Client Privacy Policy
Approved by JimPatrick Munupe, Founder & Director · 16 January 2026 · Next review due 16 January 2027
This policy explains how Ascent Onsite Group Ltd (“AOG”, “we”) handles personal data when we deliver services for a client, including data we process on client premises and sites. It sits alongside our general Privacy Policy, which covers website visitors, enquiries and job applicants. Where the two overlap, this policy governs the client-services relationship.
1. SCOPE
This policy applies where AOG delivers security, FM and cleaning, construction support, vacant property or fire protection services under a client contract, and in the course of that work processes personal data belonging to, or collected on behalf of, the client. It covers your staff, visitors, residents, contractors and members of the public who interact with a site we operate.
2. CONTROLLER AND PROCESSOR
For most site activity the client is the data controller and AOG acts as a processor, handling personal data only on the client's documented instructions under a data processing agreement. For limited activity, such as managing our own officers' records or meeting our own legal duties, AOG is the controller. The contract and its data processing schedule set out the roles for each activity.
3. DATA WE PROCESS ON CLIENT SITES
- Access and visitor records, such as sign-in logs, passes, gate registers and contractor inductions.
- CCTV and body-worn video where a site operates surveillance. See section 4.
- Incident and patrol data, such as occurrence reports, RIDDOR records and welfare checks.
- Operational personnel data, such as the names and contact details of client staff who coordinate the contract.
4. CCTV AND SURVEILLANCE
Where AOG operates CCTV, body-worn video or remote monitoring on a client's behalf, we follow the client's surveillance policy and the ICO's CCTV guidance and the Surveillance Camera Code of Practice. Footage is recorded for safety, security and the prevention and detection of crime, retained for a set period, and released only to the controller or to law enforcement on a lawful request. Signage informs people that recording is in place.
5. LAWFUL BASIS
As processor, AOG relies on the controller's lawful basis. Where AOG is the controller, we rely on legitimate interests for site safety and security, legal obligation for health and safety records, and contract to deliver the service. Our assessment for legitimate interests is summarised in our Legitimate Interest statement.
6. SHARING AND PROCESSORS
We share site personal data only with the client, with sub-processors bound by equivalent terms, and with regulators or law enforcement where the law requires. A current list of sub-processors is available to clients on request.
7. RETENTION
We retain site records for the period agreed with the client, then securely delete or return them. Default periods are set out in the data processing schedule. Incident records connected to legal claims are kept until the matter is resolved.
8. DATA SUBJECT REQUESTS
If you make a request about data held on a client site, we will pass it to the controller without undue delay and assist them in responding. Requests about AOG's own records can be made to us directly using the details below.
9. SECURITY
We apply technical and organisational measures appropriate to the risk, including access controls, encryption in transit, vetted personnel and documented breach procedures. We notify the controller of any personal data breach without undue delay.
10. CONTACT
Email support@ascentonsite.group or write to the data protection contact at our head office. Clients can also raise data matters through their named AOG contract manager.