Privacy Framework & Data Protection Policy

Last Updated: July 2026

Southgate Global Services Limited (“Southgate Global”, “we”, “us”, or “our”) is committed to protecting the privacy and security of your personal data. This Privacy Framework outlines how we collect, process, store, and protect the personal information of our framework partners, subcontractors, tier-1 contractors, and site operatives.

This policy complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Southgate Global acts as the Data Controller for the personal data we process.

1. The Data We Collect

To manage infrastructure deployments, workforce logistics, and framework administration, we collect and process specific categories of data:

  • Identity & Contact Data: Full name, title, date of birth, current address, email addresses, and operational contact numbers.
  • Professional & Vetting Data: Right-to-work documentation, CSCS card details, trade certifications (e.g., banksmen qualifications), health and safety compliance records, and employment history.
  • Financial Data: Bank account details and National Insurance numbers required for payroll and sub-contractor invoicing.
  • Logistics & Fleet Data: For operatives utilising our 16+ seat transit fleets, we may process collection point logs, transit schedules, and GPS routing data for safety and deployment tracking.
  • Technical & Usage Data: IP addresses, browser types, and interaction metrics when you use our tender submission portal or online application forms.

2. How We Use Your Data

We will only use your personal data when the law allows us to. Most commonly, we use your data to execute our corporate delivery partnerships and manage workforce welfare:

  • Contract Execution: To process framework applications, finalise subcontractor agreements, and assign operatives to active tier-1 civil engineering deployments.
  • Health, Safety, and Welfare: To ensure all deployed personnel meet strict site safety requirements, coordinate compound access, and manage site welfare cabin provisions.
  • Operational Logistics: To coordinate dispatch hubs, manage central collection checkpoints, and eliminate site congestion through organised transport.
  • Legal & Regulatory Compliance: To maintain mandatory HSE policy documentation and comply with UK employment and tax laws.

3. Data Sharing & Third-Party Disclosure

We do not sell your personal data. We only share data with trusted third parties under strict operational necessities:

  • Tier-1 Framework Partners: We share necessary vetting, certification, and identity data with principal contractors (e.g., HS2, Costain) to grant site access and comply with their internal security audits.
  • Service Providers: Third-party IT administrators, payroll processors, and logistics software providers acting as processors on our behalf.
  • Regulatory Authorities: HM Revenue & Customs, the Health and Safety Executive (HSE), and other UK regulators requiring reporting of processing activities in certain circumstances.

4. Data Security & Retention

We have implemented appropriate structural and digital security measures to prevent your personal data from being accidentally lost, used, accessed in an unauthorised way, altered, or disclosed.

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.

  • Active Operatives & Partners: Data is retained for the duration of your active framework partnership.
  • Unsuccessful Applications: Vetting and application data is securely purged after 6 months if a placement is not secured, unless you grant explicit consent for us to keep your profile on our reserve dispatch list.

5. Your Legal Rights

Under the UK GDPR, you hold specific rights regarding your personal data:

  • Request access to your personal data (a “data subject access request”).
  • Request correction of incomplete or inaccurate data we hold about you.
  • Request erasure of your personal data where there is no good reason for us continuing to process it.
  • Object to processing of your personal data under certain operational circumstances.
  • Request the restriction of processing your personal data.

6. Contacting the Data Protection Desk

If you have any questions about this Privacy Framework or wish to exercise your legal rights, please contact our administrative desk:

  • Email: info@southgateglobal.co.uk
  • Corporate Address: Bridge House Sherington, Newport Pagnell, Milton Keynes, MK16 9JA

You hold the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns operationally before you approach the ICO.