Privacy Policy
Boiler4Ever (“we,” “our,” “us”) values your trust and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and safeguard your data when you interact with our website, services, and communications. It is designed to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable UK privacy laws.
Introduction
Your privacy matters. This document outlines:
- What information we collect
- How we use and protect it
- Your rights under UK law
- How you can contact us
We aim to be transparent, responsible, and respectful in handling your personal data.
Information We Collect
We collect different types of information depending on how you interact with us:
- Personal Information — Name, email, phone number, address, and payment details.
- Account Information — Login credentials, preferences, and service history.
- Technical Data — IP address, browser type, operating system, device identifiers, and cookies.
- Usage Data — Pages visited, time spent, clicks, and navigation patterns.
- Communication Data — Emails, messages, and customer support interactions.
- Transaction Data — Orders, invoices, and payment confirmations.
How We Use Your Data
We use your information for the following purposes:
- Service Delivery — To process orders, provide installations, repairs, and customer support.
- Account Management — To maintain your profile, preferences, and service history.
- Marketing & Communication — To send updates, promotions, and newsletters (with your consent).
- Legal Compliance — To meet regulatory obligations and respond to lawful requests.
- Security — To protect against fraud, unauthorized access, and cyber threats.
- Analytics — To improve website performance, services, and customer experience.
Data Protection Measures
We implement strict technical and organizational safeguards:
- Encryption of sensitive data during transmission and storage.
- Secure servers located in the UK and EU.
- Access controls ensuring only authorized staff can view personal data.
- Regular audits to monitor compliance and detect vulnerabilities.
- Training for employees on data protection responsibilities.
Cookies & Tracking
Our website uses cookies and similar technologies:
- Essential Cookies — Required for site functionality.
- Performance Cookies — Help us analyze usage and improve services.
- Functional Cookies — Remember preferences and settings.
- Marketing Cookies — Deliver relevant ads and promotions.
You can manage or disable cookies through your browser settings.
International Data Transfers
If your data is transferred outside the UK (e.g., to EU partners), we ensure compliance with UK GDPR by using:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions by the UK government
- Binding corporate rules
Legal Basis for Processing
We process personal data under the following lawful bases:
- Consent — For marketing communications.
- Contract — To fulfill service agreements.
- Legal Obligation — To comply with UK law.
- Legitimate Interests — For business operations and fraud prevention.
Your Rights
Under UK GDPR, you have the following rights:
- Right to Access — Request a copy of your data.
- Right to Rectification — Correct inaccurate or incomplete data.
- Right to Erasure — Request deletion of your data.
- Right to Restrict Processing — Limit how we use your data.
- Right to Data Portability — Transfer your data to another provider.
- Right to Object — Opt out of certain processing activities.
- Right to Withdraw Consent — Stop receiving marketing communications.
Contact Information
If you have questions or wish to exercise your rights, contact us:
Email: privacy@boiler4ever.co.uk
Phone: +44 1234 567890
Address: Boiler4Ever Ltd, 123 Heating Street, Nottingham, UK
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
Policy Updates
We may update this Privacy Policy periodically to reflect changes in laws, technology, or business practices. Updates will be posted on our website, and we encourage you to review the policy regularly.
Extended Sections
To ensure full compliance and detail, the policy includes extended explanations on:
- Data Retention — How long we keep different categories of data.
- Third‑Party Sharing — Logistics partners, payment processors, IT providers.
- Children’s Privacy — Services are not directed at children under 16.
- Direct Marketing Practices — Opt‑in requirements and unsubscribe options.
- Automated Decision‑Making — How algorithms may affect service delivery.
- Employee Responsibilities — Internal policies for staff handling data.
- Disaster Recovery & Backups — How we protect data during outages.
- Industry Standards — Compliance with ISO/IEC 27001 and other frameworks.
- Transparency Commitment — Clear communication about how your data is handled.