Home / Legal / Privacy & Cookie Policy
Privacy & Cookie Policy
Prism Integrated Security Solutions Ltd is committed to protecting your personal data and being transparent about how we use it. This Privacy and Cookie Policy notice covers both areas, and is governed by UK law.
Last Updated: 6 April 2026Legislation: UK GDPR & DPA 2018, PECR 2003Version: 1.0
🔒 ICO Registration: Registered with the Information Commissioner’s Office — reference ZC183779. Verify on the ICO register
Privacy Policy Data Controller · Data We Collect · Lawful Basis · Data Sharing · Retention · Your Rights · CCTV Notice · Contact DPO
Cookie Policy What Are Cookies · Cookie Types · Cookie Table · Manage Cookies
Privacy Policy
1. About This Privacy Notice
This Privacy Notice explains how Prism Integrated Security Solutions Ltd collects, uses, stores and shares your personal data, and the rights available to you under UK data protection law.
This notice applies to:
- Visitors to our website at www.prismintegratedsecurity.solutions
- Individuals who contact us by telephone, email or through enquiry forms
- Customers who engage us for the installation, maintenance or monitoring of security systems
- Keyholders and contacts registered on alarm monitoring accounts
This notice is provided in compliance with Articles 13 and 14 of the UK General Data Protection Regulation (UK GDPR) as retained in UK law by the Data Protection Act 2018 (DPA 2018). Our use of cookies is additionally governed by the Privacy and Electronic Communications Regulations 2003 (PECR).
This notice describes our current data processing practices. We review it regularly and will update this page whenever our practices change. Material changes affecting existing customers will be communicated by email.
Privacy Policy
2. Data Controller
For the purposes of the UK GDPR, the data controller — the entity responsible for deciding how your personal data is used — is:
| Field | Detail |
|---|---|
| Company Name | Prism Integrated Security Solutions Ltd |
| Registered In | England and Wales |
| Registered Address | 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ |
| ICO Registration No. | ZC183779 — Verify on the ICO register |
| Data Protection Contact | dpo@prismintegratedsecurity.solutions |
| Website | www.prismintegratedsecurity.solutions |
Note on ICO Registration: Under Section 108 of the Data Protection Act 2018, organisations that process personal data for purposes other than personal, family or household activities must register with the Information Commissioner’s Office (ICO). We are registered under reference ZC183779. You can verify UK-registered data controllers at ico.org.uk/ESDWebPages/Search.
Privacy Policy
3. Personal Data We Collect
We only collect personal data that is necessary for a specific, lawful purpose. The categories we collect depend on your relationship with us.
3.1 Contact & Enquiry Data
When you contact us by telephone, email, or via our website contact forms, we may collect:
- Identity data: First name, last name, title
- Contact data: Email address, telephone number(s)
- Business data: Company name, job title (where applicable)
- Communications data: The content of your enquiry or message
3.2 Customer & Contract Data
When you engage Prism for installation, maintenance or monitoring services, we collect:
- Identity data: Full name, company name (if commercial premises)
- Contact data: Email address(es), telephone number(s), postal address
- Location data: Installation site address, site access details and codes
- Financial data: Payment information processed via our accounting system (we do not store full card numbers)
- Service data: Details of installed systems, maintenance records, service history, engineer visit notes
3.3 Alarm Monitoring & Keyholder Data
To enable 24/7 alarm monitoring via our partner EMCS (Nottingham) — the UK’s largest independent Alarm Receiving Centre — we collect and share the following with EMCS in accordance with your monitoring contract:
- Keyholder names, telephone numbers and call priorities
- Site entry codes and response procedures
- Alarm zone descriptions and layout information
- Police Unique Reference Number (URN) if applicable
If you provide us with the names and contact details of keyholders, you must ensure those individuals are aware their information will be shared with EMCS for monitoring purposes. We recommend directing them to this notice.
3.4 CCTV Footage
Prism installs and maintains CCTV systems at customer premises. For clarity on who controls what:
- Your system, your data: If Prism installs a CCTV system at your property, you are the data controller for footage captured by that system. You must display appropriate signage and maintain your own privacy notice for individuals captured on camera. ICO guidance is available at ico.org.uk/surveillance.
- Prism as installer and maintainer: During installation and maintenance visits, our engineers may briefly access live or recorded footage for testing and diagnostic purposes only. We do not retain, copy or store any footage from customer systems.
- Data Processing Agreement: Larger commercial clients who require Prism to act formally as a data processor (e.g. for remote access arrangements) may request a Data Processing Agreement (DPA) under Article 28 UK GDPR. Contact dpo@prismintegratedsecurity.solutions.
3.5 Website & Technical Data
When you visit our website, we automatically collect certain technical data:
- Technical data: IP address, browser type and version, operating system, device type
- Usage data: Pages visited, time spent on pages, links clicked, referring URL
- Cookie data: Information collected via cookies and similar technologies (see Cookie Policy below)
This data is collected via our website platform and, where you have consented, via Google Analytics. It is used in aggregate to improve our website and understand visitor behaviour.
Privacy Policy
4. Lawful Basis for Processing
Under Article 6 of the UK GDPR, we must have a lawful basis for each type of processing activity. The table below sets out the basis we rely on for each activity.
| Processing Activity | Lawful Basis | Legal Reference |
|---|---|---|
| Responding to website enquiries and providing quotations | Legitimate Interests | Article 6(1)(f) UK GDPR — our interest in responding to potential customers |
| Delivering installation, maintenance and repair services | Contract Performance | Article 6(1)(b) UK GDPR — necessary to fulfil your service contract |
| Sharing keyholder data with EMCS for 24/7 monitoring | Contract Performance | Article 6(1)(b) UK GDPR — integral to the monitoring service you contracted for |
| Sending service reminders, renewal notices and job confirmations | Contract Performance | Article 6(1)(b) UK GDPR |
| Maintaining accounting, financial and contractual records | Legal Obligation | Article 6(1)(c) UK GDPR — Companies Act 2006; HMRC requirements |
| Email marketing to existing customers for similar services | Soft Opt-In | Regulation 22 PECR 2003 — you may opt out at any time |
| Email marketing to new or prospective contacts | Consent | Article 6(1)(a) UK GDPR; Regulation 22 PECR 2003 — requires prior opt-in |
| Website analytics and performance tracking via cookies | Consent | Article 6(1)(a) UK GDPR; Regulation 6 PECR 2003 — via cookie consent banner |
| Responding to legal, regulatory or law enforcement requests | Legal Obligation | Article 6(1)(c) UK GDPR |
| Managing complaints and disputes | Legitimate Interests | Article 6(1)(f) UK GDPR — our interest in resolving complaints and defending legal claims |
Where we rely on legitimate interests (Article 6(1)(f)), we have conducted a Legitimate Interests Assessment (LIA) to balance our interests against your rights. You may request a copy of our LIA by contacting dpo@prismintegratedsecurity.solutions.
Privacy Policy
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
- To respond to your enquiries, provide quotations and arrange site surveys
- To install, commission and maintain security systems at your property
- To configure and manage your alarm monitoring account with EMCS
- To process payments and issue invoices
- To send annual maintenance reminders, contract renewal notices and service updates
- To carry out engineer scheduling and job management
- To communicate important changes to our services or this notice
- To improve and optimise our website using aggregate analytics data
- To detect, investigate and prevent fraud or security incidents
- To comply with our legal and regulatory obligations
- To defend or bring legal claims where necessary
We will never sell your personal data to third parties, and we will not use it for any purpose incompatible with the purposes set out in this notice without first obtaining your consent or notifying you.
Privacy Policy
6. Marketing Communications
We may send you information about our services, offers and security tips by email or post.
Existing Customers (Soft Opt-In)
Under Regulation 22 of PECR 2003, where you are an existing customer, we may contact you by email about similar products and services to those you have previously purchased, provided we offered you a clear opportunity to opt out at the time of collection and in every subsequent marketing communication.
New or Prospective Contacts
Where you are not an existing customer, we will only send marketing communications by email or SMS where you have given your explicit prior consent in compliance with Article 6(1)(a) UK GDPR and Regulation 22 PECR 2003.
Your Right to Opt Out
You can stop receiving marketing communications at any time by:
- Clicking the “Unsubscribe” link in any marketing email
- Emailing dpo@prismintegratedsecurity.solutions with “Unsubscribe” in the subject line
Opting out of marketing will not affect your ability to receive important service-related communications (e.g. maintenance reminders, engineer visit confirmations, emergency alerts).
Privacy Policy
7. Data Sharing & Third Parties
We do not sell, rent or trade personal data. We share data only where necessary and with appropriate contractual protections in place.
7.1 EMCS — Alarm Monitoring Partner (Data Processor)
We share keyholder and alarm event data with EMCS (Nottingham), the UK’s largest independent Alarm Receiving Centre, holding NSI Gold accreditation and responding to over 311,000 alarms per month within 30 seconds. EMCS acts as our data processor under a written Data Processing Agreement (DPA) as required by Article 28 UK GDPR. They will only process your data on our instruction and solely to provide the monitoring service.
7.2 Subcontractors & Engineers
We may engage vetted, background-checked subcontractors for installation or maintenance work. They receive only the minimum personal data necessary to complete the specific task (typically site address and access information). All subcontractors are bound by written confidentiality agreements and are required to comply with UK data protection law.
7.3 Analytics & Marketing Platforms
Where you have consented via our cookie banner, we may share data with:
- Google LLC — Google Analytics (website usage statistics)
- Meta Platforms Ireland Ltd — if you engage with our social media advertising
- LinkedIn Ireland Unlimited Company — professional network advertising and insights
- TikTok Technology Ltd — social media advertising (where applicable)
These providers act as data processors or independent controllers depending on context. See Section 8 for information on international transfers.
7.4 Our Website Platform
Our website is hosted and operated using a cloud website platform (SaaS), which processes data on our behalf as a data processor under its standard data processing terms.
7.5 Professional Advisors
We may share data with accountants, solicitors and insurers where necessary to obtain professional advice. These parties are bound by professional confidentiality obligations and applicable data protection law.
7.6 Legal & Regulatory Authorities
We may disclose personal data to law enforcement agencies, regulatory bodies, courts or other public authorities where we are required to do so by law or court order. We will notify you of any such disclosure unless legally prohibited from doing so.
Prism Integrated Security Solutions Ltd does not sell, lease, rent or otherwise monetise your personal data to any third party for their own purposes.
Privacy Policy
8. International Data Transfers
Some of the third parties we use operate servers or process data outside the United Kingdom. Under Chapter V of the UK GDPR, international transfers require appropriate safeguards.
| Recipient | Country | Transfer Mechanism |
|---|---|---|
| Google LLC (Analytics, Maps, YouTube) | United States | UK Adequacy (US-UK Data Bridge) / International Data Transfer Agreement (IDTA) |
| Meta Platforms Inc (Facebook, Instagram) | United States | UK Adequacy (US-UK Data Bridge) / IDTA |
| LinkedIn Corporation | United States / Ireland (EEA) | UK Adequacy / IDTA; EEA transfers covered by EU SCCs |
| Website hosting platform | Belgium (EEA) | UK Adequacy Decision (EEA) |
The UK Adequacy Decision for the EEA (and vice versa) means transfers to EEA-based processors are permitted without further safeguards. For US-based processors, we rely on the UK-US Data Bridge (where certified) or IDTAs (International Data Transfer Agreements) — the UK equivalent of the EU Standard Contractual Clauses.
You may request details of the specific transfer mechanisms in use for any processor by emailing dpo@prismintegratedsecurity.solutions.
Privacy Policy
9. How Long We Retain Your Data
We retain personal data only as long as necessary for the purpose it was collected, or as required by law. The table below sets out our standard retention periods.
| Data Category | Retention Period | Reason |
|---|---|---|
| Enquiry & contact form data (no contract follows) | 3 years from date of last contact | Legitimate interests — statute of limitations for civil claims |
| Customer contract records (identity, contact, service data) | 7 years from contract end date | Legal obligation — Companies Act 2006; HMRC requirements |
| Alarm monitoring & keyholder data | Duration of monitoring contract + 3 years | Contract performance; legitimate interests (post-contract queries) |
| CCTV footage at Prism’s own premises (if applicable) | 31 days | Legitimate interests — security; ICO CCTV Code of Practice guidance |
| Website analytics data (Google Analytics) | Up to 26 months (per GA4 settings) | Consent — data expires per your GA4 data retention configuration |
| Marketing consent records | Until consent withdrawn + 3 years | Legal obligation — evidence of valid consent (PECR) |
| Complaints, disputes & legal correspondence | 6 years from resolution | Legitimate interests — Limitation Act 1980 (6-year limitation period for contract claims) |
On expiry of the relevant retention period, personal data is securely and irreversibly deleted or anonymised in accordance with our Data Disposal Policy.
We may retain data beyond the periods above where required to comply with a court order, ongoing legal proceedings, or a specific regulatory obligation. We will inform you where this applies.
Privacy Policy
10. Your Rights Under UK GDPR
The UK GDPR gives you a set of rights in relation to your personal data. These rights are explained below. Some rights are absolute; others apply only in certain circumstances or may be subject to exemptions.
👁️
Right of Access (SAR)
Article 15 UK GDPR
Request a copy of the personal data we hold about you. Known as a Subject Access Request (SAR). We must respond within one calendar month of receipt.
✏️
Right to Rectification
Article 16 UK GDPR
Ask us to correct any inaccurate or incomplete personal data we hold about you without undue delay.
🗑️
Right to Erasure
Article 17 UK GDPR
Request deletion of your personal data where there is no compelling reason to continue processing it. Also known as the “right to be forgotten”. Subject to legal retention obligations.
⏸️
Right to Restrict Processing
Article 18 UK GDPR
Ask us to limit how we use your data — for example, while you contest its accuracy or while a complaint is being investigated.
📦
Right to Data Portability
Article 20 UK GDPR
Where processing is based on consent or contract and carried out by automated means, receive your data in a structured, machine-readable format.
🚫
Right to Object
Article 21 UK GDPR
Object to processing based on legitimate interests or carried out for direct marketing. We must stop processing for marketing immediately upon objection.
🤖
Automated Decisions
Article 22 UK GDPR
Not to be subject to decisions based solely on automated processing — including profiling — that produce legal or similarly significant effects on you.
↵️
Withdraw Consent
Article 7(3) UK GDPR
Where processing relies on your consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
How to Exercise Your Rights
Contact our Data Protection contact by email or in writing. We will verify your identity, respond within one calendar month (extendable by two further months for complex requests) and will not charge a fee unless requests are manifestly unfounded or excessive.
Privacy Policy
11. CCTV — Additional Data Notice
Prism designs, installs and maintains CCTV systems for homes and businesses. This section provides additional transparency as required by the ICO’s CCTV Code of Practice and the Surveillance Camera Code of Practice 2021.
If Prism installs a CCTV system at your property, you are the data controller for any footage captured on that system — not Prism. You have independent obligations under the UK GDPR as a data controller.
Your Obligations as a CCTV System Operator
As the controller of a Prism-installed CCTV system, you should:
- Display clear signage at the entrances to any area covered by cameras, informing individuals that recording is taking place (ICO recommended format available at ico.org.uk)
- Publish a privacy notice covering the purposes, retention periods and rights of individuals captured on your system
- Limit footage retention — we recommend a default of 31 days unless a specific incident requires longer retention
- Respond to Subject Access Requests from individuals who appear in footage captured on your system within one calendar month
- Ensure footage is stored securely and access is limited to authorised individuals
Prism’s Role During Installation and Maintenance
During installation, commissioning and maintenance visits, Prism engineers may access live or recorded camera feeds solely for testing and diagnostic purposes. We do not copy, retain or store any footage from customer systems. Where remote technical access is provided (e.g. for fault diagnosis), this is logged and limited to the minimum necessary.
Ajax Systems — Privacy by Design
All Prism-installed CCTV systems using Ajax technology (including Ajax MotionCam) incorporate end-to-end encryption, role-based access controls and secure cloud infrastructure. Photo verification images transmitted to your Alarm Receiving Centre (EMCS) are processed solely for alarm verification purposes. Ajax’s own Privacy Policy governs data processed through the Ajax Cloud platform.
Privacy Policy
12. Children’s Personal Data
Our website and services are not directed at children under the age of 13, and we do not knowingly collect or process personal data relating to children. If you believe that a child has provided us with personal data without appropriate parental or guardian consent, please contact us immediately at dpo@prismintegratedsecurity.solutions and we will delete that data promptly.
Privacy Policy
13. Changes to This Privacy Notice
We review this Privacy Notice periodically and will update it to reflect changes in our processing activities, changes in the law, or guidance from the ICO.
- The “Last Updated” date at the top of this page will always reflect the date of the most recent revision
- Material changes that affect existing customers will be communicated by email at least 14 days before taking effect
- Continued use of our services following notification of a change constitutes acceptance of the revised notice
We recommend checking this page periodically to stay informed of how we protect your data.
Privacy Policy
14. How to Contact Us
If you have any questions about this notice, wish to exercise your rights, or have a concern about how we handle your data, please contact us using the details below.
✉️
Data Protection Contact
For all data rights requests, privacy queries and consent withdrawals.
🏠
Write to Us
Data Protection Contact, Prism Integrated Security Solutions Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
🎯
Complain to the ICO
If you are not satisfied with our response, you have the right to complain to the UK’s supervisory authority.
🔍
ICO Register
Verify our data controller registration on the public ICO register.
We aim to acknowledge all data-related queries within 72 hours and provide a substantive response within one calendar month of receiving a verified request, as required by Article 12 UK GDPR. For complex or numerous requests, this may be extended by up to two further months — we will inform you promptly if this applies.
Cookie Policy
Cookie Policy
How and why we use cookies on www.prismintegratedsecurity.solutions, and how you can manage your preferences.
Cookie Policy
1. What Are Cookies?
Cookies are small text files placed on your device (computer, smartphone or tablet) when you visit a website. They allow the website to remember information about your visit — such as your language preference or whether you are logged in — making your next visit easier and the site more useful.
First-Party vs Third-Party Cookies
- First-party cookies are set directly by our website (prismintegratedsecurity.solutions) and are only accessible by us.
- Third-party cookies are set by external services we use (e.g. Google Analytics, Meta). These providers have their own privacy policies and may track you across multiple websites.
Session vs Persistent Cookies
- Session cookies are temporary. They are deleted automatically when you close your browser.
- Persistent cookies remain on your device until their expiry date or until you delete them manually.
Legal Framework for Cookies in the UK
The use of cookies in the UK is governed by Regulation 6 of the Privacy and Electronic Communications Regulations 2003 (PECR), which implements the EU Cookie Directive in UK law, and by the UK GDPR where cookies process personal data.
Strictly necessary cookies are exempt from the consent requirement under Regulation 6(3) PECR because they are essential for the provision of the service you have requested. All other cookies require your prior, informed consent before they are placed on your device.
Cookie Policy
2. Types of Cookies We Use
We use six categories of cookies. Strictly necessary cookies are active by default. All others require your consent via our cookie banner.
🔒
Strictly Necessary
Essential for the website to function. Cannot be switched off. No consent required under PECR Regulation 6(3).
📈
Analytics
Help us understand how visitors use our site by collecting aggregate, anonymised data. Require consent.
🎯
Marketing
Used to track your visits across sites and deliver targeted advertising. Set by social media platforms. Require consent.
⚙️
Functionality
Enable enhanced features like live chat and personalised experiences. Require consent.
📸
Third-Party Embeds
Set when content from third parties (Google Maps, YouTube) is embedded on our pages. Require consent.
🔗
Other
Additional cookies from other third-party integrations we use from time to time. Subject to provider policies.
Cookie Policy
3. Cookie Table
The table below lists the specific cookies we use, their provider, purpose and duration, grouped by category.
| Cookie Name | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
session_id | Prism / website platform | Maintains your session while browsing. Required for core website functionality — the site cannot operate without it. | Session | Strictly Necessary |
website_lang | Website platform | Stores your language or locale preference. | 1 year | Strictly Necessary |
cookieconsent_status | Prism / website platform | Records whether you have accepted or declined non-essential cookies on this website. | 1 year | Strictly Necessary |
csrf_token | Website platform | Security token that prevents cross-site request forgery (CSRF) attacks. | Session | Strictly Necessary |
_ga | Google Analytics | Registers a unique visitor ID used to generate statistical data on how you use this website. | 2 years | Analytics |
_ga_XXXXXXXXXX | Google Analytics (GA4) | Used by Google Analytics 4 to persist session state and measure website usage across pages. | 2 years | Analytics |
_gid | Google Analytics | Registers a unique ID within a 24-hour period to identify and distinguish returning visitors. | 24 hours | Analytics |
_gat_gtag_* | Google Analytics | Throttles the rate of requests to Google Analytics to limit data collection on high-traffic pages. | 1 minute | Analytics |
_fbp | Meta (Facebook / Instagram) | Used by Meta to track your visits across websites, deliver targeted advertising and measure campaign performance. | 3 months | Marketing |
li_sugr | Probabilistic user matching outside Designated Countries for LinkedIn ad targeting and audience building. | 3 months | Marketing | |
UserMatchHistory | LinkedIn Insight Tag | Enables ad analytics, Conversion Tracking and audience retargeting from LinkedIn campaigns. | 30 days | Marketing |
bcookie | Browser identifier cookie used by LinkedIn to track users across sessions for ad attribution. | 1 year | Marketing | |
_ttp | TikTok | Measures advertising performance and tracks conversions from TikTok ad campaigns. | 1 year | Marketing |
im_livechat_history | Live Chat | Stores your live chat conversation history so you can resume a session without repeating prior information. | 1 month | Functionality |
livechat_operator_pid | Live Chat Provider | Identifies the support operator assigned to your current chat session. | Session | Functionality |
NID, CONSENT, SOCS, 1P_JAR | Google (Maps / YouTube) | Set by Google when Maps or YouTube content is embedded. Used for personalisation, fraud prevention and ad measurement. | 6 months to 2 years | Embeds |
Various (see provider policy) | Other third-party services | Additional cookies may be placed by other integrations we use from time to time. Refer to each provider’s own privacy and cookie policy for full details. | Varies by provider | Other |
ⓘ This table was last reviewed on 6 April 2026. Third-party cookie names and purposes may change — always refer to the provider’s own cookie / privacy policy for the most current information.
Cookie Policy
4. Managing Your Cookie Preferences
You have several options to control or limit how cookies are used when you visit our website.
Our Cookie Consent Banner
When you first visit our website, you will see a cookie consent banner. You may:
- Accept all cookies — enables all categories including analytics and marketing
- Reject non-essential cookies — only strictly necessary cookies will be set
- Manage preferences — choose which categories to enable individually
Your preferences are stored in the cookieconsent_status cookie for 12 months. You can change your preferences at any time by clearing this cookie and revisiting the site, or by contacting dpo@prismintegratedsecurity.solutions.
Browser Settings
You can also control cookies through your browser settings. Note that blocking all cookies may affect the functionality of our website. Instructions for major browsers:
Provider Opt-Out Tools
- Google Analytics: Google Analytics Opt-out Browser Add-on
- Meta (Facebook): Facebook Ad Preferences
- LinkedIn: LinkedIn Opt-out
- All advertising cookies: Your Online Choices (EDAA) — manage preferences across all participating advertisers
Strictly necessary cookies cannot be disabled through our consent mechanism as they are essential for the website to function. Blocking them via your browser settings may prevent you from using core features of the site including contact forms and page navigation.
Third-Party Links
Our website may contain links to third-party websites (e.g. EMCS, NSI, ICO). We have no control over and accept no responsibility for the cookies or privacy practices of those sites. We recommend reviewing the privacy and cookie policies of any third-party site you visit.
Cookie Policy
5. Changes to This Cookie Policy
We review and update this Cookie Policy as our technology, legal obligations and third-party services change. The “Last Updated” date at the top of this page reflects the most recent revision. We recommend checking this page periodically.
For significant changes, we will update the cookie consent banner so that returning visitors can review and re-confirm their preferences.
© 2026 Prism Integrated Security Solutions Ltd. Registered in England and Wales. This notice is governed by the law of England and Wales. Any dispute arising from it shall be subject to the exclusive jurisdiction of the courts of England and Wales.
