Privacy Policy
Elephant And Castle Cleaners is committed to protecting the privacy and personal data of all customers in the Elephant and Castle area. This Privacy Policy explains how we collect, use, share, store, and protect personal information when we provide cleaning services to our customers in the area. It also explains the rights available to you under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Scope of this Privacy Policy
This Privacy Policy applies to all Elephant And Castle Cleaners customers in area, including anyone who requests a quotation, books a service, receives cleaning work, communicates with us, or otherwise uses our services. By engaging with our services, you acknowledge that your personal data may be processed in accordance with this policy.
2. Personal Data We Collect
We only collect personal data that is necessary, relevant, and limited to the purposes described in this policy. Depending on your interaction with us, we may collect the following types of information:
- Identity data: your name and, where needed, the name of a business or property contact.
- Contact data: address, phone number, and email address.
- Service data: details about the cleaning service requested, property access notes, preferred schedules, and service instructions.
- Billing and transaction data: payment records, invoice information, and transaction references.
- Communication data: messages, service feedback, complaints, and any correspondence with us.
- Technical data: limited information such as device or browser details if you communicate with us electronically.
- Special category data: we do not intentionally collect sensitive personal data unless it is strictly necessary and you have provided it voluntarily, or we are legally required to process it.
We do not seek to collect more data than is needed for providing a professional cleaning service. If you provide information about access codes, alarm details, or household preferences, we will treat that information with appropriate care and confidentiality.
3. How We Use Your Data
Your personal data is used for clear and legitimate business purposes. These include:
- arranging and delivering cleaning services;
- managing bookings, schedules, and service changes;
- issuing quotations, invoices, and receipts;
- communicating with you about your service or account;
- responding to enquiries, complaints, or requests;
- maintaining service quality, record-keeping, and customer support;
- meeting legal, tax, accounting, and regulatory obligations;
- protecting against fraud, misuse, or unlawful activity.
We will always ensure that our use of personal data is fair, lawful, transparent, and proportionate to the service being provided.
4. Lawful Basis for Processing
Under data protection law, we must have a lawful basis before processing your personal data. Depending on the situation, we rely on one or more of the following lawful bases:
Contract
We process your data when it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This includes handling bookings, service delivery, and customer communications.
Legal Obligation
We may process personal data when required to comply with legal obligations, including accounting, tax, and record-keeping requirements.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided these do not override your rights and freedoms. Examples include managing business operations, improving service quality, handling disputes, and keeping secure records.
Consent
In limited circumstances, we may rely on your consent, for example where you provide optional information that is not necessary for the service. Where consent is used, you can withdraw it at any time.
5. Sharing Your Information and Processors
We may share personal data with trusted third parties only where necessary and in accordance with data protection law. These third parties act as data processors or independent controllers depending on the service they provide.
- Payment processors: to process card or electronic payments securely.
- Accounting or bookkeeping providers: to support financial administration and legal compliance.
- IT and cloud service providers: to store data, manage communication systems, or maintain business tools.
- Scheduling or customer management tools: to organise bookings and service records.
- Professional advisers: such as accountants, legal advisers, or insurers, where necessary.
- Public authorities: if disclosure is required by law, court order, or regulatory request.
All processors are required to protect your data, act only on our instructions where applicable, and implement appropriate security measures. We do not sell personal data. We also do not allow processors to use your information for their own unrelated purposes.
6. Data Retention
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. Retention periods may vary depending on the type of information and the purpose of processing.
- Customer service and booking records: retained for the period needed to manage the service and any related follow-up.
- Invoice and payment records: retained for the period required by tax and accounting laws.
- Communication records: retained for a reasonable period to resolve queries, prove instructions, or handle complaints.
- Legal or dispute-related records: retained for as long as needed to defend or establish legal claims.
When data is no longer required, we will securely delete, anonymise, or destroy it. Retention is always limited to what is necessary, and we periodically review stored information to make sure it is not kept longer than needed.
7. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, disclosure, or destruction. These measures may include access controls, secure storage, staff confidentiality expectations, and limiting access to those who need the data for legitimate business purposes.
While no system can be guaranteed to be completely secure, we take reasonable steps to safeguard the information entrusted to us and to reduce the risk of misuse.
8. Your Rights Under GDPR
You have several rights regarding your personal data. Subject to legal limitations, these may include:
- Right of access: you can request confirmation of whether we hold your data and obtain a copy.
- Right to rectification: you can ask us to correct inaccurate or incomplete data.
- Right to erasure: in some circumstances, you can ask us to delete your data.
- Right to restriction: you can request that we limit the processing of your data in certain situations.
- Right to data portability: you may request a structured copy of data you have provided, where applicable.
- Right to object: you can object to processing based on legitimate interests in certain cases.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
You also have the right to raise a concern with the UK Information Commissioner’s Office if you believe your data protection rights have been breached. We encourage you to contact us first so we can address your concern promptly and fairly.
9. International Transfers
If personal data is transferred outside the UK, we will only do so where appropriate safeguards are in place to protect the information in accordance with applicable law. Such safeguards may include adequacy regulations, standard contractual clauses, or equivalent legal mechanisms.
10. Children’s Data
Our services are intended for adults and household or business customers. We do not knowingly collect personal data from children unless it is provided incidentally in connection with a service request and only where necessary. If we become aware that data has been collected inappropriately, we will take suitable steps to address it.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, services, or operational practices. When we do, we will ensure the revised version remains clear, lawful, and relevant to our customers in the Elephant and Castle area. We encourage you to review this policy periodically to stay informed about how your personal data is protected.
12. Summary of Our Commitment
At Elephant And Castle Cleaners, we believe privacy should be handled with the same care and attention as the services we provide. We collect only the information needed to deliver reliable cleaning services, use it on a lawful basis, keep it only as long as necessary, share it only with trusted processors when required, and respect your rights at every stage. Our approach is designed to be transparent, responsible, and GDPR-compliant for all customers in the area.