Privacy Policy - Removals Italy
This Privacy Policy explains how Removals Italy collects, uses, stores, shares, and protects personal data in connection with its moving, removals, packing, storage, and related services. It applies to all Removals Italy customers in area, including individuals, households, and business customers who use our services within the service area. We are committed to handling personal data in a lawful, fair, transparent, and secure manner in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.
1. Who We Are
For the purposes of data protection law, Removals Italy acts as the data controller for the personal data we collect and process for the delivery of our services, administration of customer relationships, and compliance with legal obligations. In some situations, we may also act as a data processor where we process data on behalf of a business customer or another controller under agreed instructions. This Policy applies to personal data collected through enquiries, quotations, bookings, service delivery, billing, communications, and related operational activities.
2. Personal Data We Collect
We collect only data that is relevant and necessary for the services we provide, or where we are required to do so by law. The types of personal data we may collect include:
- Identity data: name, title, and in some cases company name or job role.
- Contact data: email address, telephone number, service address, billing address, and correspondence details.
- Service and booking data: moving dates, property access details, inventory lists, floor plans, special handling requirements, and service preferences.
- Payment and transaction data: payment status, invoices, bank details where needed for refunds or payments, and records of transactions.
- Communication data: records of calls, emails, messages, complaints, and feedback.
- Technical data: limited device, browser, and usage information if collected through our digital systems.
- Special category data: generally not requested; however, if voluntarily provided and necessary to support access, safety, or health-related moving needs, we will process it only where a lawful basis exists and with appropriate safeguards.
We do not intentionally collect more information than is necessary. Where we are provided with data about third parties, such as family members, tenants, landlords, or building managers, the customer must ensure that such individuals have been informed about the disclosure and that it is lawful to share their information with us.
3. How We Use Personal Data
We use personal data for the following purposes:
- to provide quotations and assess service requirements;
- to schedule, plan, and carry out removal or relocation services;
- to communicate with customers before, during, and after the service;
- to manage accounts, invoices, payments, and refunds;
- to maintain records of services, instructions, and preferences;
- to handle complaints, claims, and customer support requests;
- to comply with legal, tax, accounting, and regulatory obligations;
- to improve our operations, service quality, safety, and customer experience;
- to establish, exercise, or defend legal claims where necessary.
We will only process data in ways that are compatible with the purposes for which it was collected, unless we have a valid legal basis and the new use is consistent with GDPR requirements.
4. Lawful Basis for Processing
We rely on the following lawful bases under GDPR, depending on the nature of the processing activity:
- Performance of a contract: where processing is necessary to provide quotations, manage bookings, deliver moving services, issue invoices, and complete contractual obligations.
- Legitimate interests: where processing is necessary for our legitimate business interests, such as improving services, preventing fraud, managing operations, protecting property, and resolving disputes, provided those interests do not override your rights and freedoms.
- Legal obligation: where we must process data to comply with tax, accounting, transport, health and safety, or other legal requirements.
- Consent: where we rely on your consent for specific optional activities, such as certain marketing communications or the processing of particular information you choose to provide.
Where consent is used as the lawful basis, you have the right to withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
5. Sharing Personal Data and Processors
We may share personal data with trusted third parties only when necessary for the purposes described in this Policy and subject to appropriate confidentiality and security obligations. These third parties may act as processors or independent controllers depending on the service they provide.
Typical processors and recipients may include:
- IT and cloud service providers that host systems or store data;
- accounting, invoicing, and payment processing providers;
- professional advisers such as lawyers, auditors, and insurers;
- subcontracted movers, storage providers, or logistics partners assisting with service delivery;
- regulatory bodies, public authorities, or law enforcement where required by law;
- complaint handling, claims, or dispute resolution service providers.
All processors are selected carefully and are required to process personal data only on our instructions, implement appropriate security measures, and comply with GDPR obligations. We do not sell personal data. If personal data is transferred outside the European Economic Area, we will ensure that appropriate safeguards are in place, such as an adequacy decision or standard contractual clauses, where required.
6. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including to meet legal, accounting, insurance, or reporting requirements. Retention periods vary depending on the type of information and the context in which it is processed.
In general:
- customer and service records are retained for the duration of the customer relationship and for a reasonable period afterwards;
- financial and accounting records are retained for the period required by applicable law;
- complaint, claim, and dispute records are retained until the matter is resolved and for any further period needed to defend legal claims;
- consent-based marketing records are retained until consent is withdrawn or the data becomes outdated;
- technical logs are kept for a limited period for security, maintenance, and troubleshooting.
When data is no longer needed, we will delete it securely or anonymise it so that it can no longer identify you.
7. Data Security
We take reasonable technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration, or disclosure. These measures may include access controls, encryption where appropriate, secure storage, staff confidentiality obligations, and regular review of our information handling practices. While we work to protect your data, no system can be guaranteed as completely secure.
8. Your Rights Under GDPR
You have a number of rights in relation to your personal data. Subject to legal limitations, these include:
- Right of access: to request confirmation of whether we process your data and to obtain a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete information.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to ask us to limit how we use your data in certain situations.
- Right to data portability: to receive certain data in a structured, commonly used format and transfer it where applicable.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent.
- Right to complain: to a supervisory authority if you believe your data has been mishandled.
To protect privacy, we may need to verify your identity before responding to a request. We will respond within the time limits required by GDPR.
9. Children???s Data
Our services are primarily intended for adults. We do not knowingly collect personal data from children unless it is necessary for the performance of a service and provided by an adult customer with the proper authority. If we learn that we have collected data inappropriately, we will take steps to delete it or seek the necessary permissions where legally possible.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, our services, or our processing practices. The updated version will apply from the date it is published or otherwise communicated. We encourage customers to review this Policy periodically so they remain informed about how personal data is handled.
11. Fair Processing Commitment
Removals Italy is committed to handling personal data in a transparent, lawful, and responsible manner. We aim to collect the minimum data necessary, use it only for clear and legitimate purposes, retain it only as long as needed, and respect all user rights under GDPR. By using our services, customers within our area can expect their data to be treated with care, security, and respect.