1. Identity of the Data Controller
Alkota Group Limited trading as EntireFM (Company No. 13535215) is the Data Controller responsible for your personal data when you interact with our public websites, engage in commercial discussions, register for client/contractor portals, or receive B2B communications.
2. Individuals Whose Data We Process
In our capacity as a national facilities management provider, we process personal information relating to several distinct categories of individuals:
- Website Visitors & Tool Users: Individuals browsing our site or using interactive calculators.
- Prospective Clients & Commercial Enquirers: Decision-makers submitting RFPs, quote requests, or survey bookings.
- Publicly Sourced Corporate B2B Contacts: Identified corporate facilities managers, estate directors, procurement personnel, and property managers.
- Client Personnel & Property Managers: Named operational, financial, and FM contacts under active service contracts.
- Building Occupants & Service Requesters: Tenants, employees, or site users logging maintenance helpdesk tickets.
- Approved Contractors, Subcontractors & Sole Traders: Vetted engineering partners, technicians, and directors.
- Field Engineers & Technicians: Operatives using mobile telemetry and visit logging tools.
- Job Applicants: Individuals submitting CVs or employment applications.
3. Categories of Personal Data Collected
We collect and process the following categories of information depending on your relationship with EntireFM:
- Identity & Contact Data: Full name, business email, direct phone number, mobile number, job title, and employer organisation.
- Property & Operational Data: Site addresses, access notes, keyholder contacts, asset identifiers, and service ticket history.
- Contractor Compliance Data: Trade qualifications, Gas Safe/NICEIC/F-Gas registrations, SSIP certifications, insurance certificates, photo ID for site security, and bank details for payment.
- Technical & Usage Data: Anonymised IP addresses, browser types, session journey trails (efm_journey_trail), portal login timestamps, and device categories.
- Communications Data: Enquiries, helpdesk logs, emails, survey feedback, and call recordings where applicable.
4. Lawful Bases for Processing (UK GDPR Art 6)
We do not rely on "consent" as a blanket ground. We identify and document the specific lawful basis for each distinct processing activity:
- Performance of a Contract (Art 6(1)(b)): Processing necessary to deliver FM services, dispatch engineers, execute work orders, process invoices, and manage client/contractor accounts.
- Compliance with Legal Obligations (Art 6(1)(c)): Retaining VAT/tax records (Companies Act/HMRC), statutory compliance certificates, health & safety logs (HASAWA/CDM 2015), and RIDDOR incident reports.
- Legitimate Interests (Art 6(1)(f)): B2B marketing to relevant corporate decision-makers, portal security monitoring, fraud prevention, service quality analytics, and commercial debt recovery.
- Consent (Art 6(1)(a)): Where explicitly required, such as non-essential analytics cookies or newsletter opt-in subscriptions for non-corporate contacts.
5. B2B Marketing, Prospect Research & Right to Object
EntireFM legitimately identifies and contacts relevant corporate business contacts (e.g. Facilities Managers, Property Managers, Estates Directors, Operations Managers, and Procurement Teams) who have a professional interest in commercial building maintenance.
- Origin of Business Contacts: Sourced from public business registries (Companies House), professional networking platforms (LinkedIn), corporate websites, industry directories, or commercial data providers vetted for UK GDPR compliance.
- Reasonable Expectations: Communications are strictly business-to-business (B2B), addressed to corporate subscribers in their professional capacity, and directly relevant to their property portfolio.
- Suppression Register: When you object to marketing, your email is immediately added to our global suppression register to ensure no further outreach is generated.
- How to Opt Out: Click the "Unsubscribe" link in any outreach email, reply with "STOP/OPT-OUT", or email privacy@entirefm.com.
6. Data Recipients & Authorized Subprocessors
We do not sell, rent, or trade your personal data. We share information only with authorised recipients under strict contractual terms:
- Authorised Contractors & Engineers: Shared strictly on a need-to-know basis (site address, contact name, phone number) to attend and resolve work orders.
- Cloud & Technology Providers: Vetted subprocessors providing edge hosting (Vercel), secure database storage (Supabase/AWS UK), transactional communications (Resend), and analytics.
- Statutory Bodies & Law Enforcement: When required by law, such as HMRC audits, HSE health & safety investigations, or court orders.
7. International Data Transfers
Our primary databases and CAFM systems are hosted within the United Kingdom (AWS London eu-west-2). Where cloud services process data outside the UK (e.g. European Union or United States), transfers are secured using UK Adequacy Regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to EU Standard Contractual Clauses.
8. Data Retention Periods
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including statutory legal, accounting, and health & safety requirements:
- Client & Contractor Contract Records: 6 years following contract termination (Limitation Act 1980).
- Financial & Tax Invoices: 6 years plus current financial year (Companies Act / HMRC).
- Statutory Compliance & Asset Records (EICR, Gas, Legionella): Retained for the lifetime of the asset or 7 years.
- B2B Marketing Prospects: Retained for up to 24 months from last interaction, or until an opt-out request is lodged (suppression record retained indefinitely).
- Helpdesk Tickets & Occupant Requests: 3 years following ticket resolution.
9. Your Statutory Data Subject Rights
Under UK GDPR and the Data Protection Act 2018, you possess comprehensive statutory rights regarding your personal information:
- Right of Access (Subject Access Request - SAR): Obtain confirmation and a free copy of your personal data.
- Right to Rectification: Correct inaccurate or incomplete personal records.
- Right to Erasure ("Right to be Forgotten"): Request deletion where data is no longer necessary or processed unlawfully.
- Right to Restriction of Processing: Temporarily restrict processing during dispute or verification.
- Right to Data Portability: Receive your electronic data in a structured, machine-readable format.
- Right to Object: An absolute right to stop direct marketing at any time, and a right to object to processing based on legitimate interests.
- Rights Related to Automated Decision-Making & AI: Request human intervention and challenge automated recommendations.
10. Right to Complain & Supervisory Authority Escalation
If you have concerns about how we handle your personal data, please submit an electronic complaint via our Data Protection Complaints Procedure or email privacy@entirefm.com. You also have the statutory right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.
Authorised by: EntireFM Legal, Risk & Compliance Committee
Operating Company: EntireFM (trading name of Alkota Group Limited). Registered in England and Wales (Company No. 13535215).
This policy is formally reviewed annually and immediately following any statutory or operational changes.
Data Protection & Legal Governance Inquiries
For statutory requests, data protection questions, contract notices, or governance inquiries, please contact our designated compliance team.
Related Governance Policies
View Legal CentreData Protection & Governance Framework
Internal governance standards, accountability measures, data classification, breach management protocols, and technical controls enforced across EntireFM operations.
Cookies & Storage Policy
Clear breakdown of cookie, session storage, and local storage technologies used on the EntireFM website in compliance with PECR and UK GDPR.
Data Processing Agreement (UK GDPR Art 28)
Statutory Data Processing Agreement (DPA) incorporating UK GDPR Article 28 terms where EntireFM processes building occupant and client personal data on behalf of commercial property clients.
Authorized Subprocessors Register
Transparent public register of third-party cloud infrastructure, database, communication, and analytics providers authorised to process data across EntireFM systems.
Data Protection Complaints Procedure
Formal electronic complaints mechanism and statutory procedure for raising data privacy, marketing opt-out, or Subject Access Request concerns.


