Legal
Privacy Policy
Your privacy matters. Last updated: January 2025 · UK GDPR compliant.
1. Who We Are
WeBraids Ltd is the data controller responsible for your personal data, registered in England and Wales. Our Data Protection Officer can be reached at privacy@webraids.co.uk.
2. What Data We Collect
Directly from you: name, email, phone, profile photo, booking details, home address (for appointments), payment info (processed by our payment provider — we never store full card numbers), and messages.
Braider-specific: proof of identity, right-to-work documents, bank details, professional qualifications.
Automatically: device info, IP, usage data, approximate location (with permission), cookies.
From third parties: identity verification results, payment confirmations, basic profile data from social login providers.
3. How We Use Your Data
- Provide the Platform and process bookings — contract performance.
- Verify Braider identity and eligibility — legal obligation / contract.
- Process payments and payouts — contract performance.
- Send booking confirmations and notifications — contract performance.
- Customer support and dispute resolution — legitimate interests.
- Improve our service — legitimate interests.
- Marketing — consent (opt-in).
- Fraud prevention and platform security — legitimate interests / legal obligation.
4. How We Share Your Data
We do not sell your personal data. We share the minimum necessary between Clients and Braiders to fulfil a Booking. We work with trusted service providers (payment processors, identity verification, hosting, analytics) all bound by UK GDPR. We disclose data when legally required.
5. Data Retention
- Account data: duration of account + 6 years.
- Booking records: 7 years (financial/legal).
- Braider verification documents: active registration + 2 years.
- Marketing data: until consent withdrawn.
- Support communications: 3 years.
6. Your Rights
Under UK GDPR you have rights of access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making. Exercise any right via privacy@webraids.co.uk — we respond within one month. You may also complain to the ICO at ico.org.uk.
7. Data Security
We use TLS 1.3 in transit, encryption at rest, regular security audits, strict staff access controls, and PCI-DSS compliant payment processing. Breaches that present a risk to your rights will be notified to you and the ICO.
8. International Transfers
Data is primarily stored within the UK and EEA. Any transfers outside use ICO-approved standard contractual clauses.
9. Changes to This Policy
Material updates will be notified by email or in-app. The “Last updated” date reflects the latest version.
10. Contact & Complaints
Data Protection Officer — WeBraids Ltd
Email: privacy@webraids.co.uk
Phone: 07771 106429
ICO: ico.org.uk · 0303 123 1113