Privacy Policy
Last updated: 19 August 2026
Britlith Ltd is committed to protecting the privacy and personal information of our customers, employees, contractors, suppliers, business contacts and website users.
This Privacy Policy explains how we collect, use, store, disclose and protect personal data and describes the rights available to individuals under applicable UK data protection legislation, including the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
Who We Are
Britlith Ltd is the data controller responsible for deciding how and why personal data is processed for the purposes described in this Privacy Policy.
Company: Britlith Ltd
Registered office: Unit 1 Saffrons Cross, Bodenham, Herefordshire, HR1 3LE
Company number: 10985169
Email: contact@britlith.co.uk
For privacy and data protection enquiries, please contact:
Data Protection Officer / Privacy Contact:
Data Protection Officer
Email: contact@britlith.co.uk
What types of personal data do we process
Depending on your relationship with Britlith, we may collect and process information including:
- name, title and contact details;
- postal and business addresses;
- telephone numbers and email addresses;
- company and job information;
- customer and supplier account information;
- identification and verification information where required;
- payment, billing and transaction information;
- communications and correspondence with us;
- contracts, quotations, orders and service records;
- delivery, collection and transport-related information;
- vehicle, driver or logistics information where relevant to our services;
- website usage information, including IP addresses and device information;
- CCTV images where CCTV operates at our premises;
- information relating to complaints, enquiries or disputes;
- recruitment and employment information where applicable; and
- any other information you choose to provide to us.
We will only collect personal data that is reasonably necessary for the purposes for which it is processed.
How We Collect Personal Data
We may obtain personal data:
- directly from you when you contact us, place an order, enter into a contract, make an enquiry or use our services;
- through our website, telephone calls, email and other communications;
- from your employer or another organisation with which you are associated;
- from customers, suppliers, contractors, transport providers or other business partners;
- from publicly available sources;
- from regulatory, government or law-enforcement bodies where appropriate; and
- through our premises, systems and security measures, including CCTV where applicable.
Where personal data is obtained from someone other than the individual concerned, we will provide appropriate privacy information where required by law.
How We Use Personal Data
We may use personal data for purposes including:
Providing our services
We process personal data to:
- provide products, transport, logistics or other services;
- process orders, bookings, deliveries and collections;
- administer customer and supplier relationships;
- manage contracts;
- communicate regarding services or transactions;
- process invoices and payments; and
- provide customer support.
Business administration
We may process personal data to:
- manage our business operations;
- maintain records;
- manage suppliers and contractors;
- conduct financial and accounting activities;
- manage insurance matters;
- establish, exercise or defend legal claims; and
- obtain professional advice.
Legal and regulatory compliance
We may process information where necessary to comply with legal obligations, regulatory requirements, transport requirements, taxation obligations, health and safety requirements and requests from competent authorities.
Security and fraud prevention
Personal data may be processed to protect our premises, vehicles, systems, staff and customers, prevent fraud or unlawful activity and investigate security incidents.
Marketing
Where permitted by law, we may use business contact information to communicate with existing or prospective customers about Britlith products and services.
Where consent is required, we will obtain consent before sending marketing communications.
You can opt out of marketing communications at any time by contacting us or using any unsubscribe mechanism included in the communication.
Our Lawful Bases for Processing
Under the UK GDPR, we must have a lawful basis for processing personal data.
Depending on the circumstances, we may rely upon:
Contract – where processing is necessary to enter into or perform a contract with you.
Legal obligation – where processing is necessary for us to comply with applicable law.
Legitimate interests – where processing is necessary for legitimate business purposes and those interests are not overridden by your rights and freedoms.
Our legitimate interests may include operating and improving our business, managing customer and supplier relationships, maintaining security, preventing fraud, recovering debts and protecting our legal rights.
Consent – where you have freely given us permission to process your personal data for a particular purpose.
Where processing is based on consent, you can withdraw that consent at any time.
Special Category Personal Data
We do not ordinarily seek to collect special category personal data unless it is necessary.
Where we process information concerning health, racial or ethnic origin, religious or philosophical beliefs, trade union membership, genetic or biometric information, sex life or sexual orientation, we will only do so where an appropriate lawful basis and additional legal condition apply.
Sharing Personal Data
We may share personal data where necessary with organisations including:
- customers and clients;
- suppliers and subcontractors;
- transport providers, drivers and logistics partners;
- IT, hosting and communications service providers;
- accountants, auditors, insurers, lawyers and other professional advisers;
- banks and payment service providers;
- government departments and regulators;
- HM Revenue & Customs;
- law-enforcement agencies;
- courts and other legal authorities; and
- other parties where disclosure is necessary to comply with legal obligations or protect our legitimate interests.
Where third parties process personal data on our behalf, we require them to process it securely and in accordance with applicable data protection requirements.
We do not sell personal data to third parties.
International Transfers
Some service providers may process personal data outside the United Kingdom.
Where personal data is transferred internationally, we will ensure that an appropriate safeguard is in place where required. This may include transferring information to a country covered by UK adequacy regulations or using approved contractual safeguards.
Further information regarding relevant safeguards may be requested by contacting us.
Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and to meet legal, regulatory, tax, accounting or reporting obligations.
Retention periods vary depending on the nature of the information and our legal or operational requirements.
When personal data is no longer required, we will securely delete, anonymise or destroy it in accordance with our retention procedures.
Data Security
We take appropriate technical and organisational measures to protect personal data against:
- unauthorised access;
- accidental loss;
- destruction;
- alteration;
- unauthorised disclosure; and
- other unlawful processing.
Measures may include access controls, passwords, cybersecurity protections, secure storage, staff training, confidentiality requirements, backups and procedures for managing personal data breaches.
Access to personal data is limited to individuals who have a legitimate business need to access it.
Your Data Protection Rights
Depending on the circumstances, UK data protection law gives you a number of rights concerning your personal data.
These may include the right to:
- access personal data we hold about you;
- rectify inaccurate or incomplete information;
- erase personal data in certain circumstances;
- restrict the processing of your personal data;
- object to certain processing, including processing based on legitimate interests;
- data portability, where applicable;
- withdraw consent where our processing relies upon your consent; and
- request safeguards regarding certain forms of automated decision-making, where applicable.
These rights are not absolute and exemptions may apply.
To exercise any of these rights, please contact us using the details in this Privacy Policy.
We may need to verify your identity before responding to a request.
Automated Decision-Making
Britlith Ltd does not currently make decisions producing legal or similarly significant effects about individuals solely through automated processing unless specifically stated to the individual concerned.
If this changes, appropriate information about the processing and applicable rights will be provided.
Cookies and Website Information
If our website uses cookies or similar technologies, they may be used to operate the website, maintain security, understand website usage and, where applicable, support analytics or marketing.
Where required, non-essential cookies will not be placed on your device without your consent.
Further information should be provided through our website Cookie Policy and cookie-management tools.
CCTV
CCTV is used at Britlith premises, it captures images of visitors, employees, contractors or members of the public.
CCTV is operated for purposes including:
- protecting people and property;
- preventing and detecting crime;
- investigating incidents; and
- maintaining site security.
Appropriate signage is displayed where CCTV is in operation, and recordings will be retained only for as long as necessary unless they are required for an investigation or legal matter.
Children
Our services are not directed at children and we do not collect children’s personal data unless there is a legitimate and lawful reason to do so.
Complaints
If you have concerns about how we process your personal data, please contact us first so that we can investigate your concerns.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority responsible for data protection.
Information about making a complaint is available from the ICO.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our business activities, technology, services or legal requirements.
The latest version will be made available on our website or otherwise provided where appropriate.
Where significant changes affect how we process personal data, we will take reasonable steps to bring those changes to the attention of affected individuals.
Contact Us
For questions concerning this Privacy Policy, your personal data or your data protection rights, please contact:
Britlith Ltd
Unit 1 Saffrons Cross, Bodenham Herefordshire, HR1 3LE
Data Protection Officer / Privacy Contact:
Data Protection Officer
Email: contact@britlith.co.uk
