How Danco Services Limited collects, uses, stores and protects your personal data — Version 1.0, effective 29 June 2026.
Data Controller: Danco Services Limited (Company No. 17189970). ICO Registration Number: [Pending — to be added once registered]. Last updated: 29 June 2026.
1.1 Danco Services Limited ("Danco", "we", "us", "our") is the data controller responsible for your personal data. We provide domestic and commercial cleaning services across Greater Manchester.
1.2 Our details:
1.3 We have not appointed a Data Protection Officer (DPO), as we are not required to under Article 37 of the UK GDPR. All data-protection enquiries should be directed to hello@dancoservices.co.uk.
Plain English: Danco is the company that decides how your personal data is used. We're based in London, operate across Greater Manchester, and you can reach us about anything data-related at hello@dancoservices.co.uk.
2.1 Information you give us when you enquire, book, or use our services:
marketing_opt_in flag in our system)2.2 Payment information. When you pay your deposit or balance, your card details are collected and processed directly by Stripe, our payment processor. Danco does not see or store your full card number. We retain a record that payment was made, the amount, and the date.
2.3 Information collected automatically when you visit our website:
Plain English: We collect what we need to clean your property and bill you — your name, address, contact details, and booking history. Your card details go straight to Stripe; we never store them.
We only use your personal data where the law allows us to. Under Article 6 of the UK GDPR, our lawful bases are:
| What we use your data for | Lawful basis (UK GDPR Article 6) |
|---|---|
| Taking and fulfilling your booking, arranging a contractor, delivering the clean, and collecting payment | Contract — Article 6(1)(b): processing necessary to perform our contract with you |
| Improving our services, preventing fraud, keeping records, and general business administration | Legitimate interests — Article 6(1)(f): necessary for our legitimate business interests, balanced against your rights |
| Sending you marketing communications about our services | Consent — Article 6(1)(a): only where you have opted in; withdrawable at any time |
| Keeping financial and tax records | Legal obligation — Article 6(1)(c): to comply with HMRC and company law requirements |
Plain English: Most of what we do with your data is to deliver the clean you booked. We only market to you if you've said yes, and you can change your mind anytime. Some data we keep because the law (tax rules) requires it.
4.1 Our website uses essential and security cookies provided through Cloudflare to keep the site running, secure, and protected against malicious traffic. These are necessary for the website to function and do not require consent under PECR Regulation 6(4).
4.2 If we introduce analytics or marketing cookies in future, we will display a cookie consent banner and obtain your consent before setting any non-essential cookies, in line with PECR and ICO guidance.
Plain English: Right now our site only uses the basic cookies needed to keep it working and secure. If that ever changes, we'll ask your permission first.
We use a number of trusted third-party service providers ("processors") to run our business. Each processes your data only on our instructions and under a data processing agreement. We do not sell your personal data to anyone.
| Processor | Purpose | Location / Transfer basis |
|---|---|---|
| Supabase | Primary database and CRM hosting — stores your customer record and booking history | EU / London region — no international transfer |
| Stripe | Payment processing (deposit and balance) | US-based; international transfer relies on the UK IDTA / UK Addendum to EU SCCs. Stripe also acts as an independent controller for its own fraud-prevention and financial-regulation purposes. |
| n8n | Workflow automation — booking dispatch and notifications | Self-hosted on Hetzner VPS (EU, Germany) — no international transfer |
| Twilio | SMS and WhatsApp messaging to customers and contractors | US-based; international transfer relies on the Twilio DPA incorporating SCCs / UK IDTA |
| Brevo | Email marketing and transactional email | EU-based (France) — no international transfer |
| Cloudflare | Website delivery, DNS, CDN, and security | Global edge network; international transfer relies on the Cloudflare DPA incorporating SCCs / UK IDTA |
5.1 We may also disclose your information:
Plain English: We use specialist services to store data, take payments, send messages, and run our website. They each handle your data under contract and only as we tell them. Some (like Stripe and Twilio) are US-based, so we rely on approved legal safeguards for sending data abroad. We never sell your data.
6.1 Some of our processors are based outside the UK (notably Stripe and Twilio in the United States, and Cloudflare's global edge network). Where your personal data is transferred outside the UK, we ensure it is protected by one of the following safeguards:
6.2 Our other processors (Supabase, n8n, and Brevo) are hosted within the EU and do not involve international transfers outside the UK/EU.
Plain English: When your data leaves the UK (mainly for payments and messaging), we make sure it's covered by legally approved protections. Most of our data stays in the UK or EU.
| Data type | Retention period | Reason |
|---|---|---|
| Customer records & booking history | Duration of the customer relationship + 6 years thereafter | Aligns with the limitation period for contract claims under the Limitation Act 1980 and HMRC record-keeping requirements |
| Payment and financial records | 6 years | HMRC / company law requirements |
| Marketing data (opt-in status) | Until you withdraw consent or opt out | Consent-based; no need to retain once withdrawn |
| Website technical/security logs | Up to 12 months | Security and troubleshooting |
Plain English: We keep your booking and payment records for 6 years, mostly because tax rules and the law require it. Marketing data is dropped as soon as you opt out.
You have the following rights over your personal data. To exercise any of them, email us at hello@dancoservices.co.uk — we will respond within one month.
Plain English: You're in control of your data — you can see it, correct it, delete it, move it, or tell us to stop using it. You can complain to the ICO if you think we've got it wrong, but we'd appreciate the chance to fix it first.
9.1 We will only send you marketing about our cleaning services where:
9.2 In every marketing message we send, we provide a simple way to opt out (for example, an unsubscribe link or a "STOP" reply). Once you opt out, we will stop sending marketing without delay.
9.3 We will not pass your contact details to third parties for their own marketing purposes.
Plain English: We only market to you if you've opted in, or if you're already a customer and we're telling you about similar cleaning services. Every message lets you opt out in one step.
10.1 We use appropriate technical and organisational measures to protect your data, including:
10.2 Payment data is handled by Stripe under PCI-DSS standards — we never store your full card number.
Plain English: We protect your data with encryption, restricted access, and secure providers. Card payments meet bank-grade security standards.
Our services and website are not directed at children. We do not knowingly collect personal data from anyone under 13. If you believe we hold data about a child, please contact us and we will delete it.
We may update this Privacy Policy from time to time. We will post the updated version on our website and change the "Last Updated" date. Where changes are significant, we will take reasonable steps to notify you directly.
| hello@dancoservices.co.uk | |
| Phone | 0161 399 5076 |
| Chat on WhatsApp | |
| Post | Danco Services Limited, 66 Paul Street, London, EC2A 4NA |
| ICO | ico.org.uk · 0303 123 1113 |
| Statute / Authority | Where it applies in this Policy |
|---|---|
| UK General Data Protection Regulation (UK GDPR), Article 6 | Section 3 — lawful bases for processing |
| UK GDPR, Article 5(1)(e) | Section 7 — storage limitation / retention |
| UK GDPR, Articles 15–22 | Section 8 — data subject rights |
| UK GDPR, Article 28 | Section 5 — processor agreements |
| UK GDPR, Articles 44–49 | Section 6 — international transfers (IDTA / SCCs) |
| Data Protection Act 2018 | Throughout — UK data protection framework |
| Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), Reg. 6 | Section 4 — cookies |
| PECR, Reg. 22 | Section 9 — marketing soft opt-in |
| Data Protection (Charges and Information) Regulations 2018 | Section 1 — ICO registration requirement |
| Limitation Act 1980 | Section 7 — 6-year retention rationale |
Danco Services Limited · Privacy Policy · Version 1.0
hello@dancoservices.co.uk · 0161 399 5076 · dancoservices.co.uk