Privacy notice
This notice explains what personal data the company collects through this website and by email or telephone, what it does with it, and the rights you have under the UK GDPR and the Data Protection Act 2018.
Last updated: 2 October 2026
Who is responsible for your data
The data controller is the company named below. "Controller" is the term the UK GDPR uses for the organisation that decides how and why personal data is used.
- Registered name
- LK BUILDING SERVICES LTD
- Company number
- 11771921
- Registered office
- C/O Burton Varley Ltd The Counting House 24 Richmond Road, Bowdon, Altrincham, England, WA14 2TT
- Contact for data protection
- (to be completed)
Cookies and tracking
This website sets no cookies. It contains no analytics, no advertising tags, no social media pixels and no third-party embeds. Nothing is stored on your device by this site and your visit is not profiled.
Because nothing but strictly necessary technical processing takes place, no consent banner is required under the Privacy and Electronic Communications Regulations 2003. If analytics or embedded content were ever added, this notice would be updated and consent sought first.
What data we collect, and why
We only hold what you choose to send us, plus the technical records our host keeps automatically.
- Enquiries: if you email or telephone us, we hold your name, your contact details and whatever you tell us about what you need. The lawful basis is legitimate interests (UK GDPR Article 6(1)(f)): we cannot answer an enquiry without keeping it long enough to reply.
- Quotes and work: if we quote for or carry out work, we hold the records needed to do the job and to invoice it. The lawful basis is performance of a contract (Article 6(1)(b)), and legal obligation (Article 6(1)(c)) for the accounting records we must keep.
- Server logs: our host records the IP address and basic technical details of requests to the site, as part of operating and securing it. We do not use these logs to identify visitors.
Data we do not want
Please do not send us health information, information about your beliefs, or other special category data under Article 9 of the UK GDPR unless we have specifically asked for it and explained why. If you send it anyway, we will delete it once we have dealt with your enquiry.
Who we share it with
We do not sell personal data, and we do not share it for marketing. It is shared only where it is needed to run the business:
- Our hosting provider, GitHub, Inc., which serves the pages of this site and keeps the technical logs described above.
- Our email provider, which transmits and stores messages you send us.
- Our accountant and HM Revenue & Customs, for invoices and accounting records.
- Professional advisers, insurers or a court, where we are required or legally entitled to disclose something.
Transfers outside the UK
Our hosting provider is based in the United States, so technical data about requests to this site is processed there. Transfers of that kind are covered by the safeguards the UK GDPR requires, such as the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, together with the UK extension to the EU-US Data Privacy Framework where the provider participates in it.
How long we keep it
- Enquiries that do not lead to work: up to twelve months, then deleted.
- Quotes, contracts and job records: six years after the work ends, matching the limitation period for contract claims under the Limitation Act 1980.
- Accounting records and invoices: six years after the end of the accounting period, as required by HM Revenue & Customs and the Companies Act 2006.
- Server logs: for the period our host retains them, which is short and set by the host.
How it is kept safe
This site is served over HTTPS. Access to email and business records is limited to the people who need it, and devices are protected by passwords and device encryption. No system is perfectly secure, but we take the care the UK GDPR requires, and we would tell you and the ICO about a breach that put your rights at risk, within 72 hours where the law requires it.
Your rights
Under the UK GDPR you have the right to:
- be told what we hold about you and get a copy of it (a subject access request);
- have inaccurate data corrected;
- have data erased, where we no longer have a reason to keep it;
- restrict how we use it while a dispute about it is resolved;
- object to processing we carry out on the basis of legitimate interests;
- receive data you gave us in a portable form, where that right applies;
- withdraw consent at any time, where we relied on consent.
To exercise any of these, contact us using the details on the contact page.
How we handle a request
We respond within one month. If a request is complex we may extend that by a further two months, and we will tell you if so. There is no charge, unless a request is excessive or repetitive. We may need to confirm who you are before releasing personal data.
Automated decisions and profiling
We do not make decisions about you by automated means, and we do not profile visitors to this site.
Complaining to the regulator
If you are unhappy with how we have handled your personal data, please tell us first so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office, the UK data protection regulator, at any time. Complaining to the ICO is free.
- Information Commissioner’s Office
- Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Helpline
- 0303 123 1113
Changes to this notice
If what we do with personal data changes, we update this page and change the date at the top. Material changes affecting people we already hold data about will be notified to them directly.