Privacy Policy - Mayfair Cleaner
Last updated: [Insert Date]
This Privacy Policy explains how Mayfair Cleaner collects, uses, stores, shares, and protects personal data when providing cleaning services. It applies to all Mayfair Cleaner customers in area, including individuals who request domestic, commercial, end-of-tenancy, deep cleaning, or related services. We are committed to handling personal data lawfully, fairly, and transparently in accordance with the UK GDPR and the Data Protection Act 2018.
1. Who we are
For the purposes of data protection law, Mayfair Cleaner acts as the data controller for the personal data we collect and use in connection with our services. This means we determine why and how your personal information is processed.
2. Personal data we collect
We collect only the information needed to deliver our services, manage our business, and meet legal obligations. Depending on the service you request, this may include:
- Identity data: your name, title, and, where relevant, business name.
- Contact data: address, email address, telephone number, and any preferred communication details.
- Service data: details about the cleaning service requested, property access instructions, booking history, and service preferences.
- Payment data: billing details, payment confirmations, and limited transaction information. We do not intentionally store full card details where payment is handled securely by a payment provider.
- Technical data: basic information such as device identifiers, browser type, and usage data when you interact with our online systems.
- Correspondence data: records of communication with us, including complaints, feedback, and support requests.
- Special category data: we do not normally collect this. If you voluntarily share information that could reveal health conditions, access needs, or other sensitive details, we will only process it where necessary and lawful.
We do not collect more data than we need. If you choose not to provide certain information, we may be unable to complete your booking or deliver the service safely and effectively.
3. How we use your personal data
We use your data for the following purposes:
- to register and manage customer bookings;
- to provide cleaning services at the requested location;
- to communicate about appointments, scheduling changes, and service updates;
- to issue invoices, process payments, and handle refunds where necessary;
- to respond to enquiries, complaints, and feedback;
- to maintain business records and service quality;
- to comply with legal, tax, insurance, and regulatory obligations;
- to protect our staff, customers, and property from fraud, misuse, or unlawful activity.
We may also use aggregated or anonymised information for reporting, planning, and operational improvement. This information does not identify you and is no longer considered personal data.
4. Lawful basis for processing
We only process personal data where we have a valid lawful basis under GDPR. Depending on the context, we rely on one or more of the following:
- Contract: we process data to enter into and perform a contract with you, such as arranging and delivering cleaning services.
- Legal obligation: we process data where required to comply with laws, such as accounting, tax, or record-keeping obligations.
- Legitimate interests: we may process data to run and improve our business, maintain service records, prevent fraud, and manage customer communications, provided these interests do not override your rights and freedoms.
- Consent: in limited circumstances, we rely on your consent, for example where it is needed for optional communications or specific processing not covered by another lawful basis. You may withdraw consent at any time.
If we process special category data, we will do so only where an additional condition under data protection law applies, such as explicit consent or necessity for legal claims or health and safety purposes.
5. Sharing your data and processors
We may share personal data with trusted third parties that help us operate our business. These parties act as processors when they process data on our instructions and are required to protect it by contract and law.
Examples of processors may include:
- Payment processors that handle secure card or online transactions;
- Booking and scheduling providers that support appointment management;
- IT and cloud service providers that host data, email, or business software;
- Communication providers used to send service messages or reminders;
- Accounting and bookkeeping providers that support financial administration;
- Professional advisers such as lawyers, insurers, or auditors where necessary.
We may also disclose data to public authorities, regulators, law enforcement, or courts where required by law or to protect our legal rights. We do not sell your personal data.
6. Data retention
We keep personal data only for as long as necessary for the purpose for which it was collected, including legal, accounting, and reporting requirements. Retention periods vary depending on the type of data and the service provided.
- Customer and booking records: kept for the duration of the service relationship and for a reasonable period afterwards to manage queries or disputes.
- Financial records: retained for the period required by tax and accounting law.
- Communication records: retained as needed to document service delivery and resolve complaints.
- Security and technical logs: kept for a limited time for operational and security purposes.
When data is no longer required, we will delete, anonymise, or securely archive it in line with our retention practices.
7. Data security
We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration, or disclosure. These measures may include access controls, secure storage, password protection, staff confidentiality obligations, and limited access on a need-to-know basis.
While we take reasonable steps to safeguard your data, no system can be guaranteed completely secure. If a personal data incident occurs, we will handle it in accordance with applicable law.
8. Your rights under GDPR
You have a number of rights in relation to your personal data. These rights may be subject to conditions and legal limitations, but we will always consider your request carefully.
- Right of access: you can request a copy of the personal data we hold about you.
- Right to rectification: you can ask us to correct inaccurate or incomplete data.
- Right to erasure: you can ask us to delete your data in certain circumstances.
- Right to restrict processing: you can ask us to limit how we use your data in certain cases.
- Right to data portability: you can request transfer of certain data to you or another controller, where applicable.
- Right to object: you can object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
We will not subject you to decisions based solely on automated processing that produce legal or similarly significant effects, unless permitted by law and subject to safeguards.
9. How to exercise your rights
If you wish to exercise any of your rights, we will ask for sufficient information to verify your identity before responding. We aim to respond within the time limits set by law. If your request is complex or numerous, we may need additional time, but we will keep you informed.
You will not usually be charged for making a rights request unless it is clearly unfounded or excessive.
10. International transfers
If any of our processors store or access data outside the UK, we will ensure appropriate safeguards are in place to protect your personal data. These safeguards may include adequacy regulations, standard contractual clauses, or other lawful transfer mechanisms.
11. Children’s data
Our services are intended for adults, and we do not knowingly collect personal data from children except where necessary in connection with service arrangements made by an adult customer. If we learn that we have collected data inappropriately, we will take steps to delete it where required.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect legal, operational, or service changes. Any updated version will apply from the date it is published or otherwise communicated. We encourage customers to review this policy periodically.
13. Summary of our commitment
Mayfair Cleaner treats privacy as a core responsibility. We collect only the data needed to provide and improve our services, use it only where we have a lawful basis, retain it for no longer than necessary, share it only with trusted processors or where required by law, and respect your rights under GDPR. This policy applies to all Mayfair Cleaner customers in area.