Privacy Policy - Man And Van Paddington
This Privacy Policy explains how Man And Van Paddington collects, uses, stores, shares, and protects personal data in connection with its moving, delivery, transport, and related services. It applies to all Man And Van Paddington customers in the area, including individuals, households, landlords, tenants, and business clients who use our services. We are committed to handling personal data in a lawful, fair, transparent, and secure manner in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
For the purposes of data protection law, Man And Van Paddington is the data controller for the personal data we collect and process in relation to our services. This means we decide why and how your personal data is used. We only process personal data that is necessary for providing our services, managing customer relationships, meeting legal obligations, and protecting our legitimate business interests.
2. Personal Data We Collect
We may collect and process various types of personal data depending on how you interact with us and which services you request. The categories of information may include:
- Identity data: such as your name, title, and any information needed to identify you or another person connected to a booking.
- Contact data: including address, email address, telephone number, and delivery or collection address.
- Booking and service data: details of requested moving services, dates, times, inventory lists, access instructions, parking requirements, and service preferences.
- Payment data: payment status, billing records, and transaction details. We do not keep more payment information than is necessary for accounting and reconciliation purposes.
- Communication data: records of emails, messages, calls, complaints, feedback, and any other correspondence with us.
- Technical and usage data: if you communicate with us electronically, we may process limited technical data such as device type, IP-related information, and service interaction details where necessary for security and service management.
- Special category data: we do not actively seek to collect special category data. However, you may voluntarily disclose such information, for example if it is relevant to access needs or delivery requirements. If this occurs, we will only process it where permitted by law and only when necessary.
We do not intentionally collect more data than needed. If you provide information about third parties, such as a family member, tenant, or business contact, you should ensure you have the authority to share that information with us.
3. How We Use Your Data
We use personal data for the following purposes:
- to provide quotes and manage bookings;
- to deliver moving, transport, and related services;
- to communicate with customers before, during, and after a service;
- to process invoices, payments, and refunds where applicable;
- to manage complaints, claims, and service issues;
- to maintain records for accounting, tax, and legal compliance;
- to improve service quality, planning, and operational efficiency;
- to protect our business, staff, customers, and property;
- to detect and prevent fraud, misuse, or unlawful activity.
We only use personal data for the purposes for which it was collected unless we reasonably believe another compatible purpose is required or permitted by law.
4. Lawful Basis for Processing
We process personal data only when we have a valid lawful basis under UK GDPR. Depending on the activity, the lawful basis may include:
- Contract: when processing is necessary to provide a quote, manage a booking, carry out a move, or perform our obligations under an agreement with you.
- Legal obligation: when we must retain or disclose information to comply with tax, accounting, regulatory, or other legal duties.
- Legitimate interests: when processing is necessary for our legitimate business interests, provided these interests are not overridden by your rights and freedoms. This may include service administration, fraud prevention, business protection, and internal record keeping.
- Consent: where required by law, such as for certain optional communications or the processing of special category data in limited circumstances.
- Vital interests: in rare cases where processing is necessary to protect someone’s life or physical safety.
We will always assess the lawful basis that best fits the specific processing activity.
5. Data Sharing and Processors
We may share personal data with trusted third parties only when necessary and proportionate. These third parties may act as processors or independent controllers depending on the situation. Our processors may include:
- IT and cloud service providers that store, secure, or manage data systems;
- payment service providers that process transactions or billing-related information;
- accounting and bookkeeping providers that help with tax and financial records;
- customer communication tools used to manage enquiries and service updates;
- legal, insurance, or claims advisers when necessary to manage disputes or comply with obligations;
- operational partners or subcontractors who help deliver services on our behalf.
Where processors are used, they are required to act only on our instructions and to protect personal data with appropriate security measures. We do not sell personal data. If data is transferred outside the UK, we will ensure appropriate safeguards are in place in accordance with data protection law.
6. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including satisfying legal, accounting, tax, insurance, and reporting requirements. Retention periods vary depending on the type of record and the reason for processing.
In general:
- booking and service records are retained for a period reasonably required for administration, disputes, and business records;
- financial and tax-related records are retained for the period required by law;
- customer communication records are retained for a time necessary to manage enquiries, complaints, or future reference;
- data that is no longer required is securely deleted, anonymised, or destroyed.
When retention is no longer necessary, we take appropriate steps to remove or anonymise the data.
7. Data Security
We use appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, misuse, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and limitation of access to only those who need the data to perform their duties. While no system can be guaranteed fully secure, we work to maintain a level of security suitable to the risks involved.
8. Your Rights Under GDPR
As a data subject, you have rights regarding your personal data. These rights may be limited in some cases by law, but we will always explain if this happens. Your rights include:
- Right of access: you can request a copy of the personal data we hold about you.
- Right to rectification: you can ask us to correct inaccurate or incomplete data.
- Right to erasure: in certain circumstances, you can ask us to delete your data.
- Right to restriction: you can request that we limit the way we process your data in certain cases.
- Right to data portability: you may request certain data in a structured, commonly used format where applicable.
- Right to object: you can object to processing based on legitimate interests or direct marketing where relevant.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
If you exercise your rights, we may need to verify your identity before responding. We aim to respond within the time limits set by law.
9. Complaints and Supervisory Authority
If you are concerned about how we handle your personal data, please raise the issue with us first so we can review and resolve it. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) if you believe your data protection rights have been infringed. We encourage you to contact us directly before escalating a concern, as many issues can be resolved quickly and fairly.
10. Children’s Data
Our services are generally intended for adults arranging moving or transport services. We do not knowingly collect personal data from children except where it is incidental to a booking or service arrangement and only where necessary and lawful. If we become aware that we have collected data from a child without appropriate authority, we will take steps to delete or otherwise handle it in accordance with applicable law.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data protection practices. Any updated version will apply from the date it is published or otherwise made available. We encourage customers in the Paddington area to review this policy periodically so they remain informed about how their data is used.
Summary of Our Commitment
We are committed to processing personal data responsibly, lawfully, and transparently. Man And Van Paddington only collects data that is necessary for service delivery, business administration, legal compliance, and legitimate operational purposes. We limit access, use trusted processors, retain data only as long as needed, and respect your rights under GDPR. This Privacy Policy applies to all Man And Van Paddington customers in the area.