Estate Management Solutions
  • Home
  • Leaseholders
  • Freeholders
  • Developers
  • Reviews
  • Useful Links
  • Contact Us
  • Menu Menu

Privacy Notice

Version: V2
Published: 11th September 2026
Effective from: 16th September 2026

1. About this notice

This notice explains how UKEMS Limited, trading as Estate Management Solutions (“we”, “us” or “our”), collects and uses personal information in connection with:

  • the residential leasehold and estate-management services we provide in England and Wales;
  • the developments, buildings and communal areas we manage;
  • our dealings with property owners, leaseholders, residents, occupiers, visitors, clients, contractors, suppliers and other external contacts;
  • our websites, online forms and owner or resident portals; and
  • CCTV, access-control and other security systems where these are operated at a managed development.

Not every section will apply to every person or every service we provide.

This notice does not cover our processing of employee information. Employees and workers receive separate privacy information appropriate to their employment.

2. Who we are and our role

Legal name: UKEMS Limited
Trading name: Estate Management Solutions
Company number: 07269267
Registered office: 31 Greek Street, Stockport, Cheshire, SK3 8AX
Correspondence address: 31 Greek Street, Stockport, Cheshire, SK3 8AX
Privacy email: GDPR@ukems.com
Telephone: 0161 475 2166

We are appointed by freeholders, residents’ management companies, right-to-manage companies, developers and other persons or organisations responsible for managing residential developments. We refer to the person or organisation that appoints us as our Client. Owners and residents are told the identity of the relevant Client in their development communications or can ask us for this information.

We act as a data controller where we determine why and how personal information is used in providing our services or operating our business. Depending on the particular activity, our Client may also act as a separate controller or we may act as joint controllers. Where another controller is responsible for a particular activity, we will identify it where necessary and assist you in directing an enquiry to the right organisation.

3. Whose personal information we use

We may process personal information about:

  • current, former and prospective property owners and leaseholders;
  • residents, occupiers and tenants living at managed developments;
  • directors, officers, company secretaries and members of our Clients;
  • people authorised to act for an owner or resident, including relatives, attorneys, solicitors and managing or letting agents;
  • visitors, guests, delivery personnel and contractors attending managed developments;
  • people who make enquiries, requests, complaints or reports, and people referred to in them;
  • witnesses and people involved in accidents, insurance claims, disputes, alleged lease breaches or antisocial-behaviour matters;
  • contractor, supplier and professional-adviser contacts;
  • prospective clients and other people who contact us about our services; and
  • visitors to our websites and users of our portals.

We may occasionally need limited information about children or other vulnerable occupants, for example for building-safety, emergency or accessibility purposes. We use it only where necessary for a documented management, safety or legal purpose.

4. Personal information we collect

Depending on our relationship with you, we may collect:

Identity and contact information

  • name, title, date of birth where necessary, signature and identity-verification information;
  • property, residential and correspondence addresses;
  • email address, telephone numbers and communication preferences; and
  • details of authorised representatives and emergency contacts.

Property, ownership and company information

  • the property you own, occupy or are connected with;
  • ownership, lease, transfer, title and completion information;
  • purchase and sale dates and details supplied during conveyancing;
  • membership, shareholding, directorship and company-secretarial records; and
  • permissions, consents and information relating to lease or transfer obligations.

Financial and account information

  • service-charge, estate-charge, reserve-fund, ground-rent and administration-charge records;
  • demands, receipts, balances, credits, payment references and account history;
  • bank details where needed to make a payment or refund;
  • arrears, repayment arrangements and recovery activity; and
  • information needed for accounting, audit, insurance, fraud prevention or legal proceedings.

We do not retain complete payment-card details where payments are handled by an independent payment-service provider.

Management and service information

  • repair, maintenance, defect and inspection records;
  • contractor appointments, access arrangements and work orders;
  • insurance policies, claims and incident information;
  • building-safety, fire-safety and emergency information;
  • parking, vehicle, permit, key, fob, entry and access-control records;
  • complaints, enquiries, feedback and correspondence;
  • reports of accidents, security incidents, alleged lease breaches and antisocial behaviour; and
  • notes and evidence reasonably required to investigate or resolve a matter.

Communications and digital information

  • letters, emails, messages, attachments and notes of conversations;
  • recordings of telephone calls where call recording is enabled;
  • portal account details, authentication records and activity logs;
  • IP address, device, browser, date, time, referring page and website-security logs;
  • online-form submissions and cookie or similar-technology preferences;
  • CCTV images and related incident or access information.

Sensitive information

Where necessary, we may process information concerning health, disability, accessibility, vulnerability, racial or ethnic origin, religion or another matter classified as special-category information. We may also process information relating to alleged or actual criminal conduct where this is relevant to fraud, safety, security, antisocial behaviour or legal proceedings. Section 8 explains the additional protections applying to this information.

5. Where personal information comes from

We may obtain personal information:

  • directly from you or a person authorised to act for you;
  • from our Client, a developer, landlord, freeholder, residents’ management company, right-to-manage company or previous managing agent;
  • from solicitors, conveyancers, estate agents or letting agents involved in a sale, purchase, letting or change of ownership;
  • from residents, owners, witnesses, contractors and other people reporting or responding to a communal issue;
  • from insurers, brokers, loss adjusters, professional advisers, courts, tribunals, local authorities, emergency services or regulators;
  • from payment, access-control, parking, CCTV and building-management systems; and
  • from public sources where appropriate, such as HM Land Registry, Companies House, court or tribunal records and publicly available sanctions information.

When we obtain your information from someone else, we will normally direct you to this notice within a reasonable period and no later than one month, or sooner if we communicate with you or disclose the information before then, unless an applicable exception applies.

6. Why we use personal information and our lawful bases

We do not generally rely on consent for processing that is necessary to manage a development. Depending on the activity, we rely on legitimate interests, a recognised legitimate interest prescribed by data-protection law, compliance with a legal obligation, performance of a contract with the individual concerned or, in an emergency, protection of vital interests. Consent is used only where it is appropriate to offer a genuine choice, such as for certain non-essential website technologies or a specific optional use of sensitive information.

Purpose

Personal information commonly used

Lawful basis and key controls

Maintain accurate ownership, resident, contact and authorised-representative records

Identity, contact, property and ownership information

Legitimate interests; legal obligation where applicable

Administer leases, transfers, management-company membership and development obligations

Identity, property, ownership, company and correspondence records

Legitimate interests; legal obligation where applicable; contract where the individual is a party

Issue budgets, demands, statements and accounts and process payments, credits or refunds

Identity, contact, property, account and payment information

Legitimate interests; legal obligation where applicable; contract where the individual is a party

Manage arrears and enforce or defend legal rights

Account history, correspondence, ownership, lease and dispute information

Legitimate interests; legal obligation where applicable

Communicate service information and respond to enquiries

Identity, contact, property and enquiry information

Legitimate interests; contract where applicable

Arrange repairs, maintenance, inspections and access

Contact, property, repair, access and contractor information

Legitimate interests; legal obligation where applicable

Manage building, fire, health and safety and respond to emergencies

Contact, occupancy, access, incident and, where necessary, vulnerability information

Legal obligation; legitimate interests; recognised legitimate interests where the prescribed safeguarding or emergency conditions apply; vital interests in exceptional emergencies

Arrange insurance and administer claims

Identity, contact, property, incident, financial and evidence records

Legitimate interests; legal obligation where applicable; contract where the individual is a party

Operate parking, keys, entry systems, visitor management and communal security

Identity, contact, vehicle, permit, access and security records

Legitimate interests

Prevent and investigate crime, fraud, security incidents, antisocial behaviour and alleged breaches

Identity, contact, CCTV, access, incident, complaint and evidential information

Legitimate interests; recognised legitimate interests where the prescribed crime-prevention or public-security conditions apply; legal obligation where applicable

Handle complaints, disputes, tribunal matters and legal proceedings

Identity, contact, correspondence, account, incident and evidence records

Legitimate interests; legal obligation where applicable

Operate and secure websites, portals, accounts and information systems

Contact, account, authentication, device, log and security information

Legitimate interests; contract where applicable; consent or a statutory exception for relevant device technologies

Meet accounting, tax, company, regulatory and data-protection obligations

Identity, ownership, company, financial, correspondence and rights-request records

Legal obligation; legitimate interests where appropriate

Obtain professional advice and manage business risk

Information relevant to the instruction, claim, audit or advice

Legitimate interests; legal obligation where applicable

Consider new-business enquiries and prepare requested proposals

Identity, contact and enquiry information

Legitimate interests; steps requested before entering a contract

Record specified telephone calls for maintaining accurate records of service requests and material instructions, monitoring service quality and staff training, and investigating complaints, disputes or incidents

Voice recordings and relevant information provided during the call

Legitimate interests, following an assessment of necessity and proportionality. Callers are informed before recording starts and access is restricted to authorised personnel

Use approved AI services to assist authorised staff with property-management work, including searching, extracting, organising, classifying, routing, prioritising, summarising, drafting, translating, checking and analysing information, and suggesting administrative next steps

Relevant communications, tickets, documents and management records; we limit the information made available where practicable

The lawful basis for the underlying task in this table. Outputs are subject to meaningful human oversight, and AI is not used without human review to make legal or similarly significant decisions. We use approved AI-processing providers under business/API arrangements and do not opt in or give permission for submitted inputs or outputs to be used to train their general-purpose models

Operate CCTV or other video-surveillance systems in communal areas, which may include fixed cameras, video-entry systems, automatic number-plate recognition or body-worn video where the relevant development uses them

Images, vehicles, date, time, location and related incident or access information

Legitimate interests in protecting people and property, controlling access, preventing or investigating crime, antisocial behaviour and safety or security incidents; recognised legitimate interests or legal obligation where applicable. Signs at each monitored location identify the relevant controller and purpose. Access is restricted, cameras are not used inside private homes, exact camera positions are not published, and audio or recognition technologies require separate justification, assessment and clear notice

Our legitimate interests

Our legitimate interests include managing developments efficiently and transparently; communicating with owners and residents; maintaining communal services; protecting people, property and funds; keeping accurate records; preventing fraud and misuse; recovering sums lawfully due; resolving disputes; securing our systems; and supporting our Client in meeting its responsibilities.

Where we rely on legitimate interests, we assess whether the processing is necessary and balance those interests against the rights and reasonable expectations of the people affected. You may object to this processing as explained in section 14.

For certain purposes prescribed by law—such as preventing crime, protecting public security, safeguarding vulnerable people or responding to emergencies—we may rely on a recognised legitimate interest where its specific conditions are met. We still assess whether the processing is necessary and proportionate.

Information we need you to provide

Some information is required by law, by a lease or transfer document, or so that we or our Client can manage the development and provide services. If necessary information is not provided, we may be unable to update ownership records, administer an account, provide portal access, make a payment or refund, arrange access or works, respond to a request, or meet a legal or safety obligation. We will explain when information is mandatory and the likely consequences of not providing it.

7. Management and service communications

Management and service communications may include demands, accounts, notices, safety information, repair updates, information about communal services and other messages reasonably connected with the management of a development. You may not be able to opt out of communications that are necessary for these purposes, although we will respect reasonable communication preferences where possible.

8. Special-category and criminal-offence information

We use special-category information only where it is necessary and proportionate for a specific purpose. Examples may include recording an accessibility requirement, supporting a person during an emergency, making a reasonable adjustment, or handling an accident, insurance matter or legal claim.

In addition to an Article 6 lawful basis, we identify an applicable Article 9 condition before using special-category information. Depending on the circumstances, this may be explicit consent where a genuine choice is available, protection of vital interests where a person is incapable of giving consent, establishment or defence of legal claims, or a specific condition based on substantial public interest under the Data Protection Act 2018. Where a condition requires an appropriate policy document, we maintain one internally.

We do not treat the unsolicited disclosure of sensitive information as consent to use it for unrelated purposes. If we receive information we do not need or cannot lawfully retain, we will securely delete or restrict it.

We process criminal-offence information only where authorised by law and with appropriate safeguards. Access is restricted to people who need the information for the relevant safety, fraud, complaint, legal or regulatory purpose.

9. Cookies

Our websites and portals may use cookies, local storage, pixels, scripts or similar technologies. For more info on the cookies we use please visit:  https://estate-management-solutions.co.uk/cookie-policy-uk/

We do not ask for consent where a technology is strictly necessary to provide a service you request. Where we rely on a statutory exception for qualifying statistical or appearance-related technologies, we provide clear information and a simple free way to object. Other non-essential technologies are disabled until you make an affirmative choice. It must be as easy to reject them and later withdraw consent as it is to accept them.

Our website may contain links to websites operated by other organisations. Those organisations are responsible for explaining their own processing.

10. Who we share personal information with

Where necessary and lawful for the purposes described in this notice, we may disclose personal information to the following meaningful categories of recipient:

  • our Client and other legal entities responsible for owning or managing the relevant development;
  • other owners or residents where limited disclosure is necessary for a communal matter, consultation, statutory process or the fair administration of shared costs;
  • property-management software, secure cloud-hosting, data-storage, backup and cybersecurity providers;
  • business email, document-management, telephony and communications providers;
  • customer-service, support-ticketing, printing and postal providers;
  • workflow-automation and system-integration providers;
  • approved AI-processing providers for the property-management purposes described in section 6;
  • contractors, surveyors, engineers, health-and-safety advisers, fire-safety providers, concierge, security and other building-service providers;
  • banks, payment-service providers, accountants, auditors and company-secretarial service providers;
  • insurers, insurance brokers, loss adjusters and claims handlers;
  • solicitors, barristers, debt-recovery providers, tracing agents, mediators, courts and tribunals;
  • local authorities, regulators, ombudsman or redress schemes, emergency services and law-enforcement bodies; and
  • prospective purchasers or advisers if our business or relevant assets are subject to a genuine sale, merger or reorganisation, under appropriate confidentiality controls.

We do not sell personal information. Processors acting for us are contractually required to protect personal information and may use it only for the agreed service or as required by law.

You may contact us for more information about the specific recipients of your personal information.

11. International transfers

Some service providers or their support operations may process personal information outside the United Kingdom. Before making a restricted transfer, we ensure that an applicable transfer mechanism is in place. Depending on the destination and recipient, this may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU standard contractual clauses, binding corporate rules or another safeguard or exception permitted by law.

Where required, we assess whether the protection will be materially lower after the transfer and implement supplementary protections. You may contact us using the details in section 15 to ask about a transfer affecting your information or how to obtain a copy of the relevant safeguards, subject to lawful redactions.

12. How long we retain personal information

We keep personal information only for as long as reasonably necessary for the relevant purpose, including legal, accounting, regulatory, insurance and dispute-resolution requirements. We then securely delete or anonymise it.

The principal retention periods are set out below. Six years is used for many financial and evidential records because of tax requirements and the usual limitation period for claims founded on a simple contract. It is not a blanket period for every item of personal information.

Record

Normal retention

Current ownership, contact and management records

While the ownership or management relationship continues

Former-owner and change-of-ownership records

Core ownership, transaction and final-account records for six years after the sale, transfer or final account settlement, whichever is later. Contact details not needed for that record are deleted or restricted earlier

Statutory register of members maintained for a client company

While the person is a member and for ten years after they cease to be a member

Leases, transfers, title documents and management agreements

While relevant to the ownership or appointment and normally for six years afterwards; up to twelve years where necessary for obligations or claims arising under a deed

Service-charge, estate-charge, payment, tax and accounting records

Six years from the end of the financial year or accounting period to which they relate; longer while an enquiry, audit, reconciliation or dispute remains open

Routine enquiries and correspondence with no continuing management significance

Up to six years after the matter is resolved

Material management correspondence and notices evidencing an ownership, financial, safety or contractual matter

Six years after the matter closes; up to twelve years where necessary for a deed-based claim

Repairs, maintenance, inspections, procurement and contractor records

Six years after completion or final payment; longer for continuing warranties, latent defects, building-safety matters or active claims

Complaints, disputes and antisocial-behaviour matters

Up to six years, or longer where reasonably required due to litigation or continued proceedings

Insurance claims, accidents, incidents and legal files

Six years after closure; up to twelve years where a deed-based claim applies, or longer where reasonably required by an insurer, court order, litigation hold or continuing proceeding

Accessibility and vulnerability information

Reviewed at least annually and retained only while the adjustment, safety or support need continues, unless an incident or legal requirement justifies longer retention

Current keys, fobs, permits and authorised-user records

While valid and normally for six months after cancellation, return or replacement

Portal accounts, profiles and access permissions

While the person remains entitled to use the portal. Access is revoked promptly when that entitlement ends; any remaining profile information follows the applicable ownership, correspondence or account-record period

Documents, messages, tickets and account information available through the portal

The period applying to the underlying record in this table. Making a record available through the portal does not shorten or extend its retention period

Portal authentication, login, security and technical audit logs

Normally twelve months, unless a security incident, investigation or legal claim requires preservation

Visitor, parking and physical access-control event logs

Normally twelve months, unless an incident or investigation requires preservation

Website and routine cybersecurity logs

Normally 90 days; up to twelve months where needed to investigate a security event, misuse or attempted fraud

Call recordings

Six months, unless a recording is preserved for a complaint, incident, insurance matter or legal claim

AI assisted processing

Provider systems may retain API inputs and outputs for up to 30 days for security, abuse-monitoring or audit purposes unless stronger contracted controls apply. Our agreements with AI processors do not allow use of personal data for training their models. An output incorporated into an Agent record follows the period for the underlying record in this table

CCTV recordings

Normally 30 days and no more than 60 days under the documented general schedule, subject to preservation for an incident, claim or proceeding

Data-rights requests and privacy complaints

A minimal record of the request, decision and response for six years after closure. Identity evidence and duplicate disclosure files are deleted sooner when no longer required

We may retain particular records for longer where reasonably necessary because of arrears, fraud concerns, an incident, safeguarding issue, complaint, insurance claim, legal advice, litigation hold, court or tribunal proceedings, or another legal or regulatory requirement.

13. Security

We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures include access controls, authentication, encryption where appropriate, secure backups, staff confidentiality, supplier due diligence, incident-management procedures and periodic review.

No internet transmission is completely risk-free, but this does not reduce our legal responsibility to apply appropriate security to the information we process.

14. Your rights

Depending on the circumstances and the lawful basis, you may have the right to:

  • be informed about our use of your personal information;
  • request access to your personal information and supplementary information about its use;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase information where no continuing lawful reason requires it;
  • ask us to restrict processing in specified circumstances;
  • object to processing based on legitimate interests or recognised legitimate interests, including profiling based on those bases;
  • receive information you provided in a structured, commonly used, machine-readable format and have it transferred where the portability right applies;
  • withdraw consent at any time where we rely on consent, without affecting earlier lawful processing; and
  • challenge a qualifying decision based solely on automated processing and request human intervention where applicable.

These rights are not absolute. For example, we may need to retain information to meet a legal obligation, maintain statutory company or accounting records, administer sums due under a lease or transfer, or establish or defend a legal claim. We will explain our decision if we cannot fully comply with a request.

Your right to object to legitimate-interest processing

You may object verbally or in writing where we rely on legitimate interests or a recognised legitimate interest. Please explain the processing you object to and the reasons relating to your particular situation so that we can properly consider the request.

This right is not an automatic right to require us to stop all processing. We may continue if we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or if the processing is necessary to establish, exercise or defend legal claims.

Core ownership and management information is often necessary to administer the lease, transfer or other ownership document; maintain accurate accounts; issue demands and notices; arrange services and repairs; manage building safety; protect service-charge funds; and establish or enforce legal rights. In those circumstances, we may have compelling grounds to continue processing despite an objection. An objection does not release an owner or another party from obligations under an ownership document and does not prevent us or our Client from meeting legal or safety responsibilities.

We will nevertheless consider every objection on its facts. We may be able to correct or reduce the information used, restrict a non-essential activity, change a reasonable communication method or otherwise address the concern even where essential processing must continue. If we refuse an objection, we will explain why and tell you about your right to complain to the ICO and seek a judicial remedy.

To protect personal information, we may ask for information reasonably necessary to confirm identity and authority. We normally respond within one month. We will tell you if the law permits an extension or if a request is manifestly unfounded or excessive.

15. Contacting us and making a complaint

Questions, rights requests and data-protection complaints can be sent to:

Privacy contact: Operations Director
Email: GDPR@ukems.com
Address: 31 Greek Street, Stockport, Cheshire, SK3 8AX
Telephone: 0161 475 2166

Please identify the development and property concerned where this will help us locate the relevant information. You do not need to use a particular form.

If you remain dissatisfied, you may complain to the Information Commissioner’s Office:

Website: ico.org.uk/make-a-complaint
Telephone: 0303 123 1113
Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

You may contact the ICO at any time, although it will often be helpful to raise the matter with us first so that we have an opportunity to resolve it.

16. Changes to this notice

We review this notice regularly and update it when our processing or the law changes. The current version, publication date and effective date are shown at the beginning.

For minor changes that do not materially affect people, such as clarifications or updated contact details, we may publish the revised notice on our website without sending a separate notification.

If we intend to use personal information for a new purpose, or make another change likely to materially affect individuals, we will update this notice and bring the change to the attention of affected people before the new processing begins. We will use email, portal notification or post as appropriate. Where consent is required, notification of the change will not itself constitute consent; we will request a separate affirmative choice.

You do not need to “accept” this notice. It explains our processing and your rights.

READ OUR INDEPENDENT REVIEWS

Contact Us

If you would like to contact EMS please call us on 0161 475 2166

Useful Links

  • Home
  • Leaseholders
  • Freeholders
  • Developers
  • Reviews
  • Useful Links
  • Contact Us

Address & Company Info

Estate Management Solutions
31 Greek Street,
Stockport,
SK3 8AX

Estate Management Solutions is the trading name of UKEMS Ltd.
Company number: 07269267

EMS Privacy Policy

Keyword Search

Search Search

Website Design

by Initiate Create

Scroll to top Scroll to top Scroll to top
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}