Data Protection Policy

Lantec Security – Customer, Website and CCTV/Surveillance Data

Version: 4.0   |   Date: 23 August 2026   |   Policy Owner: Lantec Security

Supersedes: Customer Data Protection Policy, January 2025 v.3

Any questions regarding this Policy and Lantec’s data protection practices should be sent by email to support@lantecsecurity.co.uk, or by telephone on 0118 944 0702.

Part 1 – Customer and Website Privacy Policy

1. Privacy Statement

Lantec Security is committed to protecting and respecting your privacy. This Part explains when and why we collect personal information about people who visit our website, how we use it, the conditions under which we may disclose it to others, and how we keep it secure.

We may change this Policy from time to time, so please check this page occasionally to ensure you are happy with any changes. By using our website, you are agreeing to be bound by this Policy.

2. How We Collect Information From You

We obtain information about you when you use our website – for example, when you contact us about products and services, submit a query from one of our online forms, register to receive updates via newsletters or marketing communications, or register for an event or product.

3. What Type of Information Is Collected

The personal information we collect might include your name, address, email address, IP address, and information regarding what pages are accessed and when. If you undertake a transaction online or purchase a product or service from us, your card information is not held by us; it is collected by our third-party payment processors, who specialise in the secure online capture and processing of credit/debit card transactions. If you register for an event or product, we may collect additional information such as allergies, medical conditions, and age.

4. How Your Information Is Used

We may use your information to:

  • Process a donation that you have made
  • Process orders that you have submitted or applications you have made
  • Carry out our obligations arising from any contracts entered into by you and us
  • Deal with entries into a competition
  • Deal with any registrations for events
  • Seek your views or comments on the services we provide
  • Notify you of changes to our services
  • Send you communications which you have requested and that may be of interest to you, including campaigns, appeals, other fundraising activities, and promotions of our associated companies’ goods and services
  • Process a grant or job application

We review our retention periods for personal information on a regular basis. We are legally required to hold some types of information to fulfil our statutory obligations (for example, the collection of Gift Aid, or to fulfil our duty of safeguarding). We will hold your personal information on our systems for as long as is necessary for the relevant activity, or as long as is set out in any relevant contract you hold with us.

5. How Your Data Is Processed

The primary lawful basis of processing we rely on is contract. By this we mean that your personal data will be used to:

  • Deliver any services that we are contractually committed to provide; or
  • Respond to any requests you make of us prior to entering a contract for advice services (for example, if you make an enquiry about our services via our company website)

Under the terms of the General Data Protection Regulation (GDPR), we are the Data Controller for this information. The UK data protection regime is set out in the Data Protection Act 2018, alongside the UK GDPR.

The Information Commissioner’s Office (ICO) regulates data protection in the UK, offering advice and guidance, promoting good practice, carrying out audits, considering complaints, monitoring compliance and taking enforcement action where appropriate. If you are unhappy with how we have handled your personal information, you have a right to lodge a complaint with the ICO at www.ico.org.uk.

6. Who Has Access to Your Information

We will not sell or rent your information to third parties, and we will not share your information with third parties for marketing purposes.

Third-Party Service Providers Working on Our Behalf

We may pass your information to our third-party service providers, agents, subcontractors and other associated organisations for the purposes of completing tasks and providing services to you on our behalf (for example, to process donations and send you mailings, or to service our website). When we use third-party service providers, we disclose only the personal information necessary to deliver the service, and we have a contract in place requiring them to keep your information secure and not to use it for their own direct marketing purposes. We will not release your information to any other third parties for their own marketing purposes, unless you have requested us to do so or we are required to do so by law – for example, by a court order or for the prevention of fraud or other crime.

Third-Party Product Providers We Work in Association With

We work closely with various third-party product providers to bring you a range of quality and reliable products and services. When you use one of these services, relevant third-party product providers may use your details to provide you with information and carry out their obligations arising from any contracts you have entered into with them. In some cases, they will be acting as a Data Controller of your information, and we advise you to read their privacy policy. These third-party product providers will share your information with us, which we will use in accordance with this Policy.

If you are using our secure online payment pages, your transaction is processed by a third-party payment processor, who specialises in the secure online capture and processing of credit/debit card transactions. If you have any questions regarding secure transactions, please contact us.

We may transfer your personal information to a third party if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, to enforce or apply our terms of use, or to protect the rights, property or safety of our customers. We will take steps with the aim of ensuring that your privacy rights continue to be protected.

7. Your Choices

You have a choice about whether or not you wish to receive information from us. If you do not want to receive direct marketing communications from us, you can select your choices by ticking the relevant boxes on the form on which we collect your information.

We will not contact you for marketing purposes by email, phone or text message unless you have given your prior consent. We will not contact you for marketing purposes by post if you have indicated that you do not wish to be contacted. You can change your marketing preferences at any time by contacting us.

8. How You Can Access and Update Your Information

The accuracy of your information is important to us. If you change email address, or any other information we hold is inaccurate or out of date, please contact us. You have the right to ask for a copy of the information we hold about you (we may charge £10 for information requests, to cover our costs in providing this).

9. Security Precautions

When you give us personal information, we take steps to ensure it is treated securely. Any sensitive information you provide via our systems (such as card details) is encrypted and protected using industry-standard SSL encryption. Non-sensitive details (such as your email address) are transmitted normally over the internet, and this can never be guaranteed to be 100% secure; we make our best effort to ensure the security of information once received. Where you have been given, or have chosen, a password to access parts of our website, you are responsible for keeping this password confidential and should not share it with anyone.

10. Profiling

We may analyse your personal information to create a profile of your interests and preferences so that we can contact you with information relevant to you, and may use additional information available from external sources to help us do this effectively. We may also use your personal information to detect and reduce fraud and credit risk.

11. Use of Cookies

Like many other websites, our website uses cookies – small pieces of information stored on your device that allow the website to recognise you when you visit and collect statistical data about browsing actions and patterns, without identifying you as an individual. It is possible to switch off cookies via your browser preferences; doing so may result in a loss of website functionality.

12. Links to Other Websites

Our website may contain links to other websites run by other organisations. This Policy applies only to our website; we encourage you to read the privacy statements on other websites you visit, and cannot be responsible for their policies or practices.

13. Individuals Aged 16 or Under

We are concerned to protect the privacy of children aged 16 or under. If you are aged 16 or under, please get your parent or guardian’s permission beforehand whenever you provide us with personal information.

14. Transferring Information Outside the UK/EU

Information you provide through our website may occasionally be transferred to and processed in countries outside the UK or EU – for example, where hosting infrastructure is located elsewhere. Where this occurs, we take steps to ensure appropriate security measures are applied, with the aim of ensuring your privacy rights continue to be protected as outlined in this Policy.

15. Liability

We make every effort to ensure the information available on our website is correct but cannot accept responsibility if it is not. Links from our website to other websites are not under our control, and we cannot accept liability for the content of any linked website. External links to our website are made at the other party’s own risk.

Part 2 – CCTV and Surveillance Data Protection Policy

16. Purpose

This Part sets out how Lantec Security handles CCTV and video surveillance data encountered in the course of installing, maintaining, servicing and supporting CCTV systems on behalf of our clients. It applies in addition to Part 1 above, which covers personal data collected through our website and general customer relationships rather than client-owned CCTV footage.

17. Scope

This Part applies to all Lantec engineers, subcontractors and staff who install, maintain, service, inspect or otherwise access client CCTV systems, recording devices (NVR/DVR), storage, or associated footage, whether on-site or via remote access.

18. Roles and Responsibilities

18.1 Data Controller

In the great majority of engagements, the client (for example, a school, trust, or business) remains the Data Controller for CCTV footage captured by their systems. The client determines the purpose and means of processing – including camera placement, retention periods, and who may view footage.

18.2 Data Processor

Lantec acts as a Data Processor when engineers access, view, export, or otherwise process footage or system data in the course of installation, maintenance, fault-finding, or system health checks. Lantec processes such data only on the client’s documented instructions and only to the extent necessary to deliver the contracted service.

19. Lawful Basis for Processing

Where Lantec’s engineers access CCTV footage or system data, this is done under the lawful basis relied upon by the client as Data Controller (typically legitimate interests or public task, depending on the client), and solely for the purposes of:

  • Diagnosing and resolving technical faults
  • Verifying recording, storage, and image quality during planned preventative maintenance
  • Confirming system functionality following installation, repair, or configuration changes

Lantec engineers do not access, export, review or retain footage for any purpose beyond the specific maintenance or diagnostic task being carried out, and do not use client footage for training, marketing, or any other secondary purpose.

20. Access Controls

  • Access to client CCTV systems and footage is restricted to authorised, vetted engineers assigned to that contract
  • All engineers attending school or safeguarding-sensitive sites hold Enhanced DBS clearance
  • Remote access to client systems, where used, is via secure, credentialed connections; default manufacturer passwords are changed as standard practice during installation and verified during maintenance visits
  • Access is logged where the client’s system supports activity logging, and Lantec will provide access records to the client on reasonable request

21. Handling of Footage During Maintenance

  • Footage is viewed on-site via the client’s own system wherever possible, rather than exported or copied
  • Footage or system data is only exported from a client system where strictly necessary to diagnose a fault (for example, sending a short clip to a manufacturer’s technical support team), and only with client authorisation
  • Any footage temporarily exported for diagnostic purposes is permanently deleted from Lantec devices and systems once the issue is resolved, and in any event within 30 days
  • Lantec does not retain copies of client CCTV footage as a matter of routine business practice

22. Retention

Lantec does not set or control retention periods for client CCTV footage – this remains the client’s responsibility as Data Controller. Where asked, Lantec will advise clients on retention settings appropriate to their storage capacity and operational needs, and will confirm current retention configuration as part of routine CCTV maintenance reporting.

23. Cyber Security of CCTV Systems

  • Default manufacturer credentials are changed on all cameras, NVR/DVR devices and associated network equipment at installation, and verified during subsequent maintenance visits
  • Firmware and software updates are applied in line with manufacturer guidance and reviewed at each scheduled maintenance visit
  • Where appropriate to the client’s network architecture, CCTV systems are recommended to be segmented from general office/administrative networks to reduce cross-system risk
  • User access to CCTV systems and viewing platforms is reviewed periodically with the client to ensure access remains appropriate and current

24. Data Subject Rights

Requests from individuals to access, review or query footage in which they may appear (for example, a Subject Access Request) are the responsibility of the client as Data Controller. Lantec will provide reasonable technical assistance to the client in retrieving specific footage in response to such requests, where instructed to do so.

25. Data Breach Reporting

Any suspected or actual data breach involving client CCTV systems or footage identified by Lantec staff – including unauthorised access, loss of footage, or system compromise – will be reported to the client without undue delay, and in any event within 24 hours of discovery, to support the client’s own regulatory reporting obligations under UK GDPR.

26. Compliance Framework

This Part is intended to support client compliance with, and reflects Lantec’s own commitment to, the following:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Information Commissioner’s Office (ICO) Surveillance Camera Code of Practice
  • BS EN 62676 series – Video surveillance systems for use in security applications

27. Review of This Policy

This Policy (Parts 1 and 2) is kept under regular review and will next be reviewed no later than August 2027, or sooner in response to changes in legislation, ICO guidance, or Lantec’s operational practices.