Your Basket Basket

(0 items £0.00)

Checkout
For sales & advice - Mon - Fri, 9.30am - 4.30pm
 0330 174 08510330 174 0851
Or email us here

Lock Shop Direct

Privacy Notice

This Privacy Notice, also referred to on parts of our website as our Privacy Policy, explains how N L S Security Limited uses personal information when you browse our website, contact us, request advice or a quotation, create an account, place an order, use a trade account, arrange a return or warranty claim, or otherwise deal with Lock Shop Direct.

Data controller N L S Security Limited trading as Lock Shop Direct
Version 2026.2 - effective
Privacy contact info@lockshopdirect.co.uk · 0330 174 0851
Your privacy matters. We use personal information only for identified business and legal purposes, restrict access to it, and do not sell customer personal information. This notice does not ask you to “accept” our use of information: it explains what we do, the lawful grounds we rely on, and the choices and rights available to you.

1. Who we are

The data controller is N L S Security Limited, trading as Lock Shop Direct. A data controller decides why and how personal information is used.

N L S Security Limited trading as Lock Shop Direct
Fort House, 173 West Road, Newcastle upon Tyne, NE15 6PQ
Company number 07555260 · VAT number 297 7588 75
Email: info@lockshopdirect.co.uk
Telephone: 0330 174 0851

We have a privacy contact rather than presenting an individual on this public page as a statutory Data Protection Officer. Please use the contact details above for privacy enquiries, rights requests or data protection complaints.

2. Scope of this notice

This notice applies to personal information used in connection with:

  • www.lockshopdirect.co.uk, customer accounts, checkout and related online services;
  • orders, quotations and enquiries made online, by email, by telephone or at our trade counter;
  • product identification, measurements, key cutting, keyed-alike and master-key systems, restricted keys, safes and security hardware;
  • delivery, direct shipment, returns, refunds, complaints, technical support, warranties and product-safety matters;
  • consumer customers, sole traders, business contacts and people acting for companies or other organisations; and
  • marketing preferences, customer feedback and review invitations where these activities are used.

Separate privacy information may be provided where a different activity requires it, for example recruitment or employee administration. Links to external websites are governed by the external organisation's own privacy information.

3. Personal information we collect

The information collected depends on how you interact with us. It may include the following.

Category Examples
Identity and contact Name, title, business or organisation, job title, billing and delivery addresses, email address, telephone numbers and nominated recipient or authorised contact.
Account and authentication Customer or trade-account number, username, account status, login and security records, communication preferences and order history. Passwords should be protected by the website's authentication controls; we do not need to see your password to deal with an order.
Order and transaction Products, quantities, prices, discounts, dates, order and invoice numbers, purchase orders, VAT information, payment method and status, refunds, credits, warranties and related correspondence.
Delivery and access Delivery address, recipient, carrier tracking, proof of delivery, safe-place or access instructions, site restrictions and information needed for heavy or specialist deliveries.
Security-product and technical Key codes, photographs of keys, locks, doors or hardware, measurements, product references, master-key schedules, keyed-alike groupings, restricted-system references, security-card or authority details, signatures, safe or site information and technical advice records.
Customer service Enquiries, emails, contact-form messages, call notes, photographs, video, returns, faults, complaints, warranty evidence, installation information and the outcome requested.
Website and device Internet Protocol address, browser and device details, referring and exit pages, site searches, page and product activity, basket actions, diagnostic logs, cookies, similar technologies and consent choices.
Marketing and feedback Subscription and opt-out choices, campaign interactions, review invitation status, feedback and reviews that you choose to submit.
Fraud, safety and authority checks Payment-risk indicators, failed authorisations, unusual-order information, evidence of authority for restricted keys or systems, and information needed to protect customers, staff, property and our services.
Trade account Company details, authorised buyers, purchase orders, account limits, payment history and, where relevant, information used to assess or manage credit.

We do not normally ask for special-category information such as health information. If you provide accessibility, health or safety information because it is necessary for delivery or service arrangements, we use only what is reasonably required and apply an appropriate legal condition.

4. Where personal information comes from

We normally obtain information directly from you when you browse, contact us, create an account or place an order. We may also receive relevant information from:

  • your employer, colleague, contractor, landlord, managing agent or another person ordering or enquiring on your behalf;
  • payment providers, banks and fraud-prevention services;
  • carriers, suppliers, manufacturers, direct-shipping partners, key-system licensors and warranty agents;
  • review or marketing providers where you interact with their service;
  • public sources such as Companies House, company websites and professional directories where relevant to a business account; and
  • website, analytics, security and consent-management technologies, according to your choices and applicable law.

If you provide another person's information, such as a delivery recipient or authorised system contact, you should have authority to do so and make this notice available to them where appropriate.

5. Why we use information and our lawful bases

Data protection law requires a lawful basis for each use. The basis may differ according to whether you buy personally or act for an organisation.

Purpose Information typically used Lawful basis
Answer enquiries, identify products and prepare quotations Contact details, photographs, measurements, technical and site information. Steps requested before a contract; legitimate interests in giving accurate advice and developing business with organisations.
Create and manage accounts, process orders and take payment Identity, contact, account, order, payment-status and transaction records. Contract where you are the customer; legitimate interests where you act for an organisation; legal obligations for financial and tax records.
Cut keys and configure keyed-alike, master-key or restricted systems Key codes, schedules, system references, authority evidence, contact and order information. Contract or requested pre-contract steps; legitimate interests in security, accuracy, fraud prevention and supporting authorised repeat orders.
Deliver goods and arrange specialist services Recipient, address, telephone, email, access information, order and tracking data. Contract; legitimate interests in efficient delivery and service administration.
Handle returns, faults, warranties, complaints and product-safety issues Order, communication, technical evidence, photographs, payment and delivery records. Contract; legal obligations, including consumer and product-safety duties; legitimate interests in resolving issues and defending claims.
Maintain accounts, tax and business records Invoices, payments, refunds, customer and supplier records. Legal obligation; legitimate interests in financial management, audit and debt recovery.
Operate and secure the website, accounts and systems Device data, logs, account events, payment-risk and security information. Legitimate interests in availability, security, abuse prevention and fraud prevention; consent or a specific PECR exception for device storage or access where required.
Measure and improve the website and customer experience Cookie choices, browsing, searches, product interactions and aggregated statistics. Consent where required; where a statutory statistical or appearance exception is properly used, that exception together with legitimate interests and a simple means to object.
Send service messages Contact and order information. Contract and legitimate interests. Dispatch, safety, account and support messages are not treated as optional marketing merely because they are sent electronically.
Send marketing about relevant products and services Contact details, purchase history and preferences. Consent, or legitimate interests and the existing-customer “soft opt-in” where the legal requirements are met; legitimate interests for appropriate corporate business contacts. Electronic marketing is also subject to PECR.
Request and manage customer reviews Name, email, order reference, product and feedback information. Legitimate interests in obtaining genuine feedback and improving service; consent or the soft opt-in where a message also contains direct marketing.
Establish, exercise or defend legal rights Any relevant order, communication, security, payment or technical information. Legal obligation and legitimate interests in protecting our business and others' rights.
Manage a sale, restructure or transfer of the business Relevant customer, supplier and account information, subject to confidentiality and minimisation. Legitimate interests in corporate administration and continuity; legal obligation where applicable.

Where we rely on legitimate interests, we consider the purpose, necessity and effect on individuals. You can object in the circumstances explained in section 16. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful use.

6. Information needed to provide products and services

Some information is necessary to enter into or perform a contract, comply with law, verify authority, take payment or deliver safely. For example, we cannot normally process an order without a customer name, contact route, delivery address and payment information. We may be unable to manufacture a keyed system without an approved schedule, or supply a restricted key without the required authority.

Where information is optional, the relevant form or interaction should make that clear. You do not have to agree to optional analytics or marketing in order to place an ordinary order.

7. Keys, locks and security-system records

Key codes, master-key schedules, restricted-system references, security-card details, photographs and site information are not automatically “special category” data under data protection law, but they may be security-sensitive. We therefore aim to:

  • collect only the information reasonably needed for identification, manufacture, authority checks, fulfilment, support and repeat supply;
  • restrict access to staff and service providers who need it for their role;
  • avoid displaying complete security information unnecessarily in routine communications or public areas;
  • verify authority where the system or manufacturer requires it; and
  • retain system information according to the criteria in section 11 rather than deleting active system records prematurely.
Protect the information you send us. Do not include access codes, alarm codes, card PINs, full payment-card details or unrelated confidential information in ordinary email or web forms. When sending a key photograph or security card, include only what is necessary and use the method requested by our team.

8. Payments

Online card payments are currently offered through the payment options shown at checkout, including Barclays ePDQ, and PayPal is also offered as a payment method. We may also accept telephone payments, bank transfer, pro forma payment or approved trade-account arrangements.

Card information entered into a hosted or secure payment facility is handled by the payment provider under its own security and privacy arrangements. We do not normally store the full card number or card security code. We retain transaction references, payment status, amount and related records needed to fulfil the order, provide refunds, reconcile accounts, prevent fraud and comply with law.

Payment providers and banks may act as independent controllers for some processing, including authentication, fraud checks and regulatory compliance. Their privacy information applies to those activities.

9. Who we share personal information with

We share only information reasonably necessary for the relevant purpose. Recipient categories may include:

  • payment and banking providers, including Barclays ePDQ, PayPal and the payment options shown at checkout;
  • delivery and logistics providers, including carriers such as DPD and DHL, specialist safe carriers, pallet networks and collection agents;
  • suppliers, manufacturers and direct-shipping partners where they fulfil an order, cut or configure a product, verify a system, provide technical support or assess a warranty claim;
  • key-system licensors and authorised security partners where authority or system registration must be checked;
  • website, hosting, email, communications, software and IT-support providers that operate or protect our systems;
  • analytics, personalisation and marketing providers, including Google and Salesfire where the relevant technology or service is enabled;
  • review providers, including eKomi or another provider identified in a review invitation or website widget;
  • accounting, banking, tax, debt-recovery and professional advisers;
  • insurers, brokers, legal advisers, experts and dispute-resolution bodies where needed for a claim or complaint;
  • regulators, HM Revenue & Customs, law-enforcement bodies, courts and other authorities where required or lawfully requested; and
  • a buyer, investor or successor in connection with a genuine business transaction, subject to appropriate confidentiality and data-protection steps.

N L S Security Limited operates more than one trading activity and may use shared staff or systems. Information may be accessed within the same legal company where necessary for fulfilment, customer service, finance, security or legal compliance. We do not sell customer personal information to data brokers.

10. International transfers

Some technology, payment, analytics, review or support providers may store or access information outside the United Kingdom. Where UK data protection law restricts a transfer, we use an appropriate mechanism, which may include:

  • transfer to a country covered by UK adequacy regulations;
  • the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses;
  • another lawful safeguard or an applicable legal exception; and
  • supplementary technical, contractual and organisational measures where appropriate.

You may contact us for further information about the safeguards relevant to a particular transfer.

11. How long we keep personal information

We keep information only for as long as reasonably necessary for the purpose collected, legal and accounting duties, security, warranties, repeat supply and the establishment or defence of claims. We use the following general criteria.

Record Normal retention approach
Enquiries, quotations and product-identification material where no order follows Normally up to 2 years after the last meaningful contact, unless a longer period is reasonably needed for a continuing project, complaint or legal issue.
Orders, invoices, payments, refunds and core customer-service records Normally 6 years after the end of the relevant financial year or completion of the transaction, and longer where a warranty, legal claim or statutory requirement remains relevant.
Customer and trade accounts While active and normally for up to 6 years after closure or the last transaction. Dormant accounts are reviewed and may be disabled or reduced sooner.
Delivery and tracking information Operational tracking is normally kept for up to 2 years. Evidence needed as part of the order, complaint or claim file may be kept with that file for longer.
Key codes, master-key schedules, restricted-system references and authority records For the life of an active system or for as long as authorised repeat supply and support can reasonably be expected. Inactive system records are periodically reviewed, including after prolonged inactivity, but may be retained longer where requested by the system owner or justified by security, warranty or legal needs.
Photographs, videos, measurements and technical records Normally up to 2 years if no order follows; where linked to an order or security system, they may be kept with the order or system record for the periods above.
Marketing records Until you unsubscribe, withdraw consent, object, or the information is no longer reasonably useful. We may retain a minimal suppression record for as long as necessary to ensure we respect an opt-out.
Website security logs, fraud records and consent records Ordinary logs are usually retained for a limited operational period, commonly up to 12 months. Evidence relating to suspected fraud, abuse, a security incident or a legal claim may be kept for up to 6 years or longer where proceedings require it. Cookie durations are described in the Cookie Policy.
Complaints, rights requests and legal claims Normally up to 6 years after closure, and longer where litigation, regulatory action or another legal obligation requires it.

When information is no longer needed, we delete it, anonymise it or place it beyond routine use in accordance with our systems and legal obligations. Backup copies may remain for a limited cycle before being overwritten.

12. Marketing, service messages and customer reviews

Service communications

We may contact you about an enquiry, quotation, account, payment, order, delivery, recall, safety issue, return, warranty or complaint. These operational messages are necessary to provide the service and are not optional marketing.

Electronic marketing

We send marketing emails, texts or similar messages to individuals only where permitted by the Privacy and Electronic Communications Regulations. This may be because you consented, or because the existing-customer soft opt-in applies and you were offered a clear opt-out when your details were collected and in every later message. Different rules may apply to corporate business contacts, but we still provide a simple opt-out and respect objections to use of personal information for direct marketing.

You can unsubscribe using the link in a message or contact info@lockshopdirect.co.uk. An opt-out does not stop essential order or safety communications.

Review invitations

After a purchase we may invite you to provide service or product feedback, directly or through a review provider such as eKomi. We may share the minimum information needed to issue and authenticate the invitation, such as your name, email address, order date, order reference and product information. Submitting a review is voluntary. If an invitation also promotes products or services, the direct-marketing rules apply.

13. Cookies and similar online technologies

Our website uses cookies and may use local storage, pixels, tags, scripts and similar storage or access technologies. Necessary technologies support sessions, baskets, checkout, security, account access and consent choices. Optional technologies may provide analytics, personalisation, advertising measurement or other features.

Read our Cookie Policy for categories, providers, typical durations and how to manage your choices.

Open the Cookie Control Centre

14. Fraud checks, profiling and automated decisions

We may use order, device and payment-risk information to identify suspicious activity, protect accounts and decide whether an order needs manual verification. Website tools may also group browsing behaviour to measure performance or personalise content where the relevant consent or legal exception applies.

We do not ordinarily make decisions about customers solely by automated means that produce legal or similarly significant effects. Payment providers, card issuers and fraud-prevention services may use automated checks under their own privacy information and may decline or refer a transaction. Where applicable law gives you a right to request human intervention or challenge a solely automated significant decision made by us, you may contact our privacy contact.

15. How we protect personal information

We use proportionate technical and organisational measures designed to protect personal information against accidental or unlawful loss, misuse, alteration, unauthorised access or disclosure. Measures include role-based access, account and device controls, secure connections, backups, staff procedures, supplier due diligence and additional restrictions for security-sensitive records.

No internet transmission or storage system can be guaranteed completely secure. Please use strong, unique passwords, keep account and security-system information confidential, and tell us promptly if you believe an account or communication has been compromised.

16. Your data protection rights

Depending on the circumstances and the lawful basis, you may have the right to:

  • be informed about how personal information is used;
  • request access to your personal information;
  • request correction of inaccurate or incomplete information;
  • request erasure in circumstances where we do not have a continuing lawful reason to keep it;
  • request restriction of use in certain circumstances;
  • object to processing based on legitimate interests and object at any time to use for direct marketing;
  • request portability of information you provided where the legal conditions apply;
  • withdraw consent at any time where consent is the basis; and
  • raise concerns about solely automated significant decisions where the legal right applies.

Rights are not absolute and exemptions may apply, for example where information must be retained for tax, fraud prevention, another person's rights or legal claims. We normally respond within one month, subject to any permitted extension. We may ask for information reasonably needed to verify identity, authority and the scope of the request.

To exercise a right, email info@lockshopdirect.co.uk with the subject line Data Protection Request, or write to the address in section 1. There is normally no fee, although the law permits a reasonable fee or refusal in limited circumstances.

17. How to make a data protection complaint

If you are unhappy with how we have used personal information, please contact us so we can investigate and try to resolve the issue.

Subject: Data Protection Complaint
Email: info@lockshopdirect.co.uk
Post: Privacy Contact, N L S Security Limited, Fort House, 173 West Road, Newcastle upon Tyne, NE15 6PQ

Please explain what happened, the information or order involved, relevant dates, any previous correspondence and the outcome you are seeking. Do not send original identity documents unless we specifically request them.

We will:

  • provide an accessible way to submit the complaint;
  • acknowledge receipt within 30 days;
  • take appropriate steps without undue delay, including making proportionate enquiries and keeping you informed where necessary; and
  • tell you the outcome without undue delay.

You also have the right to complain to the Information Commissioner's Office. The ICO can be contacted through its website, by telephone on 0303 123 1113, or at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would appreciate the opportunity to address the concern first, but this does not remove your right to contact the ICO.

18. Children and third-party websites

Lock Shop Direct's online shop and sales services are not directed at children. We do not knowingly use children's personal information for marketing or profiling. A parent or guardian should contact us where a child needs assistance in relation to an order or enquiry.

Our website may link to manufacturers, payment providers, carriers, review sites, social platforms or other external services. We do not control their privacy practices. Review the external provider's notice before supplying information directly to it.

19. Changes to this notice and how to contact us

We review this notice when our systems, providers, services or legal duties change. We will post the revised version on this page and update the version and effective date. Where a change materially affects an existing use of personal information, we will take additional steps where required by law.

Privacy enquiries and rights requests
Email: info@lockshopdirect.co.uk
Telephone: 0330 174 0851
Post: Privacy Contact, N L S Security Limited, Fort House, 173 West Road, Newcastle upon Tyne, NE15 6PQ

Your session will expire in xx.xx. Do you wish to Continue or Log Out
Your session will expire in xx.xx
Continue or Log Out