Privacy Policy - Man And Van Crystal Palace

This Privacy Policy explains how Man And Van Crystal Palace collects, uses, stores, shares, and protects personal data when providing removal, delivery, transportation, and related services. It applies to all Man And Van Crystal Palace customers in the area, including individuals, households, landlords, tenants, and business clients who use our services. We are committed to handling personal data in a lawful, fair, transparent, and secure manner in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data We Collect

We collect only the personal data necessary to arrange, deliver, and manage our services effectively. This may include:

  • Identity information such as your name, title, and any relevant identification details needed for service provision.
  • Contact information such as phone number, email address, billing address, and service address.
  • Service information such as collection and delivery locations, access details, moving dates, inventory descriptions, and special handling requirements.
  • Payment information such as transaction records, payment status, and invoicing details. We do not store card details unless these are processed securely by an authorised payment provider.
  • Communication records including emails, messages, notes from phone calls, and customer service correspondence.
  • Technical information where applicable, such as basic website usage data, device information, and IP address, if you interact with our digital services.

We do not intentionally collect special category data unless it is provided voluntarily and is necessary for a specific request, for example where access arrangements or mobility needs must be considered. If such information is provided, it is handled with extra care and only for the purpose for which it was given.

2. How We Use Your Data

We use personal data to operate our services and to meet legal and contractual obligations. This may include:

  • Providing quotations and confirming bookings;
  • Planning, scheduling, and completing removals or transport services;
  • Communicating with you about service updates, changes, delays, or issues;
  • Processing payments, issuing invoices, and keeping financial records;
  • Handling complaints, insurance matters, and dispute resolution;
  • Meeting legal, tax, accounting, and regulatory requirements;
  • Improving our services, training staff, and maintaining internal records;
  • Preventing fraud, misuse, or unauthorised access to our systems or services.

We will not use your personal data for purposes that are incompatible with the reason it was collected, unless required or permitted by law.

3. Lawful Basis for Processing

Under data protection law, we must have a lawful basis to process personal data. Depending on the situation, we rely on the following lawful bases:

Contract

We process your data where it is necessary to enter into or perform a contract with you. This includes quoting, booking, delivering, invoicing, and fulfilling service requests.

Legal Obligation

We may process data where needed to comply with legal requirements, such as tax, accounting, insurance, or record-keeping obligations.

Legitimate Interests

We may process personal data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. Examples include service improvement, operational planning, fraud prevention, and maintaining secure business records.

Consent

In limited cases, we may rely on your consent, for example where you voluntarily provide non-essential information or agree to certain optional communications. Where consent is used, you may withdraw it at any time.

Vital Interests and Public Task

These bases are unlikely to apply in normal circumstances, but they may be used if required by law or in an emergency to protect someone’s vital interests.

4. Sharing Your Data and Processors

We only share personal data when necessary and with appropriate safeguards. We may disclose data to trusted third parties who act as processors on our behalf or to independent organisations where required by law.

Processors may include:

  • Payment service providers who securely handle transactions;
  • Accounting and bookkeeping providers who support financial administration;
  • IT and cloud service providers who support data storage, email, scheduling, and business systems;
  • Insurance providers and claims handlers where a claim or incident must be reviewed;
  • Professional advisers such as solicitors, auditors, or tax advisers;
  • Subcontracted service providers such as drivers or logistics partners where needed to complete a job.

Where third parties act as processors, they are only allowed to process your data under our instructions and must protect it appropriately. We do not sell personal data.

We may also share data with law enforcement, regulators, courts, or other authorities when legally required or where necessary to protect our rights, customers, employees, or the public.

5. International Transfers

If any processor stores or accesses data outside the UK, we will ensure that appropriate safeguards are in place. These may include adequacy regulations, standard contractual clauses, or other legally recognised transfer mechanisms. We take reasonable steps to ensure that your data remains protected wherever it is processed.

6. Data Retention

We keep personal data only for as long as necessary for the purpose it was collected, or for as long as required by law. Retention periods depend on the type of information and the reason for holding it.

  • Booking and service records are usually kept for a reasonable period after completion of the service to allow for administration, follow-up, or complaint handling.
  • Financial and tax records are retained for the period required by applicable law.
  • Correspondence and dispute records may be kept longer if needed to resolve issues or protect legal claims.
  • Marketing preferences are kept until you change your preferences or withdraw consent, where applicable.

When data is no longer needed, we will delete it securely or anonymise it so that it can no longer identify you. We review retention regularly to ensure information is not held for longer than necessary.

7. Data Security

We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and limited data access on a need-to-know basis.

Although we work hard to protect personal data, no system can be guaranteed completely secure. If a data breach occurs that is likely to result in a risk to your rights and freedoms, we will take appropriate steps in line with legal requirements.

8. Your Rights

As a data subject, you have a number of rights under data protection law. These include:

  • Right of access – you can request a copy of the personal data we hold about you;
  • Right to rectification – you can ask us to correct inaccurate or incomplete data;
  • Right to erasure – you can request deletion of your data in certain circumstances;
  • Right to restriction – you can ask us to limit how we use your data in certain cases;
  • Right to object – you can object to processing based on legitimate interests or direct marketing;
  • Right to data portability – you may request your data in a structured, commonly used format where applicable;
  • Right to withdraw consent – where processing is based on consent, you may withdraw it at any time;
  • Right to complain – you may raise a concern with the Information Commissioner’s Office (ICO) if you believe your data rights have been infringed.

To exercise your rights, you may contact us using the usual business channels provided to you at the time of service. We may need to verify your identity before responding to a request. Some rights may be limited where legal obligations or legitimate interests apply.

9. Children’s Data

Our services are not directed at children, and we do not knowingly collect personal data from children unless it is necessary in connection with a service request made by a parent, guardian, or responsible adult. If we become aware that we have collected data from a child without appropriate authority, we will take steps to delete it where required.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in law, our services, or how we process personal data. Any updated version will apply from the date it takes effect. We encourage customers to review this policy periodically so they remain informed about how their information is handled.

11. Summary of Our Commitment

Man And Van Crystal Palace respects your privacy and is committed to protecting your personal data. We only collect information that is needed for service delivery, administration, and legal compliance. We use lawful, fair, and transparent processing practices, keep data only as long as necessary, and work with processors that are required to protect your information. You retain important rights over your data, and we aim to respond to requests promptly and responsibly.

This Privacy Policy applies to all Man And Van Crystal Palace customers in the area.

Man and Van Crystal Palace

GDPR-compliant privacy policy for Man And Van Crystal Palace covering data collection, lawful basis, retention, processors, user rights, and local applicability.

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.