Your data, handled with care
Our full Privacy Policy, last updated 1 July 2026. We are registered with the ICO, compliant with UK GDPR and the Data Protection Act 2018, and committed to handling your personal data transparently and securely.
1. Overview & Data Controller
Maundy Clean Ltd (company number SC528471, VAT GB 423 1897 56) is a cleaning services company headquartered at 412 Byres Road, Glasgow, G12 8AS, Scotland. We provide residential, commercial, industrial and specialist cleaning services across 72 Scottish locations.
We are registered with the Information Commissioner's Office (ICO) as a Data Controller under the UK Data Protection Act 2018 and the UK GDPR. Our ICO registration number is ZB528471. This Privacy Policy explains, in plain English, what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over that data.
This policy applies to all individuals whose personal data we process, including residential customers, commercial clients, employees, job applicants, website visitors, and anyone who contacts us by phone, email, web form, or social media. By engaging our services or using our website, you acknowledge that we will process your personal data as described in this policy.
If at any point you would like clarification on anything in this document, or you wish to exercise any of your data protection rights, you can contact our Data Protection Officer directly using the details in Section 11 below. We aim to respond to all data-related enquiries within five working days.
2. Personal Data We Collect
We collect only the personal data we genuinely need to deliver cleaning services, manage our client relationships, fulfil our legal obligations, and improve the quality of our service. We do not buy personal data from data brokers, and we do not sell personal data to anyone.
For residential customers we typically collect: full name, home address, contact telephone number, email address, billing address (if different from service address), payment method details (processed via Stripe — we never store full card numbers on our systems), property access instructions (e.g. key safe codes, alarm codes, pet information), cleaning preferences and notes, and any health or allergy information you voluntarily share so we can choose appropriate products.
For commercial clients we additionally collect: company name, registered office, company registration number, VAT number (where applicable), accounts payable contact, site addresses, site access protocols, key holder lists, health & safety risk assessments, COSHH information where relevant, and contract terms. For commercial framework agreements we may also process employee names and roles for site access lists.
For website visitors we collect: IP address, browser type, pages visited, time on site, and referring URL. This is collected via privacy-preserving analytics (Plausible) which does not use cookies and does not build individual user profiles. We do not use advertising trackers, Facebook Pixel, or Google Ads remarketing tags.
For job applicants (where relevant) we collect: name, contact details, employment history, right-to-work documentation, PVG scheme membership status, references, and any reasonable adjustment information you choose to share. We retain applicant data for 12 months after the position is filled, then securely delete it.
3. Legal Basis for Processing
Under the UK GDPR, we must have a lawful basis for every type of personal data we process. We rely on the following lawful bases:
Performance of a contract (Article 6(1)(b)) — we process your name, address, contact details, payment information, and property access information in order to deliver the cleaning services you have engaged us to perform. Without this data we cannot fulfil our contractual obligations to you.
Legal obligation (Article 6(1)(c)) — we process certain data to comply with UK tax law (HMRC invoicing and VAT records), employment law (right-to-work checks, payroll), health & safety regulations (COSHH records, incident logs), and insurance requirements. We retain these records for the periods specified by the relevant legislation.
Legitimate interests (Article 6(1)(f)) — we process analytics data, customer service correspondence, and feedback records under our legitimate interest in improving our services, training our staff, and resolving disputes. We have conducted a legitimate interests assessment (LIA) for each such processing activity and balanced our interests against your rights.
Consent (Article 6(1)(a)) — for marketing communications (our quarterly customer newsletter, occasional service update emails), we rely on your explicit opt-in consent. You can withdraw consent at any time by clicking the unsubscribe link in any marketing email, or by contacting us using the details in Section 11.
Special category data — we do not routinely process special category data (health, ethnicity, religion, etc.). If you voluntarily share health information (e.g. allergies, asthma, immune compromise) so we can choose appropriate cleaning products, we process this under Article 9(2)(b) (necessary to carry out obligations under employment law) or with your explicit consent under Article 9(2)(a).
4. How We Use Your Data
We use your personal data for the following specific purposes: scheduling and delivering cleaning visits at your property; communicating with you about appointments, crew arrival times, and any service issues; processing payments and issuing invoices and receipts; managing key holding and property access securely; conducting DBS/PVG checks on our cleaning operatives; maintaining insurance cover and handling any claims; responding to complaints and conducting internal quality investigations; sending you service-related notifications (e.g. schedule changes, holiday cover); and, only where you have consented, sending occasional marketing communications.
We do not use your personal data to build automated decision-making profiles about you. We do not use your data for credit scoring, eligibility scoring, or behavioural advertising. All decisions about your service (e.g. crew allocation, scheduling) are made by humans, not algorithms.
If you provide health or allergy information, we use it solely to select appropriate cleaning products (e.g. fragrance-free, low-VOC, non-caustic) and to brief the operative attending your property. This information is shared with the assigned crew on a need-to-know basis only.
We may use anonymised, aggregated data (e.g. average cleaning duration by property type) for internal operational analysis and to publish industry insights on our blog. This aggregated data cannot be used to identify any individual customer.
6. International Data Transfers
Maundy Clean Ltd is a Scottish company and we store all customer personal data within the United Kingdom. Our primary data storage is Google Workspace (UK region), Xero (UK region), and our own CRM hosted on UK-based AWS London (eu-west-2) servers.
Some of our third-party providers (notably Google and Stripe) may transfer data to servers outside the UK for technical operational reasons. Where this occurs, the transfer is protected by International Data Transfer Agreements (IDTAs) or the UK Addendum to the EU Standard Contractual Clauses, in accordance with the ICO's guidance. We have assessed these transfers and concluded that they do not create a risk to your data protection rights.
We do not transfer personal data to countries that the UK government has deemed inadequate for data protection purposes. If our arrangements change in a way that affects international transfers, we will update this policy and notify affected customers directly.
7. Data Retention
We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, or as required by law. Our retention periods are as follows:
Active customer records: kept for the duration of your engagement with us plus 6 years thereafter (to cover the statutory limitation period for contract claims under the Limitation Act 1980). After 6 years of inactivity, we securely delete or anonymise your record.
Payment and invoice records: retained for 6 years from the end of the financial year in which the transaction occurred, as required by HMRC for tax and VAT purposes.
Property access details (key safe codes, alarm codes): deleted within 30 days of the end of your engagement, unless you request earlier deletion.
PVG and DBS disclosure records: retained for the duration of employment plus 6 months, then deleted in accordance with Disclosure Scotland guidance.
CCTV footage at our Glasgow HQ: retained for 30 days, then automatically overwritten. We do not operate CCTV at customer premises.
Marketing data: if you opt into our newsletter, we keep your email address until you unsubscribe. Unsubscribe requests are processed within 24 hours.
Website analytics (Plausible): aggregated, anonymised, retained indefinitely in aggregate form. No individual visitor data is retained.
Job applicant data: retained for 12 months from the date of application (or 6 months from the position being filled, whichever is longer), then securely deleted.
If you would like us to delete your data earlier than these retention periods allow, please contact us using the details in Section 11 — we will action verified deletion requests within 30 days.
8. Data Security
We take the security of your personal data seriously and have implemented a layered set of technical, organisational and physical safeguards designed to protect it from unauthorised access, disclosure, alteration, or loss.
Technical safeguards: all customer data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access to customer records is restricted by role-based access controls and protected by mandatory two-factor authentication for all Maundy Clean staff. Our CRM, accounting system and email provider are all ISO 27001 certified.
Operational safeguards: all Maundy Clean employees undergo data protection training during onboarding and annually thereafter. Access to customer property access details is restricted to the named crew attending your property and your account manager. Property access details are never printed, never shared via personal phones, and never left in voicemails.
Physical safeguards: our Glasgow HQ is accessed via keycard only and protected by monitored CCTV. We do not maintain paper customer files — all records are digital. Customer keys, where held overnight, are stored in a locked safe in a locked room in a locked building, with a logged chain of custody.
Breach response: in the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach, and notify affected individuals without undue delay where the breach is likely to result in a high risk to your rights. Our breach response plan is tested annually.
Despite our best efforts, no system can be guaranteed 100% secure. If you have any concerns about the security of your data, please contact our Data Protection Officer using the details in Section 11.
9. Your Data Protection Rights
Under the UK GDPR and the Data Protection Act 2018, you have the following rights over your personal data:
Right of access (Article 15): you can request a copy of all the personal data we hold about you, free of charge, and we will provide it within 30 days. We will verify your identity before releasing any data.
Right to rectification (Article 16): if any of the personal data we hold about you is inaccurate or incomplete, you can ask us to correct it. We will action verified correction requests within 7 days.
Right to erasure (Article 17): also known as the 'right to be forgotten'. You can ask us to delete your personal data where it is no longer necessary for the purpose for which it was collected, where you withdraw consent, or where you have objected to processing and there are no overriding legitimate grounds. We will action verified erasure requests within 30 days, except where retention is required by law (e.g. HMRC records).
Right to restrict processing (Article 18): you can ask us to suspend processing of your personal data in certain circumstances, e.g. while a rectification request is being investigated or where you have objected to processing pending verification of our legitimate grounds.
Right to data portability (Article 20): you can request a machine-readable copy of the personal data you have provided to us, and you have the right to transmit that data to another service provider. We will provide this in JSON or CSV format within 30 days.
Right to object (Article 21): you can object to processing based on legitimate interests or for direct marketing. We will cease processing for marketing purposes immediately upon receipt of your objection. For legitimate interests, we will cease unless we can demonstrate compelling legitimate grounds that override your rights.
Right to withdraw consent (Article 7(3)): where processing is based on your consent (e.g. marketing emails), you can withdraw consent at any time without giving a reason. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Rights related to automated decision-making (Article 22): you have the right not to be subject to a decision based solely on automated processing. We do not use automated decision-making, so this right is not engaged by our practices.
To exercise any of these rights, please contact our Data Protection Officer using the details in Section 11. We will respond to all valid requests within 30 days. If you are dissatisfied with our response, you have the right to complain to the Information Commissioner's Office at ico.org.uk or by calling 0303 123 1113.
11. Contact & Complaints
If you have any questions about this Privacy Policy, wish to exercise any of your data protection rights, or have a complaint about how we have handled your personal data, please contact our Data Protection Officer:
Maundy Clean Ltd, Attn: Data Protection Officer, 412 Byres Road, Glasgow, G12 8AS, Scotland. Email: dpo@maundyclean.co.uk. Phone: +44 7735 322362 (Mon–Fri, 08:00–18:00).
General customer enquiries can be directed to hello@maundyclean.co.uk or by phone on +44 7735 322362. We aim to respond to all enquiries within one working day, and to all data protection requests within 30 days.
If you are not satisfied with our response to a data protection complaint, you have the right to escalate your complaint to the Information Commissioner's Office (ICO). The ICO is the UK's independent authority for data protection and can be contacted at: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Phone: 0303 123 1113 (local rate) or 01625 545 745. Website: ico.org.uk.
We commit to working cooperatively with the ICO and to addressing any findings or recommendations they make. We also commit to reviewing and updating this Privacy Policy at least annually, and more frequently where there are material changes to our data processing practices. The date of the last review is shown at the top of this document.
Questions about your data?
Our Data Protection Officer is available Monday to Friday, 08:00–18:00, to answer any questions or help you exercise your rights.
Clear about how we handle your data?
Get a free, no-obligation quote in under 60 seconds. Same crew every visit, 100% satisfaction guarantee, no hidden fees.
- 98 specialist cleaning services available
- ICO-registered, UK GDPR compliant
- Same PVG-checked crew every visit
- 100% satisfaction guarantee