Privacy Policy

How Khamo Certification Limited collects, uses, shares and protects personal data, and the rights you have over your information.

Last updated: 2 September 2026 UK GDPR & Data Protection Act 2018

1. Who we are

Khamo Certification Limited (“Khamo”, “we”, “us”) is an Approved Organisation accrediting energy assessors across the United Kingdom. We are the data controller for the personal data described in this policy.

  • Head Office: Suite 1, Eilidhaus, 497 Antrim Road, Belfast, BT15 3BP
  • UK Office: Peter House, Oxford Street, Manchester, M1 5AN
  • Telephone: 02890 777 111
  • Email: e@khamo.co.uk

2. Information we collect

Members and applicants

When you apply to join the scheme and throughout your membership we collect:

  • Identity and contact details — name, date of birth, address, email, telephone and mobile number
  • Your membership number, username and account credentials (passwords are stored only as a one-way hash and are never readable by us)
  • Company and employment details, including the company you assess under
  • Qualifications, accreditation strands, CPD records and training history
  • Documents you or your scheme administrator supply — photograph, qualification certificates, professional indemnity insurance, DBS/CRB certificate, passport or driving licence, signed agreement and code of conduct
  • Audit records, assessment samples, complaints, appeals and any suspension history
  • Accessibility or health information you choose to disclose so we can make reasonable adjustments
  • Bank details where you pay by Direct Debit (held encrypted)

Members of the public

  • Enquiry and complaint details you send us, including your name, contact details and the property or certificate concerned
  • Correspondence relating to an assessment carried out by one of our members

Website visitors

  • Information you enter into our enquiry and application forms
  • Standard technical data such as IP address and browser type, used to keep our systems secure

3. Why we use it, and our lawful basis

What we doLawful basis under UK GDPR
Administer your membership, account and certificationContract (Article 6(1)(b))
Verify competence, audit lodged assessments and run quality assuranceLegal obligation and legitimate interests (Article 6(1)(c) and (f)) — meeting our duties as an Approved Organisation
Publish the limited entry required on the EPC registerLegal obligation (Article 6(1)(c))
Send membership, insurance, CPD and scheme noticesLegitimate interests (Article 6(1)(f)) — keeping members informed of obligations that affect their accreditation
Investigate complaints about an assessment or a memberLegal obligation and legitimate interests (Article 6(1)(c) and (f))
Collect fees and manage Direct DebitsContract (Article 6(1)(b))
Provide reasonable adjustments you have asked forConsent (Article 6(1)(a)), and Article 9(2)(a) where health information is involved

4. DBS checks and identity documents

To accredit an assessor we may process a DBS or Access NI certificate, together with a passport or driving licence. Information about criminal convictions is handled under Article 10 of the UK GDPR and Schedule 1 of the Data Protection Act 2018, on the basis that it is necessary to assess the suitability of a person to hold accreditation.

These documents are stored outside our public websites, are reachable only by authenticated scheme staff and by the member they belong to, and every access is recorded. We do not publish them, and we do not share them for marketing of any kind.

5. Who we share it with

We share personal data only where we must, and never sell it. Recipients may include:

  • Government administrations and register operators — the EPB register for England, Wales and Northern Ireland, and the Scottish EPC Register, which show a limited public entry for accredited assessors
  • Ministry of Housing, Communities and Local Government and the devolved administrations, in periodic returns and where they request information about the scheme
  • Quality assurance auditors engaged to review assessments
  • Insurers and insurance brokers, to verify professional indemnity cover
  • Training providers and awarding bodies, to confirm qualifications and CPD
  • Our IT, hosting, email and payment providers, acting as processors on our instructions
  • Professional advisers, law enforcement or regulators, where we are required to disclose

Where a complaint concerns an assessment, we may share relevant details with the assessor involved so they can respond. Your data is held on servers within the United Kingdom.

6. How long we keep it

RecordRetention
Membership and accreditation recordsFor the duration of membership, then as required by the Scheme Operating Requirements
Audit and quality assurance recordsAs required by the Scheme Operating Requirements
Complaints, appeals and rejected applicationsRetained so the scheme can evidence how a matter was handled
Financial and Direct Debit recordsSix years, to meet HMRC requirements
Website enquiries that do not become applicationsDeleted once the enquiry is closed and no longer needed

When a retention period ends we securely delete the information or anonymise it so it can no longer identify you.

7. How we protect it

  • All our systems are served over encrypted HTTPS connections
  • Passwords are stored as one-way hashes and are never recoverable, by us or anyone else
  • Bank details are encrypted at rest
  • Member documents are stored outside our public websites and released only to authenticated users entitled to see them
  • Access is limited to scheme staff who need it for their role, and document access is logged

8. Your rights

Under UK data protection law you have the right to:

  • Ask for a copy of the personal data we hold about you
  • Have inaccurate data corrected
  • Ask us to erase data where we no longer need it — though we must keep certain accreditation records
  • Ask us to restrict how we use your data, or object to processing based on legitimate interests
  • Receive data you gave us in a portable, machine-readable format
  • Withdraw consent at any time, where consent is the basis we rely on

To exercise any of these, email e@khamo.co.uk. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

9. Cookies

Our websites use only the cookies needed to make them work — keeping you signed in to the member portal and holding your session securely. We do not use advertising or third-party tracking cookies. You can block cookies in your browser, but you will not be able to sign in to the portal if you do.

10. Contact and complaints

For any question about this policy or how we handle your data, contact us at e@khamo.co.uk or 02890 777 111, or write to Khamo Certification Limited, Suite 1, Eilidhaus, 497 Antrim Road, Belfast, BT15 3BP.

If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.

Complaints about the service you have received from the scheme, or about an assessment carried out by one of our members, are handled under our Customer Service Policy.

We review this policy at least annually and whenever our processing changes. Any update is published on this page with a revised date.