Privacy Notice

Alexander Dennis Limited (‘Alexander Dennis’, ‘we’, ‘our’ or ‘us’) collect, use, and are responsible for certain personal data about you. This means that we are a “controller” under data protection legislation, and we are subject to the UK General Data Protection Regulation (UK GDPR). We are also subject to the EU General Data Protection Regulation (EU GDPR) in relation to goods and services we offer to individuals and our wider operations in the European Economic Area (EEA).

This privacy notice contains important information on how and why we collect, store, use, and share your personal data in connection with our business and your use of our website (https://www.alexander-dennis.com/).  It also explains your rights in relation to your personal data and what to do if you have a complaint.

The table ‘How and why we use your personal data’ annexed to this privacy notice explains the most common situations in which we would be processing your personal data, and the reason (legal basis) for doing so.

The Data Protection Officer (DPO) is responsible for data protection compliance within Alexander Dennis. If you have any questions or comments about the content of this privacy notice or if you need further information regarding data protection and personal data, you should contact the DPO on DataProtectionOfficer@alexander-dennis.com.

Key data protection terms

Personal dataAny information relating to a data subject (sometimes known as personal information).
Data subjectThe individual to whom the personal data relates and who can be identified (directly or indirectly) from that data.

What personal data do we collect?

The personal data we collect about you depends on the particular goods and services we provide, and the particular activities carried out through our website. The types of personal data we collect may include:

  • Identity: name (including pronoun preferences if you choose to share these), title, job title, date of birth, username or similar identifier, and signature;
  • Contact: billing and delivery address, email address, and telephone numbers;
  • Financial: billing information, transaction and payment details (including card or bank information for transfers and direct debits), and credit checks where applicable;
  • Transaction: details about goods and services purchased by you;
  • Technical: IP and MAC address, login data, browser information, time zone setting, and location;
  • Profile: username and password, feedback, and survey responses;
  • Usage: details about how you use our website, goods, and services; and
  • Marketing: your preferences for marketing and other communications.

We may also collect and use statistical or demographic data about you, but this data does not reveal your identity. If such statistical or demographic data about could be used to identify you, we treat that combined data as personal data which will be used in accordance with this privacy notice.

If you choose not to supply certain information to us, we may not be able to provide our services, communicate with you, or comply with our legal obligations. You may also not be able to access our websites or receive communications from us.

How do we collect your personal data?

We may receive information about you, which may include personal data, when we provide you with goods or services, or when you visit our website. Most of this personal data will be collected directly from you – for example when you contact us to make enquiries or place orders via phone, email, or online.

In addition, we may collect information:

  • when you engage with us through forums such as open days, trade shows, conferences, events, meetings, entering competitions and our social media platforms;
  • from publicly accessible sources, e.g., your own website or social media pages (such as LinkedIn), or from Companies House;
  • directly from a third party, e.g., credit reference agencies or customer due diligence providers;
  • from cookies on our website (please refer to our Cookie Policy on our website); and
  • via our security or IT systems, e.g., CCTV, door entry systems, and reception logs; or through monitoring of our websites and other systems.

How and why we use your personal data

General

Under data protection law, we can only use your personal data if we have a proper reason, e.g.:

  • where you have given consent;
  • to comply with our legal and regulatory obligations;
  • for the performance of a contract with you;
  • for the purposes of a recognised legitimate interest under UK data protection law; or
  • for our legitimate interests or those of a third party.

A legitimate interest is when we have a business or commercial reason to use your personal data, so long as this is not overridden by your own rights and interests. We will carry out an assessment when relying on legitimate interests, to balance our interests against your own.

When we rely on legitimate interests, this will usually mean our own commercial interests, provided that the use of your personal information is necessary to achieve that purpose and this is not overridden by your own rights and interests.

Please refer to the purposes and legal bases set out in the table ‘How and why we use your personal data’ annexed to this privacy notice for more information.

Marketing and press releases

We may use your personal data to send you updates (by email, text message, telephone, or post) relating to our products and services, marketing material, press releases as well as other events and activities we think may be of interest to you.

We have a legitimate interest in using your personal data for marketing purposes (see the table ‘How and why we use your personal data’ annexed to this privacy notice). This means we do not usually need your consent to send you marketing information. Where this is not the case, we will always ask for your consent.

You can withdraw your consent for this at any time. This can be done by contacting our marketing team on press@alexander-dennis.com, or see ‘How to contact us’ below.

Special category personal data

Certain personal data we collect is treated as a special category to which additional protections apply under data protection law. This includes personal data revealing racial or ethnic origin, political opinions, religious beliefs, philosophical beliefs or trade union membership, genetic data, biometric data (where used for identification purposes), and data concerning health, sex life or sexual orientation. We do not routinely collect special category data. However, where we do process special category personal data, we will also ensure we are permitted to do so under data protection laws.

Who do we share your information with?

We routinely share personal data with:

  • companies within the Alexander Dennis’ group;
  • third parties we use to help deliver goods and/or services to you and to help us run our business;
  • other third parties we use to help promote our business, e.g. marketing agencies;
  • third parties approved by you;
  • credit reference agencies;
  • our insurers and brokers;
  • our bank.

We or the third parties mentioned above may occasionally also share personal data with:

  • our and their external auditors;
  • our and their professional advisors;
  • law enforcement agencies, courts, tribunals, and regulatory bodies to comply with our legal and regulatory obligations;
  • other parties that have or may acquire control or ownership of our business (and our or their professional advisers). 

We do not sell your data to any third-party organisations.

Any personal data that we share will be anonymised where possible. We only share your personal data with the organisations and third parties mentioned above if we are satisfied they only use it in accordance with this privacy notice and take appropriate security and organisational measures to protect your personal data. We also confirm appropriate contractual obligations are in place to ensure they can only use your personal data in compliance with UK data protection law. If you need further information on these measures, please contact us.

In some circumstances, we may need to send your data outside the UK, or the EEA see below: ‘Transferring your personal data out of the UK and EEA’.

Transferring your personal data out of the UK and EEA

It is sometimes necessary for us to transfer your personal data to countries outside the EEA and the UK. This may include countries which do not provide the same level of protection of personal data as the EEA and the UK.

In particular, because Alexander Dennis is part of NFI Group based in Canada, we may transfer your personal data from the UK and EEA to Canada. These transfers take place on the basis of adequacy regulations (see below).

We will only transfer your personal data to a country outside the UK or the EEA where:

  • there is an ‘adequacy regulation’ (under the UK GDPR) or ‘adequacy decision’ (under the EU GDPR) in place for that country, meaning that particular country ensures an adequate level of protection of personal data; or
  • there are appropriate safeguards in place (e.g. standard data protection clauses recognised or issued under the GDPR).

If we cannot or choose not to continue to rely on either of those mechanisms at any time, we will not transfer your personal data outside the UK or outside the EEA unless we can do so on the basis of an alternative mechanism or exception provided by UK data protection law and reflected in an update to this privacy notice.

Any changes to the destinations to which we send personal data or in the transfer mechanisms we rely on to transfer personal data internationally will be notified to you in accordance with the section on ‘Changes to this privacy notice’ below.

If you would like further information about data transferred outside the UK/EEA, please contact us or our Data Protection Officer (see ‘How to contact us’ below).

Storing your personal data

Where your personal data is held

Personal data may be held at our offices and those of our group companies, third party agencies, service providers, representatives and agents as described above (see above: ‘Who we share your personal data with’).

Some of these third parties may be based outside the UK or EEA. For more information, including on how we safeguard your personal data when this happens, see below: ‘Transferring your personal data out of the UK and EEA’.

How long your personal data will be kept

We only keep your personal data as long as is necessary for the purpose for which we collected it. Following the end of the of the relevant retention period, we will delete or anonymise your personal data.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

Keeping your personal data secure

We have implemented appropriate technical and organisational measures to keep your personal data confidential and secure from unauthorised access, use and disclosure. We limit access to your personal data to those who have a genuine business need to access it. Those processing your personal data will do so only in an authorised manner and are subject to a duty of confidentiality.

We require our business partners, suppliers and other third parties to implement appropriate security measures to protect personal data from unauthorised access, use and disclosure.

We also have procedures to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

Your rights

Under data protection law, you have the following rights:

  • Access. The right to be provided with a copy of your personal data.
  • Rectification. The right to require us to correct any mistakes in your personal data.
  • Erasure. The right to require us to delete your personal data.
  • Restriction of processing. The right to require us to restrict processing of your personal data.
  • Data portability. The right to receive the personal data you provided to us.
  • Object. The right to object at any time to your personal data being processed.
  • Not to be subject to automated individual decision making. The right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or significantly affects you.
  • Withdraw consent. If you have provided us with a consent to use your personal data you have a right to withdraw that consent easily at any time.
Exercising your rights

If you would like to exercise any of these rights, please email, call, or write to us. See below: ‘How to contact us’; and

  • provide enough information to identify yourself and any additional identity information we may reasonably request from you; and
  • let us know what right you want to exercise and the information to which your request relates.

Any withdrawal of consent will not affect the lawfulness of our use of your personal data in reliance on that consent before it was withdrawn.

Complaints

If you are unhappy with the way we have handled your personal information, you have the right to submit a complaint to us.

You can contact us to make a complaint by emailing, calling, or writing to us using the details below. See: ‘How to contact us’.

When we receive a complaint

We will acknowledge your complaint within 30 days of receiving it.

We may need to verify the identity of the person making the complaint, especially if the complaint is made on behalf of someone else because we need to check that the person making the complaint is properly authorised to do so. This may involve requesting further information or documentation from you. If, having requested additional information, we are not in a position to identify the person making the complaint or we are not satisfied that they have proper authority to make the complaint, we may be unable to deal with it.

As we investigate your complaint, we may also need to ask you for further information or documents. If so, we will ask you to provide the information within a specific period of time.

We will update you on the progress of your complaint at appropriate times.

Notifying you of the outcome of our investigation

We will inform you of the outcome of the complaint without undue delay.

We will explain clearly what we’ve done to resolve your complaint and, where appropriate, any action we have taken as a result.

What to do if we cannot resolve your complaint

If you are unhappy with the outcome of your complaint, you can also complain to the Information Commissioner’s Office (ICO), the data protection regulator for the UK. More details on how to complain to the ICO is available on their Complaints page.

Contacting the ICO

You can contact the ICO by visiting https://ico.org.uk/ or calling 0303 123 1113.

The ICO also has online guidance on individuals’ rights which can be found on their website.

How to contact us

You can contact us and/or our Data Protection Officer by post, email, or telephone if you have any questions about this privacy notice or the information we hold about you, to exercise a right under data protection law, or to make a complaint.

Our contact details are:

Alexander Dennis Limited, 9 Central Boulevard, Central Park, Larbert, FK5 4RU
+44 1324 621672
info@alexander-dennis.com

Data Protection Officer: DataProtectionOfficer@alexander-dennis.com

Changes to this Privacy Notice

We may change this privacy notice from time to time; when we do an updated version will be posted on our website.

This notice was updated on 15 June 2026.