This policy explains how AMPM Building Services Limited (“AMPM”,
“we”, “us”, “our”) collects,
uses and protects personal data — through this website and in the course of delivering our services. We are
committed to handling personal data lawfully, transparently and only for the purposes set out below.
Who we are
AMPM Building Services Limited is a building services contractor delivering mechanical, electrical and public
health (MEPH) works including HVAC; commercial fit-out and refurbishment (Cat A and Cat B); building
fabric and envelope works; groundworks, landscaping and external works; and planned preventative maintenance
(SFG20) and 24/365 reactive maintenance. We are incorporated in England and Wales under company number
17225766, with our registered office at Unit 2, Regents Business Centre, Jubilee Road,
Burgess Hill, West Sussex RH15 9TL. We are an AMPM Group company.
We are the data controller for personal data collected through this website and through our business activities.
For any data-protection enquiry or request, contact hello@ampm.co.uk or call
0330 043 0080 (answered 24 hours, 365 days).
What we collect
We collect personal data in the following situations:
- Website enquiries. When you submit the enquiry form on this site we collect your name and
(if given) company, your email address and optional phone number, the building or site address, and a
description of what you need.
- Email and phone enquiries. When you contact us directly we receive whatever personal
information you choose to share.
- Client and supplier records. When we work with a client or supplier we collect the contact
details, role and business information necessary to deliver the contract.
- Site visits and surveys. When attending site we may record building information, asset
registers, golden-thread records and contact details for relevant personnel as part of condition surveys,
maintenance visits, and installation and remediation works.
- Technical website data. Standard server-side logs, IP address, browser type, request
information and pages visited, processed by our hosting and security providers to keep the site secure. We do
not currently run third-party analytics; if we do in future, this policy will be updated.
We do not knowingly collect any special-category data. Please do not include sensitive personal information in the enquiry form.
Why we collect it and the legal basis
We process personal data under the following lawful bases of the UK GDPR:
- Legitimate interests. Responding to your enquiries, delivering and improving our services,
maintaining client and supplier records, and managing our business.
- Contract. Where we have a contract with you or your organisation, processing necessary to
perform it or to take steps at your request before entering into it.
- Legal obligation. Compliance with applicable law, including building-safety and
golden-thread record-keeping, health and safety records, and tax obligations.
- Consent. Where required, for example marketing communications — you can withdraw
consent at any time.
How long we keep it
We retain personal data only as long as needed for the purpose it was collected, or as required by law:
- Website enquiries that do not become contracts: 24 months.
- Client records and contract documentation: 7 years after the end of the engagement
(consistent with HMRC requirements).
- Golden-thread and building-safety records: for the operational life of the building, in line
with Building Safety Act 2022 requirements.
- Employee records: per the periods set out in our internal HR policy and employment law.
Who we share it with
We share personal data only where necessary:
- With clients and their building managers where relevant to deliver the contracted service.
- With subcontractors and supply-chain partners where they are delivering work under our supervision, subject
to written confidentiality and data-protection terms.
- With our professional advisers (accountants, lawyers, insurers) under their own confidentiality
obligations.
- With regulators, insurers and authorities where required by law or to defend our legal rights.
- With cloud-software providers used to run our business: Google Workspace for email and documents, Xero for
accounts, Cloudflare for website hosting, content delivery and security (including the Turnstile anti-spam
check on the enquiry form), and Resend for delivering website enquiries to our inbox as email.
Some providers may process data outside the UK under appropriate safeguards. We do not sell personal information.
Your rights
Under the UK GDPR you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate information
- Request erasure where there is no compelling reason for us to continue processing
- Object to processing based on legitimate interests
- Request restriction of processing in specific circumstances
- Request transfer of your data to another provider (data portability)
- Withdraw consent where processing is based on consent
- Lodge a complaint with the Information Commissioner’s Office
(ico.org.uk)
To exercise any of these rights, contact us at hello@ampm.co.uk.
We will respond within 30 days.
Security
We maintain technical and organisational measures to protect personal data, including encrypted email and
storage and multi-factor authentication on administrative systems, aligned to the security controls operated
across AMPM Group (certifications such as Cyber Essentials are held at Group level, not in AMPM Building Services
Limited’s own name). Despite these measures, no online transmission or storage is 100% secure; we cannot
guarantee absolute security.
Cookies
This site uses a small number of strictly-necessary cookies. See our separate
cookie policy for details of cookies and similar technologies used on this website.
Changes to this policy
We may update this policy from time to time. The “last updated” date above shows the current version.
Material changes will be highlighted at the top of the page.