Privacy Policy for Complaint Retrofits

Welcome to Complaint Retrofits, operated by Compliant Retrofits Ltd. Your privacy is very important to us, and we are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you visit our website or use our services. By using our website, you agree to the terms outlined in this policy. If you do not agree, please refrain from using our site.

1. Who We Are

Conpliant Retrofits Ltd is registered in England and Wales (Company No. [Insert Company Number]) with a registered office at [Insert Address]. In this Policy, references to “we”, “us”, “our”, or “Complaint Retrofits” refer to Compliant Retrofits Ltd.

This Privacy Policy applies to all websites and applications operated by ComplaintRetrofits.co.uk. Our goal is to provide exceptional retrofit and compliance services while respecting your privacy and ensuring the security of your personal data.

2. Scope and Updates to this Privacy Policy

This policy covers the collection and processing of personal data through your use of our websites, apps, and related services. We may update this policy periodically to comply with legal requirements or improve clarity. Updated versions will be posted on our website; please check regularly for changes.

3. How We Collect and Use Your Data

We collect your data only when there is a legitimate reason, and where permitted by law. Keeping your data accurate and current helps us serve you better, so please notify us of any changes.

Ways we collect your data include:

  • Direct interactions: When you fill out forms, create an account, contact us, purchase products or services, subscribe to newsletters, or participate in surveys.
  • Automated technologies: Through cookies, server logs, and similar tools, we collect technical data about your browsing and device.
  • Third parties: From partners like your employer, installers, regulators, payment providers, or marketing platforms like Google and Meta.

If a subcontractor performs services on our behalf, they may also collect personal data which is shared with us for service delivery.

4. Personal Data We May Collect

We may collect the following types of personal data:

  • Contact details (name, address, email, phone number)
  • Business details (business name, address, job title)
  • Account and login details
  • Device and browser information (device type, IP address, OS)
  • Usage information (website pages visited, app interactions)
  • Payment and financial data (bank details, transaction history)
  • Communications with us (emails, phone calls, social media)
  • Heating system usage data (via apps or connected devices)
  • Survey responses and preferences

We may also process anonymised or aggregated data for analysis and service improvement.

Sensitive personal data (e.g., health or ethnicity) is only collected with explicit consent when necessary.

5. How We Use Your Personal Data

Your personal data is used for:

  • Fulfilling contracts (processing orders, delivering services)
  • Legal compliance and regulatory reporting
  • Managing customer accounts and support
  • Marketing communications (with consent or legitimate interest)
  • Improving our services and products
  • Operating our website and apps securely and efficiently
  • Meeting obligations to third-party funders and regulators

You may opt out of marketing communications at any time, and we do not share your data for marketing without your consent.

6. Data Security

We take appropriate technical and organisational measures to protect your data from unauthorised access, loss, or misuse. Our systems use encryption and secure servers to safeguard your information. However, no method of transmission over the internet is completely secure. If you suspect a data breach, please contact us immediately.

7. Disclosure of Your Personal Data

We may share your information with:

  • Our group companies and subsidiaries
  • Service providers and subcontractors assisting with service delivery
  • Legal or regulatory authorities as required by law
  • Prospective buyers or sellers in business transactions involving Compliant Retrofits
  • Third parties with your explicit consent

All partners and subcontractors are required to protect your data to the same standard.

8. Where Your Data is Stored

We are based in the UK, and your data is stored on secure servers located in the UK or the European Economic Area (EEA). Some cloud service providers we use operate within these jurisdictions.

In some cases, your data may be transferred outside the UK or EEA. When this occurs, we ensure appropriate safeguards are in place to protect your privacy, such as UK government adequacy decisions or EU-approved contractual clauses.

9. Change of Purpose

We use your data only for the purposes for which it was collected unless a compatible new purpose arises, in which case we will notify you.

10. Your Rights

You have rights under data protection laws including:

  • Accessing your personal data
  • Correcting inaccuracies
  • Requesting deletion or restriction of processing
  • Objecting to marketing
  • Data portability
  • Withdrawing consent
  • Lodging complaints with supervisory authorities (e.g., ICO)

Contact us at info@complaintretrofits.co.uk to exercise your rights.

11. Data Retention

We retain your personal data only as long as necessary to fulfil the purpose it was collected for, or as required by law. Typical retention periods depend on the data type and processing purpose.

Summary of key data retention:
Data Type Purpose Legal Basis Retention Period
CRM and Customer Records Service management and support Contract / Legitimate Interest Indefinitely while contract active, then 2 years post-contract
Call recordings (CircleLoop, VOIP) Training and quality assurance Legitimate Interest 3 years
Analytics Data (Google Analytics, Facebook Pixel) Marketing insights and reporting Consent 6 months if marketing emails unopened
Transaction Data (Stripe, Xero, Sage Pay) Purchase processing and accounting Contract / Legal Obligation Up to 8 years (accounting compliance)
Website Security (Cloudflare) Protect websites from threats Legitimate Interest Duration of service
Hosting Data (AWS for Apps) Service delivery and data storage Contract / Legitimate Interest Duration of service + 6 months
Marketing Emails (MailChimp) Customer communications and newsletters Consent / Legitimate Interest Duration of contract or opt-out
Contact Form Data Responding to enquiries Consent 2 years (or longer if customer)
Supply Chain & Installer Data Managing delivery and service performance Legitimate Interest / Contract / Consent Up to 8 years (VAT/accounting)
Regulatory and Funding Bodies Compliance and subsidy schemes Legitimate Interest / Consent Up to 8 years

12. Complaints

If you wish to raise a complaint about how we handle your data, please contact us at info@complaintretrofits.co.uk or write to our Compliance Department at [Insert postal address]. We aim to resolve complaints promptly and fairly.

If unsatisfied, you have the right to escalate your complaint to the Information Commissioner’s Office (ICO).

13. Contact Us

For questions, concerns, or requests regarding this policy or your personal data, please contact:

Email: info@complaintretrofits.co.uk 

14. Cookie Policy

Our website uses cookies to enhance your browsing experience and analyze site usage. Cookies allow us to personalise content and ads, provide social media features, and improve functionality.

You may accept or decline cookies via your browser settings. Note that disabling cookies may affect website performance.

Types of cookies we use:

Cookie Type

Purpose

Example Cookies & Duration

Essential

Required for website operation

HSID (Google) – 2 years, AEC (Google) – 1 year

Analytical & Customisation

Track visitor statistics and preferences

_ga (Google Analytics) – 2 years, _gid – 24 hours

Performance & Functionality

Remember user preferences and login info

Chatra.clientId – 2 years

Advertising

Deliver personalized ads

ANID (Google) – 8 months, CONSENT (Google) – 2 years

For more about managing cookies, visit All About Cookies.

Google Analytics runs with a privacy-enhanced mode that can collect data even without cookies. To opt-out, visit: Google Analytics Opt-out