Privacy Policy - Carpet Cleaning Westminster

Effective date: This Privacy Policy applies to all Carpet Cleaning Westminster customers in the area and explains how personal data is collected, used, stored, shared, and protected when services are requested, delivered, or managed.

We are committed to handling personal data in a lawful, fair, and transparent manner in accordance with the UK GDPR and the Data Protection Act 2018. This policy sets out what information may be collected, why it is collected, the legal bases we rely on, how long data is retained, which types of service providers may process data on our behalf, and the rights available to individuals.

1. Information We Collect

We may collect personal data directly from customers, from communication records, and from service-related interactions. The type of information collected depends on the nature of the request and the services provided. Typical categories include:

  • Identity details: name, title, and any information needed to identify the customer or property occupant.
  • Contact details: address, email address, telephone number, and preferred communication method.
  • Service details: booking date and time, property access requirements, cleaning preferences, and notes relevant to the service.
  • Transaction information: payment status, invoices, receipts, and records needed for accounting or dispute handling.
  • Communication records: messages, enquiries, complaints, feedback, and correspondence relating to service delivery.
  • Technical information: limited device or usage information if data is submitted through an online form or digital system.

We do not intentionally collect special category data unless it is clearly necessary, lawful, and relevant to a specific request. If such information is provided unintentionally, it will be treated with enhanced care and processed only where there is a valid legal basis.

2. How We Use Personal Data

Personal data is used only for legitimate business and service purposes. These may include:

  • handling enquiries and quotations;
  • arranging and delivering cleaning services;
  • confirming bookings and service changes;
  • managing payments, invoices, and financial records;
  • responding to complaints or aftercare requests;
  • maintaining internal records and service history;
  • meeting legal, accounting, or insurance obligations;
  • protecting against fraud, misuse, or security incidents.

We only use data in ways that are relevant, necessary, and proportionate to the purpose for which it was collected. Where possible, information is kept up to date and limited to what is required.

3. Lawful Basis for Processing

Under GDPR, every processing activity must be supported by a lawful basis. We may rely on one or more of the following:

Contract

We process personal data when it is necessary to enter into or perform a contract with a customer. This includes booking cleaning services, providing estimates, completing work, issuing invoices, and managing service delivery.

Legal Obligation

Some information must be kept or processed because the law requires it, such as tax, accounting, record-keeping, or compliance with regulatory duties.

Legitimate Interests

We may process data where it is reasonably necessary for our legitimate business interests, provided those interests are not overridden by the individual’s rights and freedoms. This may include service administration, preventing fraud, improving operations, and maintaining customer records.

Consent

In limited situations, we may rely on consent, for example where a person chooses to receive optional marketing or agrees to a specific non-essential use of data. When consent is used, it can be withdrawn at any time.

We do not use personal data for unexpected purposes. If the purpose changes, we will assess whether a new lawful basis is required.

4. Data Sharing and Processors

We may share personal data with trusted third-party processors who assist in operating the business and providing services. These parties are only allowed to process data under our instructions and must protect it appropriately. Typical processors may include:

  • Payment providers: to process card or digital payments securely.
  • Accounting and bookkeeping providers: to manage invoices, tax records, and financial administration.
  • IT and cloud service providers: to store data securely and maintain systems used for business operations.
  • Customer communication tools: to organise messages, booking confirmations, and service updates.
  • Professional advisers: such as insurers, auditors, or legal advisers where necessary.

We require processors to apply appropriate technical and organisational measures. Processors are not permitted to use data for their own purposes. Data is not sold to third parties.

Where disclosure is required by law, or to protect rights, property, or safety, data may be shared with relevant authorities or other parties entitled to receive it.

5. International Transfers

If any service provider stores or processes data outside the UK, we will ensure that appropriate safeguards are in place. These safeguards may include adequacy regulations, standard contractual clauses, or equivalent lawful transfer mechanisms designed to protect personal data.

6. Data Retention

We retain personal data only for as long as it is needed for the purposes described in this policy. Retention periods may vary depending on the type of record and the legal or operational requirements involved.

  • Customer and service records: kept for the period necessary to deliver services and handle follow-up issues.
  • Financial records: kept for the period required by tax and accounting law.
  • Communication records: kept for a reasonable period to manage enquiries, disputes, and service quality.
  • Consent records: kept while consent remains relevant and for evidence of compliance.

When data is no longer required, it will be securely deleted, anonymised, or otherwise disposed of in a safe and appropriate manner. Retention decisions are reviewed periodically to ensure they remain proportionate.

7. Data Security

We take the security of personal data seriously and apply measures designed to prevent unauthorised access, disclosure, alteration, or loss. These measures may include access controls, secure storage, password protection, staff awareness, and restricted use of personal data.

Although no system can be guaranteed to be completely secure, we work to maintain a level of protection that is appropriate to the nature of the information processed. Confidentiality and data minimisation are important principles in our handling of customer information.

8. Your Rights Under GDPR

Individuals whose data we process have rights under data protection law. These rights may apply depending on the circumstances and the legal basis for processing. They include:

  • Right of access: to request a copy of personal data held about you.
  • Right to rectification: to ask for inaccurate or incomplete data to be corrected.
  • Right to erasure: to request deletion of data in certain situations.
  • Right to restriction: to ask us to limit processing in certain cases.
  • Right to object: to object to processing based on legitimate interests or direct marketing.
  • Right to data portability: to receive certain data in a structured, commonly used format where applicable.
  • Right to withdraw consent: where consent is relied on, it may be withdrawn at any time.

These rights are not absolute and may be subject to legal exceptions or limitations. We may need to verify identity before acting on a request to protect personal information.

9. Marketing Communications

If marketing communications are ever sent, they will be based on the appropriate lawful basis and will always include a way to stop future messages where required. Individuals can object to direct marketing at any time. Where consent is the basis for communication, the person can opt out by withdrawing consent.

10. Children’s Data

Our services are aimed at adults and properties, not children. We do not knowingly collect personal data from children as part of routine service activities. If we learn that we have collected data from a child without appropriate authority or a valid legal basis, we will take reasonable steps to delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, business practices, or service arrangements. The most current version will apply from the date it is published or otherwise communicated. Customers are encouraged to review this policy periodically.

12. Contacting Us About Privacy

For any privacy-related matter, such as a rights request, concern about data handling, or a question about this policy, please use the usual business communication route provided at the time of service. We may ask for information to confirm identity and locate relevant records before responding.

In summary: we process personal data fairly, keep it secure, retain it only as long as necessary, and respect the rights of all Carpet Cleaning Westminster customers in the area.

Carpet Cleaning Westminster

This Privacy Policy explains how Carpet Cleaning Westminster collects, uses, shares, and protects customer data in the area under GDPR.

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.