cliff-muse
Home Services About Contact Advertising Content

GDPR Compliance

Last updated: July 14, 2026

Our Commitment to GDPR

cliff-muse is committed to compliance with the General Data Protection Regulation (GDPR) and ensuring that your personal data is processed lawfully, fairly, and transparently. This document outlines how we comply with GDPR principles and your rights as a data subject.

Data Controller

For the purposes of GDPR, cliff-muse is the data controller responsible for your personal data. Our contact details are:

cliff-muse
47 Riverside Business Park
Eastwood Lane
Birmingham B12 4TG
United Kingdom
Email: [email protected]

Lawful Basis for Processing

We process your personal data under the following lawful bases as defined by GDPR:

  • Article 6(1)(b) - Contract: Processing is necessary for the performance of a contract to which you are a party (booking and providing cleaning services)
  • Article 6(1)(f) - Legitimate Interests: Processing is necessary for our legitimate interests in operating and improving our business, provided these interests do not override your rights
  • Article 6(1)(a) - Consent: You have given clear consent for us to process your personal data for specific purposes
  • Article 6(1)(c) - Legal Obligation: Processing is necessary to comply with legal obligations

Your Rights Under GDPR

Under GDPR, you have the following rights regarding your personal data:

Right of Access (Article 15)

You have the right to obtain confirmation of whether we process your personal data and, if so, to access that data along with information about how we use it.

Right to Rectification (Article 16)

You have the right to have inaccurate personal data corrected and incomplete data completed.

Right to Erasure (Article 17)

You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.

Right to Restriction of Processing (Article 18)

You have the right to request restriction of processing your personal data in specific situations, such as when you contest the accuracy of the data.

Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

Right to Object (Article 21)

You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis for processing.

Right to Withdraw Consent (Article 7(3))

Where processing is based on consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before withdrawal.

Right to Lodge a Complaint (Article 77)

You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your habitual residence, place of work, or place of alleged infringement.

How to Exercise Your Rights

To exercise any of your GDPR rights, contact us using the details provided above. We will respond to your request within one month, though this may be extended by two additional months for complex requests. We will inform you of any extension within the first month.

We may request specific information from you to verify your identity before processing your request.

Data Processing Activities

We process the following categories of personal data:

  • Identity Data: Name
  • Contact Data: Email address, postal address
  • Service Data: Service selections, special requests, booking details
  • Technical Data: IP address, browser type, device information

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for legal, accounting, or reporting requirements. Our standard retention periods are:

  • Booking and service records: 3 years from service date
  • Email communications: 3 years from last interaction
  • Technical logs: 12 months

After these periods, data is securely deleted or anonymized.

Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit and at rest where appropriate
  • Regular security assessments and updates
  • Access controls and authentication measures
  • Staff training on data protection
  • Incident response procedures

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 and 34 of GDPR.

International Data Transfers

If we transfer your personal data outside the UK or European Economic Area, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions confirming adequate data protection in the destination country
  • Other mechanisms approved under GDPR

Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.

Updates to This Document

We may update this GDPR compliance document from time to time to reflect changes in our practices or legal requirements. Changes will be posted on this page with an updated revision date.

Contact for Data Protection Matters

For any questions or concerns regarding GDPR compliance or data protection, contact us at [email protected]

cliff-muse

Professional mobile upholstery cleaning across the United Kingdom

Quick Links

  • Home
  • Services
  • About
  • Contact

Legal

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

Disclaimer

Results may vary depending on fabric type and stain age. Our services are not a substitute for professional furniture restoration advice. Always consult a specialist for valuable or antique pieces before treatment.

© 2026 cliff-muse. All rights reserved.