WESTEVO / Governance standard
← Return to WESTEVO

Responsible data, carefully handled

Data Protection Policy.

This policy sets the standard WESTEVO follows whenever personal information is collected, used, stored, shared or securely disposed of.

Owner: Harlan West Effective: 31 August 2026 Next review: 31 August 2027

Purpose, scope and responsibility

WESTEVO is committed to handling personal information lawfully, fairly, transparently and securely. This policy applies to customer, prospect, supplier, business-contact, website-visitor and other personal information handled for WESTEVO, whether digital, photographic, verbal or on paper.

Harlan West T/A Westevo is the data controller and policy owner. Harlan West remains accountable for compliance even where an authorised administrator, adviser, supplier or technology provider assists the business.

Controller & policy owner

Address: Joiners Meadow, Trevillick, Tintagel, Cornwall, PL34 0DN
Email: hello@westevo.co.uk

The standards WESTEVO follows

Lawful, fair and transparent

A valid lawful basis is identified before information is used, and people are given clear, accessible privacy information.

Purpose limited

Information is used only for the stated purpose or for a compatible and lawful purpose that people would reasonably expect.

Data minimised

Only information reasonably needed for an enquiry, service, legal duty, safety control or other authorised purpose is collected.

Accurate

Reasonable steps are taken to keep information accurate, correct errors and avoid relying on information known to be out of date.

Kept only as needed

Records follow a documented retention schedule and are deleted, anonymised or securely destroyed when there is no continuing need.

Secure and accountable

Proportionate safeguards are applied and important decisions, incidents, requests and supplier arrangements are documented.

Controls through the data lifecycle

Before collecting information

  • Define the purpose, lawful basis, necessary fields, recipients and retention period.
  • Use privacy by design: collect the least information needed and choose the least intrusive workable method.
  • Assess higher-risk or materially new processing before it begins and complete a data-protection impact assessment where legally required.
  • Make the relevant Privacy Notice available at or before collection.

While using information

  • Restrict use to authorised business purposes and access to people who need it.
  • Check accuracy where a decision, quotation, safety measure or communication depends on it.
  • Record consent where consent is relied on and make withdrawal as easy as giving it.
  • Do not reuse quotation enquiries for marketing without a separate lawful route under data-protection and electronic-marketing rules.

When the purpose ends

  • Apply the retention schedule across email, Google Workspace, Squarespace, downloaded files, photographs and paper records.
  • Delete duplicate copies where they are no longer required.
  • Use secure deletion or destruction appropriate to the sensitivity and format of the record.

Lawful use, photographs and marketing

WESTEVO's usual lawful bases are:

  • Contract or steps requested before a contract for enquiries, quotations, bookings and service delivery.
  • Legal obligation for tax, accounting, regulatory, rights and other statutory requirements.
  • Legitimate interests for proportionate business administration, security, service improvement, safety, fraud prevention and legal claims, after considering people's rights.
  • Consent where a freely given, specific and recorded choice is appropriate, including selected marketing or identifiable promotional imagery.

Photographs are data, not decoration. Site images must be relevant to assessment, delivery, safety or evidence. Marketing use requires a recorded lawful basis and any necessary property or individual permission. Unnecessary faces, number plates, addresses and neighbouring property should be excluded, cropped or obscured before publication.

WESTEVO will not make an unsupported privacy, security, environmental or accreditation claim. Direct marketing will comply with applicable data-protection and electronic-communications rules, and every marketing message will provide a straightforward way to opt out.

Security and access controls

  • Use unique authorised accounts and multi-factor authentication wherever available, especially for administrator access.
  • Give each person only the access needed for their role and review privileged access when responsibilities change.
  • Keep supported devices, browsers and security software updated; use screen locks and protect devices from loss or unauthorised use.
  • Use Google Workspace for WESTEVO business email and documents rather than uncontrolled personal storage.
  • Use secure connections and reputable providers; avoid sending unnecessary sensitive information by ordinary email.
  • Protect paper records and portable devices from casual access, and securely destroy records when retention ends.
  • Verify unusual payment, account-change or disclosure requests through a trusted channel before acting.
  • Keep recovery information and backup arrangements protected from the same incident that could affect the main account.

Security controls are reviewed proportionately as WESTEVO's services, staffing, systems and risk profile develop. Public policy wording does not replace the confidential operational details needed to implement those controls.

Suppliers, processors and transfers

A provider that processes personal information for WESTEVO is selected only after proportionate checks covering purpose, security, confidentiality, deletion, sub-processors, breach support and international transfers. Required data-processing terms must be in place before processing begins.

Core website and communication processors currently include:

If a provider processes data outside the UK, WESTEVO will rely on a recognised transfer mechanism, such as UK adequacy regulations or approved contractual safeguards, and will keep the arrangement under review.

Retention and secure disposal

Unconverted enquiries

Delete or anonymise 24 months after the last meaningful contact unless an unresolved issue justifies longer.

Customer and job records

Keep for 6 years after the job or relationship ends, unless a longer legal, insurance or claims need applies.

Tax and account records

Keep at least 5 years after the 31 January filing deadline for the relevant tax year, and longer where HMRC requires.

Complaints and incidents

Keep normal complaint, claim and incident records for 6 years after closure; keep data-rights and data-protection complaint records for 3 years after closure.

Supplier and business contacts

Keep for the active relationship and normally up to 6 years afterwards where linked to a contract, payment, warranty, dispute or legal obligation.

Marketing records

Keep permission while relied on; retain only a minimal suppression record where needed to honour an objection or opt-out.

Duplicate and backup copies

Apply the same underlying period to email, cloud storage, downloads and paper; remove working duplicates and allow protected backups to expire through their controlled cycle.

Harlan West reviews the schedule at least annually. A hold is applied where deletion could prejudice an open complaint, legal claim, insurance matter, tax enquiry, regulator request or rights request. The reason and review date must be recorded.

Individual rights and complaints

Any request about access, correction, erasure, restriction, portability, objection or consent withdrawal is treated as a data-rights request even if the person does not use legal terminology.

  1. Record the date received, scope and contact method.
  2. Confirm identity only to the extent reasonably necessary and avoid requesting excessive identification.
  3. Search all relevant systems, including email, Squarespace, Google Workspace, photographs and paper records.
  4. Protect other people's information and document any exemption or refusal.
  5. Respond without undue delay and normally within one calendar month; record any legally permitted extension and tell the requester within the first month.

A data-protection complaint can be made by emailing hello@westevo.co.uk. WESTEVO will acknowledge it within 30 days, investigate without undue delay, keep the complainant appropriately informed and communicate the outcome. Details of rights, complaints and the ICO are in the Privacy Notice.

Personal-data breach response

A suspected loss, unauthorised disclosure, alteration, access, destruction or loss of availability must be reported immediately to Harlan West. WESTEVO will:

  1. contain the incident, preserve relevant evidence and recover information where safely possible;
  2. record what happened, when it was discovered, the information and people involved, likely consequences and action taken;
  3. assess the risk to people's rights and freedoms without delay;
  4. notify the ICO without undue delay and, where feasible, within 72 hours of awareness if the legal reporting threshold is met;
  5. notify affected people without undue delay if the breach is likely to create a high risk to them; and
  6. document lessons, corrective action and whether supplier or control changes are required.

Every personal-data breach is logged, including incidents that do not meet the ICO reporting threshold. The ICO's current guidance is available on its 72-hour breach-response page.

Training, records and review

  • Anyone given access to personal information must understand this policy, confidentiality expectations, phishing risks, rights requests and incident reporting.
  • WESTEVO keeps proportionate records of processing purposes, lawful bases, retention, processors, important decisions, complaints, requests and breaches.
  • The ICO data-protection fee position is checked when processing changes and at least annually; any fee required by law must be maintained.
  • The website form, cookie settings, access permissions and supplier terms are reviewed after material changes and at least annually.
  • This policy is reviewed by Harlan West by 31 August 2027, or earlier following a material legal, service, system, supplier or incident change.

Non-compliance must be corrected promptly. Serious or repeated issues may lead to access removal, supplier review, retraining, contract action or reporting to the appropriate authority where required.

Policy owner

Contact WESTEVO.

Questions, data-rights requests and data-protection complaints can be sent to Harlan West using the details below.

Harlan West T/A Westevo
Joiners Meadow, Trevillick, Tintagel, Cornwall, PL34 0DN
hello@westevo.co.uk