure in applicable circumstances;

  • the right to restrict processing in applicable circumstances;

  • the right to data portability in applicable circumstances;

  • the right to object to certain processing;

  • rights relating to automated decision-making; and

  • the right to withdraw consent where consent is relied upon.

Requests can be made using the contact information shown in this policy.

We may ask for reasonable information to verify identity before releasing personal information.

Valid requests will be handled within the timescales required by applicable data protection legislation.

21. Automated decision-making

Sure Door IOW does not routinely carry out solely automated decision-making about individuals that produces legal or similarly significant effects.

22. Data protection concerns and complaints

Sure Door IOW welcomes the opportunity to resolve any concern about how personal information has been handled.

A data protection complaint can be submitted using the contact details at the beginning of this policy.

We will:

  • acknowledge the complaint appropriately;

  • consider the information provided;

  • investigate the relevant circumstances;

  • provide an appropriate response;

  • explain any action taken; and

  • maintain an appropriate record of the complaint.

Individuals also have the right to raise concerns with the UK supervisory authority:

Information Commissioner's Office

Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Telephone: 0303 123 1113

Further information is available directly from the Information Commissioner's Office.

23. Client confidentiality

Information obtained during the course of an inspection is treated as client information.

Inspection reports, photographs, building information, asset information and customer correspondence are handled with appropriate professional confidentiality.

Our working approach is particularly mindful of the confidentiality expectations applying within:

  • schools;

  • colleges;

  • care homes;

  • supported living settings;

  • hotels;

  • residential premises; and

  • other occupied buildings.

Information gathered for one client is used for the purposes associated with that client's service and our associated legal, professional and business obligations.

24. Changes to this Privacy Policy

We may update this Privacy Policy when our services, systems, suppliers or applicable legal requirements change.

The current version will be published on the Sure Door IOW website.

The Last updated date at the top of this page identifies the current version.

25. Contact Sure Door IOW

For questions about this Privacy Policy, your personal information or a data protection concern, please contact:

Sure Door IOW

Legal name: John Halstead
Email:info@suredoor-iow.co.uk

Last updated: 26 August 2026