Privacy Policy - Ealing Carpet Cleaning
Effective date: This Privacy Policy applies to all Ealing Carpet Cleaning customers in the Ealing area and explains how we collect, use, store, share, and protect personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We are committed to handling personal information lawfully, fairly, and transparently. This policy is designed to help you understand what data we collect, why we collect it, how long we keep it, who may process it on our behalf, and what rights you have in relation to your personal information.
1. Who this policy applies to
This policy applies to all customers, prospective customers, website users, and anyone else who interacts with Ealing Carpet Cleaning in the Ealing area. It covers personal data collected when you request a quotation, make a booking, receive a cleaning service, communicate with us, or otherwise engage with our business.
By using our services, you acknowledge that your information may be processed as described in this policy. We only collect and use personal data where we have a valid legal basis to do so.
2. Information we collect
We may collect and process the following types of personal data:
- Identity information: name, title, and any relevant customer identifiers.
- Contact details: address, email address, telephone number, and preferred communication method.
- Service information: booking details, property access notes, cleaning preferences, and records of services provided.
- Payment information: payment status, transaction references, and billing-related records. We do not intentionally store full card details unless required by a secure payment provider.
- Communication records: emails, messages, call notes, complaint records, and customer service correspondence.
- Technical and usage data: limited information about how you interact with our digital channels, where applicable, such as IP address, browser type, and device information.
- Special categories of data: we do not actively seek sensitive personal data. If you choose to provide information that is sensitive or health-related, we will only process it where strictly necessary and lawful.
We collect data directly from you when you contact us or book a service, and may also receive limited information from third parties involved in providing a service, such as payment processors or booking platforms.
3. How we use your data
We use personal data for the following purposes:
- To respond to enquiries and provide quotations.
- To manage bookings and deliver carpet cleaning services.
- To process payments and maintain financial records.
- To communicate service updates, confirmations, and follow-up information.
- To handle complaints, queries, or service-related issues.
- To maintain business records and comply with legal or regulatory obligations.
- To improve our services, customer experience, and operational efficiency.
We use the principle of data minimisation, meaning we only collect and process what is necessary for the relevant purpose.
4. Lawful basis for processing
Under UK GDPR, we must have a lawful basis for each processing activity. We rely on the following bases:
Contract
We process your personal data where it is necessary to enter into or perform a contract with you, such as providing a quotation, confirming a booking, or delivering a carpet cleaning service.
Legal obligation
We may process and retain certain information to comply with legal requirements, including accounting, tax, insurance, and record-keeping duties.
Legitimate interests
We may process data where it is necessary for our legitimate business interests, provided that those interests do not override your rights and freedoms. This may include managing customer relationships, preventing fraud, improving service quality, and maintaining internal administration.
Consent
In limited situations, we may ask for your consent, for example where you voluntarily agree to receive optional marketing communications. Where consent is used, you can withdraw it at any time.
5. Data sharing and processors
We do not sell your personal data. However, we may share information with trusted third parties who process data on our behalf, known as processors. These processors are only allowed to use personal data under our instructions and must keep it secure.
Examples of processors may include:
- Payment service providers who handle transactions securely.
- Booking and scheduling systems used to manage appointments.
- IT and cloud storage providers that support record storage, communication, and system maintenance.
- Professional advisers such as accountants or legal advisers where necessary.
- Customer service and communication tools used to send service-related messages.
We may also disclose information where required by law, court order, or a competent authority. Any transfer of data is done with appropriate safeguards to ensure your information remains protected.
6. Data retention
We keep personal data only for as long as necessary for the purpose it was collected and to satisfy legal, accounting, or reporting requirements. Retention periods may vary depending on the type of information and the reason for processing.
- Booking and service records: retained for a reasonable period to manage services, disputes, and repeat bookings.
- Financial and tax records: kept for the period required by law.
- Communication records: retained as needed to respond to issues and maintain service history.
- Marketing preferences: kept until you opt out or withdraw consent, where applicable.
When personal data is no longer required, we securely delete, anonymise, or archive it in accordance with our retention procedures. We do not keep information longer than necessary.
7. Data security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, or disclosure. These measures may include restricted access controls, secure storage, encryption where appropriate, staff awareness procedures, and supplier due diligence.
While we work hard to protect your information, no method of transmission or storage is completely risk-free. If a personal data breach occurs that presents a risk to your rights and freedoms, we will take appropriate steps in line with legal obligations.
8. Your rights
Under data protection law, you have a number of rights in relation to your personal data. These rights may be subject to legal limitations or exceptions.
- Right of access: you can request confirmation of whether we hold your personal data and obtain a copy of it.
- Right to rectification: you can ask us to correct inaccurate or incomplete information.
- Right to erasure: you may request deletion of your personal data in certain circumstances.
- Right to restriction: you can ask us to limit how we use your data in specific situations.
- Right to object: you may object to processing based on legitimate interests, including certain forms of direct marketing.
- Right to data portability: where applicable, you can request transfer of your data in a structured, commonly used format.
- Right to withdraw consent: where processing is based on consent, you can withdraw it at any time.
We aim to respond to valid requests within the time limits required by law. To protect your privacy, we may need to verify your identity before acting on your request.
9. Cookies and similar technologies
If we use online tools that collect technical information, this may include cookies or similar technologies. These are typically used for functionality, security, and basic analytics. Where required, we will provide appropriate information about their use and any choices available to you.
10. International transfers
Where any processor or service provider stores or accesses data outside the UK, we will ensure appropriate safeguards are in place to protect your information in accordance with data protection law. This may include approved contractual protections or equivalent legal mechanisms.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service arrangements. The latest version will apply from the date of publication or update.
Summary: Ealing Carpet Cleaning protects your personal data under UK GDPR, using it only for service delivery, legal compliance, and legitimate business needs.
This policy is intended to be clear, transparent, and fair, while supporting the safe and lawful handling of customer data across all services in the Ealing area.