Anglo Doorstep Collections
GDPR Policy

Last updated: 24 July 2026 · Reviewed at least annually

1. Introduction and purpose

Anglo Doorstep Collections handles the personal data of thousands of householders who generously donate to our charity partners, and we take that responsibility seriously. This policy sets out how we comply with UK data protection law — the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended (including by the Data (Use and Access) Act 2025) — and the standards everyone working for us must meet when handling personal data.

This policy explains how we protect personal data. For a plain-English explanation of what data we collect about you and why, please read our Privacy Policy — the two documents work together.

2. Who we are

Anglo Doorstep Collections is a trading name of Anglo Recycling Company Limited, a company registered in England and Wales (company number 07917282) with its registered office at Unit 111, Image Court, 328 Molesey Road, Hersham, Surrey, KT12 3PD.

We are the data controller of the personal data we process: we decide why and how it is used, and we are legally responsible for it. We are registered with the Information Commissioner's Office (ICO), registration number ZB698233.

3. Scope

This policy applies to all personal data processed by us, in any format and on any system — including data about our customers and donors, website visitors, people who contact us, job applicants and staff. It applies to all our directors, employees and contractors, and to every third party that processes personal data on our behalf.

4. Data protection contact

Day-to-day responsibility for data protection sits with our data protection lead, who can be contacted at info@anglodoorstepcollections.co.uk for any question about this policy, our data handling practices, or your rights.

5. The data protection principles

Article 5 of the UK GDPR sets out seven principles that govern everything we do with personal data. This is what each one means and how we meet it:

Principle How we comply
Lawfulness, fairness and transparency We identify a lawful basis before any processing begins, we never use personal data in ways people would not reasonably expect, and our Privacy Policy explains our processing in clear language.
Purpose limitation We collect personal data for specified, explicit purposes — principally arranging and carrying out doorstep collections — and do not reuse it for unrelated purposes.
Data minimisation We collect only what we need. Booking a collection requires a name, address and contact details — nothing more. We do not ask donors for payment details, dates of birth or any other data the service does not need.
Accuracy Customers can view and update their details through our customer account pages, and we correct inaccurate data promptly when we are told about it.
Storage limitation We keep personal data no longer than necessary, apply the retention criteria in section 14, and delete data on request wherever the law allows.
Integrity and confidentiality Personal data is protected by the technical and organisational measures described in section 13, and access is restricted to those who need it.
Accountability We document our processing, train our staff, put written contracts in place with our processors, and review our practices regularly — see section 10.

6. The personal data we process

We process personal data in order to:

  • Provide our doorstep collection service — taking bookings online and by phone, managing customer accounts, planning collection routes and providing customer support
  • Comply with legal obligations, such as tax and accounting requirements
  • Communicate with customers about our services, including marketing communications with an easy opt-out
  • Improve our services, including through analytics
  • Protect our business, including detecting and preventing fraud and misuse
  • Recruit and employ staff

The categories of data involved are: contact information (name, address, email address, phone number), booking details, communication preferences, correspondence, technical data about use of our website, and recruitment and employment records. Our collection service is free for donors and we do not collect payment card details from them. A full description of each category is in our Privacy Policy.

7. Lawful bases for processing

Every processing activity we carry out rests on one of the following lawful bases under Article 6 of the UK GDPR, identified and recorded before the processing begins:

  • Performance of a contract — processing necessary to provide the service you have requested, or to take steps at your request before entering into a contract. This covers most of what we do: arranging, amending and carrying out your collection.
  • Legal obligation — processing necessary to comply with the law, such as keeping accounting records.
  • Legitimate interests — processing necessary for our legitimate business interests (such as keeping our website secure, planning efficient routes, and telling existing customers about collections in their area), balanced in each case against your interests and fundamental rights. We do not rely on this basis where your rights override our interests.
  • Consent — where we ask for your consent, it must be freely given, specific, informed and unambiguous, and you can withdraw it at any time as easily as you gave it. Withdrawal does not affect the lawfulness of processing carried out before it.

8. Special category data

We do not ask for, and do not routinely process, special category data (such as data about health, religion or ethnicity). If you choose to share such information with us — for example, telling us about a mobility or access need so our crew can collect from a convenient place — we record only what is needed to carry out your request, treat it with additional care, and rely on your explicit consent to hold it. You can ask us to delete it at any time.

9. Data protection by design and by default

We consider data protection at the design stage of any new system, page or process, not as an afterthought. By default, our systems collect the minimum data needed for the task, restrict access to those who need it, and avoid exposing personal data unnecessarily. Where a new processing activity is likely to result in a high risk to individuals, we carry out a data protection impact assessment before it begins.

10. Accountability and governance

As controller, we must be able to demonstrate our compliance — not just assert it. We do this by:

  • Keeping records of our processing activities, the purposes and lawful bases for them, and our retention rules
  • Training staff who handle personal data in data protection practice, and limiting each person's access to what their role requires
  • Putting written data processing contracts in place with every third party that processes personal data on our behalf (see section 18)
  • Maintaining a register of any personal data breaches and near misses (see section 17)
  • Reviewing this policy, our security arrangements and our storage locations regularly

11. Where personal data is stored

Personal data we hold is stored in the following locations:

  • Cloud services
    • Amazon Web Services — data stored in the UK
    • Microsoft 365 — data stored in the UK
    • OptimoRoute (route planning) — data stored in the USA
  • Trusted third-party providers — used for specific purposes such as email delivery, address lookup and analytics. These providers store data in secure data centres and may only use it on our instructions.
  • Authorised company devices — such as laptops, tablets and phones used by our staff, protected by encryption and authentication controls.

12. International transfers

Most of our data never leaves the United Kingdom. Where personal data is transferred outside the UK (for example, to our route planning provider in the USA), the transfer is made only with safeguards recognised under UK data protection law — such as the UK Extension to the EU–US Data Privacy Framework, or the ICO's International Data Transfer Agreement or Addendum — so that the data receives an equivalent standard of protection wherever it is processed.

13. Security measures

We protect personal data with technical and organisational measures appropriate to the risk, including:

  • Encrypted connections (HTTPS) across our website and booking systems
  • Encryption and authentication controls on all company devices that hold personal data
  • Access controls that restrict personal data to authorised personnel who need it for their role
  • Protection against automated attacks and misuse of our booking systems
  • Staff training in secure data handling
  • Regular review of our security arrangements and of the third parties that hold data for us

14. Data retention

We keep personal data only for as long as necessary for the purposes it was collected for, including to satisfy legal, accounting or reporting requirements. The criteria we use to set retention periods are:

  • The length of our ongoing relationship with you and the services we provide
  • Any legal obligation to keep records for a set period (for example, accounting records)
  • Whether retention is advisable in light of our legal position (such as disputes or investigations)

Specific retention periods for each category of data are set out in our Privacy Policy. When data is no longer needed it is deleted or irreversibly anonymised, and you can ask us to delete your data at any time.

15. Individual rights and how we handle requests

Under the UK GDPR you have the right to:

  • Access your personal data and information about how it is processed
  • Rectification of inaccurate or incomplete personal data
  • Erasure of your personal data in certain circumstances
  • Restriction of processing in certain circumstances
  • Data portability — receive your data in a structured, commonly used, machine-readable format and have it transferred to another controller where technically feasible
  • Object to processing in certain circumstances, including an absolute right to object to direct marketing
  • Withdraw consent at any time where processing is based on consent
  • Not be subject to solely automated decisions with legal or similarly significant effects — we do not make such decisions

How we handle your request

Send your request to info@anglodoorstepcollections.co.uk or to our postal address below — no special form is needed. We will:

  • Confirm we have received your request
  • Ask you to verify your identity where necessary, so we never give your data to the wrong person
  • Respond without undue delay and within one month. For particularly complex or numerous requests we may extend this by up to two further months, and we will tell you within the first month if so, with the reason
  • Act free of charge, unless a request is manifestly unfounded or excessive

16. Direct marketing

Our marketing emails comply with the UK GDPR and the Privacy and Electronic Communications Regulations (PECR). We only email existing customers about our own similar services (such as future collections in their area), every message identifies us and contains a working unsubscribe link, and an opt-out takes effect promptly and permanently. You can also opt out at any time via our unsubscribe page. The right to object to direct marketing is absolute — if you object, we stop.

17. Personal data breaches

We maintain procedures to detect, contain, investigate and record personal data breaches, and we keep a register of breaches and near misses whether or not they are reportable. Where a breach is likely to result in a risk to individuals' rights and freedoms, we will report it to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to you, we will also tell you directly, without undue delay, explaining what happened and what we are doing about it.

18. Third-party processors

Before we appoint any third party to process personal data on our behalf, we check that it can provide sufficient guarantees about its security and compliance. Every processor operates under a written contract that meets the requirements of Article 28 of the UK GDPR: it may act only on our documented instructions, must keep the data confidential and secure, may not appoint sub-processors without permission, must assist us with data subject requests and breach obligations, and must delete or return the data when the contract ends. Our main processors and storage locations are listed in section 11.

19. Complaints

If you have a concern about how we handle personal data, please contact us first — we take every concern seriously and will investigate and respond to you promptly. You also have the right to complain to the UK's supervisory authority at any time:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint

20. Review of this policy

This policy is reviewed at least annually, and sooner if the law, ICO guidance or our processing activities change. The latest version is always published on this page with the date it was last updated.

21. Contact information

Anglo Doorstep Collections
Anglo Recycling Company Limited
Unit 111, Image Court
328 Molesey Road
Hersham, Surrey, KT12 3PD
info@anglodoorstepcollections.co.uk