Privacy notice for customers, website visitors and business contacts
This notice applies when you visit our website, ask for a quotation, contact us by form, telephone or WhatsApp, arrange or receive a cleaning service, act for a tenant, landlord or letting agent, provide services to us, or otherwise communicate with Cristalina.
Please do not send unnecessary sensitive information, identity documents, bank-card details, alarm codes or access instructions through an insecure or public channel.
Who we are and how to contact us
Cristalina Cleaning Services is the controller responsible for the personal information described in this notice. “Cristalina”, “we”, “us” and “our” refer to Cristalina Cleaning Services.
Our services are provided across Greater London. Privacy enquiries, rights requests and data-protection complaints can be made through the channels below. If Cristalina is operated through a registered legal entity, that entity is the controller and its full legal details should appear here.
Personal information we collect
The information we collect depends on how you interact with us. We aim to collect only what is reasonably necessary for the purpose.
Identity and contact information
Name, telephone number, email address, correspondence address, company, role and preferred method of contact.
Property and service information
Postcode, service address, property type, room count, condition, photographs, requested service, priorities, dates and frequency.
Access and safety information
Key collection details, concierge or lockbox instructions, parking, alarm or access information and relevant hazards. We limit access to people who need it.
Booking, payment and account information
Quotes, booking history, invoices, payment status, refunds and transaction references. Payment providers may process card or bank details directly.
Communications and service records
Messages, call notes, form submissions, instructions, complaints, feedback, reviews and records of how an enquiry or booking was handled.
Website and device information
IP address, device and browser information, pages viewed, referral source, timestamps, cookie identifiers and approximate location inferred from IP.
Marketing preferences
Whether you asked to receive offers, how you consented, your channel preferences and records of an unsubscribe or objection.
Limited sensitive information
Accessibility, health or vulnerability information only when you choose to provide it and it is necessary to deliver the service safely or make reasonable arrangements.
Job photographs and evidence
Where reasonably necessary, we may take limited before-and-after photographs to document condition, completion, damage, access or a complaint. We try to avoid people, identity documents, family photographs and unrelated personal belongings. Promotional use requires a separate suitable permission.
Information we do not need
Unless specifically required and agreed, please do not send passport copies, full payment-card details, medical records or information about other people that is unrelated to the cleaning service.
Where personal information comes from
We usually receive information directly from you. We may also receive it from:
- A tenant, landlord, letting or managing agent, employer, family member or other person arranging the service.
- Our website, embedded forms, communications systems, payment provider and customer-management tools.
- Advertising or social platforms when you choose to submit a lead form, send a message or interact with an advert.
- Publicly available business sources where we need to verify company or professional contact information.
- Our cleaners, contractors or service partners when they record job completion, an incident, damage, a complaint or a safety concern.
If someone gives us information about another person, they should have authority to do so and should make this notice available to that person where appropriate.
Why we use information and our lawful bases
We must have a valid reason under data-protection law for each use of personal information. The most relevant purposes and lawful bases are below.
| Purpose | Information commonly used | Lawful basis |
|---|---|---|
| Respond to enquiries and prepare quotations | Contact, property, service and communication details. | Steps requested before entering a contract; legitimate interests in operating our enquiry service. |
| Confirm and deliver cleaning services | Booking, service address, access, instructions, preferences and job records. | Performance of a contract; legitimate interests in safe, effective service delivery. |
| Manage payments, invoices and records | Billing details, transaction references, invoice and payment status. | Performance of a contract; legal obligations relating to tax, accounting and records. |
| Communicate about an appointment | Contact details, messages, reminders, changes and access information. | Performance of a contract; legitimate interests in managing appointments. |
| Handle quality issues, claims, fraud, safety and disputes | Communications, job notes, photographs, transaction and incident information. | Legitimate interests in protecting customers, staff and the business; legal claims; legal obligations where applicable. |
| Improve our service and website | Feedback, aggregated trends, technical and usage information. | Legitimate interests for service improvement; consent where non-essential cookies or tracking require it. |
| Send offers and marketing | Contact details, service history and marketing preferences. | Consent, or legitimate interests/soft opt-in where permitted by UK GDPR and PECR. You may object or unsubscribe at any time. |
| Publish reviews or promotional images | Name or initials, review, photographs or testimonial. | Consent or another clearly explained lawful basis agreed with you before publication. |
| Meet legal and regulatory duties | Any information reasonably required for the obligation. | Legal obligation; recognised or other legitimate interests where applicable. |
| Handle privacy requests and complaints | Identity, contact details, request, evidence, correspondence and outcome. | Legal obligation; legitimate interests in establishing and documenting compliance. |
Special-category information
If you voluntarily provide health, disability or other specially protected information so we can make an accessibility or safety arrangement, we will use it only where an additional lawful condition applies, such as your explicit consent or another condition allowed by law. You may withdraw consent, although this does not affect earlier lawful use.
No solely automated significant decisions
We do not currently make decisions that produce legal or similarly significant effects about customers using solely automated processing. We may use basic automation to route enquiries, send confirmations or organise follow-up tasks, with human involvement in service decisions.
Who we may share information with
We do not sell customer personal information. We may share limited information when necessary with trusted recipients, including:
Service providers acting for us must process information only for agreed purposes, keep it secure and comply with applicable data-protection duties. Some recipients act as independent controllers and apply their own privacy notices.
International data transfers
Some technology, communications, hosting, CRM, advertising or payment providers may process or allow access to personal information outside the United Kingdom.
Where a restricted transfer is made, we seek to use a lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard clauses, or another safeguard or exception permitted by law. We also consider the protection available in the destination and any supplementary measures that may be appropriate.
You may contact us for more information about the relevant safeguards, subject to commercial confidentiality and the rights of others.
How long we keep information
We keep personal information only for as long as reasonably needed for the purpose, including legal, accounting, insurance, dispute and security requirements. Our usual guide is:
| Record | Typical retention approach |
|---|---|
| Quote or enquiry that does not become a booking | Usually up to 12 months after the last meaningful contact, unless a longer period is justified or you ask us to delete it sooner. |
| Customer, booking, invoice and service records | Usually for the customer relationship and up to six years afterwards where needed for tax, accounting, insurance, contracts or legal claims. |
| Keys, access codes and alarm instructions | Removed, returned or deleted as soon as access is no longer required, subject to any short-term need to investigate an incident or dispute. |
| Payment-card information | Normally handled by the payment provider. We do not intend to store full card details in our general customer records. |
| Job photographs and incident evidence | Kept only while needed for quality, completion, insurance, a complaint or a legal claim, then deleted or anonymised. |
| Marketing information | Until you withdraw consent, unsubscribe or object. We may keep a minimal suppression record so we do not contact you again. |
| Cookie-consent records | For an appropriate period to demonstrate and respect your choices, usually up to 24 months unless the consent tool uses a different justified period. |
| Rights requests and privacy complaints | Usually up to three years after closure, or longer where needed for an ongoing dispute, legal obligation or claim. |
These are general periods, not promises that every record is kept for the maximum time. We may delete or anonymise information sooner when it is no longer needed.
Cookies, embedded forms and similar technologies
Our website and service providers may use cookies, local storage, pixels, tags, scripts and similar technologies. These can remember choices, keep forms working, protect the site, measure performance or support advertising.
Cookie categories
- Strictly necessary: essential for security, network delivery, consent preferences, form operation or a service you requested.
- Functional: remember optional settings or improve website functionality. Some limited low-risk functions may qualify for an exemption; otherwise consent is requested.
- Analytics: help us understand visits and improve the website. These should not load where consent is required until you accept them.
- Advertising: measure campaigns, limit adverts or build audiences. These require consent where applicable and are not treated as strictly necessary.
Services visible on this website
The site may load assets from assets.cdn.filesafe.space and may embed a quote form delivered through info.felipehenriques.com or related CRM infrastructure. When you submit an embedded form, the form provider processes the information and associated technical details so Cristalina can receive and respond to the enquiry.
Choosing WhatsApp takes you to a service operated by Meta. Selecting a translated version may redirect the page through Google Translate. Those providers process information under their own terms and privacy notices.
Marketing and communication choices
Service messages about a quotation, booking, payment, appointment or complaint are not marketing and may be sent where necessary to manage your request or contract.
For promotional email, text, WhatsApp or similar electronic messages, we use consent or another route permitted by the Privacy and Electronic Communications Regulations, such as the customer “soft opt-in” where all conditions are met. Marketing under data-protection law may rely on consent or legitimate interests depending on the context.
- You can unsubscribe using the link or instructions in a marketing message.
- You can tell us to stop marketing by calling us or using the website contact form.
- Your right to object to direct marketing is absolute; we will stop using your information for that purpose.
- We may retain a minimal suppression record to respect your choice.
We do not make consent to unrelated marketing a condition of receiving a cleaning quotation or service.
How we protect information
We use technical and organisational measures intended to provide security appropriate to the nature of our business and the risks involved. Measures may include controlled access, passwords and multi-factor authentication where available, secure transmission, device protection, backups, confidentiality expectations, staff guidance, limited sharing and review of service providers.
Access and alarm information receives particular care because misuse could affect property safety. It should be shared only through an agreed channel and only for as long as needed.
No website, email, messaging service or storage system can be guaranteed completely secure. If we become aware of a personal-data breach, we will assess it, contain it, keep appropriate records and notify affected people or the Information Commissioner where the law requires.
Your data-protection rights
Depending on the circumstances and lawful basis, you may have the following rights:
How to make a request
Call 07448 004530 or use our website contact form and begin your message with “Privacy request”. Tell us your name, contact details, the right you wish to exercise and enough information to locate the relevant records.
We may need to verify your identity or authority before disclosing or changing information. We usually respond within one month, although lawful extensions or limitations may apply. Rights are not absolute, and we will explain if we cannot fully comply.
Data-protection complaints
You can complain directly to us if you believe we have not handled personal information lawfully, fairly, securely or transparently, or if you are unhappy with how we handled a rights request.
Our complaint process
Use the website form and start your message with “Data protection complaint”, or call us. Explain what happened, when it happened, which information is involved and what outcome you would like.
Complaining to the Information Commissioner
We encourage you to give us an opportunity to resolve the issue. You also have the right to complain to the UK Information Commissioner’s Office. Visit ico.org.uk/make-a-complaint or call the ICO helpline on 0303 123 1113.
Children’s information
Our cleaning services and website enquiry forms are not directed at children. A person arranging a service should normally be aged 18 or over. If a child contacts us, we will use only the minimum information needed to respond appropriately and may ask for a parent or guardian to become involved.
Please do not submit unnecessary information about children living at a property. Where an accessibility, safeguarding or safety detail is genuinely necessary, provide only what is relevant.
Third-party websites, changes and contact
Third-party links
Our website may link to WhatsApp, Google, social platforms, payment services or other websites. We are not responsible for their privacy practices. Review the relevant provider’s privacy information before giving them personal information.
Changes to this notice
We review this policy when our services, providers, technology or legal duties change. Material changes will be highlighted on the website or brought to your attention where appropriate. The date at the top shows the latest revision.
Contact us
For a privacy question, rights request or complaint, call 07448 004530 or use the website contact form. Please avoid sending identity documents, access codes or other sensitive details until we confirm a suitable channel.
Need this notice in another format?
Contact Cristalina if you need help understanding this policy, a more accessible format, or assistance making a privacy request or complaint.