Privacy Notice

Last updated: 15 July 2026 · v1.0.0

NEATLY LTD ("Neatly", "we", "us", "our") is committed to protecting your personal data and handling it responsibly, transparently, and securely.

This Privacy Notice explains how we collect, use, store, and share personal data when you use the Neatly platform and website, which connects clients with vetted, DBS-checked decluttering professionals — with a particular focus on supporting neurodivergent individuals.

1. Who We Are

NEATLY LTD is a private limited company registered in England and Wales under company number 11811216. We are the data controller for the personal data described in this notice.

2. Contact Details

NEATLY LTD 36 Paganhill Estate Stroud Gloucestershire GL5 4AU United Kingdom

General enquiries: hello@neatly.uk Privacy enquiries: privacy@neatly.uk

Data Protection Officer: James Perry — DPO@neatly.world

Logged-in users can also manage cookie preferences, export their data, and request erasure from Dashboard → Privacy & Data.

3. Who This Notice Applies To

This Privacy Notice applies to personal data we process in relation to:

  • Clients who book decluttering services
  • Declutterers, trainers, managers and franchise owners who provide or coordinate services
  • Applicants applying to join Neatly
  • Website visitors, newsletter subscribers and business contacts

4. The Personal Data We Collect

Depending on your relationship with us, we may collect and process:

  • Identity and contact data — name, email address, telephone number, postal address
  • Account data — login credentials (passwords are stored only as bcrypt hashes), role, preferences and settings
  • Booking and service data — appointments, service addresses, notes about the work, communications and reviews
  • Payment data — payment status, amounts and invoices. Card details are handled directly by our payment processor (Stripe) and never stored on our servers
  • Declutterer / staff data — qualifications, training and assessment records, right-to-work information and DBS (criminal record) check outcomes
  • Website and technical data — IP address, device and browser information, and cookie/consent records

Special category data

To provide accessible, tailored support we may — only with your explicit consent — collect information about your neurotype (for example autism or ADHD), communication style, sensory needs and accessibility requirements. This is special category data under Article 9 UK GDPR. We use it solely to match you with suitable support and to adapt how we work with you, and we never share it without your explicit consent.

5. How We Collect Personal Data

We collect personal data directly from you (when you register, book, apply or contact us), from declutterers and staff during service delivery, from our compliance and screening providers (e.g. the DBS), and automatically through cookies and similar technologies (see our Cookie Policy).

6. How We Use Personal Data and Our Lawful Bases

PurposeLawful basis
Create and manage your accountContract
Match clients with suitable declutterers and manage bookingsContract
Process payments, invoicing and payoutsContract / Legal obligation
Adapt support to your accessibility and sensory needsExplicit consent (special category)
Run DBS checks and training for declutterers and staffLegal obligation / Legitimate interests (safeguarding)
Send service and transactional communicationsContract
Send marketing emails and newslettersConsent (withdraw any time)
Keep financial and tax recordsLegal obligation
Secure the platform, prevent fraud and abuseLegitimate interests
Improve our services using aggregated / anonymised dataLegitimate interests

Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.

7. Who We Share Personal Data With

We may share personal data with:

  • The declutterer, trainer or manager assigned to your booking (limited to what they need to deliver the service)
  • Our sub-processors and service providers (see the Sub-processors page) — including hosting, payment, email and screening providers
  • Professional advisers, insurers and auditors
  • Regulators, law enforcement or other authorities where legally required

We do not sell your personal data.

8. International Transfers

We primarily store and process personal data within the UK and EU. Where a provider processes data outside the UK/EEA, we rely on UK adequacy regulations, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, together with appropriate safeguards.

9. Data Retention

We keep personal data only for as long as necessary for the purposes above:

  • Account and profile data — for the life of your account, then deleted or anonymised (see §11)
  • Booking and communication records — for a reasonable period after the service for support, dispute and safeguarding purposes
  • Financial records (invoices, payments, ledger entries) — retained for 7 years to meet UK tax and company-law obligations, disconnected from your personal profile after erasure
  • DBS outcomes — retained only as long as required by DBS guidance and our safeguarding obligations
  • Consent and audit records — retained to evidence compliance

10. Your Rights

Under UK GDPR you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate or incomplete data
  • Erasure — request deletion ("right to be forgotten")
  • Restriction — limit how we use your data
  • Portability — receive your data in a machine-readable format
  • Object — object to processing based on legitimate interests or to direct marketing
  • Withdraw consent — at any time where we rely on consent

Logged-in users can export their data and request erasure from Dashboard → Privacy & Data. For any other request, contact our DPO at DPO@neatly.world. We respond within one month.

11. Account Deletion and Anonymisation

When you delete your account we hold the request for a 30-day grace period (during which your account is frozen and you can cancel). After that we remove or anonymise your personal data. Financial and other records we are legally required to keep are retained but disconnected from your personal identity.

12. Data Security

We apply appropriate technical and organisational measures, including encryption in transit and at rest, role-based access controls, multi-factor authentication for privileged accounts, rate limiting, audit logging, and DBS checks for everyone delivering services.

13. Automated Decision-Making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

14. Complaints

If you have concerns about how we use your personal data, please contact our DPO first at DPO@neatly.world. You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO)ico.org.uk.

15. Changes to This Notice

We may update this Privacy Notice from time to time. When we make material changes, logged-in users will be asked to review and accept the updated version on their next visit. The current version is always available on this page.

See also our Cookie Policy and Terms of Service.