1. Who we are Commercial Industrial Cleaning Services, we provides commercial cleaning and window cleaning services.
2. Personal data we collect
We may collect and process:
- Identity & contact data: name, job title, business name, address, email, phone.
- Service & account data: service requests, quotes, invoices, site access instructions, photos related to work completed, service history.
- Financial data: payment details (processed via our payment provider), transaction records.
- Communications: emails, messages, call notes, feedback, complaints.
- Website/cookie data: IP address, device/browser info, usage metrics (see Cookies).
- CCTV/On‑site data (if applicable): recordings at sites where you invite us to work or where we operate CCTV at our premises.
- Supplier/contractor data: contact details, certifications, insurance.
We do not intentionally collect children’s data.
3. How we use your data (purposes & lawful bases)
We process personal data only when we have a lawful basis under UK GDPR:
- Provide and manage services (quotes, scheduling, delivery, customer support) — Contractual necessity.
- Billing and payment processing — Contractual necessity and Legal obligation (tax/accounting).
- Site safety & compliance (RAMS, permits, access logs, incident reporting) — Legal obligation and Legitimate interests (safe operations).
- Quality assurance (before/after service photos, audits) — Legitimate interests (service verification).
- Marketing communications (updates, offers) — Consent or Legitimate interests (for existing customers; you can opt out anytime).
- Security & fraud prevention (system logs, CCTV at our premises) — Legitimate interests.
- Recruitment (if you apply) — Legitimate interests and Consent where required.
4. Sharing your data
We may share data with:
- Service providers/Processors: IT hosting, CRM, email, payment processors, accounting, SMS tools, cloud storage—each under contract and only as needed.
- Operational partners/subcontractors: where required to deliver your service (e.g., specialist window access teams), under confidentiality obligations.
- Professional advisors & regulators: accountants, legal counsel, HMRC, ICO, or law enforcement when legally required.
- Business transfers: in case of merger, acquisition, or asset sale (with appropriate safeguards).
We do not sell personal data.
5. International transfers
If we transfer data outside the UK (e.g., cloud services), we will ensure appropriate safeguards such as UK International Data Transfer Agreements or adequacy decisions. Details are available on request.
6. Data retention
We keep data only as long as necessary:
- Customer records & service history: typically 6 years (tax/accounting).
- Quotes & enquiries (no contract): 12–24 months.
- Marketing contacts: until you unsubscribe or after 24 months of inactivity.
- CCTV (if used): usually 30–45 days, unless required for investigations.
- Recruitment: 6–12 months unless you consent to a longer period.
We securely delete or anonymise data when retention periods expire.
7. Your rights
Under UK data protection law, you have the right to:
- Access your data
- Rectification (correct inaccuracies)
- Erasure (“right to be forgotten”)
- Restriction of processing
- Data portability
- Object to processing (especially direct marketing)
- Withdraw consent (where reliance is on consent)
To exercise these rights, contact [privacy@yourdomain.co.uk]. We may need to verify your identity.
You also have the right to complain to the Information Commissioner’s Office (ICO): ico.org.uk or 0303 123 1113. We’d appreciate the chance to resolve your concerns first.
8. Security
We use appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit where applicable, staff training, and regular reviews of our suppliers and systems.
9. Cookies & website analytics
We use cookies and similar technologies to operate our website, remember preferences, and improve performance. Where required, we will request cookie consent and provide a cookie banner with granular controls.
- Essential cookies: site functionality (no consent required).
- Analytics/marketing cookies: used only with consent; you can withdraw any time.
See our Cookie Notice for details (or ask us for a copy).
10. Direct marketing
We may send relevant updates about our services. You can opt out at any time via the link in our emails or by contacting us. For new prospects, we will only market where we have consent or legitimate interests balanced against your rights.
11. Third‑party links
Our website may link to third‑party sites (e.g., payment providers). We are not responsible for their privacy practices. Please review their policies.
12. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date shows the latest revision. Significant changes will be notified on our website or via email, where appropriate.