Introduction
Exall Group ("we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you visit our website at www.exallgroup.com, contact us, or use our services.
We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By using our website or engaging with our services, you acknowledge that you have read and understood this policy.
Who We Are
Exall Group is a commercial roofing and building envelope specialist operating across the United Kingdom. For the purposes of data protection law, Exall Group is the data controller responsible for your personal data.
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
Email: info@exallgroup.com
Phone: 0800 255 0325
Website: www.exallgroup.com/contact
What Personal Data We Collect
We may collect and process the following categories of personal data:
Information You Provide to Us
Contact details: name, email address, telephone number, company name, and job title
Enquiry details: information you provide when completing forms on our website, requesting a quote, or contacting us by phone, email, or post
Project information: details about your property, building, or roofing requirements
Correspondence: records of any communication between you and Exall Group
Information We Collect Automatically
Technical data: IP address, browser type and version, operating system, device type, and screen resolution
Usage data: pages visited, time spent on pages, navigation paths, referring website, and click behaviour
Cookie data: information collected through cookies and similar tracking technologies (see our Cookie section below)
How We Use Your Personal Data
We use your personal data for the following purposes and on the following legal bases:
To respond to your enquiries and provide quotes — based on our legitimate interest in managing customer relationships and, where applicable, to take steps prior to entering a contract
To deliver our roofing and building envelope services — necessary for the performance of a contract with you
To send relevant updates about our services, projects, and industry insights — based on your consent or our legitimate interest in marketing our services to existing and prospective clients
To improve our website and user experience — based on our legitimate interest in enhancing our digital presence
To comply with legal obligations — such as health and safety reporting, tax, and regulatory requirements
To protect our business and enforce our rights — based on our legitimate interests
How We Share Your Personal Data
We do not sell your personal data to third parties. We may share your information with:
Service providers: trusted third parties who assist us with IT services, website hosting, analytics, email delivery, and business operations — all bound by data processing agreements
Professional advisers: accountants, lawyers, and insurers where necessary for business or legal purposes
Regulatory authorities: where required by law or regulation, such as health and safety bodies
Business partners: where necessary to fulfil a project or service you have requested, such as subcontractors and material suppliers involved in your project
Where we use third-party service providers, we ensure appropriate safeguards are in place to protect your data.
Cookies and Tracking Technologies
Our website uses cookies and similar technologies to enhance your browsing experience, analyse website traffic, and understand how visitors use our site.
Types of Cookies We Use
Essential cookies: required for the website to function correctly, such as session management and security
Analytics cookies: help us understand how visitors interact with our website using tools such as Google Analytics
Marketing cookies: used to deliver relevant advertising and track the effectiveness of our marketing campaigns
You can manage your cookie preferences at any time using the cookie consent tool displayed on our website. You can also configure your browser settings to refuse or delete cookies, although this may affect website functionality.
For more information about cookies and how to manage them, visit www.allaboutcookies.org.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements.
As a general guide:
Enquiry data: retained for up to 2 years from the date of your last interaction with us, unless you become a client
Client and project data: retained for up to 7 years after project completion, in line with our legal and contractual obligations
Marketing data: retained until you withdraw your consent or unsubscribe
Website analytics data: retained in anonymised or aggregated form
When your data is no longer required, we will securely delete or anonymise it.
Your Rights
Under UK data protection law, you have the following rights regarding your personal data:
Right of access: request a copy of the personal data we hold about you
Right to rectification: request correction of inaccurate or incomplete data
Right to erasure: request deletion of your data where there is no compelling reason to continue processing it
Right to restrict processing: request that we limit how we use your data in certain circumstances
Right to data portability: request a copy of your data in a structured, commonly used, machine-readable format
Right to object: object to processing based on legitimate interests or for direct marketing purposes
Right to withdraw consent: where we rely on your consent, you may withdraw it at any time
To exercise any of these rights, please contact us at info@exallgroup.com. We will respond to your request within one month, as required by law.
If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk.
Data Security
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, or alteration. These measures include:
Secure hosting with SSL/TLS encryption across our website
Access controls limiting data access to authorised personnel only
Regular security reviews and updates
Staff awareness of data protection responsibilities
While we take all reasonable precautions, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security but are committed to protecting your data to the highest practicable standard.
Third-Party Links
Our website may contain links to external websites operated by third parties. We are not responsible for the privacy practices or content of those websites. We encourage you to read the privacy policy of every website you visit.
Children's Privacy
Our website and services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately and we will take steps to delete it.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. Any changes will be posted on this page with an updated "Last Updated" date.
We encourage you to review this policy periodically to stay informed about how we protect your data.
Abuse Contact
If you wish to report abuse, misuse, or suspicious activity relating to any domain name managed by us, please contact us using the email address below.
Email: abuse-reports@exallgroup.com
This inbox is monitored regularly, and we aim to respond to reports as soon as reasonably possible.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please do not hesitate to contact us:
Email: info@exallgroup.com
Phone: 0800 255 0325
Website: www.exallgroup.com/contact