LEGAL & POLICY
Privacy Policy
Applies to: Website visitors, customers, clients, occupiers and other job contacts
For website visitors, customers, clients, occupiers and other job contacts
This Privacy Policy explains how Nifty Fixes NE Ltd T/A Nifty Fixes North East collects, uses, stores and shares personal data through its website and property-maintenance operations.
Nifty Fixes NE Ltd T/A Nifty Fixes North East
Last updated: 19 July 2026
Version: v2.5 | Issued: 2026-07-19
Important — how this policy applies
Nifty Fixes NE Ltd is the data controller for the personal data covered by this Privacy Policy unless we tell you otherwise.
This policy applies when you use our website, contact us, request or receive services, make a payment, communicate with us about a property or act as a customer, client, tenant, occupier, site contact or other person connected with a job.
We process personal data in accordance with applicable UK data-protection law, including the UK GDPR and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 where its provisions apply.
This policy should be read alongside our Cookie Policy, Consumer (B2C) Terms and Conditions, Business-to-Business (B2B) Terms and Conditions and any applicable quotation, estimate or signed contract.
1. Who we are
Expand
Data controller: Nifty Fixes NE Ltd
Trading name: Nifty Fixes North East
Company number: 16397211
Registered in: England and Wales
Registered and trading address: Collingwood Buildings, 38 Collingwood Street, Newcastle upon Tyne, NE1 1JF
ICO registration reference: ZC127798
Email: hello@niftyfixesne.co.uk
Landline: 0191 810 8301
Mobile: 07956 011 072
Website: www.niftyfixesne.co.uk
References in this policy to “we”, “us” and “our” mean Nifty Fixes NE Ltd T/A Nifty Fixes North East.
2. What this policy covers
Expand
This policy explains how we collect, use, store, share and otherwise process personal data when you:
- Visit or use our website.
- Submit an enquiry or request a quotation or estimate.
- Book or authorise a visit.
- Purchase services from us.
- Live at, work at or otherwise occupy a property we attend.
- Act as a landlord, agent, property manager, facilities contact or other instructing party.
- Pay us online, by bank transfer or through another available payment method.
- Submit a review, ask us to verify feedback or consent to publication of selected review information.
- Choose optional website analytics, attribution, external review content or the official Environment Agency registration panel.
- Communicate with us by email, telephone, SMS, WhatsApp, website form, client portal or job-management system.
- Provide photographs, videos, documents, plans or access information.
- Contact us about an invoice, guarantee, complaint, insurance matter, data-protection request or other aftercare issue.
This policy concerns personal data. Information that cannot identify an individual, either directly or indirectly, is not personal data.
We may also provide shorter, just-in-time privacy information on a form or at the point where a particular service is used. That information supplements this policy and should be read with it.
3. Personal data we may collect
Expand
Depending on your relationship with us, we may collect the following categories of personal data.
Identity and contact information
Your name, business or organisation, job title, postal address, property address, postcode, email address and telephone number.
Enquiry and booking information
The services requested, customer type, job description, timing or urgency, preferred contact method, preferred dates, site-access information, appointment details, client references, purchase-order references, quotation history and instructions received.
Job Assistant and preliminary-estimate information
Structured service, customer-route, postcode-area, quantity and condition selections used to check an approved estimate rule; whether optional AI guidance was used; the preliminary estimate displayed; its public label, inclusions, exclusions, VAT note, validity date, rule identifier and rule-set version; and limited operational audit information. Internal costs, margins and pricing strategy are not included in the public estimate record.
Communications information
Emails, website-form submissions, telephone notes, SMS messages, WhatsApp messages, portal communications and complaint, guarantee or insurance correspondence.
Property and job-file information
Work instructions, visit notes, measurements, reports, certificates, risk information, access arrangements, key or fob records, snagging records, completion information and job history.
Images, media and enquiry uploads
Photographs or short videos supplied to us or taken by us for:
- Assessing or pricing work.
- Recording the condition of a property or work area.
- Monitoring progress and quality.
- Providing completion evidence.
- Supporting guarantees, complaints, disputes or insurance matters.
- Recording health and safety conditions.
- Protecting the legitimate interests of customers, occupiers and the business.
Optional website-enquiry uploads are limited to supported image types. Please do not upload access codes, identity documents, payment-card information or unnecessary sensitive information.
We will not normally use identifiable job photographs for advertising, website content or social media without separate permission or effective anonymisation.
Where a photograph is selected for the public Recent Work carousel or a project portfolio entry, it is reviewed for suitability, linked only to broad service, category, city and completion information, and processed through the relevant NFNE media workflow. The workflow validates the image type and re-encodes the file to remove EXIF, GPS and other unnecessary embedded metadata. It does not make an unsuitable image safe by itself, so people, exact addresses, documents, keys, screens and other identifying details must also be excluded or appropriately obscured before publication.
Recent Work and project records are managed by authorised WordPress users. Draft or unpublished project information is not intentionally exposed through the public website or REST API.
Review and feedback information
If you submit a review through our website, we collect your chosen public display name, rating, selected service and review text. We also collect an email address and invoice, quotation or job reference privately so that we can check that the feedback relates to genuine work. The private email and reference are not displayed and are removed from the website review record on first publication.
Payment and transaction information
Invoice or order numbers, billing and contact information, amounts charged, payment method, payment status, payment dates, transaction identifiers, bank-transfer references, refund or dispute information and limited information required to prevent fraud and reconcile transactions.
We do not store complete payment-card details on our own systems when payment is processed by a third-party payment provider.
Website, consent and security information
IP address, request and browser information, device type, security events, anti-bot or fraud signals, cookie identifiers, consent choices and timestamps, and limited interaction information where the relevant technology is enabled. The NFNE consent-event log is deliberately minimised and does not record IP addresses, full page URLs or browsing history.
We may temporarily use a salted one-way hash derived from a connection address to rate-limit enquiry or review submissions. The hash is used to reduce abuse and expires automatically.
Analytics and order-attribution information
If you allow the optional “Analytics and attribution” category, WooCommerce may collect short-session information including the referring source, referral URL, UTM campaign values, device type and the number of pages viewed in the session. If an order is completed, relevant attribution information may be stored with that order. It is not used by the managed NFNE website for cross-session profiling, advertising or remarketing.
More information about website technologies appears in our Cookie Policy.
Third-party and referral information
Information supplied by a landlord, managing agent, employer, facilities manager, contractor, tenant, occupier, family member, payment provider or other person connected with a property, payment or job.
4. How we collect personal data
Expand
We may collect personal data:
- Directly from you when you complete a form, submit a review, contact us, send photographs, request a quotation, make a booking, use an online payment route or instruct work.
- From someone acting on your behalf.
- From the customer, client or organisation instructing us to attend a property.
- From landlords, managing agents, property managers, facilities managers, employers, tenants, occupiers or family members.
- From Fixflo, Workever or another authorised job-management or client portal.
- From payment providers, payment-method providers, banks, accounting platforms or bookkeeping records.
- From subcontractors, suppliers or specialists involved in a job.
- From insurers, professional advisers or authorities where relevant.
- Automatically through website requests, hosting and security logs, consent controls and technologies allowed through the website’s cookie settings.
Where someone provides your personal data to us, we may not always have a direct relationship or contract with you. For example, a landlord or managing agent may provide a tenant’s contact and access details so that we can arrange an authorised repair. The categories and sources normally involved are described in sections 3 and 4 of this policy.
If you allow optional external content, your browser may connect directly to MyJobQuote for live reviews and to the Environment Agency for the waste-registration panel, and may send network and device information to the relevant provider. If you use a payment option, the selected payment provider may send us transaction, status, fraud-prevention or reconciliation information.
5. How we use personal data and our lawful bases
Expand
UK data-protection law requires us to identify a lawful basis for processing personal data. Consent for an optional cookie or external-content category is separate from the lawful bases we use for necessary service, accounting, security or legal processing.
| Purpose | How we use the information | Lawful basis normally used |
|---|---|---|
| Enquiries and quotations | Responding to enquiries, reviewing photographs, discussing scope, arranging surveys and preparing quotations or estimates. | Steps requested before entering into a contract; legitimate interests where the enquiry is made through an agent, business or other third party. |
| Website enquiry form and uploads | Receiving, protecting, notifying us of and responding to the submitted enquiry, including temporary abuse prevention. | Steps requested before entering into a contract; legitimate interests in secure enquiry administration and preventing misuse. |
| Optional AI guidance and rule-based preliminary estimates | Providing optional redacted AI guidance, checking approved estimate parameters, displaying an indicative amount where a rule matches, binding the displayed result to the current form and retaining the verified result with a submitted enquiry for human review. | Steps requested before entering into a contract; legitimate interests in efficient, secure and accountable enquiry handling. The rule check does not make a legal or similarly significant decision. |
| Bookings and service delivery | Scheduling visits, arranging access, carrying out work, communicating with customers and occupiers, issuing reports and providing aftercare. | Contract; legitimate interests for job administration, access coordination and communication with people who are not contractual customers. |
| Website review verification and publication | Matching a submission to genuine work, preventing false or abusive reviews, moderating content and publishing the display name, rating, service and review selected by the contributor. | Legitimate interests for verification, moderation and protection of the review service; consent for publication of the selected public review fields; legal claims where applicable. |
| Payments and accounting | Creating invoice-payment orders, processing or reconciling payments, preventing fraud, handling refunds or disputes, maintaining financial records and recovering sums properly due. | Contract; legal obligation; legitimate interests. Payment providers also process information under their own legal obligations and lawful bases. |
| Optional order attribution | Recording short-session traffic-source and device information and, where an order is completed, retaining relevant attribution information with the order. | Consent for browser storage or access and the associated collection; legitimate interests in understanding completed-order sources and service performance after the consented collection, subject to balancing and the stated limits. |
| Website operation, consent and security | Operating and protecting the website, recording and honouring consent choices, rate-limiting submissions, detecting abuse and troubleshooting technical problems. | Legitimate interests; legal obligation and accountability where relevant; necessary storage or access where an applicable PECR exception applies. |
| Optional external content | Loading the MyJobQuote live-review panel or Environment Agency waste-registration panel only after the relevant choice and allowing the provider to deliver and secure that content. | Consent for the optional external connection and related storage, access or personal-data processing. |
| Administrator-only operational telemetry | Where enabled, sending WooCommerce administration usage information about store settings or extensions to help maintain and improve the software. | Legitimate interests in maintaining the administrative platform. WooCommerce states that this setting does not send customer or personal data. |
| Job records and evidence | Maintaining work records, progress notes, photographs, certificates, completion records, guarantee history and evidence for disputes or insurance matters. | Legitimate interests; legal obligation; establishment, exercise or defence of legal claims where applicable. |
| Public Recent Work and project portfolio | Selecting, minimising, preparing and publishing approved descriptions and photographs to demonstrate the type and quality of completed work without exposing customer, tenant, exact-address, access, pricing or unnecessary personal information. | Legitimate interests in presenting our services and completed work, balanced against the privacy and other rights of affected individuals; consent or another appropriate basis where identifiable people or private-property details would otherwise be involved. |
| Health and safety | Assessing risks, recording hazards, managing safe access and responding to incidents. | Legal obligation; legitimate interests; an additional special-category condition where relevant. |
| Customer service and complaints | Handling complaints, guarantees, quality reviews, refunds, insurance matters and data-protection requests. | Contract; legal obligation; legitimate interests. |
| Direct marketing | Sending permitted promotional messages and maintaining suppression records. | Consent, the PECR soft opt-in or legitimate interests for permitted corporate business communications. |
| Legal and regulatory matters | Meeting tax, accounting, insurance, data-protection, health and safety, waste and other legal requirements. | Legal obligation; legitimate interests; legal claims where applicable. |
Where we rely on legitimate interests, those interests may include:
- Operating and protecting the business and website.
- Responding to enquiries and administering quotations.
- Managing jobs, access, payments and communications.
- Maintaining appropriate work, verification and transaction records.
- Preventing fraud, false submissions, misuse and security incidents.
- Establishing or defending legal claims.
- Handling complaints, guarantees, debts and insurance matters.
- Improving our services and administration in a proportionate way.
We consider whether those interests are necessary and balanced against the rights and interests of the individuals concerned. Where we rely on consent, you may withdraw it for future processing without affecting processing that was lawful before withdrawal.
6. Special-category and sensitive information
Expand
Please avoid sending health, disability or other sensitive personal information unless it is genuinely necessary.
We may occasionally need limited health or disability information to:
- Make an appropriate reasonable adjustment.
- Arrange safe access or communication.
- Protect an occupier, customer, worker or other person.
- Respond to an emergency or serious safety concern.
Where special-category personal data is processed, we require both an ordinary lawful basis and an additional legal condition. Depending on the circumstances, this may include explicit consent, vital interests in an emergency, a relevant legal obligation or the establishment, exercise or defence of legal claims.
We will limit this information to what is reasonably necessary and restrict access appropriately.
Nifty Fixes North East is a property-maintenance provider. We are not a medical, care or safeguarding service.
7. Direct marketing and your right to object
Expand
Appointment confirmations, quotation correspondence, job updates, invoice communications, guarantee responses and other service-administration messages are not promotional marketing.
Where we send promotional emails or text messages to individuals, we will do so only where:
- Valid consent has been provided; or
- The PECR soft opt-in is lawfully available and properly applied.
We may send relevant business communications to corporate contacts where permitted by law and where our legitimate interests are not overridden by the recipient’s rights.
Every recipient has the right to object to direct marketing at any time.
You can opt out by:
- Using an unsubscribe facility provided in the message.
- Replying and asking us to stop.
- Contacting hello@niftyfixesne.co.uk.
When someone opts out, we may retain a minimal suppression record so that we can continue to honour the request.
8. Who we may share personal data with
Expand
We do not sell personal data.
We may share personal data where reasonably necessary with:
- Website-hosting, content-delivery, security, consent-management and performance providers.
- Email, telephone, SMS, cloud-storage and backup providers.
- Job-management platforms and authorised client portals.
- Payment providers, payment-method providers, card networks, banks, accountants and bookkeeping systems.
- Subcontractors, trades, suppliers and specialists involved in a quotation or job.
- Customers, landlords, agents, property managers and facilities contacts who have instructed or authorised the work.
- Insurers, insurance brokers, accountants, legal advisers, debt-recovery providers and other professional advisers.
- Regulators, courts, law-enforcement bodies, emergency services and government authorities where disclosure is required or justified.
- A purchaser, successor or adviser involved in a genuine proposed sale, restructuring or transfer of the business, subject to appropriate confidentiality and legal controls.
Depending on the service being used, relevant providers may include:
- Rocket.net for managed website hosting.
- Cloudflare for content delivery, traffic routing, website security and related logs.
- WordPress and WooCommerce software operated within our hosted website. Automattic may receive limited WooCommerce telemetry or statistical attribution data only where the corresponding sharing setting is enabled.
- Stripe and PayPal for online payments, fraud prevention, refunds and payment disputes.
- Apple, Google, Klarna, Clearpay, card networks, issuing banks or other selected payment-method providers where that option is offered and chosen.
- Google where reCAPTCHA or a selected Google payment or operational service is used.
- MyJobQuote when a visitor permits the optional live-review panel or follows a link to the MyJobQuote website.
- The Environment Agency and its Data Services Platform when a visitor permits the optional waste-registration panel or follows the public-register link.
- OpenAI, where the optional Job Assistant AI guidance is enabled, for limited API processing of redacted non-contact enquiry text through the approved WordPress AI connector.
- Fixflo, Workever and authorised client portals for job management.
- Xero and HubDoc for accounts and bookkeeping.
- Zoho for email and business communications.
- Love VoIP and other telephone or messaging providers.
- Nextcloud and approved storage or backup services hosted through MassiveGRID.
- WhatsApp or other communication services where you choose to communicate with us through them.
Payments. When you start or complete an online payment, the relevant provider may receive your name, contact or billing information, invoice or order reference, amount, selected payment method, IP address, browser or device information and fraud-prevention signals. Providers may act as our processor for parts of the transaction and as a separate controller for their own legal, regulatory, fraud-prevention, security and service purposes. We normally receive transaction status and identifiers rather than full card details.
WooCommerce and Automattic. The public order-attribution feature remains off until the visitor allows the relevant category. If a consented visit results in an order, attribution details can be stored with the order. Where WooCommerce usage sharing is enabled, WooCommerce states that statistical attribution data may be sent to Automattic on a per-order basis without customer email, billing or shipping data. Administrator usage tracking is separate from the public consent choice and WooCommerce states that it does not include customer or personal data.
MyJobQuote. The live-review panel is withheld until the visitor allows optional external content. Once loaded, the browser connects to MyJobQuote and that provider may receive the visitor’s IP address, browser or device information, referring page and other information needed to deliver and secure the panel. Refusing the panel does not prevent use of the rest of our website.
Environment Agency public register. The waste-registration iframe is withheld until the visitor allows optional external content. Once loaded, the browser connects directly to the Environment Agency Data Services Platform, which may receive the visitor’s IP address, browser or device information, referring page and other information needed to deliver, secure and operate the public-register panel. A direct register link remains available when the panel is refused.
Cloudflare and hosting security. Website requests pass through infrastructure that may process IP addresses, request headers, traffic-routing information, security signals and related logs to deliver the site, prevent abuse and protect availability.
Some recipients act as processors under our instructions. Others, including banks, payment providers, client organisations, selected communication services and external websites, may act as separate controllers under their own privacy notices.
We limit the information shared to what is reasonably necessary for the relevant purpose.
9. International transfers
Expand
Some service providers may store or access personal data outside the United Kingdom or use international support, infrastructure or sub-processors.
Where we initiate a restricted transfer, we assess whether the transfer rules apply, identify an available transfer mechanism and consider whether additional safeguards are needed. Depending on the destination and provider, the mechanism may include:
- UK adequacy regulations.
- The UK International Data Transfer Agreement.
- The UK Addendum to approved standard contractual clauses.
- A permitted exception or another mechanism allowed by UK data-protection law.
Technical, organisational or contractual measures may be used where appropriate. You may contact us for further information about the safeguards relevant to a particular transfer, subject to confidentiality and security restrictions.
10. How long we retain personal data
Expand
We do not keep personal data for longer than reasonably necessary.
Retention depends on the purpose of the record and any legal, accounting, contractual, guarantee, insurance, health and safety or dispute requirements.
| Record | Typical retention approach |
|---|---|
| Protected website enquiry-form copy and optional uploads | Normally up to 90 days after submission under the current form setting. Relevant information may be copied into a quotation, customer or job record if the enquiry proceeds; that resulting record follows the applicable retention period below. |
| General enquiries received through other channels that do not proceed | Usually up to 12 months after the last meaningful contact, unless a shorter period is appropriate or a longer period is reasonably required for a dispute or repeat enquiry. |
| Unsuccessful quotations and estimates | Usually up to 18 months after issue, then deleted or minimised unless needed for legal, insurance or accounting purposes. |
| Pending website review submissions | Up to 90 days while verification and moderation are attempted. Unapproved pending submissions are then deleted automatically. On first publication, the private email and job reference are removed from the website review record. |
| Published reviews and verification record | The chosen public display name, rating, service and review may remain published while relevant. We retain a limited internal verification date and administrator record. Removal, correction or withdrawal requests are considered alongside authenticity, legal claims and the rights of others. |
| Customer job files, reports, certificates and work photographs | Normally retained for approximately seven years after completion, and longer where the nature of the work, a certificate, dispute, insurance issue or legal requirement justifies it. |
| Published Recent Work and project portfolio records | Retained while the record remains accurate, relevant, suitable and approved for public display. Records are reviewed when a project is unpublished, corrected or removed. The underlying job evidence follows the separate customer-job-file retention approach above. |
| Orders, payment records, attribution stored with an order, invoices, accounting and tax records | Normally six years plus the current financial year, or longer where legally required or needed for a payment dispute, chargeback, fraud investigation or legal claim. |
| Complaint, guarantee, insurance and legal records | Retained for the period reasonably necessary to handle the matter and protect the parties’ legal positions. |
| Marketing consent records | Retained for as long as reasonably necessary to demonstrate the consent relied upon. |
| Marketing suppression records | Retained for as long as necessary to honour the opt-out. |
| Cookie preference and consent-event records | The current preference cookie normally lasts 180 days. The minimised backend consent-event record is normally retained for 365 days and then deleted automatically, subject to configured settings and any justified legal need. |
| Short-session order-attribution cookies | Normally for the browser session, with the session counter typically lasting about 30 minutes. If no order is completed, the information is not stored by us as order metadata. |
| Security, rate-limiting and technical logs | Retained for a proportionate period based on security, troubleshooting, abuse prevention and fraud-prevention requirements. Temporary rate-limit identifiers expire automatically. |
We may retain information for longer where:
- A complaint, claim, dispute, payment investigation or regulatory enquiry is ongoing.
- An insurer, regulator, payment provider or court requires it.
- The nature of the work or certificate requires a longer record.
- Deletion would interfere with the establishment, exercise or defence of legal claims.
When information is no longer required, we will delete, anonymise or securely dispose of it as appropriate.
11. Security and confidentiality
Expand
We use proportionate technical and organisational measures designed to protect personal data.
These may include:
- Access controls and user permissions.
- Password and account-management controls.
- Secure cloud platforms.
- Encryption where appropriate.
- Backups and recovery controls.
- Confidentiality requirements.
- Limiting access to people who need the information for their work.
- Security monitoring and system maintenance.
- Appropriate arrangements with service providers.
No internet transmission or storage system is completely secure. However, we take data protection and confidentiality seriously and review our controls proportionately.
If a personal-data breach occurs, we will assess it and notify affected individuals or the ICO where required by law.
12. Your data-protection rights
Expand
Depending on the circumstances, you may have the right to:
- Ask for confirmation that we process your personal data.
- Request access to your personal data.
- Ask us to correct inaccurate or incomplete information.
- Ask us to erase personal data in certain circumstances.
- Ask us to restrict processing in certain circumstances.
- Object to processing based on legitimate interests.
- Object to direct marketing at any time.
- Request portability of certain data where the legal conditions apply.
- Withdraw consent at any time where processing is based on consent.
- Raise concerns about automated decision-making where applicable.
- Complain to us or the ICO.
These rights are not absolute. Legal exemptions may apply, including where information must be retained for legal obligations, accounting, insurance, complaints or legal claims.
To exercise a right, contact hello@niftyfixesne.co.uk.
We may ask for information needed to confirm your identity and understand the request. We will not request more information than is reasonably necessary.
We normally respond without undue delay and within one month. The period may be extended or otherwise adjusted where permitted by law, including for complex requests or where we reasonably require clarification or identity evidence.
13. Automated decision-making
Expand
We do not normally make decisions about whether to provide property-maintenance services that produce legal or similarly significant effects based solely on automated processing.
Website security, anti-bot systems, rate limiting, analytics, consent tools and spam controls may operate automatically. These controls may block or delay a suspicious website request, but they are not normally used to decide whether we will provide the requested property service.
Payment providers, banks and payment-method providers may use automated fraud, identity, credit or risk checks and may decline, hold or require additional authentication for a transaction under their own legal obligations and privacy notices. Where practical, you may contact us to discuss another available payment route, but we cannot override a provider’s legal or security decision.
If we introduce our own solely automated decision-making that has legal or similarly significant effects, we will update this policy and provide the safeguards and information required by law.
13A. Optional AI-assisted Job Assistant and rule-based estimates
Expand
Our website may offer an optional AI-assisted Job Assistant to help a visitor describe proposed property-maintenance work and identify information that may assist our human review. The normal enquiry form remains available without using the AI feature.
When a visitor chooses to use AI guidance, the website sends only minimised, redacted, non-contact text through our approved server-side WordPress AI connector to OpenAI through the configured WordPress AI provider. We do not intentionally send names, email addresses, telephone numbers, exact property addresses, full postcodes, access codes, payment details, health or vulnerability information, identity documents or uploaded photographs to the AI provider. Automated redaction is a safeguard, but visitors should still avoid entering such information in the AI message box.
The AI provider processes the submitted prompt and returns generated text to the website. The provider acts as a processor or sub-processor for this limited operation under the applicable service and data-processing terms. Provider processing may involve international transfers subject to contractual safeguards described in section 9. API data is not intended to be used to train public models by default under the configured business/API service, but limited provider-side retention or security monitoring may apply under the provider’s then-current terms and approved account controls.
The AI response is advisory only. It does not diagnose a defect, decide whether work is accepted, calculate or confirm a price, create a contract or job, take payment, confirm availability or make a booking. A separate deterministic rule engine may check the selected service, customer route, postcode prefix, quantity and relevant structured answers against administrator-approved public estimate rules. The AI provider does not receive or determine the amount.
If one approved rule matches and no mandatory-review flag applies, the website may display a preliminary estimate with its public label, pricing basis, inclusions, exclusions, VAT note, validity date and disclaimer. A short-lived signed token binds that displayed result to the non-contact form inputs for the current submission. If the enquiry is submitted, we retain the verified displayed estimate, rule identifier, rule-set version and associated audit event with the enquiry so that our team can review exactly what the visitor saw. We do not expose internal costs, margins or pricing strategy through this process.
The short AI conversation is not copied into the retained enquiry record. We may retain limited operational metadata, such as whether AI guidance was used, the number of guidance turns, the configured model identifier, character counts, status and request duration, to operate, secure and audit the service. The public AI session and the unsubmitted estimate token are short-lived and expire automatically.
Our purposes are to respond to a visitor’s request, improve the completeness of enquiry information, provide an indicative amount where approved parameters permit, protect the service from misuse and maintain an accountable audit trail. The legal basis will normally be steps requested before entering into a contract, our legitimate interests in handling and securing enquiries, and compliance with legal obligations where applicable. The rule check may determine whether a preliminary amount is displayed, but it does not accept work, bind either party, make a booking or make a decision producing legal or similarly significant effects. A member of our team reviews every submitted enquiry before any scope, suitability, final price, attendance or booking is confirmed.
14. Privacy complaints
Expand
If you are concerned about how we have handled personal data, please contact us at hello@niftyfixesne.co.uk.
Please use the subject line “Data protection complaint” where practical and provide:
- Your name and contact details.
- A description of the concern.
- Relevant dates, references or correspondence.
- The outcome you are seeking.
We will:
- Acknowledge the complaint without undue delay.
- Take reasonable steps to investigate it.
- Keep an appropriate record.
- Provide an outcome or progress update without undue delay.
- Explain any action taken or the reasons for our decision.
We may ask for further information where reasonably necessary to investigate the complaint.
You also have the right to complain to the Information Commissioner’s Office. You do not have to complain to us first, although giving us an opportunity to address the concern may resolve it more quickly.
15. Cookies and similar technologies
Expand
Our website uses cookies and similar storage or access technologies for consent management, security, requested account, cart and payment functionality, optional short-session order attribution and optional external review content.
The optional “Analytics and attribution” category controls WooCommerce order-attribution technologies. The optional “Optional external content” category separately controls the MyJobQuote live-review panel and Environment Agency waste-registration panel. Both are off by default. The managed website does not currently register general public visitor analytics, advertising, remarketing or social-media tracking pixels as active.
Where consent is required, the relevant optional technology is withheld until an affirmative choice is recorded. You can reject optional categories, allow them independently, or later withdraw permission through the persistent “Cookie settings” control.
The backend consent-event record contains a random consent identifier, event, category choices, policy version and timestamps. It intentionally excludes IP addresses, full page URLs and browsing history.
Strictly necessary security, consent, sign-in, requested cart or payment technologies may operate without an optional-category choice where a PECR exception applies. Administrator-only WooCommerce telemetry is not a public visitor cookie category.
Further information, including the current inventory and typical durations, is available in our Cookie Policy.
16. Changes to this policy
Expand
We may update this Privacy Policy to reflect changes to:
- Our services or business operations.
- The website or technology providers.
- Job-management and communication systems.
- Legal or regulatory requirements.
- ICO guidance.
- Our data-protection practices.
The latest published version applies from the last-updated or issue date shown at the top of the page.
Material changes will be brought to people’s attention where reasonably appropriate.