Privacy Policy - Movers Kingston Upon Thames
This Privacy Policy explains how Movers Kingston Upon Thames collects, uses, stores, and protects personal data when providing moving and related services. It applies to all Movers Kingston Upon Thames customers in the area, including individuals, households, and businesses that request quotes, book services, communicate with us, or receive our services. We are committed to handling personal data in a lawful, fair, and transparent way in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Movers Kingston Upon Thames acts as a data controller for the personal information we collect and use in connection with our services. This means we determine the purposes and means of processing your personal data. In some situations, we may also act as a data processor when handling data on behalf of a business customer or another organisation.
2. Information We Collect
We collect only the information that is reasonably necessary to provide our services, manage our business, and meet legal obligations. The types of data we may collect include:
- Identity details such as your name, title, and business or household name where relevant.
- Contact details such as address, email address, and telephone number.
- Service information including moving dates, property access details, inventory lists, packing requirements, special handling notes, and service preferences.
- Billing and payment information such as invoice details, payment status, and transaction records. We do not store more payment data than is necessary for accounting and record-keeping.
- Communications including emails, messages, call notes, complaints, feedback, and other correspondence.
- Technical data where applicable, such as basic website usage information, IP address, and browser details if you interact with our online services.
- Special category data only in limited circumstances, and only where necessary and permitted by law, for example if you voluntarily provide information needed to support accessibility, medical, or security requirements during a move.
We aim to minimise the amount of personal data collected and avoid collecting information that is not relevant to your move or our obligations.
3. How We Use Your Personal Data
We use personal data for the following purposes:
- To provide quotes and assess service requirements.
- To arrange, deliver, and manage moving services.
- To communicate with you about bookings, scheduling, and service updates.
- To process invoices, payments, refunds, and account records.
- To manage customer support, complaints, and feedback.
- To maintain internal records, improve operations, and analyse service performance.
- To comply with legal, tax, insurance, and regulatory requirements.
- To protect our business, staff, customers, and property from fraud, misuse, or security threats.
We do not use personal data for purposes that are incompatible with the original reason for collection unless we have a lawful basis to do so and, where required, notify you appropriately.
4. Lawful Basis for Processing
Under UK GDPR, we must have a lawful basis for each processing activity. Depending on the circumstances, we rely on one or more of the following bases:
- Contract – processing is necessary to enter into or perform a contract with you, such as arranging and delivering a move.
- Legal obligation – processing is necessary to comply with statutory requirements, such as accounting, tax, and record-keeping obligations.
- Legitimate interests – processing is necessary for our legitimate business interests, such as service management, fraud prevention, business administration, and improving our services, provided your rights do not override those interests.
- Consent – where we rely on your consent, for example for optional marketing or for processing certain sensitive information that you choose to provide.
- Vital interests – in rare situations, where processing is necessary to protect someone’s life or physical safety.
Where we rely on consent, you may withdraw it at any time. This will not affect the lawfulness of processing carried out before withdrawal.
5. Sharing Your Data and Processors
We may share personal data with trusted third parties when necessary to provide our services or meet legal obligations. These third parties may act as data processors or independent controllers depending on the service they provide.
Processors We May Use
- IT and hosting providers who support our systems, data storage, and communications.
- Accounting and bookkeeping providers who assist with invoicing, finance, and tax records.
- Payment service providers who process transactions securely.
- CRM or booking software providers who help us manage customer enquiries and service schedules.
- Insurance providers where required for claims handling or risk management.
- Professional advisers such as legal or audit advisers when necessary.
Where a third party acts as a processor, they are only permitted to process your data on our instructions and must keep it secure. We require appropriate contractual safeguards to protect personal data and ensure compliance with data protection law.
We may also disclose information to public authorities, courts, regulators, or law enforcement agencies where required by law or necessary to protect rights, property, or safety.
6. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, or reporting obligations. Retention periods vary depending on the nature of the data and the reason we hold it.
- Customer and service records are typically kept for the duration of the service relationship and for a reasonable period afterwards for administration, dispute resolution, and record-keeping.
- Financial and tax records are retained for the period required by law.
- Communications and complaint records may be retained for longer where necessary to evidence decisions or manage claims.
- Marketing preferences are kept until you opt out or withdraw consent, where relevant.
When personal data is no longer required, we will delete it or anonymise it securely. We do not keep data indefinitely.
7. Data Security
We take appropriate technical and organisational measures to protect personal data from loss, misuse, unauthorised access, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and limited access based on business need.
While no system can be guaranteed completely secure, we work to maintain reasonable safeguards that reflect the nature of the information we hold and the risks involved.
8. Your Rights Under UK GDPR
You have a number of rights in relation to your personal data. These rights may be subject to legal conditions and exemptions. They include:
- Right of access – you can request a copy of the personal data we hold about you.
- Right to rectification – you can ask us to correct inaccurate or incomplete information.
- Right to erasure – you can request deletion of your data in certain circumstances.
- Right to restriction – you can ask us to limit how we use your data in certain situations.
- Right to data portability – you can request that we provide your data in a structured, commonly used format where applicable.
- Right to object – you can object to processing based on legitimate interests and to direct marketing.
- Right to withdraw consent – where we rely on consent, you may withdraw it at any time.
- Rights relating to automated decision-making – you have rights where decisions are made solely by automated means and have legal or similarly significant effects, though we do not normally rely on such processing.
If you wish to exercise any of these rights, we will assess your request in line with applicable law and respond within the required timeframe. We may need to verify your identity before responding.
9. International Transfers
If any of our processors or service providers store or access personal data outside the UK, we will ensure that appropriate safeguards are in place. These may include adequacy regulations, standard contractual clauses, or other lawful transfer mechanisms approved under data protection law.
10. Children’s Data
Our services are generally intended for adults. We do not knowingly collect children’s personal data except where it is necessary to provide a move or related service and where a parent, guardian, or authorised adult provides the information. If we learn that we have collected data unlawfully, we will take appropriate steps to delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data-handling practices. The most recent version will apply to your use of our services. We encourage customers to review this policy periodically to stay informed about how personal data is handled.
12. Summary of Our Commitment
Movers Kingston Upon Thames is committed to respecting privacy and protecting personal data. We collect only what we need, use it for clear and lawful purposes, limit access to trusted processors, retain it only as long as necessary, and respect the rights of every customer in the area. Our approach is designed to ensure that personal data is handled lawfully, securely, and transparently throughout the moving process.