Privacy Policy

1. Introduction

Upperrail Ltd (“we,” “us,” or “our”) is committed to protecting the privacy and security of personal data. This Privacy Policy explains how we collect, use, and protect personal information in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Information We Collect

We may collect and process the following personal data:

  • Name, address, contact details (email, phone number)

  • Employment history, qualifications, and references (for job applicants)

  • Financial details for payroll processing

  • Identification documents for right-to-work verification

  • CCTV footage (where applicable for security purposes)

3. How We Collect Personal Data

We collect personal data through:

  • Job application forms

  • Direct communications (email, phone, or in person)

  • Our website and online forms

  • CCTV recordings (where applicable)

  • Third-party background checks (where required)

4. Purpose of Processing Personal Data

We use personal data for the following purposes:

  • Recruitment and employment administration

  • Payroll and payment processing

  • Compliance with legal and regulatory obligations

  • Security and fraud prevention

  • Communication with employees, clients, and contractors

5. Legal Basis for Processing

We process personal data based on:

  • The necessity for contractual performance (employment or service agreements)

  • Compliance with legal obligations

  • Legitimate business interests

  • Consent (where required)

6. Data Sharing and Disclosure

We may share personal data with:

  • Government authorities (e.g., HMRC, Home Office) where legally required

  • Third-party service providers for payroll, IT support, and security services

  • Legal and regulatory bodies for compliance purposes

7. Data Retention

We retain personal data for as long as necessary to fulfil legal, contractual, and business obligations. Retention periods vary depending on the nature of the data and regulatory requirements.

8. Data Security

We implement appropriate technical and organizational measures to safeguard personal data against unauthorized access, alteration, or loss.

9. Your Rights

Under the UK GDPR, individuals have the right to:

  • Access, rectify, or erase personal data

  • Restrict or object to processing

  • Data portability (where applicable)

  • Withdraw consent (where processing is based on consent)

  • Lodge a complaint with the Information Commissioner’s Office (ICO)

10. Contact Us

For any queries or to exercise your rights, please contact:

Data Protection Officer
Upperrail Ltd
[Company Address]
Email: [Contact Email]
Phone: [Contact Number]

11. Updates to This Policy

We may update this Privacy Policy periodically. Any changes will be communicated via our website or other appropriate means.