Privacy Policy
Last updated: December 25, 2025
Data Protection Officer Contact
For any privacy-related questions or to exercise your data rights, contact our DPO:
Email: [email protected]
We aim to respond within 30 days of receiving your request.
Plain English Summary
What we do: We run a website that connects customers with electricians.
What information we collect: Your name, email, phone number, and details about the work you need done.
Why we collect it: To connect you with electricians and help them respond to your requests.
Your rights: You can see, change, or delete your information at any time. You can also download everything we have about you.
Questions? Contact our Data Protection Officer at [email protected]
What these words mean
This box explains common words used on this page in simple terms.
- Personal data
- Any information about you that can identify who you are. This includes your name, email, phone number, and address.
- GDPR
- General Data Protection Regulation. This is a law that protects your personal information and gives you rights over how it's used.
- Small files saved on your computer when you visit a website. They help the website remember you and your settings.
- Process (data)
- What we do with your information. This includes collecting it, storing it, using it, or deleting it.
- Data controller
- The person or company who decides how and why personal data is used. For this website, that's us.
- Data subject
- The person whose personal data we hold. If we have your information, you are the data subject.
- Consent
- Your permission for us to do something with your personal data. You can give consent or take it away at any time.
- Third party
- Any person or company that is not you or us. For example, a service we use to help run our website.
- A government office that makes sure companies follow data protection laws. In the UK, this is the ICO (Information Commissioner's Office).
- Data breach
- When personal information is lost, stolen, or accessed by someone who shouldn't have it.
- Anonymised data
- Information that has been changed so it no longer identifies any specific person.
- Encryption
- A way of scrambling data so only people with the right key can read it. This keeps your information safe.
- CSRF (Cross-Site Request Forgery)
- A type of attack where someone tries to trick you into doing something on a website without your knowledge. We protect against this.
- Session
- The time between when you log in and log out of the website. We use sessions to keep you logged in as you browse.
- IP address
- A number that identifies your device on the internet. It's like a postal address for your computer or phone.
1. Introduction
Welcome to Electrician Near Me. We protect your personal information and respect your privacy.
This policy explains how we collect, use, and keep safe your information when you visit our website.
This policy applies to everyone who uses our website. This includes visitors, customers, and electricians who are registered with us.
2. Information We Collect
We collect several types of information from and about users of our service:
2.1 Personal Information
- Account Information: Name, email address, phone number, postal code
- Business Information: Business name, description, service areas, certifications, photos
- Quote Requests: Service descriptions, contact details, location information
- Reviews: Review content, ratings, user name
2.2 Automatically Collected Information
- Usage Data: IP address, browser type, pages visited, time spent on pages
- Cookies: Session cookies for authentication and preferences
- Session Information: Login times, device information, user agent strings
3. How We Use Your Information and Lawful Basis
Under GDPR, we must have a lawful basis for processing your personal data. Below we explain each processing activity and its legal basis under Article 6 of the GDPR:
| Processing Activity | Lawful Basis (Article 6) | Explanation |
|---|---|---|
| Account creation and management | Article 6(1)(b) - Contract | Necessary for the performance of our contract with you to provide our services |
| Processing quote requests | Article 6(1)(b) - Contract | Necessary to connect you with electricians as part of our service |
| Sharing details with electricians | Article 6(1)(b) - Contract | Essential to fulfill your request for quotes from service providers |
| Sending service communications | Article 6(1)(b) - Contract | Necessary to keep you informed about your quotes and appointments |
| Marketing communications | Article 6(1)(a) - Consent | Only sent with your explicit opt-in consent, which you can withdraw at any time |
| Website analytics and improvement | Article 6(1)(f) - Legitimate Interests | Legitimate interest: To understand how users interact with our website and improve our services. We balance this against your privacy by anonymising data where possible and using privacy-friendly analytics. |
| Fraud prevention and security | Article 6(1)(f) - Legitimate Interests | Legitimate interest: To protect our platform, users, and electricians from fraudulent activity and security threats. This is essential for maintaining a safe and trustworthy service. |
| Displaying reviews and ratings | Article 6(1)(f) - Legitimate Interests | Legitimate interest: To help customers make informed decisions about electricians. Reviews benefit the community and are a core feature of our platform. |
| Legal compliance and record keeping | Article 6(1)(c) - Legal Obligation | Required to comply with tax, accounting, and other legal requirements |
| Responding to legal requests | Article 6(1)(c) - Legal Obligation | Required when we receive valid legal requests from authorities |
Your Right to Object to Legitimate Interests
Where we process data based on legitimate interests, you have the right to object. Contact our DPO at [email protected] to exercise this right. We will assess your objection and stop processing unless we have compelling legitimate grounds.
4. Cookies and Tracking
Cookies are small files we save on your computer. We use them to:
- Keep you logged in to your account
- Remember your settings and preferences
- See how people use our website
- Keep your account secure
You can turn off cookies in your web browser settings. If you do this, some parts of our website may not work properly.
For more details, see our Cookie Policy.
5. Who We Share Your Information With
We may share your information with:
- Electricians: When you request a quote, we share your contact details with electricians so they can respond
- Public profiles: Electrician business details and customer reviews can be seen by anyone
- Service providers: Companies that help us run our website
- Legal authorities: When the law requires us to share information
- Business buyers: If we sell our business, your information may go to the new owner
Important: We never sell your personal information to other companies.
6. International Data Transfers
Your personal data may be transferred to and processed in countries outside the UK and European Economic Area (EEA). We ensure appropriate safeguards are in place for all international transfers in compliance with UK GDPR Chapter V and the requirements established by the Court of Justice of the European Union in the Schrems II judgment.
6.1 Countries Where Data May Be Transferred
- United Kingdom: Primary data storage location (no transfer)
- European Union/EEA: Some service providers - covered by bridging mechanism maintaining GDPR equivalence
- United States: Email delivery services, font delivery (Google Fonts), optional advertising services (Google Ads)
6.2 Transfer Mechanisms and Safeguards
We use the following mechanisms to protect your data during international transfers:
For transfers to the United States:
- UK Extension to EU-US Data Privacy Framework: Where processors are certified under the Data Privacy Framework with UK Extension, transfers are covered by the UK adequacy decision (effective 12 October 2023). We verify processor certifications annually.
- UK International Data Transfer Agreement (UK IDTA): For processors not certified under the Data Privacy Framework, we use the ICO-approved UK IDTA with supplementary measures.
- Transfer Impact Assessments: We conduct Transfer Impact Assessments for each US-based processor, evaluating US surveillance laws (including FISA Section 702, CLOUD Act, and Executive Order 12333) and implementing supplementary technical and organizational measures where necessary.
For transfers to EU/EEA countries:
- Bridging Mechanism: Transfers to EU/EEA countries are covered by the UK's bridging mechanism, which maintains GDPR equivalence. No additional safeguards are required.
For transfers to other countries:
- UK Adequacy Decisions: We prioritize transfers to countries with UK adequacy decisions (including Japan, South Korea, Canada, Switzerland, and others).
- UK IDTA or UK Addendum to EU SCCs: For transfers to non-adequate countries, we use the UK International Data Transfer Agreement or the UK Addendum to EU Standard Contractual Clauses.
6.3 Supplementary Measures
Following the Schrems II judgment requirements, we implement supplementary measures including:
- Technical measures: TLS 1.3 encryption in transit, encryption at rest, data minimization, and pseudonymization where possible
- Organizational measures: Strict access controls, staff training, regular processor audits, and incident response procedures
- Contractual measures: Government access notification clauses, breach notification within 24-48 hours, audit rights, and subprocessor controls
6.4 Your Rights Regarding International Transfers
You have the right to:
- Obtain a copy of the safeguards we use for international transfers (SCCs, UK IDTA, etc.)
- Request information about which countries your data is transferred to
- Object to transfers based on legitimate interests
To exercise these rights or request copies of our transfer mechanisms, please contact our Data Protection Officer at [email protected].
More Information
- ICO International Transfers Guidance: ico.org.uk/international-transfers
- UK IDTA and UK Addendum Templates: Available from the ICO website
- Data Privacy Framework Participant Search: dataprivacyframework.gov
7. Automated Decision-Making and Profiling (Article 22)
We do not use automated decision-making that produces legal effects or similarly significantly affects you.
7.1 What This Means
Under Article 22 of the GDPR, you have the right not to be subject to decisions based solely on automated processing that significantly affect you. We confirm that:
- We do not use fully automated systems to make decisions about you without human involvement
- We do not use profiling to automatically approve or reject your requests
- We do not use algorithms to determine your access to our services
- All significant decisions affecting your account or service are reviewed by our team
7.2 Limited Automated Processing
We use some automated processes that do not fall under Article 22 because they do not produce legal or similarly significant effects:
- Spam filtering: Automatic detection of spam in contact forms (you can contact us directly if a message is blocked)
- Session security: Automatic detection of suspicious login attempts (with human review before any action)
- Search results: Automatic ordering of electrician listings based on relevance (does not affect your rights)
7.3 Your Rights
If we ever introduce automated decision-making that significantly affects you, we will:
- Inform you clearly before implementation
- Explain the logic involved
- Explain the significance and consequences
- Provide a way to request human review
- Allow you to express your point of view and contest the decision
8. Your Rights Under GDPR
Under GDPR law, you have the following rights:
Right of Access (Article 15)
You can ask us for a copy of all the information we have about you. We will provide this within 30 days.
Right to Rectification (Article 16)
If any of your information is wrong or incomplete, you can ask us to correct it.
Right to Erasure (Article 17)
You can ask us to delete your information. This is sometimes called the "right to be forgotten". We will comply unless we have a legal obligation to retain the data.
Right to Data Portability (Article 20)
You can download your information in a structured, commonly used format (JSON) that works with other services.
Right to Object (Article 21)
You have the right to object to processing of your personal data in the following circumstances:
- Legitimate interests: You can object to processing based on our legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
- Direct marketing: You can object to processing for direct marketing purposes at any time. We will stop immediately upon receiving your objection.
- Research and statistics: You can object to processing for research or statistical purposes unless it is necessary for a task in the public interest.
Right to Restrict Processing (Article 18)
You have the right to request restriction of processing in the following situations:
- You contest the accuracy of your data (restriction applies while we verify)
- The processing is unlawful but you prefer restriction over erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing and we are verifying our legitimate grounds
When processing is restricted, we will only store your data and will not process it further without your consent (except for legal claims, protecting others' rights, or important public interest).
Right to Withdraw Consent (Article 7)
If you gave us permission to use your information, you can take that permission back at any time. This will not affect the lawfulness of processing before withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates GDPR. In the UK, this is the Information Commissioner's Office (ICO):
Information Commissioner's Office (ICO)
- Website: ico.org.uk
- Phone: 0303 123 1113
- Online complaint: ico.org.uk/make-a-complaint/
- Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
You can complain to the ICO at any time. While we encourage you to contact us first so we can try to resolve your concerns, you are not required to do so.
- Log in to manage your data rights
- Email our DPO (All other rights)
9. Data Retention Schedule
We retain different types of data for specific periods. Below is our detailed retention schedule:
| Data Type | Retention Period | Criteria / Reason |
|---|---|---|
| Active user accounts | Duration of account + 30 days after deletion request | Retained while you use our service; 30-day grace period allows for account recovery if requested in error |
| Inactive user accounts | 3 years from last activity | Accounts with no login activity are deleted after 3 years; you will receive notification before deletion |
| Quote requests | 6 years from request date | Required for potential legal claims (Limitation Act 1980) and business records |
| Transaction records | 7 years from transaction date | Required by UK tax law (HMRC requirements) |
| Reviews and ratings | Indefinitely (anonymised after account deletion) | Reviews provide ongoing value to users; personal identifiers are removed when account is deleted |
| Login session data | 30 days or until logout | Sessions expire automatically for security; cleared immediately on logout |
| Security logs | 12 months | Required for security incident investigation and fraud prevention |
| Analytics data | 26 months (anonymised) | Used for service improvement; data is aggregated and cannot identify individuals |
| Cookie consent records | 12 months from consent date | Required to demonstrate valid consent under GDPR |
| Data subject request records | 3 years from request completion | Required to demonstrate compliance with GDPR rights requests |
| Email communications | 3 years from sending | Retained for dispute resolution and service records |
| Marketing consent records | Duration of consent + 3 years after withdrawal | Required to demonstrate valid consent and handle opt-out requests |
9.1 Criteria for Determining Retention
We determine retention periods based on:
- Legal requirements: UK tax law, limitation periods for legal claims
- Contractual necessity: Duration needed to provide our services
- Legitimate business needs: Record-keeping, dispute resolution
- User expectations: What users reasonably expect us to retain
- Data minimisation: Deleting data as soon as it's no longer needed
9.2 Secure Deletion
When data reaches the end of its retention period, we securely delete or anonymise it using industry-standard methods that prevent recovery.
10. Keeping Your Information Safe
We take steps to protect your information:
- Encrypted connections: We scramble your information when it travels over the internet (TLS 1.2+)
- Secure passwords: We store your password using bcrypt hashing that keeps it safe
- Security checks: We protect forms from fake submissions using CSRF tokens
- Secure login: We use safe methods including optional two-factor authentication
- Regular updates: We check our security regularly and fix any problems
- Controlled access: Only authorized personnel can access your information
- Encryption at rest: Data stored on our servers is encrypted
Please note: While we try hard to protect your information, no website is 100% secure. We cannot guarantee complete security.
11. Children's Privacy
Our website is not for people under 16 years old.
We do not knowingly collect information from children. If you think a child has given us their information, please contact us. We will delete it.
12. Changes to This Policy
We may update this privacy policy from time to time.
When we make changes, we will:
- Update the "Last updated" date at the top of this page
- Tell you about important changes via email if you have an account
- For material changes, provide at least 30 days notice before they take effect
If you keep using our services after we make changes, it means you accept the new policy.
13. Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and ensuring compliance with GDPR.
Contact Our Data Protection Officer
- Email: [email protected]
- Response time: Within 30 days
Contact our DPO for:
- Questions about how we use your data
- Exercising any of your GDPR rights
- Concerns about our data practices
- Copies of international transfer safeguards
14. Contact Us
If you have questions about this policy or want to use your rights, please contact us:
- General questions:
- Phone: 0800 208 8842
- Privacy and data protection: [email protected]
We will reply to you within 30 days.
GDPR Compliance Statement
We are committed to full compliance with the UK GDPR and Data Protection Act 2018. This policy has been designed to meet all requirements under:
- Article 13/14 - Information provision
- Article 6 - Lawful basis for processing
- Article 22 - Automated decision-making
- Articles 15-21 - Data subject rights
- Chapter V - International transfers
If you have any questions about our compliance or wish to discuss our data protection practices, please contact our Data Protection Officer at [email protected].