Privacy policy.
Last updated: 2nd December 2025
1. Who we are
Website / Business Name: Xpress Heating
Website URL: https://www.xpressheating.com
Contact:
If you have any questions about this Privacy Policy or our data practices, you can contact us at: info@xpressheating.com.
If you have appointed a Data Protection Officer (DPO), or other privacy contact, you should also include their name and contact details here.
This Privacy Policy applies to all visitors and users of xpressheating.com (whether or not you become a client or provide services), including customers, prospective customers, and other contacts.
2. What Personal Data We Collect
2.1 Data You Provide Directly
We may collect personal information that you voluntarily provide when you:
fill in contact or enquiry forms on the website
request a quote or book services
sign up for newsletters or updates (if applicable)
otherwise contact us (phone, email, message).
Typical personal data we collect may include:
name
email address
phone number
address / property address (if relevant for heating/installation work).
any other information you choose to provide (e.g. notes about your heating system, property specifics).
2.2 Data Collected Automatically
When you visit our website, we may automatically collect certain information about your visit, such as:
IP address
browser type and version
device type and operating system
pages visited and time spent on the site
referral URL, date/time of visit
cookies or similar tracking technologies
2.3 Data from Third-Party Sources
We may receive information from third-party services we use (e.g., analytics, marketing, hosting, or other service providers) if you interact with those services (for example, if you accept cookies, or otherwise allow third-party integrations).
3. Why We Collect Your Data — Our Purposes & Lawful Basis
We process personal data for the following purposes, under the lawful bases set out in the UK data protection law (e.g. UK GDPR / Data Protection Act 2018): ICO+2Sprintlaw UK+2
PurposeLawful Basis / JustificationTo respond to your enquiries and communicate with you (quotes, bookings, support). Contractual necessity or legitimate interest — to provide the service you requestTo operate and maintain our website, improve usability and user experienceLegitimate interest (site maintenance, analytics). To send optional newsletters, updates, or marketing (only if you consent). Consent (if you opt-in). To comply with legal obligations or record-keeping requirements (e.g. invoices, services provided). Legal obligation / contract performanceTo protect against fraud, misuse, or security issuesLegitimate interest (security).
If we ever process “special categories” of personal data (sensitive data) or do anything more advanced (profiling, automated decision-making), we will update this policy and inform you accordingly.
4. Use of Cookies and Tracking Technologies
We use cookies and similar technologies to:
remember your preferences and improve site experience.
understand how users navigate our website (analytics) and improve our services.
manage any required functionality (e.g. forms).
Where cookies are not strictly necessary (e.g. for analytics or marketing), we will request your consent before using them — in line with Privacy and Electronic Communications Regulations 2003 (PECR) and UK GDPR guidance. ICO+2cy.ico.org.uk+2
If you prefer, you can manage or block cookies using your browser settings.
5. Sharing Your Data
We will not sell or rent your personal data. We may share your data with:
service providers and processors who help us run the website (hosting, email, analytics, etc.).
contractors or partners if you request services requiring them (e.g. installers, subcontractors) — only where necessary to fulfil the service.
legal or regulatory authorities if required (e.g. to comply with a legal obligation or protect rights).
Where we share data with third parties, we require them to maintain appropriate protections and only use the data for the purposes we specify.
6. Data Retention
We will retain your personal data only for as long as necessary to fulfil the purposes for which it was collected (e.g. until the service is complete, or until we no longer need to contact you), or as required by law (e.g. for accounting, tax, warranty, or legal obligations).
If we don’t have a specific retention period, the criteria used to determine retention will be made available on request (e.g. data no longer needed for service delivery, or after a reasonable period of inactivity).
7. Your Rights
Under UK GDPR, you have the following rights regarding your personal data: ICO+1
Right to access: ask what data we hold about you, why, and how it is used.
Right to correct or update inaccurate information.
Right to request erasure (delete your data), subject to certain conditions.
Right to restrict or object to processing (in certain circumstances).
Right to data portability (receive your data in a portable format).
Right to withdraw your consent (where processing is based on consent) at any time.
Right to lodge a complaint with the relevant supervisory authority if you believe data is mishandled.
To exercise any of these rights, contact us at the email above.
If you are in the UK, you also have the right to complain to the Information Commissioner's Office (ICO). ICO+1
8. International Transfers
If we transfer your personal data outside the UK (or to countries outside the UK), we will only do so where there are appropriate safeguards in place (e.g. standard data-protection clauses, adequacy decisions, or other lawful mechanisms).
If this applies, we will notify you and let you know how you can obtain a copy of those safeguards.
9. Third-Party Links and External Services
Our website may link to third-party websites or use third-party services (for example, social media, analytics, payment providers, etc.). These external sites and services have their own privacy policies and data practices.
We are not responsible for the content or privacy practices of those third parties. We encourage you to review their policies before providing personal data.
10. Children’s Privacy
We do not knowingly collect personal data from children under the age of 13 (or the applicable age of consent in your jurisdiction). If you believe we have collected data from a child without consent, please contact us — we will promptly delete the data.
11. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or technology.
When we make changes, we will revise the “Last updated” date at the top of this page and make the updated version available on our website.
We encourage you to review this Privacy Policy periodically.
12. Contact Us
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us:
Email: info@xpressheating.com
Website: https://www.xpressheating.com
You may also have the right to contact the Information Commissioner’s Office (ICO) if you believe your data protection rights have been violated.

