Privacy Policy - Man And Van Shoreditch
This Privacy Policy explains how Man And Van Shoreditch collects, uses, stores, shares, and protects personal data in connection with our moving, delivery, and transport services. It applies to all Man And Van Shoreditch customers in the area, including individuals, households, businesses, and anyone who enquires about or uses our services.
We are committed to handling personal data in a lawful, fair, and transparent manner in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy sets out what data we collect, why we collect it, the lawful basis we rely on, how long we keep it, who may process it on our behalf, and the rights you have over your personal data.
1. Data We Collect
We only collect personal data that is necessary to provide our services, manage our business, and meet our legal obligations. Depending on your interaction with us, we may collect the following categories of information:
- Identity information: name, title, and similar details needed to identify you.
- Contact information: address, email address, telephone number, and any preferred method of communication.
- Service details: move dates, collection and delivery addresses, property access information, inventory details, and relevant instructions for moving or transport.
- Billing and payment information: invoice details, payment status, and limited financial information required to process transactions.
- Communication records: enquiries, quotations, complaints, feedback, emails, text messages, and call notes.
- Website and technical information: if you visit a digital service used by us, we may collect device and usage data such as IP address, browser type, and basic analytics data.
- Special category data: we do not generally seek special category data. If such information is provided to us by you incidentally, for example because it is necessary to accommodate access needs, we will only process it where a lawful basis exists and appropriate safeguards are in place.
We ask that you only share information that is relevant to the service you require. Where you provide personal data about another person, such as a family member, employee, tenant, or landlord, you should ensure that you have the authority to do so and that they understand how their data may be used.
2. How We Use Your Data
We use personal data for the following purposes:
- to provide quotations and respond to enquiries;
- to arrange, manage, and perform moving or transport services;
- to confirm booking details and coordinate logistics;
- to process payments, issue invoices, and maintain accounting records;
- to handle customer service matters, complaints, and claims;
- to comply with legal and regulatory obligations;
- to maintain security, prevent fraud, and protect our business and customers;
- to improve our services, internal procedures, and service quality;
- to keep records of transactions and correspondence for operational and legal purposes.
We will not use your personal data in ways that are incompatible with the purposes for which it was collected unless we have a lawful reason to do so and, where required, we notify you.
3. Lawful Basis for Processing
Under the UK GDPR, we must have a lawful basis to process your personal data. Depending on the situation, we rely on one or more of the following grounds:
- Performance of a contract: when processing is necessary to provide a quote, accept a booking, carry out a move, deliver goods, or otherwise fulfil our agreement with you.
- Legal obligation: when we must keep records or disclose information to comply with tax, accounting, transport, insurance, or other legal requirements.
- Legitimate interests: when processing is necessary for our legitimate business interests, such as maintaining service records, protecting against fraud, improving operations, or responding to customer queries, provided those interests are not overridden by your rights and freedoms.
- Consent: where we rely on your clear consent, for example for certain optional communications or for specific categories of data where consent is the most appropriate basis. You may withdraw consent at any time where it is the basis used.
If we need to process special category data, we will only do so where an additional condition under UK GDPR applies, such as explicit consent or where it is necessary for legal claims or substantial public interest reasons.
4. Retention of Personal Data
We keep personal data only for as long as necessary for the purpose for which it was collected, including to satisfy legal, accounting, reporting, and insurance requirements. Retention periods may vary depending on the type of information and the nature of the service provided.
- Quotation and enquiry records: normally kept for a limited period after the enquiry ends, unless further retention is required for ongoing business or legal reasons.
- Booking and service records: retained for as long as needed to complete the service and handle any follow-up matters, including disputes or claims.
- Financial and accounting records: retained for the period required by law and business practice.
- Complaints and correspondence: kept for an appropriate period to manage customer service and legal defence needs.
When data is no longer required, we will securely delete, anonymise, or destroy it. We review retention needs periodically to ensure we do not keep information for longer than necessary.
5. Processors and Third Parties
We may share personal data with trusted third parties who process information on our behalf, known as processors. These third parties are only permitted to process your data according to our instructions and must keep it secure and confidential. Examples may include:
- accounting and bookkeeping providers;
- payment processing services;
- IT, hosting, data storage, and security service providers;
- communication and customer management tools;
- insurance providers, claims handlers, and legal advisers where relevant;
- professional advisers assisting with compliance and business operations.
We may also disclose information to independent third parties where required by law, to enforce or defend legal rights, to protect the safety of individuals, or to support the performance of a contract. Where data is transferred outside the UK, we will ensure appropriate safeguards are in place, such as adequacy regulations or approved contractual protections.
Data Protection by Design
We aim to apply data protection principles throughout our operations. This means we try to collect the minimum amount of data needed, restrict access to authorised personnel, and use reasonable technical and organisational measures to protect personal information. Security is a shared responsibility, and we expect our processors to meet equivalent standards.
6. Your Rights
As a data subject under UK GDPR, you have several rights in relation to your personal data. These rights may be limited in certain circumstances, but we will always assess and respond to your request in accordance with the law. Your rights include:
- Right of access: you can ask for a copy of the personal data we hold about you and information about how it is used.
- Right to rectification: you can request correction of inaccurate or incomplete information.
- Right to erasure: you can ask us to delete your data in certain situations, for example where it is no longer needed or where consent has been withdrawn.
- Right to restriction: you can ask us to limit how we use your data in certain cases.
- Right to data portability: where applicable, you may request a copy of certain data in a structured, commonly used format.
- Right to object: you may object to processing based on legitimate interests or direct marketing.
- Rights related to automated decision-making: you have protection against decisions made solely by automated means where such decisions produce legal or similarly significant effects.
If you wish to exercise any of these rights, we will need to verify your identity before responding. We aim to handle requests promptly and within the time limits set by law.
7. Data Security
We take reasonable steps to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and routine review of our procedures. However, no system is completely secure, and we cannot guarantee absolute protection. If a personal data breach occurs that affects your rights and freedoms, we will assess the risk and take appropriate action in line with legal requirements.
8. Children’s Data
Our services are not directed to children, and we do not knowingly collect personal data from minors unless it is necessary in connection with a move or service request made by an adult responsible for them. If we become aware that we have collected data from a child without appropriate authority, we will take steps to delete it where required.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data protection practices. Any updated version will apply from the date it is published or communicated. We encourage customers to review this policy periodically to stay informed about how we protect personal data.
10. Complaints
If you have concerns about how your personal data is handled, you should raise them with us first so that we can try to resolve the matter. You also have the right to lodge a complaint with the UK supervisory authority if you believe your data protection rights have been infringed.
Privacy and respect for your information are central to how we operate. By using our services, you acknowledge that you have read and understood this Privacy Policy and that your personal data will be handled in accordance with the principles set out above.