Security recruitment & payroll
+44 (0)161 531 5341contact@chorltonprimeprotect.co.uk
Privacy notice

Personal information used for a defined purpose and role.

This notice explains the website enquiry process and the principles that apply where CP Protect later handles client, applicant, worker or payroll information under written terms.

Notice informationReviewed 18 August 2026

This notice is not a substitute for the service-specific privacy information and contracts required before worker onboarding or payroll-data processing begins.

Website enquiriesStored for response
Service-data roleConfirm in writing
Who is responsible

The legal role follows the processing—not the brand label.

Chorlton Prime Limited, trading as CP Protect, is controller for personal information it decides to use for its own business purposes. Company number 14183140. Registered office: Bartle House, Oxford Court, Manchester, M2 3WQ.

When CP Protect is controller

We decide why and how information is used.

This may include our own enquiries, contracts, supplier records, recruitment activity, complaints, legal obligations and security records. We must provide the relevant privacy information when we collect or otherwise obtain that data.

When CP Protect is processor

We follow a controller's documented instructions.

This may apply to defined payroll or workforce administration for a client. A written data-processing agreement must identify the controller, instructions, security requirements, processors, assistance duties and return or deletion arrangements.

Information we may use

Information must be relevant to the relationship and service.

The exact information depends on whether you are a client contact, supplier, applicant, worker or payroll-service user.

01

Enquiry and client information

Names, organisations, roles, contact details, correspondence, service requirements and commercial records.

02

Applicant and worker information

Contact details, work history, availability, assignment and onboarding information, with identity, right-to-work or licence information collected only through an approved route where required.

03

Time and payroll information

Approved hours, rates, pay-cycle records, bank and tax information, deductions and query history only where payroll processing forms part of a documented role.

04

Technical and security information

Device, access, hosting and security-log information generated when the website or an authorised operational system is used.

Sensitive documents do not belong in the website enquiry.

Do not send passports, right-to-work evidence, criminal-record information, National Insurance details, bank details or copies of licences through the initial form. CP Protect must first confirm why the information is needed, its legal basis and condition, who controls it, and an appropriate collection route.

Purpose and lawful basis

The basis must match the actual activity.

Consent is not treated as a default basis for core recruitment, employment or payroll activity. Where it is genuinely used, it must be specific and as easy to withdraw as it was to give.

Enquiries and requested steps

To respond, understand a requirement and take steps requested before a possible contract. Depending on who is enquiring, the basis may be requested pre-contract steps or our legitimate interest in managing genuine business communications.

Recruitment and workforce services

To assess suitability, coordinate an agreed service and meet applicable recruitment, employment, tax, licensing or record-keeping duties. The precise purpose and basis must be stated in the relevant worker or client information before collection.

Payroll-processing support

To perform documented payroll-processing instructions or meet CP Protect's own legal and accounting duties. The contract must identify whether CP Protect is controller, processor or acting in different roles for different records.

Security, claims and service quality

To protect people and systems, prevent misuse, manage complaints and establish, exercise or defend legal claims. Any legitimate interest is limited to proportionate business, security and legal-administration needs.

Where information may come from

Direct and authorised sources.

  • You, or a person authorised to act for you
  • A client, hirer, employer, employment business or payroll controller
  • Referees and verification providers used through an approved process
  • Professional or public registers, including the SIA licence register where relevant
  • Service providers and public authorities where disclosure is lawful

Where we obtain information from someone else, we must provide the required privacy information within the applicable time unless a lawful exception applies.

Who may receive information

Only for a relevant, documented purpose.

  • Relevant clients, hirers, workers or engaging organisations
  • Contracted IT, hosting, transactional email, communications and payroll providers
  • Accountants, banks, pension or professional advisers where relevant
  • Approved screening or verification providers where lawfully used
  • HMRC, the SIA, courts, regulators or law enforcement where required

We do not sell personal information. A provider acting as processor must be bound by appropriate data-protection terms.

Website enquiries

The form stores the details needed to respond.

The enquiry form stores your name, email address, selected service and message. It also stores organisation, telephone, location and proposed start date if you choose to provide them. The form does not store an IP address or browser user-agent in the enquiry record.

Providing enquiry information is voluntary, but without enough contact and requirement information we may be unable to respond or assess a proposed service. The form is not a worker-onboarding, identity-check or payroll-data collection route.

The website enquiry database remains the authoritative record. If enquiry alerts are configured, a transactional email provider may process the information needed to notify an authorised site operator. An alert is a notification only; it does not replace or alter the stored database record.

Enquiry retentionWebsite enquiries are intended to be kept for no longer than 12 months.

When a new enquiry is submitted, the system deletes stored enquiry records older than 12 months. CP Protect must also maintain an owner-controlled review so deletion does not depend only on a future submission.

If email alerts are enabled, notification copies and delivery logs may also exist in the authorised mailbox and provider systems. Access must be restricted, the provider must act under appropriate data-protection terms, and those copies must not be kept longer than needed for the enquiry and delivery records.

Cookies and measurement

No advertising or analytics cookies are currently set by the application.

Hosting and security services may process strictly necessary technical data or logs to deliver and protect the website. Read the current cookie notice. It must be reviewed before optional analytics, advertising or embedded services are introduced.

Employment and payrollProcessing payroll does not by itself identify the employer.

The relevant contract, worker terms and privacy information must identify the employer or engaging party, who operates PAYE and RTI, and which organisation controls each category of information.

Retention and security

Keep only what remains necessary and lawful.

Retention outside the website enquiry database depends on the type of record, relationship, legal duties, limitation periods and the need to establish or defend claims. The applicable period or objective deletion criteria must be recorded in CP Protect's retention schedule and relevant service information.

We use proportionate organisational and technical safeguards, but no internet or storage system can be guaranteed completely secure.

International processing

Provider locations and safeguards must be checked.

If information is processed outside the UK, the controller must identify an applicable adequacy regulation, UK transfer agreement or other lawful safeguard and complete any required transfer-risk work. Information about an applicable safeguard can be requested using the contact details below.

When the website form is submitted, an internal alert may be sent through our business email provider to the appropriate workforce, payroll or worker-support address. The enquiry remains stored for follow-up even if that alert cannot be delivered.

Your information rights

Rights depend on the data, purpose and lawful basis.

Subject to the circumstances and legal exemptions, you may have rights to access, correct, erase or restrict personal information, receive portable data and withdraw consent. You can also ask for information about the source, recipients and retention of data we control.

Your right to object

You may object to processing based on legitimate interests. You may object at any time to direct marketing. CP Protect does not use the website enquiry form to enrol people in direct marketing.

Privacy contactChorlton Prime Limited trading as CP Protect

Bartle House, Oxford Court, Manchester, M2 3WQ

contact@chorltonprimeprotect.co.uk

You may complain to the Information Commissioner's Office at ico.org.uk. You can also read our complaints route.

Service-specific information

General website wording is not enough for onboarding or payroll.

Before collecting service data, the relevant party must provide the worker, applicant or client with information matching the actual employment, recruitment, payroll and controller/processor model.