Privacy Policy

Last Updated: 28 October 2025

Your Privacy Matters: We are committed to protecting your personal information and being transparent about how we use it. This policy explains our practices in plain English.

1. Who We Are

Oaney Limited ("we", "us", "our") is the data controller responsible for your personal information.

Our Details:
Legal Name: Oaney Limited
Trading As: Oaney Cleaning Services
Service Area: Aberdeen and Aberdeenshire, Scotland
Contact: Available through our website at oaney.com

This privacy policy explains how we comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. As a small business, we keep data collection to the minimum necessary to provide our cleaning services.

2. What Information We Collect

2.1 Information You Provide During Booking

When you book our services, we collect only what's essential:

  • Contact Information: Name, email address, phone number
  • Service Address: Postcode and property details needed to provide the cleaning service
  • Service Requirements: Type of cleaning, property size, special instructions
  • Payment Information: Processed securely through Stripe. We do NOT store your full card details— Stripe handles all payment card information in compliance with PCI-DSS standards

2.2 Information We Collect Automatically

  • Essential Technical Data: IP address, browser type to keep our website secure and functioning
  • Essential Cookies: Session cookies to keep you logged in during booking

Note: As a small business focused on providing excellent cleaning services, we do NOT use analytics tracking, marketing cookies, or other non-essential data collection tools.

3. How We Use Your Information

We use your personal data for these purposes only:

To Fulfill Your Booking (Contract Performance)

  • Confirming your booking and sending confirmation emails
  • Scheduling our cleaning team to your property
  • Processing your payment through Stripe
  • Contacting you about your service (e.g., confirming appointment, arrival notifications)

To Comply with the Law (Legal Obligation)

  • Keeping accounting records for tax purposes (HMRC requires 7 years)
  • Responding to legal requests if required

To Protect Our Business (Legitimate Interest)

  • Preventing fraud and ensuring payment security
  • Managing cancellations and refunds according to our policy
  • Resolving customer service issues or disputes

What We DON'T Do: We do not use your data for marketing, analytics, profiling, or any other purposes beyond providing your booked cleaning service and meeting our legal obligations.

4. Who We Share Your Information With

We share your personal data with very few third parties, and only when absolutely necessary:

4.1 Essential Service Providers

  • Stripe Payment Processing: Stripe processes all card payments on our behalf. They are PCI-DSS Level 1 certified (the highest security standard) and handle your payment card details directly. We never see or store your full card information. Stripe operates under strict EU/UK data protection standards.
  • Google Firebase/Cloud Platform: We use Google's cloud infrastructure to securely store booking information. All data is stored in EU/UK data centers and encrypted at rest and in transit.

4.2 Legal Requirements Only

We may disclose your information only if legally required to:

  • Comply with court orders or legal processes
  • Respond to HMRC or tax authority requests
  • Prevent fraud or illegal activity

4.3 We NEVER Sell Your Data

Guaranteed: We will never sell, rent, trade, or share your personal information with third parties for marketing purposes. Your data is used solely to provide your cleaning service.

5. How Long We Keep Your Information

We only keep your data for as long as necessary:

Data TypeHow Long We Keep ItWhy
Booking records & invoices7 yearsHMRC requires this for tax purposes
Contact information3 years after last bookingTo handle potential disputes or repeat bookings
Payment card detailsWe don't store them at allStripe handles all card data securely

After these periods, we securely delete your data unless we're legally required to keep it longer (e.g., for accounting). You can request earlier deletion by contacting us, subject to our legal obligations.

6. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

Right of Access

Request a copy of your personal data we hold (free of charge)

Right to Rectification

Correct inaccurate or incomplete personal data

Right to Erasure ("Right to be Forgotten")

Request deletion of your personal data (subject to legal obligations)

Right to Restrict Processing

Limit how we use your data in certain circumstances

Right to Data Portability

Receive your data in a commonly used format to transfer elsewhere

Right to Object

Object to processing based on legitimate interests or for marketing

Right to Withdraw Consent

Withdraw consent for processing where consent was the legal basis

How to Exercise Your Rights

To exercise any of these rights, contact us through our website contact form. We will respond within one month (extendable to two months for complex requests).

7. Data Security

We implement appropriate technical and organizational measures to protect your data:

Technical Measures

  • Encryption: SSL/TLS encryption for data in transit, encrypted databases
  • Access Controls: Password protection, multi-factor authentication for staff
  • Secure Hosting: Enterprise-grade Google Cloud Platform infrastructure
  • Regular Backups: Automated backups with encryption
  • Monitoring: 24/7 security monitoring and threat detection

Organizational Measures

  • Staff Training: Regular data protection training for all employees
  • Access Restrictions: Only authorized staff can access personal data
  • Incident Response: Procedures for handling data breaches
  • Third-Party Vetting: All suppliers undergo security assessments

Data Breach Notification

In the unlikely event of a data breach affecting your personal information, we will:

  • Notify the Information Commissioner's Office (ICO) within 72 hours
  • Inform affected individuals without undue delay
  • Provide clear information about the breach and steps to protect yourself

8. Cookies

What Cookies We Use

Cookies are small text files stored on your device. We use only essential cookies necessary for our website to work properly:

Essential Session Cookies Only

  • Keep you logged in while completing your booking
  • Remember your booking details as you move through the steps
  • Ensure secure payment processing

No Tracking: We do NOT use analytics cookies, advertising cookies, or any third-party tracking tools. Your browsing is not tracked or analyzed beyond what's necessary to complete your booking.

Managing Cookies

You can control cookies through your browser settings. However, blocking essential cookies will prevent you from booking our services online.

9. International Data Transfers

Your data stays in the UK and EU. We use:

  • Google Cloud Platform: EU/UK data centers only
  • Stripe: EU operations with UK data processing

Your personal information is not transferred outside the UK or European Economic Area (EEA).

10. Children's Privacy

Our services are not intended for children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately.

11. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. We will:

  • Post the updated policy on this page with a new "Last Updated" date
  • Notify you of significant changes via email (if we have your consent)
  • Maintain previous versions for your reference

Please review this policy periodically to stay informed about how we protect your data.

12. Contact Us & Complaints

12.1 Data Protection Queries

For questions about this privacy policy or how we handle your data:

  • Website: oaney.com/contact
  • Email: Available through our contact form
  • Subject Line: "Data Protection Enquiry"

12.2 Right to Complain

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we've mishandled your personal data:

Information Commissioner's Office (ICO)

Website: ico.org.uk

Helpline: 0303 123 1113

Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We encourage you to contact us first so we can try to resolve any concerns.

Our Privacy Promise (Plain English)

  • Minimal Data Collection: We only collect what's needed to clean your property and process payment
  • No Tracking: We don't use analytics, advertising, or marketing cookies
  • Never Sell Your Data: Your information will never be sold or shared for marketing purposes
  • UK Data Protection: Your data stays in the UK/EU with strong security measures
  • Your Rights: You can access, correct, or delete your data anytime
  • Transparent: This policy tells you exactly how we handle your information

As a small cleaning business in Aberdeen, we believe in keeping things simple and treating your data with the same care we treat your home.