Privacy Notice – ELA Container UK Limited (www.ela-container.uk)
1. Who we are (Controller)
ELA Container UK Limited ("ELA UK", "we", "us", "our") is the controller of personal data processed through www.ela-container.co.uk, related landing pages, and in connection with our sales, rental, delivery, customer service, supplier management and marketing activities.
ELA Container UK Limited
Staddlethorpe Broad Lane
Gilberdyke, Brough
HU15 2TD
United Kingdom
Telephone: +44 1724 608021
Website: www.ela-container.co.uk
Email: info@ela-container.co.uk
EU Representative
ELA Container GmbH
Zeppelinstr. 19-21
49733 Haren (Ems)
Email: info@container.de
Data protection contact
If you have questions about this Privacy Notice, our Cookie Policy or how we use personal data, please contact:
Email: privacy@ela-container.co.uk
Where and to the extent ELA UK offers goods or services to people in the EEA or monitors their behaviour in the EEA, separate EU GDPR information may also apply.
2. Scope of this notice
This Privacy Notice explains how we collect, use, share, store and otherwise process personal data when you:
- visit our website or landing pages;
- contact us by email, phone, web form, event form or campaign form;
- request a quotation or product information;
- rent or purchase goods or services from us;
- interact with our marketing communications; or
- otherwise deal with us as a customer, prospect, supplier, subcontractor or business contact.
This Privacy Notice is designed to meet the transparency requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where relevant to electronic marketing and online tracking, the Privacy and Electronic Communications Regulations 2003 (PECR).
3. Personal data we collect
Depending on how you interact with us, we may process the following categories of personal data.
3.1 Information you provide directly
- identification and contact data such as your name, employer, job title, business address, email address and telephone number;
- enquiry and correspondence data such as the contents of messages, requests, quote details, meeting notes, support communications and form submissions;
- account, contract and transaction data such as customer numbers, order history, contract details, delivery details, invoice details and payment status; and
- marketing preference data such as your subscription status, opt-in / opt-out choices and records of those choices.
3.2 Information collected automatically through website use
- technical and device information such as IP address, browser type, device type, operating system, language settings and approximate location derived from IP address;
- website usage information such as pages visited, referring URL, interactions, event data, landing-page activity, date and time of access and form traffic data; and
- cookie and similar technology data, including local storage, session storage and related script- or tag-based interactions, as described in our Cookie Policy.
3.3 Information obtained from third parties
We may obtain personal data from:
- other ELA group companies where needed for administration, fulfilment, IT support or group reporting;
- logistics providers, installers, subcontractors and service partners;
- payment providers, finance partners or credit checking services where relevant;
- event, lead-generation, campaign or CRM partners;
- public sources such as Companies House, business websites and professional networking platforms; and
- anti-spam or security service providers used to protect our website and forms.
4. Why we use personal data and our lawful bases
We process personal data only where we have a lawful basis under Article 6 UK GDPR.
4.1 To answer enquiries and prepare quotations
We use contact details, correspondence data and project information to answer requests, prepare quotations and take steps at your request before entering into a contract.
Lawful basis: Article 6(1)(b) UK GDPR (steps prior to entering into a contract) and, where the contact is made on behalf of a business, Article 6(1)(f) UK GDPR (our legitimate interests in responding to business enquiries and managing commercial relationships).
4.2 To manage contracts, rentals, purchases, deliveries and support
We use identity, contact, account and transaction information to administer contracts, arrange delivery and installation, manage invoicing, provide customer support and handle complaints.
Lawful basis: Article 6(1)(b) UK GDPR (contract performance) and Article 6(1)(f) UK GDPR (legitimate interests in efficient business administration and customer service).
4.3 To comply with legal and regulatory obligations
We process relevant records to comply with tax, accounting, sanctions, fraud prevention, health and safety, product safety and other legal requirements.
Lawful basis: Article 6(1)(c) UK GDPR (legal obligation).
4.4 To protect our business, systems and website
We process technical and security data to maintain website functionality, detect misuse, prevent fraud, protect forms, manage incidents and defend legal claims.
Lawful basis: Article 6(1)(f) UK GDPR (legitimate interests in website integrity, IT security, network protection, fraud prevention and the defence of legal rights) and, where applicable, Article 6(1)(c) UK GDPR.
4.5 To operate analytics, campaigns and measurement tools
Subject to the choices you make through our consent management tools and the rules explained in our Cookie Policy, we use website and campaign data to understand how our website and landing pages are used, measure campaign performance and improve content, navigation and user experience.
Lawful basis: where consent is required for the underlying storage/access technology under PECR, Article 6(1)(a) UK GDPR (consent). Where a narrow legal exception may apply to the storage/access activity or the subsequent processing is otherwise lawful, we will use the lawful basis appropriate to that processing and document our reasoning.
4.6 To send direct marketing
We may send information about our products, services, events and campaigns to existing or prospective business contacts.
Lawful basis: Article 6(1)(a) UK GDPR (consent) where required, or Article 6(1)(f) UK GDPR (legitimate interests in promoting our business to relevant corporate contacts) where lawful and proportionate. We assess this together with PECR. If PECR requires consent for an electronic marketing message, we will not substitute legitimate interests for consent.
4.7 To establish, exercise or defend legal claims
We may use relevant records where necessary in relation to disputes, debt recovery, litigation, insurance or compliance investigations.
Lawful basis: Article 6(1)(f) UK GDPR (legitimate interests in protecting our legal position) and, where relevant, Article 6(1)(c) UK GDPR.
5. Legitimate interests we rely on
Where we rely on Article 6(1)(f) UK GDPR, our legitimate interests may include:
- responding to business enquiries and maintaining customer and supplier relationships;
- running our business efficiently and safely;
- maintaining the security and resilience of our website, forms, networks and systems;
- preventing fraud, spam, misuse and abusive automated activity;
- improving our products, services and online presence; and
- promoting our services to relevant business contacts in a responsible and compliant way.
When we rely on legitimate interests, we consider necessity, proportionality and the rights and expectations of the individual. You may object to processing based on legitimate interests in the circumstances set out in the UK GDPR, and you have an absolute right to object to direct marketing.
6. Direct marketing and PECR
Where we send electronic marketing, we comply with PECR as well as UK data protection law.
This means:
- we only send marketing where we have a lawful route to do so;
- where consent is required, we ask for it before sending the message;
- where we rely on a lawful B2B route, we make sure the message is relevant, proportionate and includes a clear opt-out; and
- if you object to direct marketing, we will stop using your personal data for that purpose.
We may keep minimal suppression information, such as your email address and opt-out status, in order to respect your preference in future.
7. Cookies, tracking and similar technologies
We use cookies and similar technologies on our website and landing pages, including cookies, local storage, session storage, scripts and tags.
Some of these technologies are strictly necessary for website operation, consent management or security. Others are used for analytics, campaign measurement, lead generation, tag management or anti-spam functions.
Our detailed Cookie Policy explains:
- which technologies have been identified in the latest scan;
- how we classify them;
- which ones are blocked before consent according to scan evidence;
- which ones require further validation; and
- how you can manage or withdraw your choices.
Unless a technology is exempt under PECR, we seek consent before storing information on or accessing information from your device.
8. Recipients of personal data
We may share personal data, where necessary, with:
- other companies within the ELA group;
- IT, hosting, website, security, anti-spam, CRM, analytics and marketing service providers;
- logistics providers, carriers, installers and subcontractors;
- professional advisers, auditors, insurers and debt recovery providers;
- payment, banking and finance partners;
- public authorities, regulators, courts or law enforcement bodies where required; and
- carefully selected partners where this is necessary to answer an enquiry or deliver a requested service.
We require service providers acting on our behalf to process personal data only on our instructions, to keep it secure and to use appropriate contractual safeguards.
9. International transfers
Some group companies, suppliers and service providers may be located outside the UK or may access personal data remotely from outside the UK.
Where we transfer personal data outside the UK and the transfer is legally restricted, we will use an appropriate transfer mechanism and safeguards, such as:
- an adequacy regulation made by the UK government;
- the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU standard contractual clauses or other approved safeguards; or
- a derogation permitted by the UK GDPR where appropriate.
You can contact us if you would like more information about the safeguards used for a particular transfer.
10. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Notice, including to meet legal, tax, accounting, warranty, dispute-resolution and evidential requirements.
Retention periods vary depending on the type of information and the purpose of processing. In general:
- enquiry records are kept for a limited period after the enquiry closes, unless they become part of a customer relationship or legal matter;
- customer and contract records are kept for the life of the relationship and for a period afterwards to meet legal, accounting and claims requirements;
- marketing consent and suppression records are kept for as long as needed to demonstrate compliance and honour opt-outs; and
- website logs and security-related records are usually retained for shorter operational periods unless required for investigation or legal defence.
Where specific legal retention periods apply, we retain the data for those periods. We may anonymise information so that it can no longer be linked to an individual.
11. Your rights
Under the UK GDPR, you may have the right to:
- be informed about how your personal data is used;
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request erasure in certain circumstances;
- request restriction of processing in certain circumstances;
- object to processing based on legitimate interests;
- object at any time to processing for direct marketing;
- receive personal data in a portable format in certain circumstances; and
- withdraw consent at any time, where processing is based on consent.
These rights are not absolute and may be subject to legal exemptions.
To exercise your rights, please contact us at privacy@ela-container.co.uk.
12. Complaints
If you have concerns about how we use personal data, we would appreciate the opportunity to address them first. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Website: ico.org.uk
Telephone: 0303 123 1113
13. Provision of data
Where we need personal data to enter into or perform a contract, or to comply with a legal obligation, we may be unable to provide our products, services, quotation or support if that information is not supplied.
14. Automated decision-making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects about you without appropriate safeguards and a lawful basis. We may use technical anti-spam, fraud-prevention or security tools on the website, but these are intended to protect our services and forms rather than to make significant decisions about individuals.
15. Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. No transmission or storage system can be guaranteed to be 100% secure, but we maintain controls appropriate to the level of risk.
16. Children
Our website and services are not directed at children. We do not knowingly collect personal data from children via the website.
17. Changes to this notice
We may update this Privacy Notice from time to time to reflect changes in law, guidance, business operations or the technologies used on our website. The latest version will always be published on the website together with the date of the most recent update.
Appendix: Alignment note with Cookie Policy
The Privacy Notice and Cookie Policy are intended to operate as a consistent document set. Cookie-specific detail, scan results, categorisation and review points are maintained in the Cookie Policy, while personal-data purposes, lawful bases, rights, recipients and transfers are described in this Privacy Notice.
Last updated: 16 June 2026
Cookie Policy – ELA Container UK Limited
1. Introduction
This Cookie Policy explains how ELA Container UK Limited ("ELA UK", "we", "us", "our") uses cookies and other storage and access technologies on www.ela-container.co.uk and related landing pages.
This policy is intended to comply with:
- the UK General Data Protection Regulation (UK GDPR);
- the Data Protection Act 2018; and
- the Privacy and Electronic Communications Regulations 2003 (PECR).
This policy should be read alongside our Privacy Notice.
2. Why this policy matters
Under PECR, organisations must provide clear and comprehensive information about storage and access technologies and, unless an exception applies, must obtain consent before storing information on or accessing information from a user’s device.
This applies not only to traditional cookies but also to local storage, session storage, tracking pixels, device identifiers, tags, scripts and similar technologies.
3. What are cookies and storage/access technologies?
A cookie is a small data file that is stored on your browser or device. We also use or may use similar technologies, including:
- local storage (persistent browser-side storage);
- session storage (temporary browser-side storage that usually expires when the session ends);
- scripts or tags that trigger the loading of third-party technologies;
- campaign or lead-generation technologies used on forms or landing pages; and
- security technologies used to identify abusive or non-human activity.
For ease of reading, this policy refers to all of the above together as cookies and similar technologies, unless the context requires otherwise.
4. How we categorise technologies
We use the following categories.
4.1 Strictly necessary
These are required to provide a service requested by the user or to ensure core website operation and security. We do not ask for consent for strictly necessary technologies, but we still tell you about them.
4.2 Functional
These support optional website features, integrations or enhanced presentation. If they are not strictly necessary, we only use them with consent where PECR requires that.
4.3 Analytics / statistical measurement
These help us understand how visitors use our website, how pages perform and how campaigns are used. Unless a specific legal exception applies and the conditions for that exception are met, we only use analytics technologies with consent.
4.4 Marketing / campaign measurement / lead generation
These track ad interactions, form activity, campaign attribution or return visits in connection with promotions, customer acquisition and lead generation. We only use these technologies with consent.
4.5 Security / anti-spam
These help us detect bots, spam, fraud or abuse. Where they are genuinely necessary to protect a service the user has requested, we may rely on the strictly necessary exception. If that threshold is not met, we will request consent.
5. Our legal basis and PECR position
Where a technology is strictly necessary, the relevant storage/access activity is used under the PECR exception for strictly necessary technologies. Any subsequent personal data processing associated with that activity is generally carried out on the basis of Article 6(1)(f) UK GDPR (our legitimate interests in maintaining a secure and functional website), unless another lawful basis is more appropriate.
Where a technology is not strictly necessary, we rely on consent under PECR and, where personal data is processed, Article 6(1)(a) UK GDPR.
We do not treat analytics, advertising, conversion measurement, campaign attribution or lead-generation tracking as strictly necessary merely because they are useful to us.
6. How consent works on our website
We use a consent management platform (CMP) to manage cookie preferences.
This means:
- you should be able to accept, reject or configure non-essential categories;
- non-essential technologies should remain blocked until you have provided valid consent, unless a legal exception applies;
- your choice should be remembered using a consent cookie; and
- you should be able to revisit and change your settings at any time.
Where we use third-party technologies through tag managers, campaign tools or embedded scripts, we aim to ensure the same consent rules apply before those technologies are activated.
7. Detailed cookie and storage information
The information below is based on the latest scan data available to us and covers cookies and similar technologies detected on the main website and identified landing pages.
7.1 Strictly necessary and security technologies
OptanonConsent
- Provider / domain: ela-container.co.uk
- Type: HTTP document cookie
- Duration: 365 days
- Detected on: homepage
- Blocked before consent: no (as expected for a consent-preference cookie)
- Purpose: stores the user’s cookie choices so the website can remember privacy preferences and apply the chosen settings.
- PECR position: strictly necessary.
SSESS#
- Provider / domain: ela-container.co.uk
- Type: HTTP document cookie / HTTP response cookie
- Duration: 24 days
- Detected on: /treatment-rooms
- Blocked before consent: yes in the scan output
- Purpose: maintains a secure session and supports website interactions on certain pages.
- PECR position: expected to be strictly necessary if it is genuinely required for secure session handling.
sessionCachedBotScore
- Provider / domain: ela-container.co.uk
- Type: HTML session storage
- Duration: session
- Detected on: homepage
- Blocked before consent: yes in the scan output
- Purpose: stores a temporary bot or abuse-prevention score to support anti-abuse controls.
- PECR position: likely strictly necessary if used only for security and abuse prevention.
rc::a
- Provider / domain: google.com
- Type: HTML local storage
- Duration: persistent
- Detected on: /contact
- Blocked before consent: no in the scan output
- Purpose: believed to be part of Google anti-spam / anti-bot functionality associated with form protection.
- PECR position: only exempt from consent if genuinely necessary for the secure delivery of the contact form or equivalent requested service.
rc::c
- Provider / domain: google.com
- Type: HTML session storage
- Duration: session
- Detected on: /contact
- Blocked before consent: no in the scan output
- Purpose: believed to support session-based anti-bot analysis for form protection.
- PECR position: only exempt from consent if genuinely necessary for the secure delivery of the contact form or equivalent requested service.
7.2 Analytics technologies
_ga
- Provider / domain: ela-container.co.uk and co.uk
- Type: HTTP document cookie
- Duration: 730 days
- Detected on: homepage
- Blocked before consent: yes in the scan output
- Purpose: used by Google Analytics to distinguish users and support the creation of aggregate reports about website use.
- PECR position: non-essential; consent required unless a specific statutory exception truly applies and all related conditions are met.
_ga_#
- Provider / domain: ela-container.co.uk and co.uk
- Type: HTTP document cookie
- Duration: 730 days
- Detected on: homepage
- Blocked before consent: yes in the scan output
- Purpose: used by Google Analytics 4 to store and calculate page views, session state or event-related information within a property.
PECR position: non-essential; consent required unless a specific statutory exception truly applies and all related conditions are met.
ga4InSession
- Provider / domain: ela-container.co.uk
- Type: HTML session storage
- Duration: session
- Detected on: homepage
- Blocked before consent: yes in the scan output
- Purpose: supports session logic used with Google Analytics 4 or related measurement tags.
- PECR position: non-essential where used for analytics; consent required.
7.3 Marketing, campaign measurement and lead generation technologies
_gcl_au
- Provider / domain: ela-container.co.uk and co.uk
- Type: HTTP document cookie
- Duration: 90 days
- Detected on: homepage
- Blocked before consent:** yes in the scan output
- Purpose: used by Google Ads / Conversion Linker to store and process information about ad clicks and conversion attribution.
- PECR position: non-essential; consent required.
_gcl_ls
- Provider / domain: ela-container.co.uk
- Type: HTML local storage
- Duration: persistent
- Detected on: homepage
- Blocked before consent: yes in the scan output
- Purpose: stores marketing / click measurement information in local storage for attribution or conversion purposes.
- PECR position: non-essential; consent required.
pardot
- Provider / domain: go.ela-container.co.uk and storage.pardot.com / pardot.com
- Type: HTTP response cookie
- Duration: session
- Detected on: homepage and /lp/construction landing page
- Blocked before consent: yes in the scan output
- Purpose: used by Salesforce Account Engagement (Pardot) to recognise visitors, support landing-page forms, link activity with campaigns and assist lead generation or attribution.
- PECR position: non-essential; consent required if the technology stores or accesses information on the user’s device for campaign, lead-generation or similar purposes.
7.4 Unidentified technical storage item
a/n (23)
- Provider / domain: ela-container.co.uk
- Type: HTTP document cookie
- Duration: 720 days
- Detected on: homepage
- Blocked before consent: yes in the scan output
- Purpose: the scan identifies this item but does not provide enough information to map it to a confirmed service or purpose.
- PECR position: until this item is positively identified, it should not be treated as exempt from consent merely because it appears technical in nature.
8. Related services and scripts observed in the scan
The scan also detected services or scripts that may support or trigger storage/access technologies, including:
- Usercentrics Consent Management Platform;
- Google Tag Manager;
- Salesforce / Pardot scripts and analytics endpoints;
- Amazon Web Services content delivery;
- JSDelivr content delivery; and
- page-specific third-party libraries on campaign pages.
A script or tag does not always create a user-visible cookie by itself, but it may still control or load storage/access technologies that are covered by PECR.
9. How to manage or withdraw consent
You can manage your cookie settings through our cookie banner or by re-opening the cookie settings interface available on the site.
You can also remove cookies through your browser settings. However, doing so will not necessarily stop future storage/access activity unless you also change your settings through our CMP.
Please note that disabling strictly necessary technologies may affect the operation, security or availability of parts of the website.
10. International transfers and third parties
Some of the technologies listed above are provided by third parties or may involve data being made available outside the UK in connection with website hosting, analytics, CRM, marketing or anti-spam services.
Where personal data is transferred outside the UK and the transfer is legally restricted, we use an appropriate transfer mechanism under the UK GDPR, such as an adequacy regulation or approved contractual safeguards.
11. Retention and duration
The duration of each cookie or storage item identified in the scan is shown above. Where a technology is session-based, it should expire when the session ends unless technical circumstances require otherwise.
We review our use of cookies and similar technologies periodically and update this policy when there are material changes in the technologies used, their purpose, or the applicable legal requirements.
12. Our current compliance controls and review points
We maintain controls intended to support PECR and UK GDPR compliance, including:
- the use of a CMP with an autoblocker function;
- category-based consent management;
- periodic scanning and review of detected technologies; and
- efforts to prevent non-essential technologies from loading before consent.
However, the latest scan indicates areas that require continued monitoring and, where necessary, remediation, including:
- the precise identification and classification of a/n (23);
- verification that rc::a and rc::c are genuinely necessary security technologies if they are loaded before consent; and
- confirmation that page-specific campaign tools and third-party scripts remain correctly categorised and blocked where required.
13. Contact us
If you have questions about this Cookie Policy or our use of cookies and similar technologies, please contact:
ELA Container UK Limited
Staddlethorpe Broad Lane
Gilberdyke, Brough
HU15 2TD
United Kingdom
Email: privacy@ela-container.co.uk
14. Changes to this policy
We may update this Cookie Policy from time to time to reflect changes in law, regulatory guidance, technology or our website practices. The latest version will always be published on the website together with the update date.
Appendix A – Detailed Scan Table
| Category | Name | Provider / Domain | Storage Type | Duration | Page(s) | Blocked Before Consent | Purpose / Compliance Note |
|---|---|---|---|---|---|---|---|
| Strictly necessary | OptanonConsent | ela-container.co.uk | HTTP document cookie | 365 days | / | No | Stores user cookie preferences; expected consent cookie. |
| Strictly necessary / security | SSESS# | ela-container.co.uk | HTTP document cookie / HTTP response cookie | 24 days | /treatment-rooms | Yes | Secure session handling on page-specific interactions. |
| Strictly necessary / security | sessionCachedBotScore | ela-container.co.uk | HTML session storage | Session | / | Yes | Temporary bot score for anti-abuse controls. |
| Security (validate exemption) | rc::a | google.com | HTML local storage | Persistent | /contact | No | Google anti-spam item; confirm strictly necessary basis if loaded pre-consent. |
| Security (validate exemption) | rc::c | google.com | HTML session storage | Session | /contact | No | Google anti-spam session item; confirm strictly necessary basis if loaded pre-consent. |
| Analytics | _ga | ela-container.co.uk / co.uk | HTTP document cookie | 730 days | / | Yes | Google Analytics user identifier; non-essential. |
| Analytics | _ga_# | ela-container.co.uk / co.uk | HTTP document cookie | 730 days | / | Yes | Google Analytics 4 session / property measurement; non-essential. |
| Analytics | ga4InSession | ela-container.co.uk | HTML session storage | Session | / | Yes | GA4 session logic; non-essential. |
| Marketing / measurement | _gcl_au | ela-container.co.uk / co.uk | HTTP document cookie | 90 days | / | Yes | Google Ads conversion tracking; non-essential. |
| Marketing / measurement | _gcl_ls | ela-container.co.uk | HTML local storage | Persistent | / | Yes | Google click / conversion storage; non-essential. |
| Marketing / lead generation | pardot | go.ela-container.co.uk / storage.pardot.com / pardot.com | HTTP response cookie | Session | /, /lp/construction | Yes | Salesforce Account Engagement visitor / lead capture cookie; non-essential. |
| Unidentified technical item | a/n (23) | ela-container.co.uk | HTTP document cookie | 720 days | / | Yes | Unidentified item; keep under review until purpose is confirmed. |
Appendix B – Related Services and Script-Level Observations
| Service / Script | Scanner Category | Observed Location | Compliance Observation |
|---|---|---|---|
| Usercentrics Consent Management Platform | Essential | Homepage | CMP / autoblocker detected; supports consent management. |
| Google Tag Manager | Functional in scan | Homepage | Tag manager can load non-essential technologies; governance and consent controls must cover tags as well as cookies. |
| Salesforce / Pardot scripts | Functional in scan | Homepage and landing pages | Landing-page and analytics scripts can support lead generation and should stay within consent controls. |
| Amazon Web Services content delivery | Functional in scan | Homepage | Content delivery itself is not necessarily tracking but forms part of website supply chain transparency. |
| JSDelivr | Essential in scan | Homepage | Static script delivery; confirm no unexpected tracking behaviour. |
| BootstrapCDN / Google AJAX on landing page | Ignored in scan | /lp/construction | Page-specific third-party libraries should be reviewed for current necessity and supply-chain risk. |
Last updated: 16 June 2026