Lantec Security – Customer, Website and CCTV/Surveillance Data
Version: 4.0 | Date: 23 August 2026 | Policy Owner: Lantec Security
Supersedes: Customer Data Protection Policy, January 2025 v.3
Any questions regarding this Policy and Lantec’s data protection practices should be sent by email to support@lantecsecurity.co.uk, or by telephone on 0118 944 0702.
Lantec Security is committed to protecting and respecting your privacy. This Part explains when and why we collect personal information about people who visit our website, how we use it, the conditions under which we may disclose it to others, and how we keep it secure.
We may change this Policy from time to time, so please check this page occasionally to ensure you are happy with any changes. By using our website, you are agreeing to be bound by this Policy.
We obtain information about you when you use our website – for example, when you contact us about products and services, submit a query from one of our online forms, register to receive updates via newsletters or marketing communications, or register for an event or product.
The personal information we collect might include your name, address, email address, IP address, and information regarding what pages are accessed and when. If you undertake a transaction online or purchase a product or service from us, your card information is not held by us; it is collected by our third-party payment processors, who specialise in the secure online capture and processing of credit/debit card transactions. If you register for an event or product, we may collect additional information such as allergies, medical conditions, and age.
We may use your information to:
We review our retention periods for personal information on a regular basis. We are legally required to hold some types of information to fulfil our statutory obligations (for example, the collection of Gift Aid, or to fulfil our duty of safeguarding). We will hold your personal information on our systems for as long as is necessary for the relevant activity, or as long as is set out in any relevant contract you hold with us.
The primary lawful basis of processing we rely on is contract. By this we mean that your personal data will be used to:
Under the terms of the General Data Protection Regulation (GDPR), we are the Data Controller for this information. The UK data protection regime is set out in the Data Protection Act 2018, alongside the UK GDPR.
The Information Commissioner’s Office (ICO) regulates data protection in the UK, offering advice and guidance, promoting good practice, carrying out audits, considering complaints, monitoring compliance and taking enforcement action where appropriate. If you are unhappy with how we have handled your personal information, you have a right to lodge a complaint with the ICO at www.ico.org.uk.
We will not sell or rent your information to third parties, and we will not share your information with third parties for marketing purposes.
Third-Party Service Providers Working on Our Behalf
We may pass your information to our third-party service providers, agents, subcontractors and other associated organisations for the purposes of completing tasks and providing services to you on our behalf (for example, to process donations and send you mailings, or to service our website). When we use third-party service providers, we disclose only the personal information necessary to deliver the service, and we have a contract in place requiring them to keep your information secure and not to use it for their own direct marketing purposes. We will not release your information to any other third parties for their own marketing purposes, unless you have requested us to do so or we are required to do so by law – for example, by a court order or for the prevention of fraud or other crime.
Third-Party Product Providers We Work in Association With
We work closely with various third-party product providers to bring you a range of quality and reliable products and services. When you use one of these services, relevant third-party product providers may use your details to provide you with information and carry out their obligations arising from any contracts you have entered into with them. In some cases, they will be acting as a Data Controller of your information, and we advise you to read their privacy policy. These third-party product providers will share your information with us, which we will use in accordance with this Policy.
If you are using our secure online payment pages, your transaction is processed by a third-party payment processor, who specialises in the secure online capture and processing of credit/debit card transactions. If you have any questions regarding secure transactions, please contact us.
We may transfer your personal information to a third party if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, to enforce or apply our terms of use, or to protect the rights, property or safety of our customers. We will take steps with the aim of ensuring that your privacy rights continue to be protected.
You have a choice about whether or not you wish to receive information from us. If you do not want to receive direct marketing communications from us, you can select your choices by ticking the relevant boxes on the form on which we collect your information.
We will not contact you for marketing purposes by email, phone or text message unless you have given your prior consent. We will not contact you for marketing purposes by post if you have indicated that you do not wish to be contacted. You can change your marketing preferences at any time by contacting us.
The accuracy of your information is important to us. If you change email address, or any other information we hold is inaccurate or out of date, please contact us. You have the right to ask for a copy of the information we hold about you (we may charge £10 for information requests, to cover our costs in providing this).
When you give us personal information, we take steps to ensure it is treated securely. Any sensitive information you provide via our systems (such as card details) is encrypted and protected using industry-standard SSL encryption. Non-sensitive details (such as your email address) are transmitted normally over the internet, and this can never be guaranteed to be 100% secure; we make our best effort to ensure the security of information once received. Where you have been given, or have chosen, a password to access parts of our website, you are responsible for keeping this password confidential and should not share it with anyone.
We may analyse your personal information to create a profile of your interests and preferences so that we can contact you with information relevant to you, and may use additional information available from external sources to help us do this effectively. We may also use your personal information to detect and reduce fraud and credit risk.
Like many other websites, our website uses cookies – small pieces of information stored on your device that allow the website to recognise you when you visit and collect statistical data about browsing actions and patterns, without identifying you as an individual. It is possible to switch off cookies via your browser preferences; doing so may result in a loss of website functionality.
Our website may contain links to other websites run by other organisations. This Policy applies only to our website; we encourage you to read the privacy statements on other websites you visit, and cannot be responsible for their policies or practices.
We are concerned to protect the privacy of children aged 16 or under. If you are aged 16 or under, please get your parent or guardian’s permission beforehand whenever you provide us with personal information.
Information you provide through our website may occasionally be transferred to and processed in countries outside the UK or EU – for example, where hosting infrastructure is located elsewhere. Where this occurs, we take steps to ensure appropriate security measures are applied, with the aim of ensuring your privacy rights continue to be protected as outlined in this Policy.
We make every effort to ensure the information available on our website is correct but cannot accept responsibility if it is not. Links from our website to other websites are not under our control, and we cannot accept liability for the content of any linked website. External links to our website are made at the other party’s own risk.
This Part sets out how Lantec Security handles CCTV and video surveillance data encountered in the course of installing, maintaining, servicing and supporting CCTV systems on behalf of our clients. It applies in addition to Part 1 above, which covers personal data collected through our website and general customer relationships rather than client-owned CCTV footage.
This Part applies to all Lantec engineers, subcontractors and staff who install, maintain, service, inspect or otherwise access client CCTV systems, recording devices (NVR/DVR), storage, or associated footage, whether on-site or via remote access.
18.1 Data Controller
In the great majority of engagements, the client (for example, a school, trust, or business) remains the Data Controller for CCTV footage captured by their systems. The client determines the purpose and means of processing – including camera placement, retention periods, and who may view footage.
18.2 Data Processor
Lantec acts as a Data Processor when engineers access, view, export, or otherwise process footage or system data in the course of installation, maintenance, fault-finding, or system health checks. Lantec processes such data only on the client’s documented instructions and only to the extent necessary to deliver the contracted service.
Where Lantec’s engineers access CCTV footage or system data, this is done under the lawful basis relied upon by the client as Data Controller (typically legitimate interests or public task, depending on the client), and solely for the purposes of:
Lantec engineers do not access, export, review or retain footage for any purpose beyond the specific maintenance or diagnostic task being carried out, and do not use client footage for training, marketing, or any other secondary purpose.
Lantec does not set or control retention periods for client CCTV footage – this remains the client’s responsibility as Data Controller. Where asked, Lantec will advise clients on retention settings appropriate to their storage capacity and operational needs, and will confirm current retention configuration as part of routine CCTV maintenance reporting.
Requests from individuals to access, review or query footage in which they may appear (for example, a Subject Access Request) are the responsibility of the client as Data Controller. Lantec will provide reasonable technical assistance to the client in retrieving specific footage in response to such requests, where instructed to do so.
Any suspected or actual data breach involving client CCTV systems or footage identified by Lantec staff – including unauthorised access, loss of footage, or system compromise – will be reported to the client without undue delay, and in any event within 24 hours of discovery, to support the client’s own regulatory reporting obligations under UK GDPR.
This Part is intended to support client compliance with, and reflects Lantec’s own commitment to, the following:
This Policy (Parts 1 and 2) is kept under regular review and will next be reviewed no later than August 2027, or sooner in response to changes in legislation, ICO guidance, or Lantec’s operational practices.
Why not leave us a review?
Please click below to review us.