GDPR Policy

Last updated: October 22, 2025

This GDPR Policy explains how Paint and Smart Repairs Limited (“we”, “us”, or “our”) collects, uses, and protects personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

We are committed to protecting the privacy and security of our customers, suppliers, and website users.


1. Company Information

Paint and Smart Repairs Limited
Company number: 16432726
Registered address: 187 Brent Crescent, NW10 7XR, London, United Kingdom
Email: info@psrteam.co.uk
Website: www.psrteam.co.uk

We are the Data Controller responsible for your personal information collected through our Website and business operations.


2. Principles of Data Protection

We comply with the principles of data protection set out in the UK GDPR by ensuring that personal data is:

  1. Processed lawfully, fairly, and transparently

  2. Collected for specified, explicit, and legitimate purposes

  3. Adequate, relevant, and limited to what is necessary

  4. Accurate and kept up to date

  5. Stored only as long as necessary

  6. Processed securely to protect against unauthorised or unlawful processing, loss, destruction, or damage


3. Lawful Basis for Processing Personal Data

We process personal data under one or more of the following lawful bases:

  • Consent – when you have given clear consent for us to process your personal data.

  • Contract – when processing is necessary for the performance of a contract or to take steps before entering into one.

  • Legal obligation – when we must comply with the law.

  • Legitimate interests – when processing is necessary for our legitimate business interests and does not override your rights and freedoms.


4. Types of Personal Data We Collect

We may collect and process the following categories of data:

  • Identity Data: name, title, contact details

  • Contact Data: address, email, telephone number

  • Service Data: details related to vehicle repairs, quotes, or bookings

  • Technical Data: IP address, browser type, device information, and usage data

  • Marketing Data: your preferences regarding marketing communications


5. How We Use Your Data

We use your personal data for purposes including:

  • Responding to enquiries and providing our services

  • Processing bookings, quotes, and payments

  • Managing customer relationships

  • Improving our Website and services

  • Sending relevant updates or marketing (with consent)

  • Complying with legal or regulatory obligations


6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected or as required by law.
After this period, personal data will be securely deleted or anonymised.


7. Data Sharing and Transfers

We do not sell or rent personal data.
We may share data with trusted third parties who assist us in running our business (e.g., hosting providers, analytics tools, IT support), but only when:

  • They have agreed to keep your data secure and confidential; and

  • They only process it under our instructions.

We do not transfer personal data outside the UK unless adequate safeguards are in place to protect your information.


8. Data Security

We implement appropriate technical and organisational measures to secure your personal data against unauthorised access, alteration, disclosure, or destruction.

This includes encryption, secure servers, restricted access, and staff training on data protection.


9. Your Data Protection Rights

You have the following rights under the UK GDPR:

  • Right of access – request a copy of your personal data we hold

  • Right to rectification – correct inaccurate or incomplete data

  • Right to erasure – request deletion of your data where applicable

  • Right to restrict processing – limit how we use your data

  • Right to object – object to certain types of processing

  • Right to data portability – request transfer of your data to another controller

  • Right to withdraw consent – withdraw consent at any time for processing based on consent

To exercise these rights, please contact us at info@psrteam.co.uk.


10. Data Breach Procedure

In the event of a data breach, we will:

  1. Assess the severity and potential risk to individuals.

  2. Notify the Information Commissioner’s Office (ICO) within 72 hours if required.

  3. Inform affected individuals if the breach poses a high risk to their rights and freedoms.

  4. Document all breaches and remedial actions taken.


11. Children’s Privacy

We do not knowingly collect personal data from anyone under the age of 16.
If you believe that a child has provided us with personal information, please contact us so we can delete it promptly.


12. Changes to This GDPR Policy

We may update this GDPR Policy periodically to reflect changes in legal requirements or our practices.
The latest version will always be available on this page with the updated “Last updated” date.


13. Contact Information

If you have any questions, concerns, or complaints about how we handle your personal data, please contact:

📧 info@psrteam.co.uk
🏢 Paint and Smart Repairs Limited, 187 Brent Crescent, NW10 7XR, London, United Kingdom

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection:
https://ico.org.uk