Scope and responsibility
This policy sets the security standard for Bacland Limited's information, including client and resident data, surveys and drawings, access details, financial and personnel records, credentials and contracts. The Director is accountable for it. Staff and subcontractors follow the controls that apply to the information they handle.
Access and devices
- Each user has a named account with only the access their role needs.
- Multi-factor authentication is used on company email and cloud storage, with unique passwords held in a password manager.
- Devices are encrypted where supported, screen-locked, kept up to date and protected against malware.
- Access is reviewed when roles change and removed within 1 working day of an engagement ending.
Sharing property information
We use approved company storage and sharing methods and check recipients before sending. Survey data, security layouts, keys, entry codes and occupancy details are treated as sensitive: access is restricted, shared links are reviewed and removed when no longer needed.
Personal accounts and unmanaged messaging apps are not used to get around these controls.
Suppliers and retention
Suppliers that handle our information are assessed and bound by suitable confidentiality and data processing terms, and we check where data is hosted and any international transfer requirements.
Project and financial records are kept for 6 years after completion (12 years for contracts executed as a deed), and enquiry records for 2 years after last contact, unless a contract or the law requires otherwise. Information is then securely deleted. Records are held longer where needed for a dispute or incident.
Incidents and continuity
Suspected loss, unauthorised disclosure, phishing or compromised passwords must be reported immediately to the Director at contact@baclands.co.uk (subject "Security incident") or by phone on 020 7096 9989. We contain the incident safely, preserve evidence and record decisions.
We assess promptly whether clients, regulators or affected people must be told; a personal data breach that must be reported is notified to the ICO within 72 hours. Business data is backed up and recovery is tested at least once a year.
Review
Users are briefed on this policy, and risks, access and incidents are reviewed at least annually and after significant changes. This public summary does not disclose operational security details. We do not hold a security certification.
Approved by the Director on 11 October 2026. Next review October 2027.