PRIVACY POLICY
Last updated: October 1st, 2026
​
At Energy and System Technical Limited (East Solutions) we care about the use and storage of your personal information and we value your trust in allowing us to do this in a careful and sensible manner. We have created this privacy notice in order to demonstrate our commitment to your privacy.
​
1. Who we are and how to contact us
EastSolutions is the controller of your personal data. Our registered office is Unit 1 Sovereign House, 2 Sovereign Way, Trafalgar Industrial Estate, Downham Market, Norfolk, PE38 9SW and our company number is 06996921. You can contact us about privacy matters by emailing our data controller, the Managing Director of East Solutions, at enquiries@east-solutions.co.uk or by writing to the Managing Director at our head office referred to above.
​
2. Scope of this notice
This notice applies to personal data we process in the course of our business in relation to customers and prospective customers, suppliers and other business contacts, and visitors to our website, and visitors to our premises. It also includes a separate section for job applicants.
​
3. The personal data we collect
We collect and process the following categories of personal data, as applicable:
-
Identity and contact details, such as name, business or home address, email address and telephone number.
-
Business contact details and role information, such as employer, job title and site contact information.
-
Billing and payment information, such as invoicing details, bank transfer references and payment confirmations. We do not store full card details if card payments are processed by a third-party provider.
-
Project and site information, such as site access requirements, permits, drawings, method statements, risk assessments, and details of works performed, including contact logs and work reports.
-
Communications, such as emails, letters, messages, call notes and customer service records.
-
CCTV and visitor logs, where applicable, for sites or offices we operate or attend.
-
Health and safety incident information, where applicable, including accident/near-miss reports and related investigation records.
-
Special category data only where strictly necessary, for example health information relevant to site access assessments or incident reporting, and only with an appropriate lawful basis and safeguards. We do not knowingly collect data relating to children.
​
4. How we obtain your personal data
We obtain personal data directly from you when you contact us, request a quotation, place an order, contract with us, visit our premises or site, correspond with us, or apply for a job. We may also receive personal data from your employer, our customers (for site coordination), suppliers, subcontractors, professional advisers, publicly available sources, or via our website and IT systems.
5. Purposes and lawful bases
We use your personal data for the purposes set out below. For each purpose we identify our lawful basis under the UK General Data Protection Regulation (UK GDPR). Where we rely on legitimate interests, we explain those interests in section 6. Where consent applies, you can withdraw it at any time.
Purpose: Providing quotations, pre-contract discussions and taking steps at your request prior to entering into a contract.
Lawful basis: Contract (performance of a contract or steps prior to entering into it).
Purpose: Entering into and performing our contracts, including project management, site access coordination, installation, maintenance and support, and customer service
Lawful basis: Contract (to perform our contract with you).
Purpose: Business administration, quality assurance and improving our services.
Lawful basis: Legitimate interests (running and improving our business efficiently).
Purpose: Supplying contractual and project documentation, drawings, RAMS, method statements, warranties and handover packs.
Lawful basis: Contract; Legal obligation for records where required.
Purpose: Invoicing, payments, credit control, and accounting.
Lawful basis: Contract; Legal obligation (tax and accounting).
Purpose: Managing supplier relationships, purchase orders and subcontractor coordination.
Lawful basis: Contract; Legitimate interests (efficient supply chain management).
Purpose: Health and safety management, incident reporting, and compliance with site rules.
Lawful basis: Legal obligation; Legitimate interests (safe operations); Vital interests where necessary.
Purpose: Security, including CCTV at offices or controlled sites and visitor logs
Lawful basis: Legitimate interests (security and crime prevention); Legal obligation where applicable.
Purpose: Communications about our services, service updates and important notices.
Lawful basis: Legitimate interests (business communications and service continuity).
Purpose: Direct marketing by email or phone to business contacts.
Lawful basis: Legitimate interests (promoting and developing our business); Consent where required under the Privacy and Electronic Communications Regulations.
Purpose: Regulatory and legal compliance, asserting and defending legal claims, and insurance.
Lawful basis: Legal obligation; Legitimate interests (protection of our legal rights).
Purpose: Recruitment, assessing candidates, arranging interviews and making offers.
Lawful basis: Legitimate interests (recruitment and talent management); Contract (pre-contractual steps).
​
6. Our legitimate interests
Where we rely on legitimate interests, they include running and developing our business, delivering and improving our services, ensuring site and information security, preventing fraud, managing supplier and customer relationships, and communicating with our business contacts about relevant services.
​
7. Marketing communications
We may send marketing communications about our services to business contacts where permitted. You can opt out at any time by contacting the Managing Director via enquiries@east-solutions.co.uk. We will respect your marketing preferences and will not sell your personal data to third parties for their own marketing.
​
8. Sharing your personal data
We share personal data with trusted recipients as necessary for the purposes above, including:
-
Service providers acting as processors, such as IT hosting and infrastructure, email and productivity tools, CRM, accounting systems, document management, and payment service providers. These providers are appointed under written contracts that include data protection terms required by the UK GDPR.
-
Professional advisers, such as lawyers, accountants and auditors.
-
Insurers and insurance brokers.
-
Clients or site operators where necessary for site access, inductions, permits, and coordination of works.
-
Regulators, law enforcement, courts or other authorities where required or permitted by law.
-
Prospective buyers and their advisers in connection with a business transaction, subject to confidentiality.
​
9. International data transfers
We do not transfer your data outside of the UK.
​
10. Retention of your personal data
We keep personal data only for as long as necessary for the purposes set out in this notice, taking into account legal, regulatory, tax, accounting, warranty and insurance requirements, and applicable limitation periods. Example retention periods include:
​
-
Project and contract records: typically for the project lifecycle and for 6 years (or 12 years where deeds are involved) after completion to cover limitation periods and warranties.
-
Financial and VAT/tax records: typically for 6 years after the relevant financial year.
-
Health and safety records and incident reports: retained in accordance with statutory requirements, which vary depending on the nature of the record.
-
CCTV recordings: typically for 30–90 days unless required longer for investigations.
-
Customer service correspondence: typically for 3–6 years after last interaction.
-
Recruitment records: typically for 6–12 months for unsuccessful candidates; personnel files follow separate retention rules if employment is offered.
In some circumstances we may retain personal data for longer than the periods above where required to comply with legal obligations, resolve disputes, establish, exercise or defend legal claims, or where there is an ongoing investigation or litigation. Where personal data is no longer required, we will securely delete or anonymise it.
​
11. Security
We apply appropriate technical and organisational measures to protect personal data, including access controls, user authentication, encryption in transit where applicable, secure storage, system monitoring, staff training, and policies and procedures designed to manage risks and respond to incidents.
​
12. Your rights and Complaints
You have the following rights under the UK GDPR, subject to conditions and exemptions: to request access to your personal data; to request rectification of inaccurate data; to request erasure; to request restriction of processing; to object to processing, including objection to direct marketing; to data portability; and to withdraw consent where we rely on consent.
If you wish to exercise any of the rights set out above, please contact us per the provisions of section 1 above.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
​
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
​
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
You also have the right to make a complaint to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). However, before doing so please make sure you have first made your complaint to us or asked us for clarification if there is something you do not understand. The ICO will expect you to have done this before reviewing your complaint.
​
13. Automated decision-making and profiling
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. If this changes or if we use profiling for marketing or credit screening, we will provide you with meaningful information about the logic involved and the envisaged consequences, and we will ensure appropriate safeguards are in place.
​
14. Job applicants
If you apply for a role with us, we will process your identity and contact details, CV, qualifications, experience, references, interview notes, right to work information and, where applicable, background check results. We process this information to assess your application, to take steps prior to entering into a contract, and for our legitimate interests in managing recruitment. Where we collect special category data, such as health data for reasonable adjustments, we do so with your consent or where necessary for employment law obligations. If your application is unsuccessful, we will retain your data for approximately 6–12 months, unless you agree to a longer period or we are required to retain it for longer to establish, exercise or defend legal claims.
15. Changes to this notice and your duty to inform us of changes
​
We keep our privacy policy under regular review.
​
We may update this notice from time to time. We will post the updated version on our website and will indicate the effective date. If the changes are material, we will notify you by an appropriate method.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us, for example a new address or email address.
​
Effective date: 21 July 2026
Contact Us
If you have any questions about this Privacy Policy, you can contact us by visiting this page on our website: