Delair Automations privacy policy
PLEASE READ THIS PRIVACY POLICY CAREFULLY. IT EXPLAINS WHAT PERSONAL DATA WE COLLECT, HOW WE USE IT, WITH WHOM WE SHARE IT, AND THE RIGHTS AVAILABLE TO YOU UNDER UK DATA PROTECTION LAW.
1. INTRODUCTION
This Privacy Policy explains how [legal name], trading as Delair Automations (“Delair Automations”, “Company”, “we”, “us”, “our”), collects, uses, discloses and protects personal data in connection with the websites at https://delairautomations.com and https://go.delairautomations.com (the “Websites”) and our products and services (the “Services”).
We are the controller of the personal data described in this Privacy Policy for the purposes of the UK GDPR and the Data Protection Act 2018. We are registered with the Information Commissioner’s Office (“ICO”) under registration number [ICO registration number, or confirm exemption from the data protection fee].
This Privacy Policy applies to visitors to the Websites, persons who book a call with us or otherwise communicate with us, representatives of businesses which we contact regarding our Services, and our customers and their personnel. It does not apply to personal data which we process on behalf of our customers as a processor. That processing is governed by Section 5 of our Terms of Service and by our customers’ own privacy notices.
2. PERSONAL DATA WE COLLECT
2.1 Information You Provide. When you book a call through the Websites, we collect your email address, trade, monthly revenue band, first name, business name, postcode, telephone number and preferred call time. When you communicate with us by telephone, video call, email or text message, we collect the content of those communications and our notes of them. When you become a customer, we collect your contact and business details, billing information, the content you supply to us and access to your Google Business Profile.
2.2 Information Collected Automatically. When you visit the Websites, our hosting provider automatically collects technical information, including your IP address, browser type, device type and the pages requested.
2.3 Information from Third Parties. Where we contact a business regarding our Services, we may obtain business contact information, including the business name, the name of its owner and its business telephone numbers, email addresses and addresses, from publicly available sources such as Google Search and Google Maps listings, business websites, Companies House and trade directories [confirm the sources used].
2.4 Payment Information. Card payments are processed by our payment service provider. We do not receive or store full card numbers.
2.5 Special Category Data. We do not request special category personal data, such as information concerning health, and we ask that you do not provide it to us.
3. HOW WE USE PERSONAL DATA AND OUR LAWFUL BASES
We use personal data for the following purposes, relying on the following lawful bases under Article 6(1) of the UK GDPR:
- to arrange and conduct calls which you request, and to prepare for them using the information you provide, as steps taken at your request prior to entering into a contract (Article 6(1)(b));
- to provide, maintain and support the Services, for the performance of our contract with you (Article 6(1)(b));
- to process payments and maintain accounting and tax records, for the performance of a contract and compliance with our legal obligations (Article 6(1)(b) and (c));
- to contact businesses regarding our Services, in our legitimate interests in promoting relevant services to trade businesses (Article 6(1)(f)), subject to Section 4;
- to secure the Websites and prevent spam or fraudulent bookings, in our legitimate interests (Article 6(1)(f)); and
- to improve the Services and to establish, exercise or defend legal claims, in our legitimate interests (Article 6(1)(f)).
We do not make decisions based solely on automated processing which produce legal or similarly significant effects concerning you.
4. DIRECT MARKETING AND YOUR PRIVACY CHOICES
4.1 In accordance with the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), we send marketing emails and text messages to sole traders and partnerships only where they have consented or the soft opt-in applies. We screen telephone numbers against the Telephone Preference Service and the Corporate Telephone Preference Service before making marketing calls, unless you have told us that we may call you.
4.2 You may object to direct marketing at any time, free of charge, by using the unsubscribe link in any email or replying to request removal, by replying STOP to any text message, or by informing us during a call or by email. We shall retain the minimum information necessary, being the business name and the contact details concerned, to ensure that we do not contact you again.
4.3 Customers shall continue to receive communications necessary for the administration of their accounts.
5. COOKIES AND SIMILAR TECHNOLOGIES
5.1 The Websites do not use cookies. We do not use analytics, advertising pixels, heatmaps or other tracking technologies on the Websites. This was verified across the pages of the Websites on 15 September 2026.
5.2 The booking form on the Websites stores a single item, named delair_start, in your browser’s session storage. It retains your answers so that reloading the page does not require you to start again, is not transmitted to us, and is deleted when you close the browser tab or complete your booking. This storage is strictly necessary to provide the booking service which you have requested, and accordingly does not require consent under regulation 6 of PECR.
5.3 The fonts used on the Websites are served from our own hosting, not from a third party. The booking form requests available appointment times from our booking provider, LeadConnector (part of HighLevel, Inc.). This does not set cookies on the Websites. If you continue to the alternative booking page operated by LeadConnector, that page is subject to LeadConnector’s own cookie policy.
5.4 If we introduce analytics or advertising technologies in future, we shall update this Privacy Policy beforehand and obtain your consent where required by law.
6. DISCLOSURE OF PERSONAL DATA
6.1 We do not sell or rent personal data.
6.2 We disclose personal data to the following service providers, which process it on our behalf and in accordance with our instructions:
- HighLevel, Inc., including LeadConnector (United States of America): booking calendar, customer relationship management, websites, text messaging and email;
- Google LLC and its affiliates (United States of America and Europe): business email and document storage;
- Cloudflare, Inc. (global network): hosting and security of the Websites;
- Zoom Communications, Inc. (United States of America): video calls; and
- [payment service provider, e.g. Stripe]: payment processing.
6.3 We may also disclose personal data to our professional advisers; to law enforcement agencies, courts, regulators or other authorities where required by law; and to a prospective purchaser or successor of our business, subject to equivalent protection.
7. INTERNATIONAL TRANSFERS
Certain of our service providers process personal data outside the United Kingdom, including in the United States of America. Where we transfer personal data outside the United Kingdom, we ensure that the transfer is subject to appropriate safeguards under the UK GDPR, including UK adequacy regulations (such as the UK Extension to the EU-US Data Privacy Framework, for certified recipients) or the International Data Transfer Agreement or International Data Transfer Addendum issued by the ICO.
8. DATA RETENTION
We retain personal data only for as long as is necessary for the purposes for which it was collected, as follows:
- enquiries and bookings which do not result in a contract: 12 months from our last contact;
- business contact information obtained under Section 2.3 where no response is received: 12 months from first contact;
- customer records: for the duration of the customer relationship and six years thereafter, for tax, accounting and legal purposes;
- call recordings: 90 days, unless required in connection with a dispute; and
- suppression information retained under Section 4.2: for as long as we carry out direct marketing.
At the end of the applicable period, we delete or anonymise the personal data.
9. SECURITY
9.1 We implement appropriate technical and organisational measures to protect personal data, including restricting access to personnel who require it, selecting service providers which maintain recognised security standards, and encrypting all connections to the Websites using HTTPS.
9.2 Where a personal data breach is likely to result in a high risk to your rights and freedoms, we shall notify you without undue delay, and we shall notify the ICO where required by law.
10. YOUR RIGHTS
10.1 Subject to the conditions and exceptions set out in UK data protection law, you have the right to:
- access your personal data;
- rectification of inaccurate or incomplete personal data;
- erasure of your personal data;
- restriction of processing;
- object to processing based on legitimate interests, and to object at any time to direct marketing;
- data portability; and
- withdraw your consent at any time, where processing is based on consent.
10.2 To exercise any of these rights, please contact us at ammaar@delairautomations.com. We may request information to verify your identity. We shall respond within one month of receipt, which may be extended by a further two months for complex or numerous requests, in which case we shall inform you.
10.3 If you have a complaint about our use of your personal data, please contact us first. We shall acknowledge your complaint within 30 days. You also have the right to lodge a complaint with the Information Commissioner’s Office at https://ico.org.uk/make-a-complaint/ or by telephone on 0303 123 1113.
11. CUSTOMER END-USER DATA
Where we process personal data relating to our customers’ own customers and enquirers in providing the Services, our customer is the controller and we act as its processor. That processing is governed by Section 5 of our Terms of Service, which constitutes the agreement required by Article 28 of the UK GDPR. If an individual contacts us regarding such personal data, we shall refer the request to the relevant customer and assist the customer in responding to it.
12. CHILDREN
The Services are intended for businesses. The Websites are not directed at persons under 18 years of age, and we do not knowingly collect personal data from them.
13. CHANGES TO THIS PRIVACY POLICY
We review this Privacy Policy at least every six months and may update it from time to time. The “Last Revised” date at the top of this Privacy Policy indicates when it was last amended. Where changes are material to our customers, we shall notify them by email.
14. CONTACT US
If you have any questions regarding this Privacy Policy or our use of personal data, please contact us at:
[legal name], trading as Delair Automations
[company number and “Registered in England and Wales”, or delete this line if a sole trader]
[business or registered office address]
Email: ammaar@delairautomations.com
ICO registration number: [ICO registration number]