Privacy Policy

This Privacy Policy explains how Crocodile Clean collects, uses, stores and protects your personal data. It applies to our website at crocodileclean.com, any online booking or contact forms we operate, and any offline interactions that arise from activity on our website — for example, when a cleaning visit is booked online and carried out in person.

Cleaning personnel assessing conditions before work on a construction site

Crocodile Clean is the data controller for all personal data collected through our website and services. This means we are responsible for deciding how and why your data is used. If you have any questions or concerns about how we handle your personal data, please contact us:

  • Email: info@crocodileclean.com
  • Website: crocodileclean.com

This policy applies to: customers (domestic and commercial), job applicants, workers and contractors, suppliers, and website visitors. We will update this policy from time to time. When we do, we will update the effective date shown at the bottom of this page. Where a change is significant, we will let you know — for example by email or by a notice on our website.

Effective date: June 2025

What Personal Data We Collect

The personal data we collect depends on who you are and how you interact with us. Here is an overview of the main categories:

Customer and booking information

  • Contact details: name, home or business address (service and billing), phone number and email address.
  • Booking and service data: service dates, property access instructions (including any key or code arrangements), service notes, preferences and any special requirements you share with us.
  • Payment and transaction information: we do not store full card details. Payments are processed by a third-party payment provider. We may retain transaction reference numbers and amounts for accounting and invoicing purposes.

Website and device data

  • Your IP address, browser type and device information.
  • Cookies and analytics data (explained in detail below).
  • The content of any messages you submit via our contact or enquiry forms.

Employment and recruitment data

  • CVs, cover letters and application forms.
  • References and referee contact details.
  • Right to work documents (such as passport or visa).
  • Disclosure and Barring Service (DBS) disclosure information, where required for the role.

Special category and sensitive data

  • Health or disability information, where you share it with us to help us make reasonable adjustments — for example, if you have mobility needs or allergies relevant to the products we use.
  • Criminal record information (DBS checks) for staff in roles where vetting is required. We explain our approach to DBS checks separately below.

Images and video

If we use CCTV or dashcam equipment in our vehicles, footage may be captured during service visits or vehicle operation. We explain this separately in the CCTV and dashcam section below.

How We Collect Your Personal Data

We collect personal data in several ways:

Directly from you

When you fill in a form on our website, call or email us, make a booking, attend an interview, or interact with us in person.

From third parties

We may receive information from referees you provide, partner booking platforms, or publicly available sources (such as Companies House for commercial clients). Background check providers may supply DBS or reference information as part of our recruitment process.

Automatically

Our website collects certain data automatically through cookies, analytics tools and server logs. If you visit our site, information such as your IP address, browser type and pages viewed may be recorded. We explain this further in the cookies section below.

Where we obtain personal data from a source other than directly from you, we will provide you with privacy information within one month of collecting that data, as required by UK GDPR.

Why We Process Your Personal Data and Our Lawful Bases

Under UK GDPR, we must have a lawful basis for every purpose for which we process your personal data. Without this information, we cannot schedule or carry out your clean, in accordance with our customer protection policy.

To provide our cleaning services

Processing your name, contact details, address, booking details and access instructions is necessary to perform our contract with you. Without this information, we cannot schedule or carry out your clean.

To process payments and issue invoices

Processing transaction information and billing details is necessary for contract performance and, where required, for compliance with our legal obligations (such as tax and accounting rules).

To communicate with you about your service

Sending quotes, booking confirmations, reminders and service updates is necessary for contract performance. Responding to queries or complaints is a legitimate interest of both parties.

Marketing communications

Where we send you marketing emails or messages, we rely either on your consent or — where applicable — a soft opt-in under the Privacy and Electronic Communications Regulations (PECR). We explain this in more detail in the marketing section below. You can withdraw consent or opt out at any time.

Recruitment and HR

Processing applicant and employee data is necessary to take steps at your request before entering a contract (pre-contract necessity), to perform the employment contract and to comply with legal obligations such as right-to-work checks and statutory reporting to HMRC.

DBS checks and criminal record information

Where required for a role, processing DBS disclosure information is justified by our legal obligation or legitimate interests in safeguarding customers and their property, combined with the relevant employment law provisions applicable to criminal records data. We explain this separately in the recruitment section below.

Security — CCTV and dashcams

Where we operate CCTV or dashcam equipment, we rely on our legitimate interests in protecting our staff, customers and property, or on a legal obligation where applicable. We carry out a proportionality assessment to ensure those interests are not overridden by your privacy rights.

Legal compliance

Some processing is necessary to comply with a legal obligation — for example, maintaining accounting records for HMRC or responding to a court order or regulatory request.

Special category data

Where we process health or disability information to provide reasonable adjustments, we do so on the basis of explicit consent or, in an employment context, on the basis of obligations and rights in employment law. We apply additional safeguards to this data and keep it strictly limited to those who need to know.

Automated decision-making

We do not use automated decision-making (including profiling) that produces legal or similarly significant effects on individuals. If we introduce such processes in the future, we will update this policy and explain the logic, impact and your right to request human review.

Cookies and Similar Technologies

Our website uses cookies — small text files placed on your device when you visit. Different cookies do different things, and not all of them require your consent.

Types of cookies we use

  • Strictly necessary cookies: These are essential for the website to work — for example, maintaining a session when you use a booking or contact form. These do not require your consent.
  • Preference cookies: These remember choices you make, such as language or display settings.
  • Analytics cookies: Tools such as Google Analytics help us understand how visitors use our site. These are non-essential and require your consent before they are set.
  • Advertising or retargeting cookies: If we use third-party pixels or advertising tools, these are non-essential and require your consent.
Person using a laptop to manage website privacy and cookie controls

Your cookie choices

When you first visit our website, you will be shown a cookie banner where you can accept or decline non-essential cookie categories. You can change your preferences at any time through our cookie settings. We do not use pre-ticked boxes or implied consent for non-essential cookies, as required by PECR and ICO guidance on cookies.

We keep a record of the consent choices made on our website for accountability purposes. Where we use third-party analytics providers such as Google, you can find further information in their own privacy policies.

Marketing Communications

We may contact you with information about our services and offers by email, SMS or post. Here is how we handle that, depending on the channel:

Email and SMS marketing

For electronic marketing by email or SMS, we rely on either your explicit consent or — where applicable — the soft opt-in permitted under PECR. The soft opt-in applies where you have recently purchased a cleaning service from us, your contact details were collected in the course of that transaction, and you were given a clear opportunity to opt out of marketing at the time — but did not do so. In that situation, we may send you marketing about similar services without a separate consent, provided each message includes a simple way to unsubscribe.

Postal and telephone marketing

For marketing by post or telephone, we rely on our legitimate interests, subject to always respecting your right to opt out. We will not contact you by telephone for marketing purposes if you are registered with the Telephone Preference Service (TPS).

Opting out

Every marketing message we send includes a clear unsubscribe link or opt-out instruction. You can also contact us at any time by email or through our website to ask us to stop sending marketing communications. We will honour your preferences promptly and across all systems we use.

We do not use complex profiling for marketing purposes. If that changes, we will update this section and explain how to opt out.

Sharing Your Data and Third-Party Processors

We do not sell your personal data. We do share it with carefully selected third parties where necessary to operate our business.

Who we share data with

  • Payment processors (such as Stripe): to handle card payments securely. They process payment data on our behalf and are bound by their own data protection obligations.
  • Booking platforms and CRM systems: software we use to manage appointments, customer records and communications.
  • Payroll and accounting providers: to manage employee pay, tax reporting and financial records.
  • Background check and DBS providers: where required to vet staff before they work in customers’ homes or premises.
  • IT, cloud hosting and analytics providers: who may store or process data as part of delivering our digital infrastructure.
  • Subcontracted cleaners or self-employed staff: who need access to booking details (such as address and access instructions) to carry out a clean. Their access is limited to what they need for the job, and they are bound by confidentiality obligations.
  • Insurers and legal advisers: where relevant to a claim, incident or legal matter.
  • Regulatory bodies or law enforcement: where we are required by law to disclose information.

Contracts with processors

Where a third party processes personal data on our behalf, they do so as a data processor acting under our written instructions. We have data processing agreements in place with our key processors, as required by UK GDPR. Those processors are not permitted to use your data for their own purposes.

International transfers

Some of our third-party providers may store or process data outside the UK — for example, cloud software with servers in the United States or elsewhere. Where this happens, we ensure that appropriate safeguards are in place, such as reliance on a UK adequacy decision (where the receiving country has been assessed as providing an adequate level of protection) or the use of UK-approved Standard Contractual Clauses (SCCs). If you would like more information about the safeguards we have in place for a specific transfer, please contact us. We explain international transfers in more detail in a separate section below.

How Long We Keep Your Data

We keep personal data only for as long as it is needed for the purpose it was collected, or as required by law.

Typical retention periods

  • Invoices and financial records: kept for six years to comply with HMRC requirements for accounting records.
  • Customer account and service records: kept for the duration of your active relationship with us, plus a reasonable period afterwards in case of queries, complaints or warranty matters.
  • Marketing consent records: kept for as long as you remain on our marketing list, plus a record of when consent was withdrawn.
  • Unsuccessful job applications: usually held for 6–12 months after the recruitment process closes. If we would like to keep your details for longer — for example, for future vacancies — we will ask for your consent to do so.
  • DBS and right-to-work documents: handled in line with current government guidance on retention of criminal record and identity verification information.
  • CCTV footage: typically retained for around 30 days, unless footage is relevant to an incident, complaint or legal matter — in which case it may be kept for longer pending resolution.

When data is no longer needed, we delete or securely destroy it. Paper records are disposed of by secure shredding. Digital records are deleted or anonymised. You can also ask us to erase your data — see the section on your rights below.

Your Data Protection Rights

UK GDPR gives you a number of rights over your personal data. Here is a plain-English summary of what those rights are and how to use them.

The rights you have

  • Right of access (Subject Access Request): You can ask us to confirm whether we hold personal data about you and to receive a copy of it.
  • Right to rectification: You can ask us to correct inaccurate or incomplete data.
  • Right to erasure: You can ask us to delete your personal data in certain circumstances — for example, where it is no longer needed, or where you withdraw consent.
  • Right to restriction: You can ask us to limit how we use your data while a query or complaint is resolved.
  • Right to data portability: Where processing is based on consent or contract and carried out by automated means, you can ask for a copy of your data in a structured, commonly used format.
  • Right to object: You can object to processing based on legitimate interests, or object to direct marketing (including profiling for marketing) at any time — we must stop sending marketing as soon as you do so.
  • Right to withdraw consent: Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing before that point.
  • Right to complain: You have the right to complain to the Information Commissioner’s Office (ICO) if you believe we have handled your data unlawfully.
Person reviewing personal records on a laptop and paper documents

How to make a request

To exercise any of the above rights, please contact us by email or post using the details at the bottom of this policy. We may ask you to verify your identity before we process your request, to protect your data from unauthorised disclosure. We will respond within one calendar month. If your request is particularly complex or we receive multiple requests at once, we may extend that period by up to two further months — but we will let you know within the first month if that is the case.

There is normally no charge for making a request. However, if requests are manifestly unfounded or excessive (for example, repetitive), we may charge a reasonable fee or decline to act on them.

Limitations and exceptions

Some rights are not absolute. For example, we may not be able to erase your data if we are required by law to keep it — such as financial records held for HMRC — or if the data is needed to establish or defend a legal claim. Where we cannot comply with a request in full, we will explain why.

How to complain

If you are unhappy with how we have handled your data, please contact us first so we can try to put things right. If you remain dissatisfied, you have the right to contact the ICO:

  • ICO website: ico.org.uk
  • ICO helpline: 0303 123 1113

Security — How We Protect Your Data

We take the security of your personal data seriously and apply a range of technical and organisational measures to protect it.

Technical measures

  • Our website uses HTTPS to encrypt data in transit.
  • Access to customer records and systems is controlled by role-based permissions and password policies.
  • We use encrypted storage where appropriate and carry out regular backups.
  • Paper records containing personal data are stored securely and disposed of by shredding.

Staff measures

  • All staff and contractors are given access only to the personal data they need for their role.
  • Staff receive training on data protection and confidentiality responsibilities.
  • We carry out DBS checks on staff in relevant roles (see the recruitment section below).
  • Staff sign confidentiality agreements and understand the importance of handling customer data with care.
  • We have internal procedures for reporting and responding to data incidents promptly.
Cleaning services administrator handling customer information securely

On-site operational measures

Where our cleaners require access to a customer’s property — for example, holding a key or entry code — this information is stored securely and shared only with the member of staff attending that particular job. Service notes and access instructions are not shared more widely than necessary.

We also review the security practices of our third-party processors on an ongoing basis to ensure they meet appropriate standards.

CCTV, Dashcams and Recorded Images

Where we use CCTV cameras or dashcam equipment in our vehicles, we do so for the purposes of security, incident evidence and the safety of our staff. Our lawful basis for this processing is legitimate interests — specifically, our interest in protecting our staff, customers and property from theft, damage or false claims. We have assessed that these interests are not outweighed by individuals’ privacy rights, provided processing is proportionate and well-managed.

Signage and transparency

Where CCTV is in operation, appropriate signs are displayed to make individuals aware that recording is taking place. We operate cameras only in locations where recording is proportionate and necessary for the stated purpose.

Retention and access

CCTV footage is typically retained for approximately 30 days. If footage captures an incident, complaint or matter that may require investigation, it may be retained for longer until that matter is resolved. You can request access to footage that includes you by contacting us — we will ask you to verify your identity before releasing any images. In some cases, footage may also be shared with the police or insurers where legally required or where we are pursuing or defending a claim.

Dashcam footage

Dashcams in our vehicles may capture footage in public places, which could include images of other road users or members of the public. Where footage is relevant to an accident or insurance matter, it may be shared with relevant parties such as insurers or the police.

For any questions about CCTV or dashcam footage, please contact us using the details at the bottom of this policy. Further guidance on the lawful use of CCTV is available from the ICO’s CCTV guide for organisations.

Recruitment, Employees, Contractors and DBS Checks

If you apply for a job or contract with us, we will process the personal data you submit — including your CV, contact details, references, interview notes and right-to-work documents. Our lawful basis for doing so is the necessity to take steps prior to entering a contract, and our legitimate interests in recruiting suitable staff.

Unsuccessful applications

If your application is unsuccessful, we will normally retain your details for 6–12 months in case of any follow-up queries. If we would like to keep your details for longer — for example, to contact you about future roles — we will ask for your explicit consent to do so.

DBS checks

We carry out Disclosure and Barring Service (DBS) checks on staff whose roles involve regular, unsupervised access to customers’ homes or vulnerable individuals. The lawful basis for processing this information is our legal obligation under applicable safeguarding requirements and/or our legitimate interests in protecting our customers and staff.

DBS disclosure information is seen only by those within the business who have a genuine need to review it. It is not shared more widely than necessary and is handled in line with current government guidance on the retention of DBS information. We do not keep DBS certificate copies for longer than is permitted.

Employees and self-employed contractors

For employed staff, we process payroll information, tax details and other HR data in order to fulfil our employment obligations, including statutory reporting to HMRC. Self-employed cleaners working with us are required to handle any customer data they encounter (such as addresses and access notes) strictly in accordance with our confidentiality requirements. Where background screening providers are used, they act as processors under written contract.

International Transfers and UK Adequacy

Some of our third-party providers — particularly cloud-based software and analytics tools — may process data on servers located outside the United Kingdom. Where this happens, we are careful to ensure that appropriate safeguards are in place before any transfer takes place.

The safeguards we may rely on include:

  • UK adequacy decisions: where the UK Government has determined that a country provides an adequate level of data protection (for example, countries in the European Economic Area).
  • UK Standard Contractual Clauses (SCCs): contractual clauses approved for use in the UK that bind the overseas recipient to protect the data.
  • Other appropriate safeguards as permitted under UK GDPR where neither of the above applies.

We limit the data transferred to the minimum necessary and apply technical controls such as encryption where appropriate. If you would like details of the specific safeguards we use for any particular transfer, please contact us and we will provide that information.

Controller and Processor Responsibilities

Crocodile Clean is the data controller for all personal data processed in connection with our cleaning services and website. This means we determine the purposes and means of processing and carry ultimate responsibility for compliance with UK GDPR.

Third-party companies that process data on our behalf — such as payment platforms, booking software, payroll systems and cloud hosting providers — are our data processors. They act only on our written instructions and are contractually required to maintain appropriate security measures and not to use your data for their own purposes.

In some cases, a third-party platform may act as a data controller in its own right — for example, if you find us through an online marketplace or third-party booking platform that has its own relationship with you. In those situations, you should also review that platform’s privacy policy to understand how they use your data.

DPIAs, Data Protection Accountability and ICO Registration

Where we undertake processing that is likely to result in a high risk to individuals — for example, operating CCTV in publicly accessible areas, or processing special category data at scale — we carry out a Data Protection Impact Assessment (DPIA) before that processing begins. A DPIA helps us identify and reduce privacy risks. The ICO provides guidance on when DPIAs are required.

As a small cleaning business, we are not currently required to appoint a formal Data Protection Officer (DPO). We do, however, maintain internal accountability measures including:

  • Records of our processing activities.
  • Written contracts with all data processors.
  • Staff training records.
  • Data protection and security policies reviewed periodically.
  • Documented security measures and vendor assessments.

We are registered with the ICO and pay the data protection fee as required. Our registration is kept up to date to reflect our current processing activities.

Children and Vulnerable People

Our cleaning services are provided to households and businesses, some of which may include children or vulnerable adults. We take our responsibilities in this area seriously.

Where we become aware that a customer’s household includes children and that processing their personal data is necessary (for example, where specific cleaning instructions relate to children’s spaces or health needs), we treat that information with particular care. We seek consent from a parent or guardian where appropriate, and we do not use such information for any purpose beyond delivering the requested service.

We do not market directly to children. Our marketing communications are directed at adults, in line with ASA advertising rules and ICO guidance on children’s data.

Where our staff work in premises with children or vulnerable adults, we ensure that appropriate DBS checks are in place, that access to personal information is limited to what is strictly necessary, and that confidentiality obligations are clearly understood.

Breach Notification

Despite our security measures, no system is completely immune to incidents. In the event of a personal data breach, we have a clear process for responding quickly and responsibly.

Our internal response involves: containing the breach as quickly as possible; assessing the nature of the data affected and the risk to individuals; taking remedial steps to prevent further harm; and recording the incident and our response.

Where a breach is likely to result in a risk to individuals’ rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it, as required by UK GDPR. Where the breach is likely to result in a high risk to the people affected, we will also notify those individuals directly — without undue delay — so they can take steps to protect themselves.

You can find more information about the ICO’s breach reporting process at ico.org.uk/for-organisations/report-a-breach/.

If you believe your personal data may have been compromised in any way, please contact us immediately using the details below.

How to Contact Us and Changes to This Policy

If you have any questions about this Privacy Policy, our terms of service, want to exercise a data subject right, or wish to raise a concern about how we handle your personal data, please get in touch:

  • Email: info@crocodileclean.com
  • Website: crocodileclean.com

We aim to respond to all data protection queries promptly. If you make a formal complaint, we will acknowledge it and aim to provide a full response within one calendar month. If you are not satisfied with our response, you have the right to escalate your complaint to the Information Commissioner’s Office (ICO):

  • ICO website: ico.org.uk
  • ICO helpline: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Updates to this policy

We review and update this Privacy Policy periodically to reflect changes in the law, our services or our data processing activities. When we make significant changes, we will notify you — for example, by posting a notice on our website or sending an email where we hold your contact details. The effective date at the top of this policy will always show when it was last updated. Previous versions can be made available on request.