1. Scope & Relationship of the Parties
Where EntireFM delivers facilities management, helpdesk triage, keyholding, or CAFM software services to a Client, the Client acts as Data Controller and EntireFM acts as Data Processor in respect of personal data processed in connection with the Agreement.
2. Processor Obligations (UK GDPR Article 28(3))
EntireFM agrees to:
- Documented Instructions: Process personal data only on documented instructions from the Client, including regarding international transfers.
- Staff Confidentiality: Ensure that all personnel authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Security Measures (Art 32): Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
- Subprocessors: Not engage any subprocessor without prior specific or general written authorisation from the Client and maintaining a transparent Subprocessor Register.
- Data Subject Rights Assistance: Assist the Client by appropriate technical and organisational measures in fulfilling the Client’s obligation to respond to Subject Access Requests.
- Breach Notification: Notify the Client without undue delay and within 48 hours of becoming aware of a personal data breach.
- Deletion or Return: At the choice of the Client, delete or return all personal data to the Client after the end of the provision of services.
- Audits & Inspections: Make available to the Client all information necessary to demonstrate compliance and allow for and contribute to audits conducted by the Client or an appointed auditor.
3. Configurable Schedule of Processing (FM Operations)
Subject Matter: Delivery of commercial facilities management, reactive engineering, statutory compliance testing, and tenant helpdesk services. Duration: For the duration of the Principal Agreement. Nature & Purpose: Scheduling work orders, attending site, logging compliance certificates, communicating with building occupants. Categories of Data: Contact details, site addresses, access logs, service request descriptions. Categories of Data Subjects: Client personnel, tenants, building occupants, visitor keyholders.
Authorised by: EntireFM Legal, Risk & Compliance Committee
Operating Company: EntireFM (trading name of Alkota Group Limited). Registered in England and Wales (Company No. 13535215).
This policy is formally reviewed annually and immediately following any statutory or operational changes.
Data Protection & Legal Governance Inquiries
For statutory requests, data protection questions, contract notices, or governance inquiries, please contact our designated compliance team.
Related Governance Policies
View Legal CentrePrivacy Notice
Comprehensive UK GDPR, DPA 2018, and PECR privacy notice explaining how EntireFM collects, uses, protects, and respects personal information across all FM services, B2B marketing, and digital platforms.
Data Protection & Governance Framework
Internal governance standards, accountability measures, data classification, breach management protocols, and technical controls enforced across EntireFM operations.
Authorized Subprocessors Register
Transparent public register of third-party cloud infrastructure, database, communication, and analytics providers authorised to process data across EntireFM systems.
Standard Terms of Business
Core commercial terms governing facilities management services, planned preventative maintenance (PPM), reactive engineering, statutory compliance, and CAFM technology delivery.


