Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your personal information in accordance with UK data protection laws.
Last Updated: 28 December 2025
Tillet & Saunders ("we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, process, disclose, and safeguard your information when you visit our website, contact us, or engage with our building and construction services.
This policy is written in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By using our website or services, you consent to the data practices described in this policy.
1. Information We Collect
Personal Information You Provide
We collect personal information that you voluntarily provide to us in the following circumstances:
- Quote Requests and Consultations: When you request a quote, consultation, or site visit, we collect your name, email address, phone number, postal address, and details about your project requirements
- Contact Forms: Information submitted through our website contact forms, including your name, email, phone number, and message content
- Email Communications: When you email us directly, we collect your email address and any personal information contained in your message
- Phone Communications: When you call us, we may collect your phone number and any information you provide during the conversation
- Service Engagement: When you engage our services, we collect information necessary to perform the work, including property details, project specifications, and payment information
- Newsletter Subscriptions: If you subscribe to our newsletter or marketing communications, we collect your email address and name
This information may include: full name, email address, telephone number, postal address, property address (for project work), project details and specifications, budget information, preferred contact methods, and any other information you choose to provide.
Information Collected Automatically
When you visit our website, we automatically collect certain technical information about your device and browsing behaviour:
- Device Information: IP address, browser type and version, operating system, device type (mobile, tablet, desktop)
- Usage Data: Pages visited, time spent on pages, click patterns, referring website addresses, date and time of visits
- Location Data: General geographic location based on IP address (city/country level, not precise location)
- Cookies and Tracking Technologies: Information collected through cookies, web beacons, and similar technologies (see our Cookie Policy for details)
Information from Third Parties
We may receive information about you from third parties in limited circumstances, such as when you are referred to us by another business partner, or when we work with subcontractors or suppliers who may share relevant project information with us.
2. Legal Basis for Processing Your Data
Under UK GDPR, we process your personal data based on the following legal grounds:
- Contractual Necessity: To perform our contract with you or take steps at your request before entering into a contract (e.g., providing quotes, delivering building services)
- Legitimate Interests: For our legitimate business interests, such as improving our services, website functionality, marketing our services (where you haven't opted out), and preventing fraud
- Consent: Where you have given clear consent for us to process your data for specific purposes (e.g., marketing communications, newsletter subscriptions)
- Legal Obligations: To comply with legal requirements, such as tax obligations, health and safety regulations, and building regulations
- Vital Interests: To protect your vital interests or those of another person (e.g., in emergency situations)
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, maintain, and improve our building and construction services, including project planning, execution, and completion
- Communication: To respond to your inquiries, provide quotes and estimates, send project updates, and communicate about our services
- Customer Support: To provide customer service, address complaints, and resolve issues related to our services
- Contract Management: To manage contracts, process payments, issue invoices, and maintain business records
- Legal Compliance: To comply with legal obligations, including building regulations, health and safety requirements, tax obligations, and insurance requirements
- Website Improvement: To analyse website usage, improve website functionality, and enhance user experience
- Marketing: To send you marketing communications about our services, special offers, and company news (only with your consent or where we have a legitimate interest)
- Security: To detect, prevent, and address technical issues, security threats, and fraudulent activity
- Business Operations: To manage our business operations, including supplier relationships, subcontractor coordination, and quality assurance
4. Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties for their marketing purposes. We may share your information in the following circumstances:
- Service Providers and Contractors: We may share information with trusted third-party service providers who assist us in operating our business, including website hosting, email services, payment processing, accounting software, and cloud storage providers. These providers are contractually obligated to protect your information and use it only for the purposes we specify
- Subcontractors and Suppliers: When necessary for project delivery, we may share relevant project information with subcontractors, suppliers, and tradespeople working on your project
- Professional Advisors: We may share information with our professional advisors, including accountants, solicitors, and insurance brokers, as necessary for business operations
- Regulatory Authorities: We may disclose information to regulatory bodies, local authorities, building control officers, and other government agencies as required by law or building regulations
- Legal Requirements: We may disclose information if required by law, court order, or in response to valid requests by public authorities (e.g., police, HMRC)
- Business Transfers: In the event of a merger, acquisition, sale of assets, or business transfer, your information may be transferred to the new owner, subject to the same privacy protections
- With Your Consent: We may share your information with third parties when you have given explicit consent for us to do so
- Emergency Situations: We may share information in emergency situations to protect your vital interests or those of others
All third parties with whom we share your information are required to maintain appropriate security measures and use your information only for the purposes we specify, in accordance with applicable data protection laws.
5. Data Security
We implement appropriate technical and organisational security measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. Our security measures include:
- Encryption of data in transit using SSL/TLS protocols
- Secure storage of data with access controls and authentication
- Regular security assessments and updates to our systems
- Staff training on data protection and security best practices
- Physical security measures for our premises and equipment
- Regular backups of data with secure storage
- Limited access to personal data on a need-to-know basis
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security. If we become aware of a data breach that may affect your personal information, we will notify you and the relevant supervisory authority in accordance with UK GDPR requirements.
6. Your Data Protection Rights
Under UK GDPR and the Data Protection Act 2018, you have the following rights regarding your personal data:
- Right of Access: You have the right to request copies of your personal data that we hold. This is commonly known as a "data subject access request". We will provide this information within one month of your request, free of charge (unless the request is manifestly unfounded or excessive).
- Right to Rectification: You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. We will update your information promptly upon verification.
- Right to Erasure ("Right to be Forgotten"): You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the original purpose, you withdraw consent, or the data has been unlawfully processed. However, we may need to retain certain information for legal or contractual reasons (e.g., tax records, warranty information).
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
- Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to have that data transmitted to another data controller where technically feasible.
- Right to Object: You have the right to object to processing of your personal data for direct marketing purposes or where we process your data based on legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds for the processing.
- Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing before the withdrawal.
- Rights Related to Automated Decision-Making: You have rights regarding automated decision-making and profiling, though we do not currently use automated decision-making processes that produce legal or similarly significant effects.
To exercise any of these rights, please contact us using the information provided in the "Contact Us" section below. We will respond to your request within one month. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection supervisory authority.
7. Data Retention
We will retain your personal information only for as long as necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Our retention periods are based on:
- Legal Requirements: We retain financial and tax records for at least 6 years as required by HMRC
- Contractual Obligations: We retain contract and project information for the duration of warranties and guarantees (typically 12 months to 10 years depending on the work)
- Business Needs: We retain customer contact information and project history for legitimate business purposes, such as providing references and maintaining relationships
- Consent: We retain marketing contact information until you withdraw consent or unsubscribe
- Legal Claims: We may retain information longer if necessary for the establishment, exercise, or defence of legal claims
When we no longer need your information, we will securely delete or anonymise it in accordance with our data retention schedule and applicable legal requirements.
8. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse website usage, and improve our services. For detailed information about the cookies we use, their purposes, and how to manage them, please refer to our Cookie Policy.
9. International Data Transfers
Your personal data is primarily processed and stored within the United Kingdom and the European Economic Area (EEA). If we need to transfer your data outside the UK or EEA, we will ensure appropriate safeguards are in place, such as standard contractual clauses approved by the ICO, or transfers to countries with adequacy decisions. We will only transfer your data internationally when necessary for service delivery or with your explicit consent.
10. Third-Party Links
Our website may contain links to third-party websites, such as accreditation bodies (Federation of Master Builders, TrustMark), social media platforms, or partner organisations. We are not responsible for the privacy practices, content, or security of these external sites. We encourage you to review the privacy policies of any third-party sites you visit. This Privacy Policy applies only to information collected by Tillet & Saunders.
11. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information promptly.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational, legal, or regulatory reasons. We will notify you of any material changes by:
- Posting the updated Privacy Policy on this page
- Updating the "Last Updated" date at the top of this policy
- Sending you an email notification (if we have your email address and the changes are significant)
You are advised to review this Privacy Policy periodically for any changes. Your continued use of our website or services after changes are posted constitutes acceptance of the updated policy.
13. Contact Us and Data Protection Officer
If you have any questions, concerns, or requests regarding this Privacy Policy, our data practices, or wish to exercise your data protection rights, please contact us:
Tillet & Saunders
Email: info@tilletandsaunders.co.uk
Phone: 01234 567 890
Address: 123 Builder's Lane, London, SW1A 1AA
Supervisory Authority: If you are not satisfied with our response to your data protection concerns, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: www.ico.org.uk
Phone: 0303 123 1113