Legal

GDPR Policy

How we protect your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Last updated: 23 May 2026

1. Data controller

Kriss Professional Cleaning is the data controller responsible for your personal information. We are based in Watford, United Kingdom.

Contact: info@krissprocleaning.co.uk · 07387 007943

2. What personal data we process

  • Identity & contact details: name, phone, email, service address.
  • Booking details: type of clean, date, time, access notes.
  • Communications: messages sent by email, WhatsApp, contact form or phone.
  • Financial data: invoicing and payment records (no card details stored).
  • Technical data: anonymous analytics, IP address, browser type.

3. Lawful bases for processing

  • Contract — to provide the cleaning services you book.
  • Legitimate interests — to respond to enquiries, manage bookings and run our business.
  • Legal obligation — to keep financial, tax and insurance records.
  • Consent — where required, e.g. for non-essential cookies or marketing.

4. Your rights under UK GDPR

You have the right to:

  • Be informed about how your data is used.
  • Access the personal data we hold about you.
  • Have inaccurate data corrected.
  • Request erasure (“right to be forgotten”).
  • Restrict or object to processing.
  • Data portability — receive your data in a portable format.
  • Withdraw consent at any time, where consent is the lawful basis.
  • Not be subject to solely automated decision-making.

5. How to make a data request

Email info@krissprocleaning.co.uk with the subject line “GDPR request”. We will respond within 30 days, free of charge. We may ask you to verify your identity before releasing any data.

6. Data retention

  • Enquiry data: up to 24 months.
  • Booking & invoicing records: 6 years (HMRC requirement).
  • Marketing consents: until you withdraw consent.

After these periods, data is securely deleted or anonymised.

7. Data sharing & processors

We only share your data with vetted providers who help us deliver our service (email hosting, accounting software, WhatsApp, website hosting, analytics). All processors are bound by data-processing agreements and are required to keep your data secure. We do not sell your personal data.

8. International transfers

Some of our providers (e.g. Meta/WhatsApp) may transfer data outside the UK. Where this happens, transfers are protected by adequacy decisions or Standard Contractual Clauses approved by the UK ICO.

9. Data security

We use appropriate technical and organisational measures — including encrypted email, access controls, secure devices and staff training — to protect your data against unauthorised access, loss or disclosure.

10. Data breaches

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office (ICO) within 72 hours and notify you without undue delay where required.

11. Cookies

Our website uses only essential cookies needed for it to function, plus anonymous analytics where you have consented. See our privacy policy for details.

12. Complaints

If you are not satisfied with how we handle your data, please contact us first so we can put things right. You also have the right to lodge a complaint with the UK supervisory authority:

Information Commissioner's Office (ICO) · 0303 123 1113

13. Updates to this policy

We review this policy regularly and will publish any updates on this page with a refreshed “last updated” date.