Effective date: 01/10/2025
Last reviewed: 07/01/2026
1. Introduction
THPP Management Company Limited (“we”, “us”, “our”) is committed to protecting your personal data and respecting your privacy.
This Privacy Policy explains how we collect, use, store and protect personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy applies to residents, leaseholders, freeholders, contractors and others whose personal data we process in connection with the management of the building.
2. Who We Are (Data Controller)
We are the Data Controller for the personal data we process.
Company name: THPP Management Company Limited
Registered address: c/o Plymouth Block Management, Queen Anne’s Battery, Plymouth, PL4 0LP.
Email: admin [at] thppmanagement.co.uk
If you have any questions about this policy or how we use your data, please contact us using the details above.
3. What Personal Data We Collect
We may collect and process the following types of personal data:
Resident and Leaseholder Information
- Name
- Postal address and apartment number
- Email address
- Telephone number
- Emergency contact details
- Proof of ownership or tenancy (where required)
Building Safety and Management
- Records of safety communications and engagement
- Reports of safety concerns or defects
- Responses to consultations and surveys
- Attendance at meetings
Financial and Administrative Data
- Maintenance charge records
- Payment history
- Bank details (where payments are made to or from us)
Other Information
- Complaints or correspondence
- Reasonable adjustments or accessibility needs (where provided)
- CCTV images (if applicable – see section 11)
We do not intentionally collect special category data unless it is necessary and lawful (for example, accessibility needs).
4. How We Collect Personal Data
We collect personal data:
- Directly from you (e.g. forms, emails, surveys)
- From managing agents or professional advisers acting on our behalf
- From public records (e.g. Land Registry)
- Through building systems such as CCTV (if applicable)
5. Lawful Bases for Processing
Under UK GDPR, we rely on the following lawful bases:
- Legal obligation – to comply with laws such as the Building Safety Act 2022
- Contract – to manage the building and provide services
- Legitimate interests – for effective building management and resident engagement
- Consent – where required (e.g. optional communications)
Where consent is used, it can be withdrawn at any time.
6. How We Use Personal Data
We use personal data to:
- Manage and maintain the building
- Comply with building safety and legal requirements
- Communicate with residents and owners
- Carry out consultations and engagement activities
- Manage service charges and accounts
- Handle complaints and enquiries
- Ensure the safety and security of the building
We only use personal data for legitimate purposes and do not process it in a way that is incompatible with those purposes.
7. Sharing Personal Data
We may share personal data with:
- Our Managing Agents
- Accountable Persons and Principal Accountable Persons (where applicable)
- Contractors and consultants (e.g. fire safety inspectors and engineers)
- Professional advisers (e.g. solicitors, accountants)
- Regulatory bodies (e.g. the Building Safety Regulator)
We only share data where necessary and ensure appropriate data protection safeguards are in place.
8. Data Security
We take appropriate technical and organisational measures to protect personal data, including:
- Secure digital systems
- Restricted access to personal data
- Password protection and encryption where appropriate
- Staff and director awareness of data protection obligations
9. Data Retention
We keep personal data only for as long as necessary for the purposes it was collected, including legal and regulatory requirements.
Typical retention periods include:
- Building safety records: in line with statutory requirements
- Financial records: at least 6 years
- Correspondence and complaints: as long as necessary to resolve matters
Data is securely deleted or destroyed when no longer required.
10. Your Data Protection Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request erasure of data (in certain circumstances)
- Restrict processing
- Object to processing
- Data portability (where applicable)
- Withdraw consent (where consent is relied upon)
Requests can be made in writing using the contact details above. We will respond within one month.
11. CCTV
Where CCTV is in operation:
- It is used for safety and security purposes only
- Signage is clearly displayed
- Images are retained for a limited period unless required for investigation
- Access is restricted to authorised persons only
12. Complaints
If you are unhappy with how we handle your personal data, please contact us first. More information, including how you can register a complaint, can be found on our detailed Complaints Procedure page.
You also have the right to complain to the Information Commissioner’s Office (ICO):
www.ico.org.uk
13. Changes to This Policy
We may update this Privacy Policy from time to time. The most recent version will always be available on this website.