Privacy Policy - Man With Van Surrey
Last updated: June 2026
This Privacy Policy explains how Man With Van Surrey collects, uses, shares, stores, and protects personal data when providing moving, transport, and related services. It applies to all Man With Van Surrey customers in the area, including prospective customers, current customers, and anyone who contacts us, requests a quote, or uses our services. We are committed to handling personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using our services, you acknowledge that your personal data may be processed as described in this policy. We aim to be transparent, fair, and secure in the way we manage data.
1. Personal Data We Collect
We collect only the information necessary to provide our services, manage bookings, communicate effectively, and meet legal or contractual obligations. The information we may collect includes:
- Identity information such as your name and title.
- Contact details such as your address, email address, and telephone number.
- Service details including pickup and delivery locations, moving dates, property access details, inventory information, and special handling requirements.
- Payment and billing data such as billing address and payment confirmation details.
- Communication records including emails, messages, calls, and notes from service enquiries or complaints.
- Usage and technical information where relevant, such as basic device or browser information if you interact with digital services used to manage bookings.
- Special category data only if you choose to provide it and only where it is necessary to meet a legitimate purpose and allowed by law. We do not actively seek sensitive data unless required for a specific service need.
We generally collect data directly from you. In some cases, we may receive information from third parties, such as payment providers, property managers, estate agents, or another person arranging a move on your behalf.
2. How We Use Personal Data
We use personal data for the following purposes:
- To respond to enquiries and provide quotations.
- To arrange, manage, and deliver moving and transport services.
- To communicate about bookings, changes, delays, and service updates.
- To process payments and maintain financial records.
- To manage customer support, complaints, and service improvements.
- To maintain accurate business records and comply with legal obligations.
- To prevent fraud, misuse, and security incidents.
- To defend or establish legal claims where necessary.
We only process personal data where we have a valid reason to do so. We do not sell personal information. We also do not use personal data for unrelated purposes that would be unexpected or unfair.
3. Lawful Basis for Processing
Under UK GDPR, we must have a lawful basis for each processing activity. Depending on the situation, we rely on one or more of the following legal bases:
- Contract: We process your data when it is necessary to provide a quote, complete a booking, or perform our moving services.
- Legal obligation: We process data to comply with tax, accounting, insurance, and other legal requirements.
- Legitimate interests: We may process data to run our business efficiently, improve services, manage customer relationships, protect against fraud, or handle disputes, provided these interests do not override your rights and freedoms.
- Consent: In limited cases, we may rely on your consent, for example if you voluntarily provide optional information or agree to a specific type of communication. You can withdraw consent at any time where it is used as the lawful basis.
Important: where we rely on legitimate interests, we consider the impact on your privacy and ensure appropriate safeguards are in place.
4. Sharing Personal Data and Processors
We may share personal data with trusted third parties, but only where necessary and only with appropriate safeguards. These third parties act as processors or independent controllers depending on the service they provide.
Examples of processors may include:
- Payment service providers who handle card or electronic payments.
- IT and cloud storage providers that host secure business systems.
- Communication service providers used for email, messaging, or phone systems.
- Accounting or bookkeeping providers who help maintain financial records.
- Scheduling, invoicing, or customer management software providers.
- Professional advisers such as insurers, auditors, or legal advisers where necessary.
Where we use processors, we require them to process data only on our instructions, keep it secure, and not use it for their own purposes unless they are acting as an independent controller and have their own lawful basis.
We may also disclose personal data if required by law, to enforce our terms, protect our rights, or respond to lawful requests from public authorities.
5. Data Retention
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, and reporting obligations. The retention period depends on the type of data and the reason it was collected.
- Quotation and enquiry data: retained for a reasonable period to respond to follow-up requests and support customer service.
- Booking and service records: retained for the duration of the service relationship and for a further period where needed for dispute resolution or business records.
- Payment and invoice records: retained for the period required by tax and accounting law.
- Complaint and correspondence records: retained as long as necessary to resolve the matter and maintain proper records.
- Technical and security logs: retained for a limited period unless needed longer for investigation or legal compliance.
When personal data is no longer required, we securely delete, anonymise, or archive it in a way that prevents unauthorised access.
6. Data Security
We take appropriate technical and organisational measures to protect personal data against accidental loss, misuse, unauthorised access, disclosure, alteration, or destruction. These measures may include access controls, secure storage, restricted permissions, and staff awareness practices.
While we work hard to protect your information, no system can be guaranteed to be completely secure. If a data incident occurs, we will act promptly and in line with our legal obligations.
7. Your Rights
Under data protection law, you have certain rights in relation to your personal data. These rights may not apply in every case, but we will always assess your request carefully and respond appropriately. Your rights include:
- Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You can ask us to correct inaccurate or incomplete information.
- Right to erasure: You can request deletion of your personal data in certain circumstances.
- Right to restrict processing: You can ask us to limit how we use your data in certain situations.
- Right to object: You can object to processing based on legitimate interests or direct marketing, where applicable.
- Right to data portability: You can ask for certain data to be transferred to you or another controller in a commonly used format.
- Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time.
If you wish to exercise any of these rights, we may need to verify your identity before responding. We may also retain certain information where required by law or where we have overriding legitimate grounds.
8. Automated Decision-Making
We do not usually make decisions about customers based solely on automated processing that produces legal or similarly significant effects. If this changes, we will update this policy and provide the required information about your rights.
9. International Data Transfers
Where personal data is transferred outside the United Kingdom, we will ensure that appropriate safeguards are in place to protect it. These safeguards may include adequacy regulations, standard contractual clauses, or equivalent protections required by law.
10. Children’s Data
Our services are not directed at children, and we do not knowingly collect personal data from children unless it is necessary in connection with a service arranged by an adult customer. If we become aware that we have collected data from a child without appropriate consent or lawful basis, we will take reasonable steps to delete it.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, our services, or the way we process personal data. Any updated version will apply from the date it is published. We encourage customers to review this policy periodically to stay informed about how we protect their information.
12. Contacting Us About Privacy
If you have questions about this Privacy Policy, or if you wish to exercise your rights, please contact us using the appropriate business communication channels provided in your service documents. We will aim to respond within the time limits required by law.
Summary statement: This policy explains how Man With Van Surrey collects, uses, shares, retains, and protects personal data for customers in the area, and outlines your rights under UK GDPR.
We respect your privacy and process data only when necessary, lawful, and proportionate.
This Privacy Policy applies to all Man With Van Surrey customers in area.