1. Scope of This Policy
This Privacy Policy describes how TYH CONSTRUCTIONS LTD, a company registered in the United Kingdom with its principal office at 3A The Vale, London - NW11 8SB, United Kingdom (GB), handles personal data. The policy applies to visitors of our website, to prospective clients, to existing clients, to our suppliers, to our subcontractors and to anyone else whose personal information comes into the possession of the Company through the ordinary conduct of our business.
The Company provides services within the sector of computer systems design and computer integrated systems design, as well as professional, scientific and technical services relating to construction, structural engineering and building management. This policy covers every activity we undertake, whether it happens online through this website or offline through a telephone call, an email exchange or a meeting on site.
We encourage you to read this document in full so that you understand how your data moves through our business. Where we use the words the Company, we or us, we mean TYH CONSTRUCTIONS LTD. Where we refer to you or the user, we mean the individual whose personal data is described here. Every term in this policy carries the same meaning that the General Data Protection Regulation (GDPR) gives to similar words, so the policy reads consistently with the law that applies in the United Kingdom and the European Economic Area.
If any single clause of this policy conflicts with a mandatory rule of the law that applies to you, then that mandatory rule takes precedence over the conflicting clause, and the rest of the policy continues to apply in full force. We do not intend this policy to override any right that you cannot lawfully waive.
2. The Data Controller
For the purposes of applicable data protection legislation, TYH CONSTRUCTIONS LTD is the data controller for the personal data described in this policy. Being the data controller means that the Company decides why and how your personal data is processed. We own that responsibility and we accept it in full.
The Company keeps its registered and operational base at 3A The Vale, London - NW11 8SB, United Kingdom (GB). Our primary contact email for privacy matters is inbox@tyhconstruct.lol and our telephone number, which connects to the person responsible for data matters, is +19146165947. These channels are answered during our normal business hours, which are listed on our contact page.
Because data protection rules can change and because the law sometimes requires a formal representative in another country, the Company may from time to time nominate a representative or a data protection officer. Where such a nomination exists, the identity and contact details of that person will be published on this page in a clear place so that you can always find the correct point of contact without delay.
3. Types of Data We Collect
We collect only the personal data that we genuinely need to run our business well. The categories of data that we process are described below so that you have a complete picture of what the Company holds about you at any point in time.
Contact and identity data includes your full name, your business or private postal address, your email address, your telephone number and, where relevant, your job title and your professional registration number. We gather this information so that we can talk to you about a building project and respond to your messages.
Project and technical data includes descriptions of your building works, drawings you send to us, survey reports, structural photographs, planning references and records of decisions that we make together during the design and construction phases. This data is essential to delivering our service and is retained for the length of the project file.
Financial and billing data includes invoices, payment records, bank account details for refunds and credit references where we extend terms. We only hold these records where a commercial relationship actually exists and we never collect payment card numbers through this website.
Technical browsing data includes your internet browser type, your device operating system, the pages you view on this site, the date and time of your visit and an anonymised form of your internet protocol address. We use this data to keep the site working, to understand our audience and to improve the user experience.
We make a point of not collecting so called sensitive categories of data unless the law requires us to do so and unless the specific project makes that unavoidable. Where a project touches a sensitive matter, we will ask for your explicit consent before we process any such information.
4. How We Collect Personal Data
The Company collects personal data through a limited number of clear routes, and we are transparent about each one. The first and most common route is direct contact. When you send us an enquiry using the form on our contact page, when you telephone our office or when you write to our email address, you are providing the Company with your own data freely and knowingly.
A second route is the use of our website. Like most healthy institutional sites, we gather technical data through server logs and through cookies that are described later in this policy. This happens automatically whenever any browser requests a page from us and it does not require you to type anything in.
A third route runs through our business partners. If a developer, an architect, a planning consultant or another professional refers you to the Company, that professional may share your basic contact details with us so that we can follow up on the introduction you have agreed to receive.
A fourth route is the public record. We may collect data that you have already published, such as the name of a building owner on a planning application or a company directorship held on the public register of Companies House, where that information helps us to verify who we are dealing with on a project.
We never buy mailing lists of strangers and we never scrape personal data from the internet. Every piece of personal data in our care has arrived through one of the routes described in this section, which keeps our records clean, lawful and worthy of your trust.
5. Purposes of Processing
The Company processes personal data for a clear list of purposes, and we only move your data towards a purpose that you have been told about. The central purpose is the delivery of our professional services, which covers structural design, calculations, build project management, renovations, extensions, site surveying, building information modelling and safety compliance reviews across the London area and the wider United Kingdom.
We process contact data to respond to enquiries, to arrange site visits, to prepare quotations and to keep prospective clients informed about the progress of their requests. Without this processing, we simply could not conduct the ordinary dialogue that a construction business depends on.
We process project and technical data to perform the very work that a client has commissioned. This means producing designs, issuing drawings, managing programmes, supervising trades, checking compliance and lodging documentation with the authorities that govern building work.
We process billing and financial data to produce invoices, to chase an account, to issue refunds and to keep the books of the Company accurate for our accountants and for the tax authority. Certain legal obligations, such as anti money laundering checks on larger transactions, also require us to verify who we are dealing with.
We process technical browsing data to keep our website secure, to diagnose faults, to prevent abuse and to understand which pages genuinely help our visitors. We never use this browsing data to build a profile that could identify you outside the site itself.
6. Legal Basis for Processing
Under the GDPR, every act of processing must rest on a lawful foundation. The Company relies on several foundations depending on what we are doing with the data at that moment.
For most client work, the lawful basis is the performance of a contract. When a client asks us to design or build and we accept that instruction, we must necessarily use the client data to perform our side of the deal. Processing that is needed to run the contract requires no separate consent because it is anchored in the contract itself.
For many enquiries that arrive before a formal contract exists, our basis is an intended contract. Where you ask us to quote for a project, we process your data in steps that are necessary to take at your request before entering into the agreement.
For some marketing and audience analysis activities, our basis is a legitimate interest. We take the view that keeping a professional relationship warm, after a genuine enquiry or a completed project, serves both the Company and the client, and we weigh that interest against your privacy before any such activity begins.
Where neither of the above applies, we ask for your clear consent. Consent under this policy is freely given, specific, informed and unambiguous, and you may withdraw it at any time by contacting the address given in the final section. Withdrawing consent does not affect the lawfulness of processing that happened before withdrawal.
Finally, some processing is necessary to comply with our legal obligations, such as keeping tax records, confirming our duty of care on a construction site and cooperating with regulators. That processing continues for as long as the underlying law demands.
8. Retention of Personal Data
The Company keeps personal data only for as long as the purpose that justified it still stands. We do not hold records on the chance that they may become useful; we apply a deletion timetable that is written down, followed and audited.
Enquiry records that never become a project are reviewed after a short period. If a prospective client does not respond to a quotation within a reasonable time, we remove the associated contact data unless the law requires us to keep an audit trail of the quote itself.
Project records are kept for the lifetime of the relevant building design and for a sensible period afterwards, because structural documents sometimes have to answer questions years after a handover. The precise period reflects the engineering guidance that recommends keeping technical records for the useful life of the structure and then for a further review window.
Financial records are kept for the full term required by tax law in the United Kingdom, which generally runs for several years from the end of the tax year to which each invoice belongs. This retention is not optional and overrides any shorter preference we might hold.
Technical browsing logs are anonymous by design and are erased on a rolling cycle so that no single log entry outlives its diagnostic value. Where we retain a cookie that records a choice you made, that cookie expires automatically within the limits set out on the relevant notice.
9. Security Measures
Protecting your personal data is woven into the daily habits of the Company. We apply organisational and technical controls that match the sensitivity of the data we hold and the harm that a breach could cause an individual.
Access to personal data inside the Company is limited to the people who need it to do their job. We operate on a principle of least privilege, so an accountant does not see structural files and a site manager does not hold the full billing ledger unless the task demands it.
Where we store data on computers, those systems are protected by current operating system updates, by strong passwords, by two factor authentication on privileged accounts and by device encryption at rest. Portable devices holding project data are password protected and remotely wipeable where the technology allows.
Paper records, including signed inspection sheets and structural calculations, are held in a locked office and are shredded when their retention window closes. We treat paper as data even though it does not sit on a server, and we guard it with the same seriousness.
Our staff complete data protection awareness as part of their induction and they refresh that training when the law or our procedures change. Everyone who touches your data understands the responsibility they carry and the disciplinary consequences of careless handling.
No method of transmission over the internet and no method of electronic storage is completely secure. While the Company works hard to protect personal data, we cannot guarantee absolute security, and we encourage you to guard your own passwords and to report anything suspicious to the address in the final section.
11. Privacy for Children
Our building and design services are offered to adults and to organisations, and the ordinary content of this website is not aimed at children. In line with that, the Company does not knowingly collect personal data from any person under the age of sixteen without the consent of a parent or a legal guardian.
Where a project involves a home that is occupied by children, we take extra care around any incidental data, such as photographs or access arrangements that touch on a family living together. We handle that material with restraint and we only ever include what the building works actually require.
If you believe that a child has sent us personal information without the proper consent, please contact the Company using the address in the final section. On receiving a verified report, we will remove that data from our records as quickly as our systems allow and we will confirm the deletion to the reporting adult.
12. Your Data Subject Rights
Under the data protection law that applies to you, you hold a family of rights over your personal data. The Company respects each one and will act on an exercise of a right without undue delay and in every case within the time limit the law sets.
You have the right of access, which lets you ask for a copy of the personal data the Company holds about you together with an explanation of how it is used. This is often called a subject access request.
You have the right to rectification, which lets you ask us to correct personal data that is inaccurate or to complete data that is incomplete. We will fix the records and confirm the correction to you.
You have the right to erasure, sometimes called the right to be forgotten, which lets you ask us to delete personal data where there is no good reason for us to keep it. This right has boundaries where the law or a contract requires us to retain the data.
You have the right to object, which lets you challenge processing that relies on our legitimate interests. On receiving a valid objection, we will stop that processing unless we demonstrate compelling grounds that override your interests.
You have the right to restrict processing, which lets you pause our use of the data while a question about its accuracy is under review or while you consider an objection. Restricted data is stored but not otherwise used by us.
You have the right to data portability, which lets you receive the personal data you gave us in a structured, commonly used and machine readable format so that you can move it to another provider where the technical basis of the processing allows.
To exercise any of these rights, contact the Company at the address in the final section. We may ask you to verify your identity before we act, and we may need to ask a few questions to locate the specific data your request covers. You can make a request free of charge, although we may charge a reasonable fee in the rare case where a request is clearly unfounded or excessive.
13. International Transfers
The Company operates primarily in the United Kingdom, and most personal data is stored and processed here. From time to time, a project or a supplier may take your data to a country outside the United Kingdom and outside the European Economic Area.
Where we transfer personal data to another country, we make sure that the transfer rests on a recognised safeguard. This may be an adequacy decision by the relevant authorities, a set of standard contractual clauses with the recipient or another transfer tool that the law accepts.
If you would like a copy of the safeguards that apply to a particular transfer, or an outline of how they protect your data, please contact the Company using the details in the final section, and we will supply the relevant information without charging you for it.
14. Automated Decision Making
The Company does not undertake automated decision making, and we do not carry out automated profiling that produces legal effects on any individual. Every material decision in our business, from the shape of a quote to the choice of a safe methodology, is taken by a human who has considered your particular circumstances.
If the Company ever introduces a process that makes an automated decision about an individual, the data protection law requires us to tell you, to explain the logic involved and to give you a route to human review. We set that commitment down in writing here so that the introduction of any such system would have to be disclosed openly and cannot be slipped in silently.
15. Third Party Services and Links
This website may occasionally carry links to third party services, such as a professional directory, a planning portal or a standards body. When you follow such a link, you leave the pages of the Company and the privacy practices of the destination site apply from that point onwards.
We review the links we publish and we aim to point only to services that behave responsibly, but we cannot accept responsibility for the content or the privacy conduct of sites we do not operate. We encourage you to read the privacy policy of every outside service before you share any of your data with it.
16. Data Breach Procedure
The Company maintains a written incident response plan that describes what to do if personal data is lost, stolen or wrongly disclosed. The plan names the people who lead the response, the evidence we preserve and the notifications we issue.
When a breach is likely to put your rights and freedoms at high risk, we will tell you directly and without undue delay. That message will describe the nature of the breach, the data affected, the measures we have taken and the steps you can take to protect yourself.
Where the law requires it, we will also report the breach to the supervisory authority within the time limit set out in the regulation. We keep a log of every incident, however small, so that we can learn and harden our controls for the future.
17. Changes to This Policy
The Company reviews this Privacy Policy at least once a year and every time the law, our services or the technology we rely on changes in a way that affects how we treat personal data. We reserve the right to update this page to reflect those developments.
When we make a material change, we will update the date at the foot of this page and we will flag the revision on our homepage so that regular visitors can see that a new version exists. Where a change requires your consent, we will ask for that fresh consent rather than treating the old consent as covering the new activity.
We encourage you to review this policy from time to time so that you remain informed about how the Company protects the personal data in its care.
18. How to Contact Us
If you have a question about this Privacy Policy, if you wish to exercise any of the rights described above, or if you want to report a concern about how your data is handled, please get in touch with the Company by any of the routes below.
By email, write to inbox@tyhconstruct.lol. By telephone, call +19146165947. By post, address your letter to TYH CONSTRUCTIONS LTD, 3A The Vale, London - NW11 8SB, United Kingdom (GB). We aim to acknowledge every privacy message quickly and to resolve genuine concerns honestly.
You also have the right to lodge a complaint with a supervisory authority if you believe that the Company has not handled your personal data properly. In the United Kingdom, that authority is the Information Commissioner, whose contact details are published on the official regulator website.