Data Protection Policy

1. Purpose and scope

PSM Solutions Ltd, trading as DamperTek ("DamperTek", "we"), collects and uses personaldata to run its suspension damper business.
This policy sets out how we keep that datasafe, lawful and fair.

It covers all personal data we handle about customers, website visitors, suppliers andstaff, in any format: paper, email, our website, our systems and phones. It applies toeveryone who works for or on behalf of DamperTek, including owners, employees andcontractors.

Data controller:

PSM Solutions Ltd T/A DamperTek, www.dampertek.co.uk

Data protection contact:

Peter Maze, info@dampertek.co.uk, 07869159988

2. The law we follow

We comply with UK data protection law, which is:

UK GDPR — the main rules on handling personal data

Data Protection Act 2018 — sits alongside UK GDPR and adds UK-specific rules

Data (Use and Access) Act 2025 — updates the above, including a requirement tohandle data protection complaints

Privacy and Electronic Communications Regulations (PECR) — covers marketingemails, texts and website cookies

We pay the annual data protection fee to the Information Commissioner's Office (ICO),the UK regulator.

3. What we collect and why

We only collect the personal data we need, and every use has a lawful basis under UK GDPR.

Card payments are handled by our payment provider. We do not store full card numbers.

We do not collect special category data (such as health information). Where we must wewill keep it to a minimum and restrict access.

4. Our data protection principles

Whenever we handle personal data, we make sure it is:

  1. Used lawfully, fairly and openly, as explained in our privacy notice on our website
  2. Collected for a clear purpose and not used for anything unrelated
  3. Limited to what we actually need
  4. Accurate and kept up to date
  5. Kept no longer than necessary
  6. Kept secure

We are responsible for showing that we follow these principles, so we keep simplerecords of what data we hold and why.

5. Security, retention and sharing

Keeping data secure

  • Computers, laptops and phones are password or PIN protected and kept up to date
  • Business accounts use strong passwords and two-factor authentication whereavailable
  • Only people who need customer, contractor or supplier details can access it
  • Paper records are kept in a locked cabinet or office
  • Data is backed up regularly
  • Personal data is not sent to personal email accounts or stored on personal deviceswithout approval

How long we keep data

When data is no longer needed, we delete it securely or shred paper copies.

  1. Invoices, accounts and tax records - 6 years from the end of the Financial Year
  2. Customer Order, Service and Warranty History - 6 years from the last job
  3. Staff and Payroll - 6 years after employment ends

5. Security, retention and sharing

Sharing data

We never sell personal data. We only share it wn needed to run the business, forexample with couriers, our payment provider, our accountant, website and IT providers, orwhere the law requires it.
We use providers who protect data properly and, whererequired, have a written agreement with them. If data is stored outside the UK, we makesure proper safeguards are in place.

6. People's rights and complaints

Anyone whose data we hold can ask us to:

  • Give them a copy of their data (a subject access request)
  • Correct inaccurate data
  • Delete their data, where we no longer have a reason to keep it
  • Restrict or object to how we use it, including stopping marketing at any time
  • Transfer their data to another provider, where this applies

Requests can be made in writing, by email or verbally, and are passed to the dataprotection contact straight away. We respond within one month and do not charge a fee.We may ask for proof of identity first.

If someone is unhappy with how we have handled their data, they can complain to ususing the contact details in section 1. We acknowledge complaints within 30 days andrespond without undue delay. They also have the right to complain to the ICO at ico.org.ukor on 0303 123 1113.

7. Breaches, responsibilities and review

Data breaches

A data breach is any loss, theft, or unauthorised access to or sharing of personal data,such as a lost phone, a hacked account or an email sent to the wrong person.

  1. Report it to the data protection contact immediately
  2. Take steps to contain it, such as changing passwords or recalling the email
  3. If it is likely to put people at risk, report it to the ICO within 72 hours of becomingaware of it
  4. If the risk to people is high, tell the people affected without delay
  5. Record every breach, even ones not reported to the ICO

Responsibilities

  • Directors are responsible for making sure DamperTek complies with this policy
  • The data protection contact handles requests, complaints and breaches, and keep srecords
  • Everyone who works or acts for DamperTek must follow this policy and raise anyconcerns straight away

Review

This policy is reviewed every year, or sooner if the law or our business changes.
‍

Approved by:

Peter Maze, Director

Date: 27/09/2026

Next review: 1 year