PHPerfect HandsCleaning ServicesBack to website

Private trial using training data. These pages describe the commercial service terms; submitting a request here does not place a real booking with the Company.

Your data and your rights

Customer Privacy Policy

The data we retain, how we use it, who can access it and your rights regarding it.

Version 1.0 · Published 13 September 2026 (UAE time)Abu Dhabi, United Arab EmiratesFor booking requests submitted after publication. No retrospective change to previously confirmed bookings.
Terms and ConditionsCancellation, Rescheduling and RefundsPrivacy

On this page

1. Who is responsible for the data2. Data we collect3. How we receive data and where it is stored4. Why we process data5. Grounds for processing and consent6. Who can access the data7. Processing outside the United Arab Emirates8. How long data is retained9. Data security and incidents10. Individual data rights11. Required and optional information12. Cookies and browser storage13. Children and information about other people14. Policy updates and contact details

1. Who is responsible for the data

This policy explains how PERFECT HANDS CLEANING SERVICES handles the data of customers and people submitting booking requests. Our business details and address are set out in the Terms and Conditions. Privacy enquiries may be sent through WhatsApp 0547936669 or to perfecthands.business@gmail.com.

The policy covers the website form, bookings entered by an employee following contact with a customer, service-related correspondence, invoices, payment collection, attachments and support requests. Its scope is limited to customers and people submitting requests; employee data is handled through the establishment’s employment procedures.

2. Data we collect

We may collect the customer’s name, telephone number and communication language; the property type, villa, apartment or office number, area, address and location link provided by the customer; and access notes and instructions needed to perform the service.

We retain booking-request details, appointment time, duration, number of cleaners, named or automatic assignment, requested materials, confirmation status, changes and cancellations, service-performance records, and correspondence or notes needed to manage the request and complaints.

We process invoice data, amounts due, collected and outstanding, the payment method, optional tips, and notes and proof of transfer or payment submitted as an image or file. We may collect technical data needed to operate and protect the website, such as access, error and connection logs, depending on the settings of the services used.

The booking form does not request full card numbers, card security codes, passwords or banking verification codes. Please conceal unnecessary financial information in any receipt before sending it. Do not attach identity documents, health information or other people’s data unless there is a clear need and an appropriate procedure.

3. How we receive data and where it is stored

When a booking request is submitted through the website, the data is stored in the system’s database for review and follow-up. An employee may add information received from the customer through WhatsApp, by telephone or during the service. Submitted attachments are held in the system’s designated storage and linked to the relevant record.

We use technical services for hosting, databases, file storage and communication. Correspondence through WhatsApp is also subject to its provider’s terms and privacy policy. Using WhatsApp does not mean that booking data remains only in the conversation; information needed for the service is transferred into our records.

4. Why we process data

We use data to review requests, check service scope and availability, communicate about requests, confirm appointments, assign work and send necessary instructions to the team, perform services and document changes, issue invoices, verify payments, and follow up outstanding amounts and refunds.

We also use necessary data to handle complaints and claims, maintain financial records and meet applicable obligations, protect the system, monitor unauthorised access, correct errors and improve service operations. Notes and attachments are not used for purposes unrelated to these needs without an appropriate basis and any required notice.

5. Grounds for processing and consent

We process data when it is necessary to take the steps requested for a booking and perform the agreement with the customer, comply with an applicable legal obligation, or establish or defend claims and rights where permitted by law. We request appropriate consent when consent is the required basis for the processing concerned.

Reading the Privacy Policy does not give unrestricted consent to every use or to marketing. Booking data is not used for promotional campaigns under this policy. Any future optional marketing service requires a review of its specific rules, a notice and a separate subscription mechanism where permitted. General agreement to a booking is not assumed to authorise marketing. Consent to optional processing based on consent may be withdrawn, without affecting earlier lawful processing or data that must be retained on another basis.

6. Who can access the data

The owner and authorised employees, including those coordinating bookings, drivers, finance and customer service, access the data needed for their duties according to their assigned permissions. A cleaner’s account shows her confirmed appointments for today and tomorrow, but does not show the customer’s name, telephone number or address. Necessary service instructions may be passed to her by the person coordinating the service without disclosing unnecessary information.

Hosting, storage, support, communication and payment providers may process data needed for the services they provide under the applicable arrangements. Appropriate disclosure may be made to competent authorities or advisers where an obligation or legitimate need permitted by law exists. We do not sell customer data or share it with independent advertising organisations.

7. Processing outside the United Arab Emirates

We use hosting, application operation, database and file-storage providers, including Cloudflare, together with WhatsApp for communication and Google’s Gmail for email. These services may involve processing outside the UAE, including in the United States and other countries where the providers’ infrastructure or support teams operate, depending on the service and settings. The establishment or customer being in the UAE does not mean that all data is processed there.

The hosting plan adopted for this version includes allocating Cloudflare databases and attachments to the European Union, with backups and a financial archive in Amazon Web Services’ UAE region. These arrangements are planned; this policy alone does not establish that they are active. The storage-location statement will be updated after activation and verification and before data is received on that basis. Restricting the storage location alone does not prevent some request, connection and security data from being processed through a provider’s global infrastructure. Before any transfer subject to international-transfer rules, we document its legally permitted basis and the required safeguards, including appropriate agreements, access restrictions, encryption and a review of processors. General consent to use the website is not unrestricted permission for international transfers.

8. How long data is retained

Implementation status in this trial: the retention periods below are the adopted policy for commercial operations. Not all scheduled deletion mechanisms or the 35-day independent backup cycle have yet been activated or tested. Your agreement does not mean these procedures are operating automatically now. We will complete their setup and verification before operating the commercial service on this basis. You may contact us to request a review of your data, what can be deleted, what must be retained and why.

The establishment has adopted a policy of archiving financial records, invoices and necessary supporting data for seven years after the end of the relevant financial period, documenting the obligation or legitimate purpose that justifies retaining each category. The archive policy alone does not justify keeping unnecessary additional personal information. At the end of that period, the data is deleted or anonymised, except to the extent that an applicable obligation or an ongoing claim requires longer retention. This is not an automatic retention period for every item of personal information or every conversation.

Under the adopted retention plan, requests closed without becoming bookings are retained for 90 days from closure, while correspondence and notes unrelated to a financial record or claim are retained for one year from closure of the matter. Technical logs are retained for no more than 90 days from creation, according to security and operational needs. When the period expires, data is deleted or anonymised so that it can no longer be attributed to the individual. These are organisational periods adopted by the establishment, not a single statutory limit for all these categories. If part of the data becomes necessary for an invoice, dispute or obligation, the necessary part is separated and retained for the justified purpose and period without automatically extending retention of the remaining data.

Some data may not be deleted because a legal obligation or claim justifies keeping it; its use is restricted to the purpose that justifies retention. The operational backup plan sets a rolling cycle of no more than 35 days from creation of each backup. Once activated, data deleted from the active system may remain in an earlier backup until its cycle ends. Access is restricted to restoration, and previous deletion requests are reapplied before restored data is returned to use. The necessary financial archive is separate and follows the seven-year period described above. Backups do not justify indefinite retention. The individual will be told what can be deleted, what must be retained and why.

9. Data security and incidents

We take administrative and technical measures appropriate to the nature of the data, including managing permissions, protecting access, monitoring records and handling attachments carefully. These measures are reviewed according to the risks and actual operating arrangements.

If a data incident occurs, it is assessed and steps are taken to contain and address it and notify the people or authorities who must be notified under the applicable requirements. Complete absence of risk cannot be guaranteed. This statement is not intended to release us from our data-protection duties.

10. Individual data rights

Within the limits and circumstances provided by law, a customer may request information about their data, its purposes and the recipients with whom it is shared; access a copy; correct inaccurate information or complete missing information; request deletion or restriction of processing or object to processing; request portability where that right applies; withdraw consent for processing based on consent; and request human review of an automated decision affecting them where that right applies.

Requests may be submitted through the contact details in this policy. We may verify the requester’s identity in a manner proportionate to the data requested, without asking for excessive information. If a request cannot be fulfilled in whole or in part because of an applicable obligation or exception, we explain the reason, what can be done, and the available way to object or complain to the competent authority.

11. Required and optional information

We need sufficient contact details, an address and service details to fulfil a booking. A request may not be accepted if the customer does not provide them or they are incorrect. The form identifies required fields. Additional notes and payment evidence requested on an optional basis are not used to seek unnecessary details.

A customer who cannot provide an attachment may ask about an appropriate alternative for verifying payment. An optional attachment does not mean that payment is accepted as received without verification.

12. Cookies and browser storage

The system uses cookies or browser storage for operational purposes, such as signing in, protecting sessions and remembering the selected language. Based on the current settings, the website does not currently use advertising-tracking tools.

If non-essential analytics or advertising-tracking tools are added in future, the policy, notices and any required consent or refusal options will be updated before they are used. Disabling some essential tools in the browser may affect sign-in or website functions.

13. Children and information about other people

Booking is intended for people aged 18 or over, and the website does not intentionally request data directly from children. Please do not include children’s names or information in booking notes. If a precaution is needed because children are present at the property, the necessary safety instructions are sufficient.

If the customer provides details of a person authorised to receive the team, the customer must explain why those details are being provided and ensure they are authorised to share them, limiting the information to what is needed for coordination.

14. Policy updates and contact details

The policy is updated when practices or applicable requirements change, and the effective date and version number are displayed. Material changes are communicated appropriately, and fresh consent is requested when required. An update alone is not used to authorise an earlier unlawful use.

For requests and enquiries, contact WhatsApp 0547936669 or perfecthands.business@gmail.com, or write to: Abu Dhabi, Al Danah, East 5, Afraa Mohammed Masoud Building, United Arab Emirates.

Have a question?

Customer service, complaints and privacy requests.

perfecthands.business@gmail.com
Call now+971547936669WhatsApp
PHPerfect HandsCleaning Services

PERFECT HANDS CLEANING SERVICES — Sole establishment

Back to website