Legal
Privacy Policy
This policy explains what personal data Clean Bee collects, why we collect it, how we protect it and what rights you have under the EU General Data Protection Regulation (GDPR) and Cyprus data protection law.
Last updated: [INSERT DATE OF PUBLICATION]
1. Who we are
Clean Bee LTD (“Clean Bee”, “we”, “us”) provides cleaning and property care services in Paphos, Cyprus and surrounding areas. We are the data controller for the personal data described in this policy.
- Trading name: Clean Bee
- Registered legal entity name: [INSERT REGISTERED LEGAL ENTITY NAME]
- Registered address: [INSERT REGISTERED COMPANY ADDRESS]
- Company registration number: [INSERT COMPANY REGISTRATION NUMBER]
- Contact address: Apostolou Pavlou Avenue 7, Paphos, 8046
- Privacy contact: info@cleanbeecy.com (a dedicated privacy address can be configured: [INSERT PRIVACY EMAIL ADDRESS])
- Telephone: 26 911 180
2. The data we collect
We only collect what we genuinely need to provide our services.
When you book a clean or request a quote
- Name, email address and telephone number
- Service address, postal code, access and parking notes (where a visit is needed)
- Requested date and time, property details and the answers you give in the form
- Any notes or special instructions you choose to send us
- Service, pricing and payment status information for your job
When you contact us
- Name, email address, optional telephone number, subject and your message
Automatically
- Technical data needed to serve and secure the website (for example IP address in server logs).
- Anonymous usage statistics through Google Analytics 4 — only if you consent to analytics cookies. We never send your name, email, phone number, address, booking notes or booking answers to analytics.
We do not knowingly collect special category data (such as health data) and we do not ask for payment card details through this website.
3. Why we use your data and our legal basis
- To perform our contract with you — arranging, scheduling, delivering and invoicing your cleaning service, and contacting you about your booking.
- Legitimate interests — running and improving our business, keeping records of jobs and quotes, preventing fraud and abuse, and securing our systems.
- Consent — optional analytics cookies and, where offered, marketing messages. You can withdraw consent at any time.
- Legal obligation — keeping accounting and tax records as required by Cyprus law.
You never have to accept marketing to make a booking. Marketing consent, where offered, is always separate and optional.
4. Who can see your data
- Clean Bee staff, only to the extent needed for their role. Cleaning teams see the job information required to carry out the service.
- Clean Bee administrators, who manage bookings, customers, quotes and pricing.
- Our service providers acting as processors on our instructions (see “Service providers” below).
- Authorities or advisers where we are legally required to disclose information.
We do not sell your personal data and we do not publish customer information anywhere on the public website.
5. Service providers
The website and business systems are operated using the providers listed below. Details marked for confirmation must be completed by Clean Bee before publication.
- Application hosting — Lovable Cloud hosting infrastructure. Purpose: serving this website and its server functions. Processing location and transfer safeguards: [INSERT HOSTING PROVIDER DETAILS / DPA REFERENCE].
- Database, authentication and file storage — Supabase (provided through Lovable Cloud). Purpose: storing bookings, customers, quotes, enquiries, staff accounts and uploaded media. Processing location and transfer safeguards: [INSERT DATABASE REGION / DPA REFERENCE].
- Google Analytics 4 — Google Ireland Limited / Google LLC. Purpose: anonymous website statistics. Only active with your consent. Involves an international transfer to the United States under Google’s standard terms: [CONFIRM GOOGLE ADS DATA PROCESSING TERMS ACCEPTED].
- Google Search Console — used for search-performance reporting; does not receive customer personal data.
- Payments — no online payment provider is currently connected to this website. Payment is arranged directly with you. If a provider is added: [INSERT PAYMENT PROVIDER AND DPA REFERENCE].
- Email — [INSERT EMAIL PROVIDER USED FOR CUSTOMER CORRESPONDENCE].
- Other processors — [INSERT ANY ADDITIONAL PROCESSORS, e.g. accounting software].
6. International transfers
Some providers may process data outside the European Economic Area. Where that happens we rely on the safeguards offered by the provider, such as the European Commission’s standard contractual clauses. Confirmed arrangements: [INSERT INTERNATIONAL TRANSFER ARRANGEMENTS].
7. How long we keep your data
We keep personal data only for as long as necessary for the purpose it was collected for, and for as long as we are legally required to keep records.
- Booking, quote and customer records: [INSERT RETENTION PERIOD]
- Website enquiries and messages: [INSERT RETENTION PERIOD]
- Accounting and invoicing records: retained for the period required by Cyprus tax law — [INSERT CONFIRMED PERIOD]
- Cookie consent record: stored in your browser until you clear it or change it
Retention periods must be confirmed by Clean Bee; we do not delete records where the law requires us to keep them.
8. How we protect your data
- All traffic is encrypted in transit over HTTPS.
- Customer data is stored in a database protected by row-level security policies, so access is enforced by the database itself rather than by the website interface.
- Anonymous visitors cannot read customer data. The private admin area requires a password-protected account with an administrator or staff role.
- Access is limited by role, and each team member has their own account.
- Service credentials and secret keys are stored server-side only and are never included in the website’s public code.
- Addresses and booking details are treated as confidential customer information.
No system can be guaranteed completely secure, and this policy does not claim certification of compliance. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Office of the Commissioner for Personal Data Protection in Cyprus and affected individuals as required by law.
9. Cookies
We use strictly necessary cookies and storage to run the site, and optional analytics cookies only with your consent. Full details are in our Cookie Policy. You can change or withdraw your choice at any time using “Cookie Settings” in the website footer.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- ask us to delete data where there is no ongoing legal reason to keep it;
- ask us to restrict processing;
- object to processing based on our legitimate interests;
- receive your data in a portable format where applicable;
- withdraw consent for analytics or marketing at any time;
- lodge a complaint with the Office of the Commissioner for Personal Data Protection (Cyprus).
To exercise any of these rights, email info@cleanbeecy.com or write to us at Apostolou Pavlou Avenue 7, Paphos, 8046. We will respond within one month. We may need to confirm your identity before acting on a request.
11. Children
Our services are intended for adults. We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this policy to reflect changes in our services or legal obligations. The date at the top of this page shows when it was last revised.
Questions about your data?
Contact us at info@cleanbeecy.com or call 26 911 180. You can also use our contact form.
