Privacy Policy - Man And Van Brompton

This Privacy Policy explains how Man And Van Brompton collects, uses, stores, shares, and protects personal data when providing moving, delivery, transport, and related services. It applies to all Man And Van Brompton customers in the area, including individuals and businesses who request quotes, book services, communicate with us, or otherwise use our services. We are committed to handling personal data in a lawful, fair, transparent, and secure manner in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

For the purposes of data protection law, Man And Van Brompton is the data controller for the personal data described in this policy. This means we determine why and how your personal data is processed. We take our responsibilities seriously and aim to collect only the information that is necessary to provide our services, manage our operations, and comply with legal obligations.

2. Personal Data We Collect

We may collect the following categories of personal data depending on how you interact with us:

  • Identity data such as your name and, where relevant, business name.
  • Contact data such as address, email address, and telephone number.
  • Service information such as moving date, collection and delivery addresses, inventory details, access notes, and special handling requirements.
  • Billing and transaction data such as payment records, invoices, and service history.
  • Communication data such as enquiries, feedback, complaints, and correspondence.
  • Technical data where relevant, such as device or browser information if you communicate with us electronically.

We generally do not seek to collect special category data unless it is strictly necessary and you have provided it voluntarily or it is required for a specific legal or operational reason. If such data is ever needed, we will apply additional safeguards and only process it where permitted by law.

3. How We Use Your Personal Data

We use personal data for the following purposes:

  • To provide quotes and process bookings.
  • To plan and carry out moving, delivery, and related services.
  • To communicate with you about your service, schedule, and requirements.
  • To issue invoices, manage payments, and keep accurate financial records.
  • To respond to questions, complaints, and service requests.
  • To improve our services, operations, and customer experience.
  • To comply with legal, tax, accounting, and regulatory obligations.
  • To protect our business, staff, customers, and property from fraud, misuse, or unlawful activity.

We will only use your personal data for the purposes for which it was collected unless we reasonably believe we need to use it for another compatible purpose. If we need to use your data for an unrelated purpose, we will explain the legal basis for doing so.

4. Lawful Basis for Processing

We process personal data only when we have a valid lawful basis under UK GDPR. Depending on the activity, our lawful bases may include:

  • Contract: where processing is necessary to take steps at your request before entering into a contract or to perform our contract with you.
  • Legal obligation: where processing is necessary to comply with tax, accounting, employment, or other legal requirements.
  • Legitimate interests: where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. Examples include service administration, fraud prevention, and service improvement.
  • Consent: where we ask for your permission for certain optional activities. You may withdraw consent at any time where processing is based on consent.

When we rely on legitimate interests, we assess the impact on your privacy and ensure the processing is proportionate and necessary. We do not rely on consent where another lawful basis is more appropriate.

5. Data Sharing and Processors

We may share personal data with trusted third parties where necessary to provide our services, operate our business, or comply with the law. These parties act as processors or independent controllers depending on the relationship. Processors only handle data on our instructions and must protect it appropriately.

Examples of processors may include:

  • IT and cloud service providers used for secure storage, email, scheduling, and data management.
  • Accounting and bookkeeping providers used for invoicing, tax, and financial administration.
  • Payment service providers used to process card or online payments.
  • Administrative support providers assisting with booking or customer communications.

We may also disclose data to legal, regulatory, or law enforcement authorities where required by law, or to professional advisers such as insurers, auditors, or legal representatives when necessary. If a third party is an independent controller, it will be responsible for its own data protection obligations.

6. International Transfers

Where personal data is transferred outside the UK, we will ensure appropriate safeguards are in place to protect it. These may include adequacy regulations, standard contractual clauses, or equivalent legal measures. We aim to make sure any transfer is lawful and that your data remains protected to a standard consistent with UK data protection law.

7. Data Retention

We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, and reporting requirements. Retention periods vary depending on the type of data and the purpose for which it is held.

  • Customer and service records are usually retained for the duration of the relationship and for a reasonable period afterwards.
  • Financial and tax records are retained for the period required by law or accounting rules.
  • Communication records may be kept for as long as needed to manage enquiries, disputes, or follow-up actions.

When data is no longer required, we will securely delete, anonymise, or archive it in line with our retention practices. Where possible, we apply a minimum necessary retention approach to reduce the amount of personal data held.

8. Data Security

We use appropriate technical and organisational measures to safeguard personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, secure systems, staff confidentiality obligations, and regular review of our data handling practices. While no system is completely secure, we work to maintain a level of protection appropriate to the risks involved.

9. Your Rights

Under data protection law, you have a number of rights in relation to your personal data. These rights may apply in different circumstances and may be subject to legal exceptions.

  • Right of access: you can request a copy of the personal data we hold about you.
  • Right to rectification: you can ask us to correct inaccurate or incomplete data.
  • Right to erasure: you can ask us to delete your data in certain situations.
  • Right to restriction: you can ask us to limit how we use your data in certain cases.
  • Right to object: you can object to processing based on legitimate interests or direct marketing.
  • Right to data portability: you can request certain data in a structured, commonly used format.
  • Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.

You also have the right to lodge a complaint with the Information Commissioner’s Office if you believe your data has been handled unlawfully. We encourage you to raise concerns with us first so we can try to resolve the issue promptly and fairly.

10. Automated Decision-Making

We do not normally use automated decision-making or profiling that produces legal or similarly significant effects. If this changes, we will update this policy and explain the logic involved, the significance of the processing, and your rights in relation to it.

11. Children’s Data

Our services are intended for adults and businesses. We do not knowingly collect personal data from children except where it is necessary in connection with a customer’s household move or where a parent or guardian provides the information for a legitimate service-related purpose. In such cases, we will only use the data as needed to provide the service safely and appropriately.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the law, our services, or our operational practices. Any updates will take effect when published, and we encourage customers to review this policy periodically to stay informed about how we protect personal data.

Summary of Our Commitment

Man And Van Brompton is committed to transparent, lawful, and secure handling of personal data. We collect only what we need, use it for clear and lawful purposes, retain it only as long as necessary, and respect your data protection rights at all times.

Man and Van Brompton

GDPR-compliant Privacy Policy for Man And Van Brompton covering data collection, lawful basis, retention, processors, user rights, and area-wide applicability.

Get a Quote

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.