1. Principles of Data Protection
Metro Fixings Ltd strictly complies with the data protection principles set out under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Personal data shall be:
- Processed lawfully, fairly, and in a transparent manner in relation to individuals.
- Collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
- Adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
- Accurate and, where necessary, kept up to date; reasonable steps are taken to ensure inaccurate data is erased or rectified without delay.
- Kept in a form which permits identification of data subjects for no longer than is necessary.
- Processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage.
2. Lawful Grounds for Processing
We collect and hold personal information (such as contact names, business addresses, telephone numbers, email details, and trade payment records) under the following legal bases:
3. Data Sharing & Third Parties
We do not sell, rent, or trade personal data to third parties for commercial marketing. Information is shared strictly with essential operational partners bound by confidentiality and data processing agreements:
- Freight couriers and transport hauliers for direct site delivery fulfillment.
- PCI-DSS compliant merchant banks and payment processing gateways.
- Credit reference agencies and debt recovery specialists for trade credit evaluation and account administration.
- IT hosting, ERP database maintainers, and professional advisers (auditors and legal counsel).
4. Storage & Retention Schedule
Personal data is stored securely within UK-based server infrastructure. Financial transaction records, invoicing, and contract history are retained for 6 years following the end of the relevant financial year to comply with HMRC statutory requirements, after which records are securely destroyed or permanently anonymised.
