Legal

Privacy Policy

Your privacy matters. Last updated: January 2025 · UK GDPR compliant.

1. Who We Are

WeBraids Ltd is the data controller responsible for your personal data, registered in England and Wales. Our Data Protection Officer can be reached at privacy@webraids.co.uk.

2. What Data We Collect

Directly from you: name, email, phone, profile photo, booking details, home address (for appointments), payment info (processed by our payment provider — we never store full card numbers), and messages.

Braider-specific: proof of identity, right-to-work documents, bank details, professional qualifications.

Automatically: device info, IP, usage data, approximate location (with permission), cookies.

From third parties: identity verification results, payment confirmations, basic profile data from social login providers.

3. How We Use Your Data

  • Provide the Platform and process bookings — contract performance.
  • Verify Braider identity and eligibility — legal obligation / contract.
  • Process payments and payouts — contract performance.
  • Send booking confirmations and notifications — contract performance.
  • Customer support and dispute resolution — legitimate interests.
  • Improve our service — legitimate interests.
  • Marketing — consent (opt-in).
  • Fraud prevention and platform security — legitimate interests / legal obligation.

4. How We Share Your Data

We do not sell your personal data. We share the minimum necessary between Clients and Braiders to fulfil a Booking. We work with trusted service providers (payment processors, identity verification, hosting, analytics) all bound by UK GDPR. We disclose data when legally required.

5. Data Retention

  • Account data: duration of account + 6 years.
  • Booking records: 7 years (financial/legal).
  • Braider verification documents: active registration + 2 years.
  • Marketing data: until consent withdrawn.
  • Support communications: 3 years.

6. Your Rights

Under UK GDPR you have rights of access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making. Exercise any right via privacy@webraids.co.uk — we respond within one month. You may also complain to the ICO at ico.org.uk.

7. Data Security

We use TLS 1.3 in transit, encryption at rest, regular security audits, strict staff access controls, and PCI-DSS compliant payment processing. Breaches that present a risk to your rights will be notified to you and the ICO.

8. International Transfers

Data is primarily stored within the UK and EEA. Any transfers outside use ICO-approved standard contractual clauses.

9. Changes to This Policy

Material updates will be notified by email or in-app. The “Last updated” date reflects the latest version.

10. Contact & Complaints

Data Protection Officer — WeBraids Ltd

Email: privacy@webraids.co.uk

Phone: 07771 106429

ICO: ico.org.uk · 0303 123 1113