Data Retention & Evidence Handling Policy

Version 1.0 · Effective 1 July 2026
FBSA Technology Ltd · Company No. 17249280

1. Purpose 

This policy explains how FBSA Technology Ltd collects, stores, protects, retains, and disposes of survey evidence, inspection records, and personal data. The policy supports the requirements of the AD4 Standard™ and our commitment to Securing the Golden Thread for Wales™, ensuring evidence remains reliable, traceable, and available when required. 

2. AD4 Evidence Integrity 

All inspection evidence is managed in accordance with the AD4 Standard™:

  • Identity – Evidence is attributable to a specific property, inspection, and client.
  • Location – Evidence is linked to the inspected location.
  • Time – Photographs, readings, and records are time-stamped at the point of collection.
  • Integrity – Original evidence is preserved and protected against unauthorised alteration.

FBSA maintains an auditable chain of evidence from collection through to final reporting. Evidence is not altered, manipulated, or edited in any manner that would compromise its evidential value. Any observations, annotations, or conclusions remain linked to the original evidence record. 

3. Lawful Handling of Information 

FBSA processes personal information only where there is a legitimate business purpose, contractual requirement, legal obligation, or consent where required by law. Information is collected only where necessary for:

  • Delivering inspections, surveys, and assessments
  • Producing reports and recommendations
  • Managing enquiries, bookings, and client communications
  • Meeting legal, regulatory, and insurance requirements
  • Maintaining business and financial records

4. Retention Periods 

FBSA retains records for the following minimum periods: Survey Evidence & Inspection Records
15 years AD4 Evidence Reports
15 years EPC Records & Supporting Documentation
15 years Financial & Accounting Records
6 years Complaints, Disputes & Claims Records
6 years Business Correspondence
3 years Records may be retained for longer where required by law, regulatory obligations, ongoing disputes, insurance requirements, or legitimate business interests. 

5. Storage & Security 

FBSA takes reasonable technical and organisational measures to protect information against loss, misuse, unauthorised access, disclosure, alteration, or destruction. Measures include:

  • Encrypted digital storage systems
  • Secure UK-based cloud backups
  • Password-protected devices and accounts
  • Multi-factor authentication where available
  • Restricted access controls
  • Routine backup and recovery procedures
  • Regular software and security updates
  • Secure transmission of reports and client documentation

Access to survey evidence and retained records is restricted to authorised personnel only. Responsibility for evidence management rests with David Matthews, Director of FBSA Technology Ltd

6. Data Breaches & Security Incidents 

FBSA takes all reasonable precautions to prevent data breaches and security incidents. Any suspected or confirmed breach involving personal data or retained evidence will be investigated promptly and appropriate corrective action taken. Where required by law, FBSA will notify affected individuals and the Information Commissioner's Office (ICO) within the applicable statutory timescales. 

7. Client Rights

 Individuals may request access to personal data held by FBSA and may exercise other rights available under applicable data protection legislation, subject to any lawful exemptions. Requests should be submitted in writing to: Email: david.matthews@fbsa.co.uk 

8. Disposal of Records 

When retention periods expire and records are no longer required, they are securely disposed of using appropriate deletion or destruction methods designed to prevent recovery, reconstruction, or unauthorised access.

 9. Accountability

Overall responsibility for data retention, evidence management, and information security rests with David Matthews, Director of FBSA Technology Ltd. FBSA is committed to continual improvement in its management systems, information governance, and evidence handling procedures. 

10. Policy Review 

This policy will be reviewed at least annually, or sooner where required by changes in legislation, regulatory requirements, business operations, security risks, or industry best practice. All revisions will be version controlled and recorded to maintain document integrity and traceability. Evidence Preserved. Integrity Maintained. Confidence Assured.

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.