Privacy Policy - Man With Van Tooting
This Privacy Policy explains how Man With Van Tooting collects, uses, stores, shares, and protects personal data when providing removal and van services. It applies to all Man With Van Tooting customers in the area, including individuals, households, and business customers who book, enquire about, or receive services from us.
We are committed to handling personal data in a lawful, fair, and transparent manner in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy is intended to help you understand what information we process, why we process it, how long we keep it, and what rights you have over your personal data.
1. Personal Data We Collect
We only collect personal data that is necessary for providing our services, managing our business operations, and meeting our legal obligations. The information we may collect includes:
- Identity data such as your name and title.
- Contact data such as telephone number, email address, and service address.
- Booking and service data such as moving date, property access details, inventory notes, service preferences, and delivery instructions.
- Payment data such as billing details, transaction records, and payment confirmations.
- Communication data such as emails, messages, call notes, and complaint records.
- Technical data such as basic website or device information if you make an enquiry online, including IP address and browser type where relevant.
- Special category data only where you voluntarily provide it and it is necessary for a specific request, for example accessibility requirements or other information needed to safely deliver the service.
We do not intentionally collect more information than is needed. If you choose not to provide certain data, we may still be able to offer services, but some requests may not be possible to complete.
2. How We Use Your Personal Data
We process personal data for specific business and service purposes. These include:
- To respond to enquiries and provide quotations.
- To manage bookings, plan routes, and deliver moving services.
- To process payments, invoices, and refunds where applicable.
- To communicate with you about your booking, service updates, or changes.
- To maintain internal records and customer service histories.
- To handle complaints, disputes, or claims.
- To meet legal, tax, accounting, and insurance obligations.
- To improve our services, operations, and customer experience.
- To prevent fraud, misuse, or unlawful activity.
We use a principle of data minimisation, meaning we only use the data needed for the purpose stated. We do not sell personal data.
3. Lawful Basis for Processing
Under UK GDPR, we must have a lawful basis to process personal data. Depending on the situation, we rely on one or more of the following:
Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes taking bookings, arranging services, handling payment, and delivering the move.
Legal Obligation
We may process personal data to comply with legal duties, including tax records, accounting rules, insurance requirements, and other regulatory obligations.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This can include service planning, fraud prevention, record keeping, customer support, and business improvement.
Consent
In limited circumstances, we may rely on your consent, for example where you provide optional information or agree to specific communications. Where consent is used, you may withdraw it at any time.
Vital Interests
In rare cases, we may process data to protect someone’s vital interests, such as in an emergency relating to safety during a move.
4. Sharing and Processors
We may share personal data with trusted third parties where necessary to operate our business and provide our services. These third parties act as processors on our behalf or, in some cases, as independent controllers.
Examples of processors and service providers may include:
- Payment processors that handle card or electronic payments.
- Accounting providers that support bookkeeping, invoices, and tax compliance.
- IT and cloud service providers that store data securely and support our systems.
- Communication providers that help deliver emails, messages, or customer notifications.
- Insurance and claims handlers where required for liability or dispute resolution.
- Professional advisers such as lawyers, auditors, or consultants when needed.
We require processors to protect personal data, use it only for permitted purposes, and apply appropriate security measures. Where personal data is shared with independent third parties, we only do so when there is a lawful reason, such as legal obligation, contract performance, or legitimate interests.
We may also disclose information if required by law, court order, law enforcement request, or to protect our rights, property, staff, customers, or the public.
5. International Transfers
Where any processor or service provider stores or accesses personal data outside the UK, we take steps to ensure the data remains protected. This may include using standard contractual clauses, adequacy decisions, or equivalent safeguards permitted under data protection law.
6. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including legal, accounting, and reporting requirements. Retention periods vary depending on the type of data and the reason for processing.
- Booking and service records are generally kept for a reasonable period after completion of the service to manage queries, disputes, or follow-up needs.
- Financial records are kept for the period required by tax and accounting law.
- Complaint and claims records may be retained for longer where needed to resolve legal matters or insurance issues.
- Consent-based communications are kept until you withdraw consent or the data is no longer needed.
When personal data is no longer required, it is securely deleted, anonymised, or otherwise disposed of in a safe and lawful manner.
7. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction. These measures may include access controls, secure storage, staff training, password protection, and limited access on a need-to-know basis.
While we take data security seriously, no system can be guaranteed to be completely secure. If a personal data breach occurs and poses a risk to your rights and freedoms, we will respond in line with legal requirements.
8. Your Rights
As a data subject under UK GDPR, you have a number of rights in relation to your personal data. These include:
- Right of access - to request a copy of the personal data we hold about you.
- Right to rectification - to correct inaccurate or incomplete data.
- Right to erasure - to ask us to delete your data in certain circumstances.
- Right to restriction - to ask us to limit how we use your data.
- Right to data portability - to receive certain data in a portable format where applicable.
- Right to object - to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent - where processing is based on consent.
You may also have the right to challenge decisions made solely by automated means, although we do not normally rely on fully automated decision-making that produces legal or similarly significant effects.
If you wish to exercise any of these rights, we will respond in accordance with applicable law. We may need to verify your identity before acting on your request to protect your privacy.
9. Children’s Data
Our services are not intended for children as primary customers. We do not knowingly collect personal data from children unless it is necessary in the context of a household move and provided by an adult responsible for the booking. Where this occurs, the data is handled with the same care and legal safeguards described in this policy.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or data handling practices. Any revised version will apply from the date it is published or otherwise communicated. We encourage customers to review this policy periodically to stay informed.
11. Summary of Our Approach
In summary, Man With Van Tooting processes personal data only where it is necessary, lawful, and proportionate. We aim to be transparent about what we collect, careful about how we use it, and respectful of your rights. Our commitment is to keep your information secure, retain it only for as long as needed, and use trusted processors where appropriate to support our services.
Italic note: This policy is designed to reflect privacy principles that apply to customers throughout the area served by Man With Van Tooting.