Privacy Policy

Close-up of a combination lock on a computer keyboard with white keys, featuring a yellow sticky note nearby.
A person holding a smartphone with a screen displaying a VPN protection icon, with a green shield and a check mark, in front of a leafy green background.

Last Updated: June 2, 2026

At A. Semmens Health & Safety Consultancy, we are committed to protecting and respecting your privacy. This Privacy Policy explains when, why, and how we collect personal information about people who visit our website, engage our consultancy services, or otherwise interact with us, as well as how we keep it secure and your rights regarding your data.

1. Who We Are

A. Semmens Health & Safety Consultancy operates as a data controller. This means we are responsible for deciding how we hold and use personal information about you.

If you have any questions regarding this policy or our privacy practices, you can contact us via email or phone through our primary business channels.

2. How We Collect Your Information

We obtain information about you when you interact with our business. For example, this occurs when you:

  • Enquire about or engage our health and safety consultancy services.

  • Contact us via email, phone, or contact forms.

  • Provide business cards, documentation, or site information during corporate consultations.

  • Allow us to conduct on-site inspections, audits, and risk assessments, which may include taking photographs of workspaces, equipment, and operational practices.

  • Visit our website (via cookies and analytical tracking).

3. The Types of Data We Collect

We may collect, store, and use the following categories of personal information:

Corporate & Client Data

  • Contact details: Name, professional title, company name, email address, telephone number, and business address.

  • Operational details: Information regarding your company’s infrastructure, employee rosters, incident logs, risk assessments, or specific workplace hazards required for safety audits.

  • Site Photographic Data: Photographs captured during workplace inspections and safety audits. These images are used strictly as visual evidence to document compliance, highlight specific hazards, or clarify safety recommendations in our consultancy reports.

  • Financial data: Billing addresses, bank account details, and transaction histories for invoicing and accounting purposes.

Website & Technical Data

  • Technical Identifiers: IP addresses, browser types, operating systems, and automated tracking data showing how you navigate our website.

4. How Your Information is Used

We will only use your personal data when the law allows us to. Most commonly, we use your data under the following legal bases:

Purpose / Activity

Type of Data

Legal Basis for Processing

To deliver consultancy services: Conducting risk assessments, workplace audits, safety training, and drafting health & safety policies.

Client Contact, Operational Data

Performance of a Contract with you.

Site Photography: Capturing visual evidence of hazards or compliant setups during active site audits to include in official client reports.

Site Photographic Data

Performance of a Contract & Legitimate Interests (ensuring accurate, evidence-based safety reporting).

Business administration: Managing invoices, processing payments, and maintaining tax records.

Financial, Client Contact

Performance of a Contract & Legal Obligation.

Answering enquiries: Responding to potential client queries submitted through our website or via email.

Client Contact

Legitimate Interests (to supply requested information).

Improving website performance: Analysing user traffic to ensure content is presented effectively.

Technical Data

Legitimate Interests (to optimise our digital tools).

5. Specific Protocols for Site Photography

When taking photographs for health and safety audits, our primary focus is on equipment, machinery, infrastructure, and physical working environments.

We make every reasonable effort to avoid capturing identifiable individuals (faces) or sensitive personal data. If an employee or bystander is incidentally captured in a photograph and their identity is visible, we will apply digital blurring or redaction to their face/identifying features before the final report is issued or archived, unless their identity is critical to illustrating a specific safety breach (e.g., lack of mandatory PPE) and processing is permitted under our contract with the client.

6. Use of Artificial Intelligence (AI) Tools

Our Zero-Data AI Policy: We may occasionally use Artificial Intelligence (AI) software and large language models to assist with administrative efficiency, such as formatting documents, proofreading, or optimising the structural layout of health and safety manuals and reports.

To guarantee total confidentiality, we enforce a strict zero-input policy regarding personal and identifying information. No names, specific company titles, financial details, site locations, or identifying photographs are ever submitted, uploaded, or processed within third-party AI tools. All generative drafting is done using entirely anonymised, generic templates or technical phrases, ensuring your private data never enters external AI training sets or logs.

7. Data Sharing & Third Parties

We do not sell or rent your information to third parties. We will not share your information with third parties for marketing purposes.

We may, however, pass your information to third-party service providers working strictly on our behalf. These include:

  • Cloud storage and professional software providers used to securely manage risk assessments, photographic evidence, and consultancy reports.

  • Accounting and invoicing platforms required for standard financial operations.

  • Regulatory authorities or legal advisors if required by law, or to enforce our business contracts.

All our third-party service providers are required to take appropriate security measures to protect your personal information in line with UK data protection laws.

8. Where We Store Your Data & Security Measures

We implement rigorous physical, electronic, and managerial security measures to protect your data from unauthorised access, loss, alteration, or disclosure.

  • Digital data—including all site audit photographs—is stored on secure, password-protected devices, encrypted local storage, or secure cloud environments.

  • Where hard-copy site documentation exists, it is securely locked away when not in use.

International Data Transfers

While we operate primarily within the United Kingdom, some of our software-as-a-service (SaaS) providers (such as cloud storage) may store data on servers located outside the UK or the EEA. Where this occurs, we ensure that appropriate safeguards (such as UK International Data Transfer Agreements) are in place to guarantee your data remains protected.

9. Data Retention

We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

For standard consultancy contracts, we typically retain core health and safety records, project briefs, associated audit photographs, and risk assessment reports for 6 years following the completion of the service, in line with corporate liability, professional indemnity requirements, and UK tax regulations.

10. Your Legal Rights

Under the UK GDPR, you have specific rights regarding your personal data. You have the right to:

  • Access: Request a copy of the personal information (including photographic data) we hold about you.

  • Correction: Request that we correct any inaccurate or incomplete data.

  • Erasure ("Right to be Forgotten"): Request that we delete your data where there is no compelling legal reason for its continued processing.

  • Restriction: Request that we suspend the processing of your data under certain conditions.

  • Data Portability: Request the transfer of your data to another organisation.

  • Objection: Object to the processing of your data where we are relying on a legitimate interest.

If you wish to exercise any of these rights, please contact us directly.

You also have the right to lodge a formal complaint at any time with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us first.

11. Changes to This Policy

We keep this Privacy Policy under regular review. Any updates will be posted directly to this page.

Contact Us