Privacy Policy | Cristalina Cleaning Services
Your privacy matters. This notice explains how we handle your information. View your rights →
Privacy, transparency and control

How Cristalina protects your personal information.

This privacy policy explains what information we collect, why we use it, who may receive it, how long we keep it and the choices available to you.

Effective 23 July 2026 UK GDPR & DPA 2018 Updated for the Data (Use and Access) Act 2025
Data controllerCristalina Cleaning Services
Main purposesQuotes, bookings, service delivery and support
No data sellingWe do not sell customer personal information
You stay in controlAccess, correction, deletion, objection and complaints

Privacy notice for customers, website visitors and business contacts

This notice applies when you visit our website, ask for a quotation, contact us by form, telephone or WhatsApp, arrange or receive a cleaning service, act for a tenant, landlord or letting agent, provide services to us, or otherwise communicate with Cristalina.

Please do not send unnecessary sensitive information, identity documents, bank-card details, alarm codes or access instructions through an insecure or public channel.

Section 01

Who we are and how to contact us

Cristalina Cleaning Services is the controller responsible for the personal information described in this notice. “Cristalina”, “we”, “us” and “our” refer to Cristalina Cleaning Services.

Our services are provided across Greater London. Privacy enquiries, rights requests and data-protection complaints can be made through the channels below. If Cristalina is operated through a registered legal entity, that entity is the controller and its full legal details should appear here.

Telephone 07448 004530 Rights requests and verbal complaints are accepted.
Online Website contact form Start the message with “Privacy request” or “Data protection complaint”.
Service area Greater London, United Kingdom Ask us for a postal contact address if you prefer to write.
Data protection contact: privacy matters are handled by Cristalina’s management. We have not listed a separate Data Protection Officer in this notice.
Section 02

Personal information we collect

The information we collect depends on how you interact with us. We aim to collect only what is reasonably necessary for the purpose.

Identity and contact information

Name, telephone number, email address, correspondence address, company, role and preferred method of contact.

Property and service information

Postcode, service address, property type, room count, condition, photographs, requested service, priorities, dates and frequency.

Access and safety information

Key collection details, concierge or lockbox instructions, parking, alarm or access information and relevant hazards. We limit access to people who need it.

Booking, payment and account information

Quotes, booking history, invoices, payment status, refunds and transaction references. Payment providers may process card or bank details directly.

Communications and service records

Messages, call notes, form submissions, instructions, complaints, feedback, reviews and records of how an enquiry or booking was handled.

Website and device information

IP address, device and browser information, pages viewed, referral source, timestamps, cookie identifiers and approximate location inferred from IP.

Marketing preferences

Whether you asked to receive offers, how you consented, your channel preferences and records of an unsubscribe or objection.

Limited sensitive information

Accessibility, health or vulnerability information only when you choose to provide it and it is necessary to deliver the service safely or make reasonable arrangements.

Job photographs and evidence

Where reasonably necessary, we may take limited before-and-after photographs to document condition, completion, damage, access or a complaint. We try to avoid people, identity documents, family photographs and unrelated personal belongings. Promotional use requires a separate suitable permission.

Information we do not need

Unless specifically required and agreed, please do not send passport copies, full payment-card details, medical records or information about other people that is unrelated to the cleaning service.

Section 03

Where personal information comes from

We usually receive information directly from you. We may also receive it from:

  • A tenant, landlord, letting or managing agent, employer, family member or other person arranging the service.
  • Our website, embedded forms, communications systems, payment provider and customer-management tools.
  • Advertising or social platforms when you choose to submit a lead form, send a message or interact with an advert.
  • Publicly available business sources where we need to verify company or professional contact information.
  • Our cleaners, contractors or service partners when they record job completion, an incident, damage, a complaint or a safety concern.

If someone gives us information about another person, they should have authority to do so and should make this notice available to that person where appropriate.

Section 04

Why we use information and our lawful bases

We must have a valid reason under data-protection law for each use of personal information. The most relevant purposes and lawful bases are below.

Purpose Information commonly used Lawful basis
Respond to enquiries and prepare quotations Contact, property, service and communication details. Steps requested before entering a contract; legitimate interests in operating our enquiry service.
Confirm and deliver cleaning services Booking, service address, access, instructions, preferences and job records. Performance of a contract; legitimate interests in safe, effective service delivery.
Manage payments, invoices and records Billing details, transaction references, invoice and payment status. Performance of a contract; legal obligations relating to tax, accounting and records.
Communicate about an appointment Contact details, messages, reminders, changes and access information. Performance of a contract; legitimate interests in managing appointments.
Handle quality issues, claims, fraud, safety and disputes Communications, job notes, photographs, transaction and incident information. Legitimate interests in protecting customers, staff and the business; legal claims; legal obligations where applicable.
Improve our service and website Feedback, aggregated trends, technical and usage information. Legitimate interests for service improvement; consent where non-essential cookies or tracking require it.
Send offers and marketing Contact details, service history and marketing preferences. Consent, or legitimate interests/soft opt-in where permitted by UK GDPR and PECR. You may object or unsubscribe at any time.
Publish reviews or promotional images Name or initials, review, photographs or testimonial. Consent or another clearly explained lawful basis agreed with you before publication.
Meet legal and regulatory duties Any information reasonably required for the obligation. Legal obligation; recognised or other legitimate interests where applicable.
Handle privacy requests and complaints Identity, contact details, request, evidence, correspondence and outcome. Legal obligation; legitimate interests in establishing and documenting compliance.

Special-category information

If you voluntarily provide health, disability or other specially protected information so we can make an accessibility or safety arrangement, we will use it only where an additional lawful condition applies, such as your explicit consent or another condition allowed by law. You may withdraw consent, although this does not affect earlier lawful use.

No solely automated significant decisions

We do not currently make decisions that produce legal or similarly significant effects about customers using solely automated processing. We may use basic automation to route enquiries, send confirmations or organise follow-up tasks, with human involvement in service decisions.

Section 05

Who we may share information with

We do not sell customer personal information. We may share limited information when necessary with trusted recipients, including:

Cleaners, employees and contractorsOnly the information needed to attend, access and complete the agreed service safely.
Website, hosting, CRM and form providersTo host the site, receive enquiries, store records, manage workflows and support communications.
Telephone, email and messaging providersIncluding WhatsApp/Meta when you choose to communicate through WhatsApp.
Payment and banking providersTo process payments, refunds and transaction verification.
Accountants, insurers and professional advisersFor accounting, insurance, claims, legal advice, disputes and business administration.
Landlords, tenants and property agentsWhere needed for a service they arranged or are authorised to manage.
Authorities and regulatorsWhere disclosure is required by law or necessary to protect rights, safety, prevent fraud or respond to lawful requests.
Business successorsIf the business or relevant assets are reorganised, sold or transferred, subject to appropriate confidentiality and legal protections.

Service providers acting for us must process information only for agreed purposes, keep it secure and comply with applicable data-protection duties. Some recipients act as independent controllers and apply their own privacy notices.

Section 06

International data transfers

Some technology, communications, hosting, CRM, advertising or payment providers may process or allow access to personal information outside the United Kingdom.

Where a restricted transfer is made, we seek to use a lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard clauses, or another safeguard or exception permitted by law. We also consider the protection available in the destination and any supplementary measures that may be appropriate.

You may contact us for more information about the relevant safeguards, subject to commercial confidentiality and the rights of others.

Section 07

How long we keep information

We keep personal information only for as long as reasonably needed for the purpose, including legal, accounting, insurance, dispute and security requirements. Our usual guide is:

Record Typical retention approach
Quote or enquiry that does not become a booking Usually up to 12 months after the last meaningful contact, unless a longer period is justified or you ask us to delete it sooner.
Customer, booking, invoice and service records Usually for the customer relationship and up to six years afterwards where needed for tax, accounting, insurance, contracts or legal claims.
Keys, access codes and alarm instructions Removed, returned or deleted as soon as access is no longer required, subject to any short-term need to investigate an incident or dispute.
Payment-card information Normally handled by the payment provider. We do not intend to store full card details in our general customer records.
Job photographs and incident evidence Kept only while needed for quality, completion, insurance, a complaint or a legal claim, then deleted or anonymised.
Marketing information Until you withdraw consent, unsubscribe or object. We may keep a minimal suppression record so we do not contact you again.
Cookie-consent records For an appropriate period to demonstrate and respect your choices, usually up to 24 months unless the consent tool uses a different justified period.
Rights requests and privacy complaints Usually up to three years after closure, or longer where needed for an ongoing dispute, legal obligation or claim.

These are general periods, not promises that every record is kept for the maximum time. We may delete or anonymise information sooner when it is no longer needed.

Section 08

Cookies, embedded forms and similar technologies

Our website and service providers may use cookies, local storage, pixels, tags, scripts and similar technologies. These can remember choices, keep forms working, protect the site, measure performance or support advertising.

Cookie categories

  • Strictly necessary: essential for security, network delivery, consent preferences, form operation or a service you requested.
  • Functional: remember optional settings or improve website functionality. Some limited low-risk functions may qualify for an exemption; otherwise consent is requested.
  • Analytics: help us understand visits and improve the website. These should not load where consent is required until you accept them.
  • Advertising: measure campaigns, limit adverts or build audiences. These require consent where applicable and are not treated as strictly necessary.

Services visible on this website

The site may load assets from assets.cdn.filesafe.space and may embed a quote form delivered through info.felipehenriques.com or related CRM infrastructure. When you submit an embedded form, the form provider processes the information and associated technical details so Cristalina can receive and respond to the enquiry.

Choosing WhatsApp takes you to a service operated by Meta. Selecting a translated version may redirect the page through Google Translate. Those providers process information under their own terms and privacy notices.

Important: this policy does not replace a cookie-consent banner. Non-essential technologies should be blocked before consent where the law requires it. The live cookie banner should identify the actual cookies, providers, purposes and durations detected on the website.

Section 09

Marketing and communication choices

Service messages about a quotation, booking, payment, appointment or complaint are not marketing and may be sent where necessary to manage your request or contract.

For promotional email, text, WhatsApp or similar electronic messages, we use consent or another route permitted by the Privacy and Electronic Communications Regulations, such as the customer “soft opt-in” where all conditions are met. Marketing under data-protection law may rely on consent or legitimate interests depending on the context.

  • You can unsubscribe using the link or instructions in a marketing message.
  • You can tell us to stop marketing by calling us or using the website contact form.
  • Your right to object to direct marketing is absolute; we will stop using your information for that purpose.
  • We may retain a minimal suppression record to respect your choice.

We do not make consent to unrelated marketing a condition of receiving a cleaning quotation or service.

Section 10

How we protect information

We use technical and organisational measures intended to provide security appropriate to the nature of our business and the risks involved. Measures may include controlled access, passwords and multi-factor authentication where available, secure transmission, device protection, backups, confidentiality expectations, staff guidance, limited sharing and review of service providers.

Access and alarm information receives particular care because misuse could affect property safety. It should be shared only through an agreed channel and only for as long as needed.

No website, email, messaging service or storage system can be guaranteed completely secure. If we become aware of a personal-data breach, we will assess it, contain it, keep appropriate records and notify affected people or the Information Commissioner where the law requires.

Section 11

Your data-protection rights

Depending on the circumstances and lawful basis, you may have the following rights:

Be informedReceive clear information about how your personal information is used.
AccessAsk for confirmation and a copy of personal information we hold about you.
RectificationAsk us to correct inaccurate information or complete incomplete information.
ErasureAsk us to delete information where the legal conditions apply.
RestrictionAsk us to limit how information is used in certain circumstances.
Data portabilityReceive certain information in a structured, commonly used machine-readable format.
ObjectObject to processing based on legitimate interests and always object to direct marketing.
Withdraw consentWithdraw consent at any time where consent is the basis, without affecting earlier lawful use.
Automated decisionsRights may apply where a significant decision is made solely by automated means.
ComplainRaise a data-protection complaint with us and, if unresolved, with the ICO.

How to make a request

Call 07448 004530 or use our website contact form and begin your message with “Privacy request”. Tell us your name, contact details, the right you wish to exercise and enough information to locate the relevant records.

We may need to verify your identity or authority before disclosing or changing information. We usually respond within one month, although lawful extensions or limitations may apply. Rights are not absolute, and we will explain if we cannot fully comply.

Section 12

Data-protection complaints

You can complain directly to us if you believe we have not handled personal information lawfully, fairly, securely or transparently, or if you are unhappy with how we handled a rights request.

Our complaint process

Use the website form and start your message with “Data protection complaint”, or call us. Explain what happened, when it happened, which information is involved and what outcome you would like.

1. AcknowledgementWe will acknowledge receipt within 30 days.
2. InvestigationWe will investigate appropriately, without undue delay, and keep you informed.
3. OutcomeWe will explain the result and any action taken without undue delay.

Complaining to the Information Commissioner

We encourage you to give us an opportunity to resolve the issue. You also have the right to complain to the UK Information Commissioner’s Office. Visit ico.org.uk/make-a-complaint or call the ICO helpline on 0303 123 1113.

Section 13

Children’s information

Our cleaning services and website enquiry forms are not directed at children. A person arranging a service should normally be aged 18 or over. If a child contacts us, we will use only the minimum information needed to respond appropriately and may ask for a parent or guardian to become involved.

Please do not submit unnecessary information about children living at a property. Where an accessibility, safeguarding or safety detail is genuinely necessary, provide only what is relevant.

Section 14

Third-party websites, changes and contact

Third-party links

Our website may link to WhatsApp, Google, social platforms, payment services or other websites. We are not responsible for their privacy practices. Review the relevant provider’s privacy information before giving them personal information.

Changes to this notice

We review this policy when our services, providers, technology or legal duties change. Material changes will be highlighted on the website or brought to your attention where appropriate. The date at the top shows the latest revision.

Contact us

For a privacy question, rights request or complaint, call 07448 004530 or use the website contact form. Please avoid sending identity documents, access codes or other sensitive details until we confirm a suitable channel.

Need this notice in another format?

Contact Cristalina if you need help understanding this policy, a more accessible format, or assistance making a privacy request or complaint.

Call Cristalina

Questions about your data? Talk to us directly.

Privacy question