Fortis Merchants Limited is a Builders' Merchant buying group registered in England No. 8519394 and our registered office is Sussex House, Quarry Lane, Chichester PO19 8PE. This Privacy Notice explains how we use any personal information we collect about you when you use our website or contact us directly.

The Data Protection Act and the EU General Data Protection Regulations (GDPR)

The Data Protection Act and GDPR requires us to manage personal information in accordance with Data Protection Principles and in particular requires us to process your personal information fairly and lawfully. This means you are entitled to know how we intend to use any information you provide. You can then decide whether you want to give it to us in order that we may provide the product or service that you require. All our employees are personally responsible for maintaining customer or employee confidentiality and will do their utmost to keep all data accurate, timely and secure. We provide training and education to all employees to remind them about their obligations.

What personal information do we collect?

We collect information about you when you open an account with us, when you register on our website, when you make an enquiry or place an order for goods and when you apply for employment with us. We also collect information when you voluntarily engage in social media, provide feedback, participate in competitions or attend our events. Website usage information is collected using cookies and Google analytics, which may capture your IP address. The personal information we collect from you will depend on the nature of your enquiry, the type of product or service you are enquiring about, or to satisfy any contractual or statutory obligation. This may include personal information, sensitive personal information, recorded voice conversations or CCTV images. Typically, the information might include:

  • Contact details (name, address, telephone / mobile numbers, email address)
  • Photographic identification & proof of address documents (to carry out due diligence)
  • Bank and financial details (to establish source of funds to pay for the product or service)
  • Professional information (if you are applying for employment with us or as a part of HR records)
  • Other information in order for us to fulfil your needs and complete the transaction
  • By what methods you wish us to contact you.

On what basis will we process your personal information?

The basis for processing your personal information is:

  • It is necessary for the performance of a contract
  • It is necessary to comply with mandatory legal or statutory obligations
  • It is necessary for Public Interest (or National Interest & Criminal Background Record checks as per DPA 2017)
  • It is necessary to protect the vital interest of you or other persons, such as safety issues regarding your purchases
  • It is necessary for the purposes of our legitimate interests, always ensuring that this does not cause undue damage or distress to you
  • Consent, whereby you have given us permission to use the personal data

How we will use your personal information?

We may use your information in the following ways:

  • to ensure the web site’s content is presented as effectively as possible for you
  • to provide the services and information that you have requested
  • for our own internal record keeping
  • to prepare documentation in order to complete transactions for services, which may require sharing your data with 3rd parties
  • to develop and improve the products and services we offer, including those from selected suppliers* listed below, and notify you of these
  • to review our employees interaction with you with a view to improve our performance by training and development.
  • we will, with your consent, use your data for marketing purposes, and will always give you the option to withdraw this consent.
  • in the event that you apply for a job at Fortis Merchants Ltd, to assess your suitability for the role and to carry out any subsequent interview process
  • to respond to complaints or allegations of negligence against us
  • we may aggregate your information with other data so as to provide statistics in order to make business decisions and assess data about web traffic patterns, sales, demand for products, etc. This aggregated information does not identify any individual or individual’s personal data.

With whom will we share your personal information?

In limited circumstances we may disclose your information to third parties:

  • if we are under a duty to disclose or share your information to comply with a legal or statutory obligation, or in order to enforce or apply our terms and conditions, or protect the rights, property or safety of our customers, employees or others.
  • to fulfil certain compliance requirements, such as external auditor needs
  • to our insurers in the event that a claim is made against us in order to defend ourselves
  • to regulators, including but not limited to the Information Commissions Office (ICO), in connection with any ongoing regulatory investigation. This may involve the exchange of information with other companies or organisations for the purpose of fraud protection and credit risk reduction.
  • any disclosure to law enforcement agencies where required by law

How long will your information be stored for?

The GDPR requires that personal data is stored for no longer than is necessary and this is the principle that we follow. Occasionally, legislation obliges us to store data for a certain period of time which overrides other considerations.

Your Rights?

Under the Data Protection Act and GDPR you have a right:

  • to be informed – as per this Privacy Notice
  • of access – we will provide a copy of the data we hold about you within 30 days of receiving your request in writing – see address below
  • to rectification – of any inaccuracies or omissions in your data
  • to erasure and to be forgotten – whereby personal data is no longer necessary for the purpose it was originally collected, but subject to contractual, statutory or legal obligations
  • to data portability – whereby personal data is transferred from one data controller to another at your request. It will be your responsibility to check that the receiving data controller complies with GDPR requirements and operates within the EEA.
  • to restrict processing of the personal data, or withdraw consent in any or all of the areas previously given
  • to object to processing based upon legitimate interest and/or direct marketing
  • to be informed in relation to automated decision making and profiling – where decisions may be taken without human intervention

Personal Data Security

We take the responsibility for the security of your data very seriously. Your data will be held on secure servers within the EEA where possible, with all reasonable technological and operational measures put in place to safeguard it from unauthorised access.

How to contact us?

If you have any queries, requests or complaints on the subject of data protection or would like to opt in or out of any contact or communications, please do not hesitate to contact us at the address below:

Fortis Merchants Ltd

Sussex House

Quarry Lane


PO19 8PE


Telephone: 07500 877919