Privacy Policy
This Privacy Policy explains how East Sheen Carpet Cleaners collects, uses, stores, shares, and protects personal data when providing carpet cleaning and related services. It applies to all East Sheen Carpet Cleaners customers in the area, including anyone who requests a quote, books a service, communicates with us, or receives our services. We are committed to handling personal data in a lawful, fair, and transparent manner, in accordance with the UK GDPR and the Data Protection Act 2018.
1. Who We Are
East Sheen Carpet Cleaners is a local service provider that processes personal data in connection with booking, delivering, and managing cleaning services. For the purposes of data protection law, we act as a data controller for the personal information we determine the purposes and means of processing.
2. Information We Collect
We collect only the personal data that is necessary to provide and manage our services. The categories of data we may collect include:
- Identity information such as your name and title.
- Contact details such as your address, email address, and telephone number.
- Service details such as property access notes, cleaning preferences, appointment dates, and instructions relevant to the job.
- Billing and payment information such as invoice details and payment status. We do not intentionally store full card details unless a secure third-party payment provider is used.
- Communication records such as messages, quotes, complaints, feedback, and service history.
- Technical information where relevant, such as limited device or usage data from our systems used to support security and service administration.
We may also receive data from third parties acting on your behalf, such as family members, landlords, letting agents, or business managers, where they arrange services for you and are authorised to do so.
3. How We Use Your Data
We use personal data to operate our business and provide a reliable service. The purposes include:
- responding to enquiries and providing quotations;
- booking and delivering cleaning services;
- managing customer accounts and service records;
- issuing invoices, processing payments, and maintaining financial records;
- communicating about appointments, changes, and service updates;
- handling complaints, disputes, or claims;
- improving service quality, training, and operational efficiency;
- meeting legal, tax, accounting, and regulatory obligations;
- protecting our business, staff, and customers from fraud, misuse, or security incidents.
We will only use your personal data where we have a valid legal basis to do so.
4. Lawful Basis for Processing
We process personal data under one or more of the following lawful bases:
Contract
We process data when it is necessary to enter into or perform a contract with you, such as arranging, delivering, and invoicing for cleaning services.
Legal Obligation
We process data to comply with legal requirements, including accounting, tax, record-keeping, and other obligations required by law.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This can include managing customer relationships, improving services, maintaining security, and preventing fraud.
Consent
In limited situations, we may rely on your consent, for example where you have clearly agreed to specific communications or optional processing. You may withdraw consent at any time where consent is the basis relied upon.
5. Data Sharing and Processors
We may share personal data with trusted third parties who help us operate our business. These parties act as processors on our behalf or, in some cases, as independent controllers. We only share the minimum information necessary for the relevant purpose.
Examples of processors may include:
- booking and scheduling software providers;
- payment service providers;
- IT support, hosting, and cloud storage providers;
- email and communication service providers;
- accounting, bookkeeping, and invoicing systems;
- professional advisers such as accountants or legal advisers;
- debt recovery or dispute resolution services, where required.
All processors are required to protect your data, use it only under our instructions, and maintain appropriate security measures. We do not sell personal data.
6. International Transfers
Where any service provider stores or processes data outside the United Kingdom, we will take appropriate steps to ensure your information is protected. These steps may include the use of approved contractual safeguards or other legally recognised transfer mechanisms.
7. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected and to meet legal or operational requirements. Retention periods depend on the type of data and the reason it is held.
- Customer service records are normally retained for the duration of the customer relationship and for a reasonable period afterwards.
- Invoices, payment records, and accounting data are retained for the period required by tax and accounting law.
- Communication records may be retained for operational, audit, and dispute-handling purposes.
- Security or incident records may be retained for as long as needed to investigate or prevent future issues.
When personal data is no longer required, we will securely delete, anonymise, or archive it in accordance with our retention practices.
8. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, disclosure, or destruction. These measures may include restricted access, secure storage, staff confidentiality obligations, and vendor due diligence. While no system can be guaranteed completely secure, we take reasonable steps to safeguard the information we hold.
9. Your Rights
Under data protection law, you may have the following rights in relation to your personal data:
- Right of access – to request a copy of the personal data we hold about you.
- Right to rectification – to ask us to correct inaccurate or incomplete data.
- Right to erasure – to request deletion of your data in certain circumstances.
- Right to restriction – to ask us to limit the way we use your data in some situations.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to data portability – to receive certain data in a structured, commonly used format where applicable.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
These rights are not absolute, and some requests may be limited by legal obligations or legitimate business reasons. We will respond to valid requests in accordance with applicable law.
10. Cookies and Similar Technologies
If we use websites, booking tools, or digital services that rely on cookies or similar technologies, these may be used to support functionality, security, and performance. Where required, we will provide appropriate notice and obtain consent for non-essential cookies. This policy does not include website details or contact information.
11. Children’s Data
Our services are intended for adults. We do not knowingly collect personal data from children except where it is incidentally included in service instructions, property access arrangements, or records provided by an adult customer. If we become aware that we have collected data improperly, we will take appropriate steps to delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. The updated version will apply from the date it is issued. We encourage customers to review this policy periodically so they remain informed about how their data is handled.
13. Summary of Our Approach
In summary, East Sheen Carpet Cleaners collects only the information needed to provide services, uses it on a lawful basis, retains it only for as long as necessary, and shares it only with trusted processors under proper safeguards. We respect your privacy and aim to handle all personal data responsibly, securely, and transparently.
