1. Overview & Controller Identity
Empress Monitoring ASM Limited ("we", "us", "our") is committed to protecting and respecting your personal data. This Privacy Policy outlines how we collect, process, store, and share personal data in complete compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
For the purposes of data protection law, we act as the Data Controller for personal data relating to our website visitors, commercial prospects, and direct contract customers. Where we provide remote CCTV and alarm monitoring services under contract to our clients, we act as a Data Processor, and our client acts as the Data Controller.
Company Registration Details:
Empress Monitoring ASM Limited (Company No. 14346708, England & Wales)
Unit 7, The Generation Centre, Church Street, Rochdale, OL12 6XB, United Kingdom.
Information Commissioner's Office (ICO) Registration Number: ZB816112.
2. Personal Data We Collect
We process several categories of personal data, which may include:
- Contact Information: Names, company names, business email addresses, direct telephone numbers, and site billing addresses.
- Site Operational Data: Keyholder contact details, perimeter diagrams, alarm system configurations, and routine system transmission heartbeat logs.
- CCTV Video Footage: Video recordings, imagery, and operator telemetry captured from monitored security cameras on client premises.
- Alarm Event Records: Logs of sensor triggers, system activations, operator audio warnings, and recorded emergency dispatch communications.
3. Lawful Bases for Processing
We only process your personal data where we have a valid lawful basis under Article 6 of the UK GDPR. These bases are mapped below:
| Data Category | Processing Purpose | UK GDPR Lawful Basis |
|---|---|---|
| Contact & Account Data | Invoicing, customer service, and contract administration. | Performance of a Contract (Article 6(1)(b)) |
| CCTV & Event Records | Detecting, preventing, and intercepting criminal trespass on client sites. | Legitimate Interests (Article 6(1)(f)) in protecting property and assets. |
| Keyholder Details | Contacting designated site contacts during active security alerts. | Performance of a Contract (Article 6(1)(b)) / Legitimate Interests. |
| Contact Forms | Responding to inbound site survey inquiries and service quotes. | Consent (Article 6(1)(a)) / Pre-Contractual Steps. |
4. CCTV & Remote Monitoring Data Handling
As a specialist remote security monitoring company, the protection of CCTV video feeds is paramount. We maintain highly restrictive controls over all video and telemetry assets:
- Partner ARC Handling: All remote CCTV feeds, intruder alerts, and fire signals are routed directly to, and managed by, our partner Alarm Receiving Centre (ARC), Advanced Signal Monitoring (ASM). ASM operates under strict physical and logical security controls.
- Chain of Custody & Auditing: Every single instance of footage retrieval, live stream viewing, or digital export is fully logged. Disclosures are subject to a strict chain of custody and are audited continuously.
- Footage Retention: Under standard operating guidelines, CCTV video footage is automatically overwritten after a period of 30 days, unless specific recordings are preserved as evidence of a security activation, trespass event, or police investigation.
5. Data Sharing & Disclosures
We never sell or lease your personal data. We only share personal data with external entities under the following restrictive scenarios:
- Advanced Signal Monitoring (ASM): Our partner ARC receives telemetry, keyholder directories, and live video signals to handle security alarms.
- Law Enforcement & Emergency Services: We disclose verified alarm logs and CCTV video clips to the police and fire services to support emergency dispatch and criminal prosecution.
- Designated Clients: Contractual account contacts are provided event logs and clips relating to security incidents on their owned or leased premises.
- Approved Service Providers: Essential subcontractors (such as maintenance engineers) are granted limited operational access under strict confidentiality agreements.
6. Technical Security & Storage
We employ robust physical and technical security measures to safeguard all personal data. All data is processed and stored within the United Kingdom. We apply end-to-end transport layer encryption on video transmission networks, enforce strict multi-factor authentication (MFA) across our software directories, and maintain physical access controls at our Rochdale operations centre.
7. Your Rights as a Data Subject
Under the UK GDPR, you possess the following statutory rights regarding your personal data:
- Right of Access: You can request copies of your personal data (including specific CCTV footage in which you are clearly identifiable).
- Right to Rectification: You can request that we correct inaccurate or incomplete operational databases.
- Right to Erasure: You can request the deletion of your personal data where there is no overriding legal reason to continue processing.
- Right to Restrict Processing: You can request that we suspend processing in certain dispute scenarios.
- Right to Object: You can object to data processing conducted under legitimate interest grounds.
To exercise any of these rights, please contact our Data Protection representative at hello@empressasm.uk. We will respond to verified statutory requests within one calendar month.
8. Lodging a Complaint
If you have concerns about our data handling practices, we request that you contact us first so we can address your query. You also have the legal right to lodge a formal complaint at any time with the UK supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk · Helpline: 0303 123 1113