Storage Nags Head Privacy Policy
This Privacy Policy explains how Storage Nags Head collects, uses, stores, and protects personal data relating to our customers and prospective customers in our service area. It also explains your rights under the UK General Data Protection Regulation and the EU General Data Protection Regulation, where applicable. This Privacy Policy applies to all Storage Nags Head customers and individuals who use, enquire about, or are otherwise connected with our storage services in the area we serve.
Data Controller
Storage Nags Head is the data controller in respect of the personal data we collect and process about you. This means that we determine the purposes and means of processing your personal data in connection with our storage services.
Personal Data We Collect
We may collect and process the following categories of personal data when you interact with Storage Nags Head as a customer or prospective customer:
Identity data such as your full name, title, date of birth, and identification details where required for verification.
Contact data such as your home address, billing address, and any other address you provide to us as well as your preferred communication details.
Account and contract data such as your customer reference number, storage unit details, contract start and end dates, and information about services you have purchased or requested.
Payment and billing data such as billing history, payment method details excluding full card numbers where processed by secure payment processors, invoices, and records of payments made or due.
Usage data such as records of your access to our storage facilities, including entry and exit times, as well as logs relating to the use of our services.
Communications data such as records of your correspondence and communications with us, including enquiries, complaints, and feedback.
Technical and security data such as CCTV footage in and around our premises, access control logs, and other data necessary to maintain the safety and security of our facilities and customers.
How We Collect Your Data
We collect personal data directly from you when you enquire about our services, enter into a storage agreement, manage your account, make a payment, contact us with a query, or visit our facilities. We may also receive personal data from third parties, such as payment processors and credit reference agencies, where this is necessary to provide our services or manage risk.
Lawful Basis for Processing
We only process your personal data where we have a lawful basis to do so under the GDPR. Depending on the specific processing activity, we rely on the following lawful bases:
Performance of a contract: We process personal data when it is necessary to enter into or perform your storage agreement or to take steps at your request prior to entering into a contract. This includes managing your bookings, administering your account, taking payments, and providing customer support.
Legal obligation: We process certain personal data to comply with legal and regulatory obligations, such as tax and accounting requirements, anti-money laundering and fraud prevention obligations, and health and safety laws.
Legitimate interests: We process personal data where it is necessary for our legitimate business interests and these interests are not overridden by your rights and freedoms. This includes ensuring the security of our premises and property, preventing and detecting fraud or misuse of our services, managing business operations, and improving our services.
Consent: In some cases, we may ask for your consent to process your personal data, for example for certain types of direct marketing that are not covered by legitimate interests. Where we rely on consent, you have the right to withdraw it at any time.
Purposes of Processing
We process your personal data for the following purposes:
To provide, manage, and administer storage services and related products you request from us.
To create and maintain your customer account and manage our relationship with you.
To process payments, issue invoices, manage debt recovery, and handle financial administration.
To respond to your enquiries, requests, and complaints, and to provide customer support.
To maintain the safety and security of our customers, staff, and premises, including through CCTV and access control systems.
To comply with applicable laws and regulations and to cooperate with law enforcement or regulatory authorities when legally required.
To conduct internal record keeping, business planning, and service improvement.
To send you service-related communications that are necessary for the performance of your contract or our legal obligations.
To send you marketing communications about similar services, where permitted, and to manage your marketing preferences.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. The length of time we keep your data depends on the type of information and the purpose of processing.
Generally, we retain contract and billing records for a period required by applicable tax and financial regulations. CCTV and access logs are retained for a shorter period necessary to investigate incidents, protect property, and ensure security, unless a longer retention period is required due to an ongoing investigation or legal claim.
When personal data is no longer required for the purposes for which it was collected, we will securely delete or anonymise it.
Data Processors and Third Parties
We may use carefully selected third party service providers acting as data processors to process personal data on our behalf. These processors may provide services such as secure payment processing, IT hosting and infrastructure, customer relationship management, access control systems, and professional advisory services.
We ensure that all processors are subject to appropriate contractual and technical safeguards so that your personal data is processed only in accordance with our instructions, under a duty of confidentiality, and in compliance with GDPR requirements.
We may also need to share personal data with other third parties acting as controllers, such as banks, insurers, legal advisers, law enforcement agencies, regulatory authorities, or debt collection agencies, where this is necessary to perform a contract, comply with a legal obligation, or protect our legitimate interests and the rights of others.
We do not sell your personal data to third parties.
International Transfers
Where we or our processors transfer personal data outside the United Kingdom or the European Economic Area, we will ensure that an adequate level of protection is in place. This may include using countries that have been recognised as providing an adequate level of data protection or implementing appropriate safeguards such as standard contractual clauses approved by relevant authorities.
Security of Your Data
We take the security of your personal data seriously. We implement appropriate technical and organisational measures designed to protect your data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures may include access controls, encryption, secure storage systems, staff training, and regular review of our security procedures.
Your Data Protection Rights
Under the GDPR, you have a number of rights in relation to the personal data we hold about you. These rights apply to all Storage Nags Head customers in our area, subject to certain legal limitations and exemptions.
Right of access: You have the right to obtain confirmation as to whether we process your personal data and, if so, to receive a copy and certain information about how it is processed.
Right to rectification: You have the right to request correction of inaccurate personal data and to have incomplete data completed.
Right to erasure: You have the right to request deletion of your personal data in certain circumstances, for example where the data is no longer necessary for the purposes for which it was collected or where you withdraw consent and no other lawful basis applies.
Right to restriction of processing: You have the right to request that we restrict the processing of your personal data in certain situations, such as while we verify the accuracy of the data or consider an objection you have raised.
Right to data portability: In some cases, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine readable format and to transmit that data to another controller.
Right to object: You have the right to object to processing based on our legitimate interests, including profiling, and we will stop processing unless we can demonstrate compelling legitimate grounds. You also have the right to object at any time to the processing of your personal data for direct marketing.
Rights in relation to automated decision making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects, unless certain conditions apply.
Exercising Your Rights and Complaints
If you wish to exercise any of your data protection rights, or if you have any questions or concerns about how we handle your personal data, you can contact Storage Nags Head using the contact details provided in your service agreement or on our official customer communications.
You also have the right to lodge a complaint with the relevant data protection supervisory authority in your country of residence, place of work, or place of the alleged infringement if you believe that your data protection rights have been breached.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our processing activities, legal requirements, or business practices. Any updates will be made available to customers, and the revised policy will apply from the date of publication. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.




