Privacy Policy (UK GDPR)

Effective date: 14/10/2025

Who we are: Lost Sock (“we”, “us”, “our”) – 20 Theobald St., Borehamwood WD6 4SE, United Kingdom. Phone: 0773 810 6536 / 0 203 581 2493. For privacy enquiries email: radlett@o2.pl

1) What this policy covers

This explains what personal data we collect, why we collect it, how we use and share it, how long we keep it, and the rights you have under the UK GDPR and Data Protection Act 2018.

2) The data we collect

We collect only what we need to provide our services:

Contact & identity data – name, phone, email, address.

Service details – garment cleaning (fabric, brand, issues), cleaning/checklist notes, alteration measurements, before/after photos you share, booking preferences, access instructions for cleaning/handyman visits.

Communications – emails, messages, call notes, and quotes/invoices.

Device/usage (minimal) – essential technical data our website needs to function (see “Cookies” below).

Payments – amount, time, last-4 digits/token (processed via our payment provider; we don’t store full card details).

3) How we get your data

Directly from you: by phone, email, messages, in-store/at collection, or via any website forms.

From your device: strictly necessary cookies/technical logs that keep the site secure and working.

From partners you ask us to liaise with (e.g., landlord/agent for an end-of-tenancy clean).

4) Why we use your data (lawful bases)

To provide a service / perform a contract – take bookings, do the work, and keep you updated.

Legitimate interests – respond to enquiries; improve scheduling/quality; keep basic job history to support queries or repeat work; protect our business from fraud/abuse.

Legal obligations – tax/VAT records; health & safety; accident records.

Consent – optional marketing (only if you opt in). You can withdraw consent anytime.

5) Who we share it with

We share only when necessary, under data-processing agreements as relevant:

IT/hosting & email providers (website hosting, email, backup).

Payments processors (for card transactions).

Operational partners you ask us to coordinate with (e.g., letting agents).

Professional advisers (accountants/insurers) and law enforcement/regulators where required by law.

We do not sell your personal data.

6) International transfers

Some providers may process data outside the UK. When that happens, we ensure appropriate safeguards (e.g., UK Addendum to EU Standard Contractual Clauses or other ICO-recognised mechanisms).

7) How long we keep data (retention)

Enquiries (no job): up to 12 months (to answer follow-ups), then delete.

Customer/job records: typically 6 years (accounting/tax limitation periods).

Alteration measurements: up to 24 months (to support repeat work), then delete.

CCTV (if ever implemented on-site): typically 30 days (or as legally required).
If you ask us to delete earlier, we’ll do so unless we need to keep records for legal reasons.

8) Your rights

You can ask us to: access, correct, erase, or restrict your data; object to certain uses (including our legitimate interests); and receive your data in a portable format. You also have the right to withdraw consent for marketing at any time.

To exercise your rights, email radlett@o2.pl. You also have the right to complain to the Information Commissioner’s Office (ICO). See: Make a complaint – ICO (includes helpline 0303 123 1113 and online routes).

9) Cookies & similar tech

At the time of writing, our Contact and Home pages do not load third-party analytics or advertising tags; only essential elements (e.g., navigation, fonts, links) are present. If we add analytics/ads or embed external widgets (e.g., Google Maps iframe) in future, we’ll update this section and, where required, display a consent banner.

Your browser lets you block or delete cookies; essential cookies may be required for basic site functions.

10) Security

We apply reasonable organisational and technical measures: access controls, least-privilege staff access, secure deletion, device protections, and TLS for data in transit on the website.

11) Children

Our services are aimed at adults. We don’t knowingly collect children’s data except where necessary to deliver a family service (e.g., school uniform alterations) under a parent/guardian booking.

12) Marketing

We’ll only send marketing if you opt in. You can opt out any time (email us).

13) Changes to this policy

We’ll post updates on this page and revise the “Effective date”. For material changes, we’ll take additional steps if required by law.

14) Contact us about privacy

Controller: Lost Sock

Address: 20 Theobald St., Borehamwood WD6 4SE, United Kingdom

Phone: 0773 810 6536 / 0 203 581 2493

Email: radlett@o2.pl