Call today and claim your FREE! Alarm System – 0330 236 8191 – Terms & Conditions Apply

Home / Legal / Privacy & Cookie Policy

Privacy & Cookie Policy

Prism Integrated Security Solutions Ltd is committed to protecting your personal data and being transparent about how we use it. This Privacy and Cookie Policy notice covers both areas, and is governed by UK law.

Last Updated: 6 April 2026Legislation: UK GDPR & DPA 2018, PECR 2003Version: 1.0

🔒 ICO Registration: Registered with the Information Commissioner’s Office — reference ZC183779. Verify on the ICO register

Privacy Policy   Data Controller   ·   Data We Collect   ·   Lawful Basis   ·   Data Sharing   ·   Retention   ·   Your Rights   ·   CCTV Notice   ·   Contact DPO

Cookie Policy   What Are Cookies   ·   Cookie Types   ·   Cookie Table   ·   Manage Cookies

Privacy Policy

1. About This Privacy Notice

This Privacy Notice explains how Prism Integrated Security Solutions Ltd collects, uses, stores and shares your personal data, and the rights available to you under UK data protection law.

This notice applies to:

  • Visitors to our website at www.prismintegratedsecurity.solutions
  • Individuals who contact us by telephone, email or through enquiry forms
  • Customers who engage us for the installation, maintenance or monitoring of security systems
  • Keyholders and contacts registered on alarm monitoring accounts

This notice is provided in compliance with Articles 13 and 14 of the UK General Data Protection Regulation (UK GDPR) as retained in UK law by the Data Protection Act 2018 (DPA 2018). Our use of cookies is additionally governed by the Privacy and Electronic Communications Regulations 2003 (PECR).

Not a contractual document.

This notice describes our current data processing practices. We review it regularly and will update this page whenever our practices change. Material changes affecting existing customers will be communicated by email.

Privacy Policy

2. Data Controller

For the purposes of the UK GDPR, the data controller — the entity responsible for deciding how your personal data is used — is:

FieldDetail
Company NamePrism Integrated Security Solutions Ltd
Registered InEngland and Wales
Registered Address71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
ICO Registration No.ZC183779Verify on the ICO register
Data Protection Contactdpo@prismintegratedsecurity.solutions
Websitewww.prismintegratedsecurity.solutions

Note on ICO Registration: Under Section 108 of the Data Protection Act 2018, organisations that process personal data for purposes other than personal, family or household activities must register with the Information Commissioner’s Office (ICO). We are registered under reference ZC183779. You can verify UK-registered data controllers at ico.org.uk/ESDWebPages/Search.

Privacy Policy

3. Personal Data We Collect

We only collect personal data that is necessary for a specific, lawful purpose. The categories we collect depend on your relationship with us.

3.1 Contact & Enquiry Data

When you contact us by telephone, email, or via our website contact forms, we may collect:

  • Identity data: First name, last name, title
  • Contact data: Email address, telephone number(s)
  • Business data: Company name, job title (where applicable)
  • Communications data: The content of your enquiry or message

3.2 Customer & Contract Data

When you engage Prism for installation, maintenance or monitoring services, we collect:

  • Identity data: Full name, company name (if commercial premises)
  • Contact data: Email address(es), telephone number(s), postal address
  • Location data: Installation site address, site access details and codes
  • Financial data: Payment information processed via our accounting system (we do not store full card numbers)
  • Service data: Details of installed systems, maintenance records, service history, engineer visit notes

3.3 Alarm Monitoring & Keyholder Data

To enable 24/7 alarm monitoring via our partner EMCS (Nottingham) — the UK’s largest independent Alarm Receiving Centre — we collect and share the following with EMCS in accordance with your monitoring contract:

  • Keyholder names, telephone numbers and call priorities
  • Site entry codes and response procedures
  • Alarm zone descriptions and layout information
  • Police Unique Reference Number (URN) if applicable
Third-party data.

If you provide us with the names and contact details of keyholders, you must ensure those individuals are aware their information will be shared with EMCS for monitoring purposes. We recommend directing them to this notice.

3.4 CCTV Footage

Prism installs and maintains CCTV systems at customer premises. For clarity on who controls what:

  • Your system, your data: If Prism installs a CCTV system at your property, you are the data controller for footage captured by that system. You must display appropriate signage and maintain your own privacy notice for individuals captured on camera. ICO guidance is available at ico.org.uk/surveillance.
  • Prism as installer and maintainer: During installation and maintenance visits, our engineers may briefly access live or recorded footage for testing and diagnostic purposes only. We do not retain, copy or store any footage from customer systems.
  • Data Processing Agreement: Larger commercial clients who require Prism to act formally as a data processor (e.g. for remote access arrangements) may request a Data Processing Agreement (DPA) under Article 28 UK GDPR. Contact dpo@prismintegratedsecurity.solutions.

3.5 Website & Technical Data

When you visit our website, we automatically collect certain technical data:

  • Technical data: IP address, browser type and version, operating system, device type
  • Usage data: Pages visited, time spent on pages, links clicked, referring URL
  • Cookie data: Information collected via cookies and similar technologies (see Cookie Policy below)

This data is collected via our website platform and, where you have consented, via Google Analytics. It is used in aggregate to improve our website and understand visitor behaviour.

Privacy Policy

4. Lawful Basis for Processing

Under Article 6 of the UK GDPR, we must have a lawful basis for each type of processing activity. The table below sets out the basis we rely on for each activity.

Processing ActivityLawful BasisLegal Reference
Responding to website enquiries and providing quotationsLegitimate InterestsArticle 6(1)(f) UK GDPR — our interest in responding to potential customers
Delivering installation, maintenance and repair servicesContract PerformanceArticle 6(1)(b) UK GDPR — necessary to fulfil your service contract
Sharing keyholder data with EMCS for 24/7 monitoringContract PerformanceArticle 6(1)(b) UK GDPR — integral to the monitoring service you contracted for
Sending service reminders, renewal notices and job confirmationsContract PerformanceArticle 6(1)(b) UK GDPR
Maintaining accounting, financial and contractual recordsLegal ObligationArticle 6(1)(c) UK GDPR — Companies Act 2006; HMRC requirements
Email marketing to existing customers for similar servicesSoft Opt-InRegulation 22 PECR 2003 — you may opt out at any time
Email marketing to new or prospective contactsConsentArticle 6(1)(a) UK GDPR; Regulation 22 PECR 2003 — requires prior opt-in
Website analytics and performance tracking via cookiesConsentArticle 6(1)(a) UK GDPR; Regulation 6 PECR 2003 — via cookie consent banner
Responding to legal, regulatory or law enforcement requestsLegal ObligationArticle 6(1)(c) UK GDPR
Managing complaints and disputesLegitimate InterestsArticle 6(1)(f) UK GDPR — our interest in resolving complaints and defending legal claims
Legitimate Interests Assessment.

Where we rely on legitimate interests (Article 6(1)(f)), we have conducted a Legitimate Interests Assessment (LIA) to balance our interests against your rights. You may request a copy of our LIA by contacting dpo@prismintegratedsecurity.solutions.

Privacy Policy

5. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

  • To respond to your enquiries, provide quotations and arrange site surveys
  • To install, commission and maintain security systems at your property
  • To configure and manage your alarm monitoring account with EMCS
  • To process payments and issue invoices
  • To send annual maintenance reminders, contract renewal notices and service updates
  • To carry out engineer scheduling and job management
  • To communicate important changes to our services or this notice
  • To improve and optimise our website using aggregate analytics data
  • To detect, investigate and prevent fraud or security incidents
  • To comply with our legal and regulatory obligations
  • To defend or bring legal claims where necessary

We will never sell your personal data to third parties, and we will not use it for any purpose incompatible with the purposes set out in this notice without first obtaining your consent or notifying you.

Privacy Policy

6. Marketing Communications

We may send you information about our services, offers and security tips by email or post.

Existing Customers (Soft Opt-In)

Under Regulation 22 of PECR 2003, where you are an existing customer, we may contact you by email about similar products and services to those you have previously purchased, provided we offered you a clear opportunity to opt out at the time of collection and in every subsequent marketing communication.

New or Prospective Contacts

Where you are not an existing customer, we will only send marketing communications by email or SMS where you have given your explicit prior consent in compliance with Article 6(1)(a) UK GDPR and Regulation 22 PECR 2003.

Your Right to Opt Out

You can stop receiving marketing communications at any time by:

Opting out of marketing will not affect your ability to receive important service-related communications (e.g. maintenance reminders, engineer visit confirmations, emergency alerts).

Privacy Policy

7. Data Sharing & Third Parties

We do not sell, rent or trade personal data. We share data only where necessary and with appropriate contractual protections in place.

7.1 EMCS — Alarm Monitoring Partner (Data Processor)

We share keyholder and alarm event data with EMCS (Nottingham), the UK’s largest independent Alarm Receiving Centre, holding NSI Gold accreditation and responding to over 311,000 alarms per month within 30 seconds. EMCS acts as our data processor under a written Data Processing Agreement (DPA) as required by Article 28 UK GDPR. They will only process your data on our instruction and solely to provide the monitoring service.

7.2 Subcontractors & Engineers

We may engage vetted, background-checked subcontractors for installation or maintenance work. They receive only the minimum personal data necessary to complete the specific task (typically site address and access information). All subcontractors are bound by written confidentiality agreements and are required to comply with UK data protection law.

7.3 Analytics & Marketing Platforms

Where you have consented via our cookie banner, we may share data with:

  • Google LLC — Google Analytics (website usage statistics)
  • Meta Platforms Ireland Ltd — if you engage with our social media advertising
  • LinkedIn Ireland Unlimited Company — professional network advertising and insights
  • TikTok Technology Ltd — social media advertising (where applicable)

These providers act as data processors or independent controllers depending on context. See Section 8 for information on international transfers.

7.4 Our Website Platform

Our website is hosted and operated using a cloud website platform (SaaS), which processes data on our behalf as a data processor under its standard data processing terms.

7.5 Professional Advisors

We may share data with accountants, solicitors and insurers where necessary to obtain professional advice. These parties are bound by professional confidentiality obligations and applicable data protection law.

7.6 Legal & Regulatory Authorities

We may disclose personal data to law enforcement agencies, regulatory bodies, courts or other public authorities where we are required to do so by law or court order. We will notify you of any such disclosure unless legally prohibited from doing so.

We will never sell your data.

Prism Integrated Security Solutions Ltd does not sell, lease, rent or otherwise monetise your personal data to any third party for their own purposes.

Privacy Policy

8. International Data Transfers

Some of the third parties we use operate servers or process data outside the United Kingdom. Under Chapter V of the UK GDPR, international transfers require appropriate safeguards.

RecipientCountryTransfer Mechanism
Google LLC (Analytics, Maps, YouTube)United StatesUK Adequacy (US-UK Data Bridge) / International Data Transfer Agreement (IDTA)
Meta Platforms Inc (Facebook, Instagram)United StatesUK Adequacy (US-UK Data Bridge) / IDTA
LinkedIn CorporationUnited States / Ireland (EEA)UK Adequacy / IDTA; EEA transfers covered by EU SCCs
Website hosting platformBelgium (EEA)UK Adequacy Decision (EEA)

The UK Adequacy Decision for the EEA (and vice versa) means transfers to EEA-based processors are permitted without further safeguards. For US-based processors, we rely on the UK-US Data Bridge (where certified) or IDTAs (International Data Transfer Agreements) — the UK equivalent of the EU Standard Contractual Clauses.

You may request details of the specific transfer mechanisms in use for any processor by emailing dpo@prismintegratedsecurity.solutions.

Privacy Policy

9. How Long We Retain Your Data

We retain personal data only as long as necessary for the purpose it was collected, or as required by law. The table below sets out our standard retention periods.

Data CategoryRetention PeriodReason
Enquiry & contact form data (no contract follows)3 years from date of last contactLegitimate interests — statute of limitations for civil claims
Customer contract records (identity, contact, service data)7 years from contract end dateLegal obligation — Companies Act 2006; HMRC requirements
Alarm monitoring & keyholder dataDuration of monitoring contract + 3 yearsContract performance; legitimate interests (post-contract queries)
CCTV footage at Prism’s own premises (if applicable)31 daysLegitimate interests — security; ICO CCTV Code of Practice guidance
Website analytics data (Google Analytics)Up to 26 months (per GA4 settings)Consent — data expires per your GA4 data retention configuration
Marketing consent recordsUntil consent withdrawn + 3 yearsLegal obligation — evidence of valid consent (PECR)
Complaints, disputes & legal correspondence6 years from resolutionLegitimate interests — Limitation Act 1980 (6-year limitation period for contract claims)

On expiry of the relevant retention period, personal data is securely and irreversibly deleted or anonymised in accordance with our Data Disposal Policy.

Exceptional circumstances.

We may retain data beyond the periods above where required to comply with a court order, ongoing legal proceedings, or a specific regulatory obligation. We will inform you where this applies.

Privacy Policy

10. Your Rights Under UK GDPR

The UK GDPR gives you a set of rights in relation to your personal data. These rights are explained below. Some rights are absolute; others apply only in certain circumstances or may be subject to exemptions.

👁️

Right of Access (SAR)

Article 15 UK GDPR

Request a copy of the personal data we hold about you. Known as a Subject Access Request (SAR). We must respond within one calendar month of receipt.

✏️

Right to Rectification

Article 16 UK GDPR

Ask us to correct any inaccurate or incomplete personal data we hold about you without undue delay.

🗑️

Right to Erasure

Article 17 UK GDPR

Request deletion of your personal data where there is no compelling reason to continue processing it. Also known as the “right to be forgotten”. Subject to legal retention obligations.

⏸️

Right to Restrict Processing

Article 18 UK GDPR

Ask us to limit how we use your data — for example, while you contest its accuracy or while a complaint is being investigated.

📦

Right to Data Portability

Article 20 UK GDPR

Where processing is based on consent or contract and carried out by automated means, receive your data in a structured, machine-readable format.

🚫

Right to Object

Article 21 UK GDPR

Object to processing based on legitimate interests or carried out for direct marketing. We must stop processing for marketing immediately upon objection.

🤖

Automated Decisions

Article 22 UK GDPR

Not to be subject to decisions based solely on automated processing — including profiling — that produce legal or similarly significant effects on you.

↵️

Withdraw Consent

Article 7(3) UK GDPR

Where processing relies on your consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

How to Exercise Your Rights

Contact our Data Protection contact by email or in writing. We will verify your identity, respond within one calendar month (extendable by two further months for complex requests) and will not charge a fee unless requests are manifestly unfounded or excessive.

Privacy Policy

11. CCTV — Additional Data Notice

Prism designs, installs and maintains CCTV systems for homes and businesses. This section provides additional transparency as required by the ICO’s CCTV Code of Practice and the Surveillance Camera Code of Practice 2021.

Who is the data controller for your CCTV system?

If Prism installs a CCTV system at your property, you are the data controller for any footage captured on that system — not Prism. You have independent obligations under the UK GDPR as a data controller.

Your Obligations as a CCTV System Operator

As the controller of a Prism-installed CCTV system, you should:

  • Display clear signage at the entrances to any area covered by cameras, informing individuals that recording is taking place (ICO recommended format available at ico.org.uk)
  • Publish a privacy notice covering the purposes, retention periods and rights of individuals captured on your system
  • Limit footage retention — we recommend a default of 31 days unless a specific incident requires longer retention
  • Respond to Subject Access Requests from individuals who appear in footage captured on your system within one calendar month
  • Ensure footage is stored securely and access is limited to authorised individuals

Prism’s Role During Installation and Maintenance

During installation, commissioning and maintenance visits, Prism engineers may access live or recorded camera feeds solely for testing and diagnostic purposes. We do not copy, retain or store any footage from customer systems. Where remote technical access is provided (e.g. for fault diagnosis), this is logged and limited to the minimum necessary.

Ajax Systems — Privacy by Design

All Prism-installed CCTV systems using Ajax technology (including Ajax MotionCam) incorporate end-to-end encryption, role-based access controls and secure cloud infrastructure. Photo verification images transmitted to your Alarm Receiving Centre (EMCS) are processed solely for alarm verification purposes. Ajax’s own Privacy Policy governs data processed through the Ajax Cloud platform.

Privacy Policy

12. Children’s Personal Data

Our website and services are not directed at children under the age of 13, and we do not knowingly collect or process personal data relating to children. If you believe that a child has provided us with personal data without appropriate parental or guardian consent, please contact us immediately at dpo@prismintegratedsecurity.solutions and we will delete that data promptly.

Privacy Policy

13. Changes to This Privacy Notice

We review this Privacy Notice periodically and will update it to reflect changes in our processing activities, changes in the law, or guidance from the ICO.

  • The “Last Updated” date at the top of this page will always reflect the date of the most recent revision
  • Material changes that affect existing customers will be communicated by email at least 14 days before taking effect
  • Continued use of our services following notification of a change constitutes acceptance of the revised notice

We recommend checking this page periodically to stay informed of how we protect your data.

Privacy Policy

14. How to Contact Us

If you have any questions about this notice, wish to exercise your rights, or have a concern about how we handle your data, please contact us using the details below.

✉️

Data Protection Contact

For all data rights requests, privacy queries and consent withdrawals.

dpo@prismintegratedsecurity.solutions

🏠

Write to Us

Data Protection Contact, Prism Integrated Security Solutions Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ

General Contact Page

🎯

Complain to the ICO

If you are not satisfied with our response, you have the right to complain to the UK’s supervisory authority.

ico.org.uk/make-a-complaint

🔍

ICO Register

Verify our data controller registration on the public ICO register.

ICO Register Search

Response time commitment.

We aim to acknowledge all data-related queries within 72 hours and provide a substantive response within one calendar month of receiving a verified request, as required by Article 12 UK GDPR. For complex or numerous requests, this may be extended by up to two further months — we will inform you promptly if this applies.

Cookie Policy

Cookie Policy

How and why we use cookies on www.prismintegratedsecurity.solutions, and how you can manage your preferences.

Cookie Policy

1. What Are Cookies?

Cookies are small text files placed on your device (computer, smartphone or tablet) when you visit a website. They allow the website to remember information about your visit — such as your language preference or whether you are logged in — making your next visit easier and the site more useful.

First-Party vs Third-Party Cookies

  • First-party cookies are set directly by our website (prismintegratedsecurity.solutions) and are only accessible by us.
  • Third-party cookies are set by external services we use (e.g. Google Analytics, Meta). These providers have their own privacy policies and may track you across multiple websites.

Session vs Persistent Cookies

  • Session cookies are temporary. They are deleted automatically when you close your browser.
  • Persistent cookies remain on your device until their expiry date or until you delete them manually.

Legal Framework for Cookies in the UK

The use of cookies in the UK is governed by Regulation 6 of the Privacy and Electronic Communications Regulations 2003 (PECR), which implements the EU Cookie Directive in UK law, and by the UK GDPR where cookies process personal data.

Strictly necessary cookies are exempt from the consent requirement under Regulation 6(3) PECR because they are essential for the provision of the service you have requested. All other cookies require your prior, informed consent before they are placed on your device.

Cookie Policy

2. Types of Cookies We Use

We use six categories of cookies. Strictly necessary cookies are active by default. All others require your consent via our cookie banner.

🔒

Strictly Necessary

Essential for the website to function. Cannot be switched off. No consent required under PECR Regulation 6(3).

📈

Analytics

Help us understand how visitors use our site by collecting aggregate, anonymised data. Require consent.

🎯

Marketing

Used to track your visits across sites and deliver targeted advertising. Set by social media platforms. Require consent.

⚙️

Functionality

Enable enhanced features like live chat and personalised experiences. Require consent.

📸

Third-Party Embeds

Set when content from third parties (Google Maps, YouTube) is embedded on our pages. Require consent.

🔗

Other

Additional cookies from other third-party integrations we use from time to time. Subject to provider policies.

Cookie Policy

3. Cookie Table

The table below lists the specific cookies we use, their provider, purpose and duration, grouped by category.

Cookie NameProviderPurposeDurationCategory
session_idPrism / website platformMaintains your session while browsing. Required for core website functionality — the site cannot operate without it.SessionStrictly Necessary
website_langWebsite platformStores your language or locale preference.1 yearStrictly Necessary
cookieconsent_statusPrism / website platformRecords whether you have accepted or declined non-essential cookies on this website.1 yearStrictly Necessary
csrf_tokenWebsite platformSecurity token that prevents cross-site request forgery (CSRF) attacks.SessionStrictly Necessary
_gaGoogle AnalyticsRegisters a unique visitor ID used to generate statistical data on how you use this website.2 yearsAnalytics
_ga_XXXXXXXXXXGoogle Analytics (GA4)Used by Google Analytics 4 to persist session state and measure website usage across pages.2 yearsAnalytics
_gidGoogle AnalyticsRegisters a unique ID within a 24-hour period to identify and distinguish returning visitors.24 hoursAnalytics
_gat_gtag_*Google AnalyticsThrottles the rate of requests to Google Analytics to limit data collection on high-traffic pages.1 minuteAnalytics
_fbpMeta (Facebook / Instagram)Used by Meta to track your visits across websites, deliver targeted advertising and measure campaign performance.3 monthsMarketing
li_sugrLinkedInProbabilistic user matching outside Designated Countries for LinkedIn ad targeting and audience building.3 monthsMarketing
UserMatchHistoryLinkedIn Insight TagEnables ad analytics, Conversion Tracking and audience retargeting from LinkedIn campaigns.30 daysMarketing
bcookieLinkedInBrowser identifier cookie used by LinkedIn to track users across sessions for ad attribution.1 yearMarketing
_ttpTikTokMeasures advertising performance and tracks conversions from TikTok ad campaigns.1 yearMarketing
im_livechat_historyLive ChatStores your live chat conversation history so you can resume a session without repeating prior information.1 monthFunctionality
livechat_operator_pidLive Chat ProviderIdentifies the support operator assigned to your current chat session.SessionFunctionality
NID, CONSENT, SOCS, 1P_JARGoogle (Maps / YouTube)Set by Google when Maps or YouTube content is embedded. Used for personalisation, fraud prevention and ad measurement.6 months to 2 yearsEmbeds
Various (see provider policy)Other third-party servicesAdditional cookies may be placed by other integrations we use from time to time. Refer to each provider’s own privacy and cookie policy for full details.Varies by providerOther

ⓘ This table was last reviewed on 6 April 2026. Third-party cookie names and purposes may change — always refer to the provider’s own cookie / privacy policy for the most current information.

Cookie Policy

4. Managing Your Cookie Preferences

You have several options to control or limit how cookies are used when you visit our website.

Our Cookie Consent Banner

When you first visit our website, you will see a cookie consent banner. You may:

  • Accept all cookies — enables all categories including analytics and marketing
  • Reject non-essential cookies — only strictly necessary cookies will be set
  • Manage preferences — choose which categories to enable individually

Your preferences are stored in the cookieconsent_status cookie for 12 months. You can change your preferences at any time by clearing this cookie and revisiting the site, or by contacting dpo@prismintegratedsecurity.solutions.

Browser Settings

You can also control cookies through your browser settings. Note that blocking all cookies may affect the functionality of our website. Instructions for major browsers:

Provider Opt-Out Tools

Blocking strictly necessary cookies.

Strictly necessary cookies cannot be disabled through our consent mechanism as they are essential for the website to function. Blocking them via your browser settings may prevent you from using core features of the site including contact forms and page navigation.

Third-Party Links

Our website may contain links to third-party websites (e.g. EMCS, NSI, ICO). We have no control over and accept no responsibility for the cookies or privacy practices of those sites. We recommend reviewing the privacy and cookie policies of any third-party site you visit.

Cookie Policy

5. Changes to This Cookie Policy

We review and update this Cookie Policy as our technology, legal obligations and third-party services change. The “Last Updated” date at the top of this page reflects the most recent revision. We recommend checking this page periodically.

For significant changes, we will update the cookie consent banner so that returning visitors can review and re-confirm their preferences.

© 2026 Prism Integrated Security Solutions Ltd. Registered in England and Wales. This notice is governed by the law of England and Wales. Any dispute arising from it shall be subject to the exclusive jurisdiction of the courts of England and Wales.