1. Organizational Accountability & Principles
EntireFM maintains strict adherence to the core data protection principles set out in Article 5 of the UK GDPR: Lawfulness, Fairness, and Transparency; Purpose Limitation; Data Minimisation; Accuracy; Storage Limitation; and Integrity and Confidentiality (Security).
2. Privacy by Design & Default
All CAFM platform features, automated dispatch algorithms, mobile engineering applications, and client reporting tools are architected under strict Privacy by Design principles. Data Protection Impact Assessments (DPIAs) are conducted prior to deploying new technologies, automated processing, or AI models.
3. Data Classification Standard
EntireFM classifies all corporate, operational, and customer information into four structured tiers:
- PUBLIC: Information approved for public dissemination (marketing guides, public legal policies).
- INTERNAL: General business communications, standard operational procedures, and anonymised analytics.
- CONFIDENTIAL: Commercial contracts, client asset registers, rate cards, and financial invoice details.
- RESTRICTED: Highly sensitive personal data, portal authentication credentials, contractor criminal record checks (where required for sensitive sites), and bank details.
4. Security Incident & Personal Data Breach Response
EntireFM maintains a formal Incident Response Protocol to identify, contain, assess, and remediate suspected personal data breaches.
5. Supply Chain & Vendor Governance
All third-party cloud providers, IT subcontractors, and specialist service vendors undergo rigorous data protection due diligence and are bound by written Data Processing Agreements compliant with UK GDPR Article 28.
6. Training, Auditing & Governance Oversight
All EntireFM employees, helpdesk operators, commercial estimators, and management personnel undergo mandatory data protection training upon onboarding and annually thereafter. Internal audits of access logs and data retention are conducted semi-annually.
Authorised by: EntireFM Legal, Risk & Compliance Committee
Operating Company: EntireFM (trading name of Alkota Group Limited). Registered in England and Wales (Company No. 13535215).
This policy is formally reviewed annually and immediately following any statutory or operational changes.
Data Protection & Legal Governance Inquiries
For statutory requests, data protection questions, contract notices, or governance inquiries, please contact our designated compliance team.
Related Governance Policies
View Legal CentrePrivacy Notice
Comprehensive UK GDPR, DPA 2018, and PECR privacy notice explaining how EntireFM collects, uses, protects, and respects personal information across all FM services, B2B marketing, and digital platforms.
Data Protection Complaints Procedure
Formal electronic complaints mechanism and statutory procedure for raising data privacy, marketing opt-out, or Subject Access Request concerns.
Data Processing Agreement (UK GDPR Art 28)
Statutory Data Processing Agreement (DPA) incorporating UK GDPR Article 28 terms where EntireFM processes building occupant and client personal data on behalf of commercial property clients.
Information Security & Trust Overview
High-level security overview covering database encryption, role-based access controls, tenant isolation, automated backups, and vulnerability management.
Responsible AI & Technology Governance
Authoritative transparency statement governing AI-assisted CAFM workflows, predictive maintenance models, human-in-the-loop safeguards, and automated processing rights.


