Data Protection
At Boiler4Ever, we take your data protection and privacy seriously. This page outlines our commitment to protecting your personal information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all applicable UK privacy laws. We are dedicated to transparency, security, and your rights as a data subject.
1. Our Commitment to Data Protection
Data protection is not just a legal obligation for us — it is a fundamental part of how we operate. Boiler4Ever is committed to safeguarding the privacy and security of all personal data we process. We recognise that you entrust us with sensitive information, and we take that responsibility seriously.
Our approach to data protection is built on the principles of the UK GDPR:
- Lawfulness, fairness, and transparency — We process data in a lawful, fair, and transparent manner.
- Purpose limitation — We collect data for specified, explicit, and legitimate purposes.
- Data minimisation — We only collect data that is adequate, relevant, and limited to what is necessary.
- Accuracy — We ensure personal data is accurate and kept up to date.
- Storage limitation — We retain data only for as long as necessary.
- Integrity and confidentiality — We protect data against unauthorised or unlawful processing.
- Accountability — We take responsibility for our data processing activities.
✅ Our Promise: We will always be transparent about how we use your data, respect your rights, and handle your information with the highest standards of security and care.
2. Data Protection Officer (DPO)
Boiler4Ever has appointed a Data Protection Officer (DPO) to oversee our data protection strategy and ensure compliance with UK GDPR requirements. Our DPO is responsible for monitoring our data protection practices, conducting audits, and serving as the primary point of contact for data protection authorities and data subjects.
If you have any questions about how we handle your personal data, or if you wish to exercise your rights under UK GDPR, you can contact our DPO directly:
DPO Email: dpo@boiler4ever.co.uk
Phone: +44 1234 567890
Address: Boiler4Ever Ltd, 123 Heating Street, Nottingham, UK
3. What Personal Data We Collect
We collect different categories of personal data depending on how you interact with us. The table below summarises the types of data we process:
| Category | Examples | Purpose |
|---|---|---|
| Identity Data | Full name, title, date of birth | Account creation, service delivery, verification |
| Contact Data | Email address, phone number, postal address | Communication, service updates, marketing |
| Financial Data | Bank account details, payment card information | Payment processing, invoicing, refunds |
| Transaction Data | Order history, service records, invoices | Fulfilment of services, customer support |
| Technical Data | IP address, browser type, device information, cookies | Website analytics, security, user experience |
| Usage Data | Pages visited, time spent, navigation patterns | Improving our services and website performance |
| Communication Data | Emails, chat messages, call recordings (with consent) | Customer support, quality assurance, dispute resolution |
| Marketing Data | Preferences, consent records, engagement metrics | Targeted communications, campaign analysis |
Note: We only collect data that is relevant and necessary for the purposes described. We do not process special category data (e.g., health, biometrics, religious beliefs) unless explicitly required and with your explicit consent.
4. How We Collect Your Data
We collect personal data through the following channels:
- Direct interactions: When you fill in forms on our website, book a service, call us, or email us.
- Automated technologies: Cookies, server logs, and analytics tools that track your interaction with our website.
- Third-party sources: Trusted partners (e.g., payment processors, marketing platforms) with your consent.
- Public sources: Information available through public registers or social media (only when relevant to our services).
🔍 Transparency: We always provide clear information about what data we collect and why at the point of collection.
5. How We Use Your Personal Data
We use your personal data for the following purposes, under the lawful bases set out in UK GDPR:
5.1 Service Delivery
To provide and manage our services, including: processing orders, scheduling appointments, carrying out installations and repairs, and providing customer support. (Legal basis: Contract performance)
5.2 Account Management
To create and maintain your account, track your service history, and personalise your experience. (Legal basis: Contract performance and legitimate interests)
5.3 Marketing and Communications
To send you updates, promotional offers, and newsletters — but only where you have given us explicit consent or where we have a legitimate interest (for existing customers with relevant services). (Legal basis: Consent and legitimate interests)
5.4 Legal Compliance
To meet our regulatory obligations, respond to lawful requests from public authorities, and comply with UK law. (Legal basis: Legal obligation)
5.5 Security and Fraud Prevention
To protect against fraud, unauthorised access, and cyber threats. (Legal basis: Legitimate interests)
5.6 Analytics and Improvement
To analyse website usage, customer behaviour, and service performance — helping us improve our offerings. (Legal basis: Legitimate interests)
⚠️ Important: We do not use your data for automated decision-making or profiling that has a significant legal or financial impact on you.
6. Legal Basis for Processing
Under UK GDPR, we rely on the following lawful bases for processing your personal data:
- Consent: You have given clear consent for us to process your data for a specific purpose (e.g., marketing communications).
- Contract: Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
- Legal Obligation: Processing is necessary for compliance with a legal or regulatory obligation.
- Legitimate Interests: Processing is necessary for our legitimate interests (or those of a third party), provided your fundamental rights and freedoms do not override those interests.
We conduct regular legitimate interest assessments to ensure our processing activities are balanced, proportionate, and respect your privacy rights.
7. Data Sharing and Third Parties
We may share your personal data with trusted third-party service providers who perform functions on our behalf, such as payment processing, IT support, logistics, and marketing. We ensure that all third parties are contractually bound to comply with UK GDPR and implement appropriate security measures.
We do not sell, trade, or rent your personal data to third parties for their own marketing purposes.
Categories of third parties we may share data with include:
- Payment processors (e.g., Stripe, PayPal)
- IT and cloud service providers (e.g., hosting, backup, email services)
- Logistics and delivery partners
- Analytics providers (e.g., Google Analytics)
- Marketing and email service platforms (e.g., Mailchimp)
- Legal and regulatory authorities (when required by law)
8. International Data Transfers
Boiler4Ever is headquartered in the UK, and most of your data is stored on secure servers located within the UK and the European Economic Area (EEA). However, in some cases, we may transfer data to countries outside the UK (e.g., to EU partners or cloud providers with servers outside the UK).
When we transfer data internationally, we ensure an equivalent level of protection by relying on:
- UK adequacy decisions — Where the UK government has deemed a country's data protection framework adequate.
- Standard Contractual Clauses (SCCs) — Approved contractual clauses that ensure data is protected to UK GDPR standards.
- UK International Data Transfer Agreement (IDTA) — The UK's approved transfer mechanism for international data flows.
- Binding Corporate Rules (BCRs) — For intra-group transfers, where applicable.
You can request a copy of the safeguarding measures used for international data transfers by contacting our DPO.
9. Data Security Measures
We implement robust technical and organisational security measures to protect your personal data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
9.1 Technical Measures
- Encryption: Data is encrypted during transmission (using TLS/SSL) and at rest.
- Firewalls: Secure firewalls protect our network infrastructure.
- Access Controls: Role-based access ensures only authorised personnel can access personal data.
- Multi-Factor Authentication (MFA): Required for administrative and sensitive systems.
- Regular Security Audits: We conduct periodic vulnerability assessments and penetration testing.
9.2 Organisational Measures
- Staff Training: All employees receive mandatory data protection and security awareness training.
- Policies and Procedures: Clear internal policies govern data handling, breach reporting, and access.
- Incident Response Plan: A documented plan ensures swift action in the event of a data breach.
- Third-Party Vetting: We assess and monitor the security practices of all third-party processors.
🔒 Our Commitment: We are continuously investing in our security infrastructure to stay ahead of evolving threats and protect your data.
10. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. Retention periods vary depending on the type of data and the purpose of processing.
General Retention Guidelines:
- Customer Account Data: Retained for the duration of your relationship with us plus 6 years (to comply with tax and legal obligations).
- Transaction Data: Retained for 7 years to meet financial and accounting requirements.
- Marketing Data: Retained until you unsubscribe or withdraw your consent.
- Website Analytics: Aggregated for up to 26 months; individual IP data is anonymised.
- Call Recordings: Retained for 12 months for quality and training purposes (with consent).
When data is no longer needed, we securely delete or anonymise it in accordance with our retention policy.
11. Your Data Protection Rights
Under UK GDPR, you have the following rights regarding your personal data. We are committed to facilitating the exercise of these rights and will respond to all requests within one month (or within three months for complex requests).
11.1 Right to Access
You have the right to request a copy of the personal data we hold about you, along with information about how we process it. This is commonly known as a "Subject Access Request" (SAR).
11.2 Right to Rectification
If your personal data is inaccurate or incomplete, you have the right to request correction or completion.
11.3 Right to Erasure (Right to be Forgotten)
You can request the deletion of your personal data where there is no compelling reason for us to continue processing it. This right applies in certain circumstances, such as when the data is no longer necessary, or when you withdraw your consent.
11.4 Right to Restrict Processing
You have the right to restrict the processing of your data in specific situations, such as while we verify the accuracy of the data or when you object to processing.
11.5 Right to Data Portability
You can request that we transfer your data to another organisation or provide it to you in a structured, commonly used, and machine-readable format.
11.6 Right to Object
You have the right to object to the processing of your data for certain purposes, including direct marketing and processing based on legitimate interests.
11.7 Right to Withdraw Consent
Where we rely on your consent, you can withdraw it at any time. We will make it easy for you to do so, and we will stop processing your data for that purpose.
📞 How to Exercise Your Rights:
To exercise any of your rights, please contact our Data Protection Officer at dpo@boiler4ever.co.uk
or write to us at the address provided earlier. We will verify your identity before processing your request.
You are also entitled to lodge a complaint with the Information Commissioner's Office (ICO)
if you are not satisfied with our response.
12. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to enhance your experience, analyse site traffic, and deliver relevant content. Cookies are small text files stored on your device.
Types of Cookies We Use:
- Essential Cookies: Required for the website to function properly (e.g., session management).
- Performance Cookies: Help us understand how visitors interact with our site (e.g., Google Analytics).
- Functional Cookies: Remember your preferences and settings (e.g., language, region).
- Marketing Cookies: Used to deliver targeted advertisements and measure campaign effectiveness.
You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality of our website.
For more detailed information, please see our full Cookie Policy.
13. Children's Privacy
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child under 16, we will take immediate steps to delete that data.
If you are a parent or guardian and believe that your child has provided us with personal data, please contact us so that we can take appropriate action.
14. Direct Marketing
We may use your personal data to send you marketing communications about our services, promotions, and industry updates — but only where we have your explicit consent (for new contacts) or a legitimate interest (for existing customers with related services).
You have the right to opt out of direct marketing at any time. You can do this by:
- Clicking the "unsubscribe" link in any marketing email we send.
- Contacting our DPO at dpo@boiler4ever.co.uk.
- Updating your communication preferences in your account settings.
📧 Opt-Out Right: We respect your choice and will stop sending marketing communications as soon as we receive your opt-out request (within 72 hours).
15. Automated Decision-Making and Profiling
Boiler4Ever does not engage in automated decision-making or profiling that has a significant legal or financial impact on individuals. Any automated processes we use are limited to non-sensitive tasks, such as categorising service requests or routing enquiries to the appropriate team.
If we ever introduce automated decision-making that affects your rights, we will inform you in advance and provide details of the logic involved, as well as your right to request human intervention.
16. Data Breach Response Plan
We have a robust data breach response plan in place to detect, contain, investigate, and remediate any personal data breaches. In the event of a breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it.
Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, providing clear information about the nature of the breach and the steps we are taking to mitigate it.
- Immediate Containment: We isolate affected systems and stop further data loss.
- Investigation: We identify the cause and scope of the breach.
- Remediation: We implement fixes and prevent recurrence.
- Communication: We inform affected individuals and the ICO as required.
17. Employee Training and Responsibilities
All Boiler4Ever employees undergo mandatory data protection and information security training upon joining and on an annual basis thereafter. This training covers:
- UK GDPR principles and obligations
- How to handle personal data securely
- Identifying and reporting data breaches
- Customer rights and how to respond to requests
- Best practices for password management and access control
Employees are contractually bound to confidentiality and data protection policies. Breaches of these policies may result in disciplinary action, including termination of employment.
18. Third-Party Data Processors
We engage trusted third-party processors to help us deliver our services. We only work with processors that provide sufficient guarantees regarding their technical and organisational security measures. We sign Data Processing Agreements (DPAs) with all processors, ensuring compliance with UK GDPR.
Our processors include:
- Payment Processors: Stripe, PayPal (for secure payments)
- Cloud Hosting: AWS, Google Cloud (data storage)
- Email Services: Mailchimp, SendGrid (marketing communications)
- Analytics: Google Analytics, Hotjar (website usage)
- Support Platforms: Zendesk, Freshdesk (customer support)
A full list of our processors is available upon request. We regularly review our processors to ensure continued compliance with UK data protection standards.
19. Industry Standards and Compliance
Boiler4Ever is committed to maintaining the highest industry standards for data protection and information security. We align our practices with internationally recognised frameworks, including:
- ISO/IEC 27001: Information Security Management (where applicable)
- Cyber Essentials: UK government-backed cybersecurity certification (in progress)
- PCI DSS: Payment Card Industry Data Security Standard (for payment processing)
- UK GDPR Code of Conduct: Adherence to best practice guidelines
We are committed to continuous improvement and regularly review our policies and procedures to ensure they reflect the latest regulatory developments and industry best practices.
20. Transparency and Accountability
We believe that transparency is the foundation of trust. That is why we provide clear, accessible information about our data protection practices. This page is designed to be easy to understand and regularly updated to reflect any changes in our processing activities.
We maintain a detailed record of our processing activities (RoPA) and conduct regular Data Protection Impact Assessments (DPIAs) for high-risk processing. Our DPO reviews our practices quarterly to ensure ongoing compliance.
📋 Accountability: We take ownership of our data protection obligations and are always ready to demonstrate compliance to regulators and data subjects.
21. Contact Us
If you have any questions, concerns, or requests regarding this Data Protection page or how we handle your personal data, please do not hesitate to contact us.
Email: privacy@boiler4ever.co.uk
Phone: +44 1234 567890
Address: Boiler4Ever Ltd, 123 Heating Street, Nottingham, UK
ICO Registration: We are registered with the Information Commissioner's Office (ICO) under registration number ZB123456.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at any time. The ICO is the UK's independent authority set up to uphold information rights.
22. Updates to This Data Protection Page
We may update this page from time to time to reflect changes in our practices, legal requirements, or technology. We will post any updates here and, where appropriate, notify you by email or via a notice on our website.
Please check this page regularly to stay informed about how we are protecting your data. The date of the latest revision is displayed at the top of this page.
Last Updated: August 2026