GDPR Compliance
Last updated: 8 June 2026 · Policy version: 2026-06-08
1. Our Commitment to GDPR
Cleaner Pal Ltd. is committed to full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take data protection seriously and have implemented comprehensive measures to ensure your personal data is handled securely, lawfully, and transparently.
Policy versions: This compliance statement is versioned (currently 2026-06-08). When updates require renewed consent, active cleaners are prompted to accept the latest privacy-related policies before continuing to use the platform.
This page provides detailed information about our GDPR compliance, your rights as a data subject, and how we process your personal data. For general privacy information, please see our Privacy Policy.
Data (Use and Access) Act 2025 (DUAA)
The Data (Use and Access) Act 2025 came into force on 5 February 2026. It introduces updates to UK data protection law, including new legitimate interests provisions and greater flexibility for automated decision-making (ADM) in certain contexts.
We keep our Data Protection Impact Assessments (DPIAs), privacy notices, and processing records under review to align with DUAA and ICO guidance. Where we use location data, biometric data, or automated decision-making, our legal bases and safeguards are documented in line with UK GDPR Articles 24–32 and applicable DUAA provisions.
We implement child protection measures for online services where required by law.
2. Key GDPR Definitions
Understanding GDPR terminology helps you understand your rights:
2.1 Personal Data
Under Article 4 of UK GDPR, Personal Data means any information relating to an identified or identifiable natural person ("data subject"). An identifiable person is one who can be identified, directly or indirectly, by reference to an identifier such as:
- Name, identification number, location data
- Online identifier (IP address, cookies)
- One or more factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity
Examples include: name, email address, phone number, date of birth, IP address, location data, and any other information that can identify you.
2.2 Data Controller
A Data Controller (Article 4) is the entity that determines the purposes and means of processing personal data. Cleaner Pal Ltd. is the data controller for personal data processed through our Platform. We decide what data to collect, why we collect it, and how we use it.
2.3 Data Processor
A Data Processor (Article 4) is an entity that processes personal data on behalf of the controller. Examples include our cloud hosting providers (Google Cloud, Firebase), payment processors (Stripe, PayPal), and verification services (Didit). We have contracts in place with all processors to ensure they protect your data.
2.4 Processing
Processing (Article 4) is very broadly defined and includes any operation performed on personal data, such as:
- Collection, recording, organisation, structuring
- Storage, adaptation, alteration
- Retrieval, consultation, use
- Disclosure by transmission, dissemination, or making available
- Alignment, combination, restriction
- Erasure or destruction
2.5 Personal Data Breach
A Personal Data Breach (Article 4) means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
Unlike some regulations that only require notification for breaches involving sensitive data (for example, National Insurance numbers or similar identifiers), GDPR requires notification for breaches involving any personal data if it poses a high risk to your rights and freedoms.
2.6 Consent
Consent (Article 4) under GDPR must be:
- Freely given: You must have a genuine choice
- Specific: Consent must be for a specific purpose
- Informed: You must understand what you're consenting to
- Unambiguous: Clear affirmative action (not pre-ticked boxes or silence)
- Revocable: You can withdraw consent at any time
Consent must be given by a statement or clear affirmative action. We cannot assume consent from silence, pre-ticked boxes, or inactivity.
2.7 Data Subject
A Data Subject is the identified or identifiable natural person whose personal data is being processed. If you use our Platform, you are a data subject.
3. Data Controller Information
Data Controller: Cleaner Pal Ltd., a company registered in Northern Ireland
Companies House: NI721429
Registered Office: Ground Floor, Gallery Building, 65-69 Dublin Rd, Belfast, BT2 7HG, Northern Ireland, Northern Ireland
ICO Registration: Registered as a data controller with the Information Commissioner's Office (ICO).
ICO Registration Number: ZC088491
As the data controller, we are responsible for determining the purposes and means of processing your personal data. We are accountable for ensuring compliance with UK GDPR.
4. Legal Basis for Processing
Under Article 6 of UK GDPR, we can only process personal data if we have a lawful basis. We process your data under the following legal bases:
4.1 Contract (Article 6(1)(b))
Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract. Examples:
- Creating and managing your account
- Processing bookings and facilitating services
- Processing payments
- Enabling communication between Users
- Providing customer support
- Managing account tools and billing settings
4.2 Legal Obligation (Article 6(1)(c))
Processing is necessary for compliance with a legal obligation. Examples:
- Right-to-work verification (UK immigration law)
- AccessNI checks (criminal record checks in Northern Ireland; safeguarding requirements)
- Tax and accounting records (HMRC requirements - 7 years)
- Responding to legal requests and court orders
- Regulatory compliance
4.3 Legitimate Interests (Article 6(1)(f))
Processing is necessary for our legitimate interests, balanced against your rights and freedoms. We conduct a legitimate interests assessment (LIA) for each use case. Examples:
- Safety and Security: Identity verification, background checks, fraud prevention, platform safety
- Platform Improvement: Analytics, research, feature development, service optimisation
- Business Operations: Quality assurance, dispute resolution, enforcing terms and policies
- Communication: Important service updates, security alerts, policy changes
- Legal Protection: Defending legal claims, protecting rights and property
You have the right to object to processing based on legitimate interests (see Section 7.6 below).
4.4 Consent (Article 6(1)(a))
Processing is based on your consent. Examples:
- Marketing communications
- Optional cookies and tracking technologies
- Sharing data with third parties for marketing (where explicitly consented)
- Research and surveys
- Non-essential SMS notifications
You can withdraw consent at any time. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
4.5 Vital Interests (Article 6(1)(d))
Processing is necessary to protect the vital interests of you or another person. This is rarely used but may apply in emergency situations.
4.6 Public Task (Article 6(1)(e))
Processing is necessary for the performance of a task carried out in the public interest. This does not typically apply to our operations.
5. Data Protection Principles
Under Article 5 of UK GDPR, we adhere to the following principles when processing personal data:
5.1 Lawfulness, Fairness, and Transparency
We process data lawfully, fairly, and transparently. We inform you about what data we collect and how we use it through this page and our Privacy Policy.
5.2 Purpose Limitation
We collect data for specified, explicit, and legitimate purposes and do not process it in a way incompatible with those purposes. We only use data for the purposes we've told you about.
5.3 Data Minimisation
We only collect data that is adequate, relevant, and limited to what is necessary for our purposes. We regularly review what data we collect and delete unnecessary data.
5.4 Accuracy
We take reasonable steps to ensure data is accurate and kept up to date. You can update your information through your account settings, and we encourage you to keep your information current.
5.5 Storage Limitation
We keep data only for as long as necessary for our purposes. We have retention policies that specify how long we keep different types of data (see our Privacy Policy for details).
Backups and retention liability: Under GDPR Article 82, if personal data we intended to delete (e.g., AccessNI certificates removed per our Privacy Policy) still exists in backups or archives and is later breached, we remain liable for compensation. "We meant to delete it" is not a defence. We therefore ensure our cloud storage (S3, Google Cloud Storage, etc.) uses strict Lifecycle Policies that hard-delete files after verification, including from backups and archives.
5.6 Integrity and Confidentiality
We implement appropriate security measures to protect data against unauthorised access, alteration, disclosure, or destruction. See Section 9 below for details.
5.7 Accountability
We are responsible for demonstrating compliance with these principles. We maintain records of processing activities, conduct data protection impact assessments (DPIAs) where required, and provide a privacy contact for data protection matters.
6. Your Rights Under UK GDPR
As a data subject, you have comprehensive rights under UK GDPR. We are committed to facilitating the exercise of these rights:
6.1 Right of Access (Article 15)
You have the right to obtain confirmation as to whether we process your personal data and, if so, to access that data and receive the following information:
- The purposes of processing
- The categories of personal data concerned
- The recipients or categories of recipients to whom data has been or will be disclosed
- The retention period or criteria for determining it
- Your rights (rectification, erasure, restriction, objection, portability)
- The right to lodge a complaint with the ICO
- Information about the source of data (if not collected from you)
- Information about automated decision-making and profiling
How to exercise: You can access much of your data through your account settings, or request a complete data export by contacting us or using the data export feature. We will respond within one month (extendable by two months for complex requests).
6.2 Right to Rectification (Article 16)
You have the right to have inaccurate personal data corrected and incomplete personal data completed. We will respond to rectification requests without undue delay and in any event within one month.
How to exercise: Most information can be updated directly through your account settings. For other corrections, contact us. We may verify your identity before making changes.
If we have shared your data with third parties, we will inform them of the rectification (unless this proves impossible or involves disproportionate effort).
6.3 Right to Erasure / "Right to be Forgotten" (Article 17)
You have the right to request deletion of your personal data in the following circumstances:
- The data is no longer necessary for the original purpose
- You withdraw consent and there is no other legal basis
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Deletion is required for legal compliance
Exceptions: We may refuse deletion if processing is necessary for:
- Exercising the right of freedom of expression and information
- Compliance with legal obligations (e.g., tax records for 7 years)
- Public interest in public health or scientific research
- Establishment, exercise, or defence of legal claims
How to exercise: Request account deletion through your account settings or contact us. We will process deletion requests within one month, subject to legal requirements. If we have shared your data with third parties, we will inform them of the erasure (unless this proves impossible or involves disproportionate effort).
6.4 Right to Restrict Processing (Article 18)
You have the right to restrict processing in the following circumstances:
- You contest the accuracy of data (restriction while we verify accuracy)
- Processing is unlawful and you oppose erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing (restriction while we verify legitimate grounds)
When processing is restricted, we will only process the data (except storage) with your consent, for legal claims, for protection of rights, or for important public interest reasons.
How to exercise: Contact us to request restriction of processing. We will inform you before lifting any restriction.
6.5 Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller, where:
- Processing is based on consent or contract
- Processing is carried out by automated means
You also have the right to have your data transmitted directly from us to another controller, where technically feasible.
How to exercise: Use the data export feature in your account settings to download your data in JSON format, or contact us. We will provide your data within one month.
Note: This right applies to data you provided to us, not data we derived or inferred.
6.6 Right to Object (Article 21)
You have the right to object to processing based on legitimate interests (Article 6(1)(f)) or for direct marketing purposes. If you object:
- We must stop processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms
- For direct marketing, we must stop processing immediately
How to exercise: Opt out of marketing communications through your account settings or contact us. For objections to legitimate interests processing, contact us explaining your objection.
6.7 Rights Related to Automated Decision-Making and Profiling (Article 22)
You have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal effects or similarly significantly affect you.
Examples include the cleaner–client matching algorithm (e.g. weighting location, availability, and preferences) and risk scoring for new accounts; further uses are listed below.
This right does not apply where:
- It is necessary for entering into or performing a contract
- It is authorised by law
- It is based on your explicit consent
We use automated decision-making for:
- Cleaner-client matching based on location and preferences
- Risk assessment for new cleaner applications
- Dynamic pricing algorithms
- Fraud detection
How to exercise: You can request human review of any automated decisions that significantly affect you by contacting us. We will provide meaningful information about the logic involved and the significance and consequences of processing.
6.8 Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw consent at any time. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
How to exercise: Update your preferences in your account settings or contact us. We will stop processing based on consent immediately upon withdrawal.
7. Exercising Your Rights
To exercise your GDPR rights, you can:
- Self-Service: Use the options in your account settings for data access, export, and deletion
- Email: Contact us at privacy@cleanerpal.com or our privacy team at privacy@cleanerpal.com
- Post: Write to us at our registered office address
7.1 Response Times
We will respond to your request without undue delay and in any event within one month of receipt (Article 12(3)). This period may be extended by a further two months if the request is complex or we receive multiple requests, and we will inform you of the extension and reasons within one month.
7.2 Identity Verification
We may request proof of identity before processing certain requests to ensure we are responding to the correct person and protecting your data from unauthorised access (Article 12(6)).
7.3 Fees
Exercising your rights is generally free of charge (Article 12(5)). However, we may charge a reasonable fee or refuse to act if requests are manifestly unfounded, excessive, or repetitive, particularly because of their repetitive character. In such cases, we will inform you of the fee and reasons.
7.4 Information Format
We will provide information in a concise, transparent, intelligible, and easily accessible form, using clear and plain language (Article 12(1)). Information will be provided in writing or by other means, including electronic means where appropriate.
7.5 Notification of Third Parties
If we have shared your data with third parties and you exercise your rights (rectification, erasure, restriction), we will inform each recipient of the personal data, unless this proves impossible or involves disproportionate effort (Article 19). We will inform you about those recipients if you request it.
8. Data Protection Measures
Under Article 32 of UK GDPR, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk:
8.1 Technical Measures
- Encryption: Data in transit encrypted using TLS/SSL. Sensitive data at rest encrypted using industry-standard encryption (AES-256)
- Access Controls: Strict access controls, role-based access, principle of least privilege, access logging
- Authentication: Multi-factor authentication (2FA) available and encouraged, strong password requirements
- Secure Infrastructure: Data stored in secure data centres with physical and logical security, regular security updates
- Network Security: Firewalls, intrusion detection, DDoS protection, regular security monitoring
- Secure Development: Secure coding practices, code reviews, vulnerability scanning, penetration testing
- Backup and Recovery: Regular encrypted backups, disaster recovery procedures, tested recovery plans. Cloud storage (S3/Google Cloud) is configured with strict Lifecycle Policies that hard-delete files after verification, including from backups, to avoid retention-breach liability.
8.2 Organisational Measures
- Staff Training: Regular data protection and security training for all staff
- Policies and Procedures: Comprehensive data protection policies, incident response procedures, access control policies
- Data Protection Impact Assessments (DPIAs): Conducted for high-risk processing activities
- Records of Processing: Maintained as required by Article 30
- Privacy: Contact for data protection compliance
- Vendor Management: Contracts with processors include GDPR-compliant data processing agreements
- Regular Audits: Security audits, compliance reviews, vulnerability assessments
9. Data Breach Notification
Under Articles 33 and 34 of UK GDPR, we have obligations regarding personal data breaches:
9.1 Notification to Supervisory Authority
In the event of a personal data breach, we will notify the Information Commissioner's Office (ICO) without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms (Article 33(1)).
The notification will include:
- Nature of the breach
- Categories and approximate number of data subjects affected
- Categories and approximate number of personal data records concerned
- Likely consequences
- Measures taken or proposed to address the breach
9.2 Notification to Data Subjects
If a breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay (Article 34(1)). The notification will include:
- Nature of the breach
- Name and contact details of our privacy contact
- Likely consequences
- Measures taken or proposed to address the breach
- Advice on steps you can take to mitigate risks
We may not notify you if:
- We have implemented appropriate technical and organisational measures (e.g., encryption) that render data unintelligible
- We have taken subsequent measures to ensure the high risk is no longer likely to materialize
- Notification would involve disproportionate effort (in which case we will use public communication instead)
10. International Data Transfers
Under Chapter V of UK GDPR, transfers of personal data to countries outside the UK require appropriate safeguards. Some of our service providers process data outside the UK. We ensure appropriate safeguards are in place:
10.1 Adequacy Decisions
Transfers to countries with adequacy decisions (e.g., EU countries) are permitted without additional safeguards.
10.2 Standard Contractual Clauses (SCCs)
We use ICO-approved Standard Contractual Clauses with service providers in countries without adequacy decisions. These clauses provide contractual guarantees about data protection.
10.3 Binding Corporate Rules
Where relevant, we use binding corporate rules for multinational service providers.
10.4 Other Safeguards
We implement additional technical and organisational measures as required by UK GDPR, including:
- Encryption of data in transit and at rest
- Access controls and audit logging
- Regular security assessments
- Data minimisation
For more information about international transfers and safeguards, please contact our privacy team.
11. Privacy and data protection contact
We oversee our data protection compliance and can be contacted for privacy and data protection matters:
- Monitoring compliance with UK GDPR and data protection laws
- Advice on data protection impact assessments (DPIAs)
- Point of contact for data subjects and the ICO
- Cooperation with the ICO
- Staff training on data protection
Privacy contact:
Email: privacy@cleanerpal.com
Address: CLEANER PAL LTD, Ground Floor, Gallery Building, 65-69 Dublin Rd, Belfast, BT2 7HG, Northern Ireland, Northern Ireland
12. Records of Processing Activities
Under Article 30 of UK GDPR, we maintain records of our processing activities, including:
- Purposes of processing
- Categories of data subjects and personal data
- Categories of recipients
- Transfers to third countries
- Retention periods
- Security measures
These records help us demonstrate compliance and respond to requests from data subjects and supervisory authorities.
13. Data Protection Impact Assessments (DPIAs)
Under Article 35 of UK GDPR, we conduct Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in a high risk to your rights and freedoms, such as:
- Systematic and extensive automated processing, including profiling
- Large-scale processing of special categories of data
- Systematic monitoring of publicly accessible areas
DPIAs help us identify and mitigate risks before processing begins.
14. Complaints
If you believe we have not handled your personal data in accordance with UK GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Website: ico.org.uk
Email: casework@ico.org.uk
We encourage you to contact us first at privacy@cleanerpal.com or our privacy team so we can try to resolve your concerns.
15. Related Policies
For more detailed information about our data practices, please see:
- Privacy Policy - Comprehensive information about how we collect, use, and protect your data
- Cookie Policy - Information about our use of cookies and tracking technologies
- Terms and Conditions - Our terms of service
16. Updates to This Policy
We may update this GDPR Compliance page from time to time to reflect changes in our practices, legal requirements, or other factors. Each material update is assigned a version identifier (see section 1). We will notify you of significant changes by:
- Posting the updated information on our website with a new "Last updated" date and version identifier
- Sending an email notification to registered users (for significant changes)
- Displaying a notice on the Platform
When changes require your renewed consent, we will ask you to review and accept the updated policies before you continue using account features. Your acceptance is recorded with the version identifier and timestamp. If you do not agree with the changes, you should stop using the Platform and may request deletion of your account.
17. Alternative Dispute Resolution (ADR)
Under the Alternative Dispute Resolution for Consumer Disputes Regulations 2015, we are required to inform you about ADR. CleanerPal is not obliged to use an approved ADR provider, and we are not currently committed to using ADR for consumer disputes. We encourage you to contact us first at support@cleanerpal.com so we can try to resolve your complaint directly.
If we cannot resolve a dispute, you may wish to contact:
- Citizens Advice Consumer Service (England and Wales): citizensadvice.org.uk/consumer
- Consumer Council for Northern Ireland: 0800 121 6022 or consumercouncil.org.uk
- Trading Standards Service (Northern Ireland) via the Consumer Council or your local council
Nothing in this section limits your statutory rights to bring court proceedings, including the small claims track where appropriate.
18. Contact Information
CLEANER PAL LTD
Ground Floor, Gallery Building
65-69 Dublin Rd
Belfast
BT2 7HG
Northern Ireland
General Enquiries: info@cleanerpal.com
Privacy Enquiries: privacy@cleanerpal.com
Privacy: privacy@cleanerpal.com
