Legal
Privacy Policy
Last updated: 2026-10-04
This policy explains what personal data Fibrion collects, why we collect it, how long we keep it, and the rights you have over it. It is written in plain English: if anything is unclear, contact us at support@fibrion.co.uk.
Fibrion is the data controller for the personal data described in this policy. Fibrion is operated by the Fibrion team in the United Kingdom.
1. What we collect
We collect the following categories of personal data:
- Account details. Your name, email address, telephone number, billing and service addresses, and login credentials when you create an account or place an order.
- Order and service data. Products and services you order, order status, service addresses, and correspondence with us about your services.
- Payment data. Card payments are processed directly by Stripe. We never see or store your full card number; we retain only the transaction references Stripe provides so we can reconcile your payments.
- Usage data. How you interact with our website and portal — pages visited, approximate location derived from your IP address, device and browser type — collected through cookies and similar technologies (see section 5).
- Support data. Records of conversations when you contact us for help.
2. Our lawful bases for processing
Under UK GDPR we must have a lawful basis for each use of your personal data. We rely on the following:
- Contract. To provide the services you order, take payment, and manage your account.
- Legal obligation. To comply with tax, accounting and regulatory requirements, including keeping records of transactions.
- Legitimate interests. To keep our platform secure, prevent fraud, improve our services, and — where you have an existing account — tell you about relevant products and services. You can object to this at any time.
- Consent. For non-essential cookies and marketing communications, where you have given consent. You can withdraw consent at any time (see section 5).
3. How we use your data
- Processing and fulfilling your orders and service installations.
- Taking payment and managing billing, refunds and credits.
- Providing customer support and responding to your queries.
- Keeping the platform, your account and our services secure.
- Meeting legal, tax and accounting obligations.
- Improving our website and services through aggregated usage analysis.
- Sending service messages (for example, appointment reminders and service status updates) and, with your consent, marketing communications.
6. How long we keep your data
We keep personal data only for as long as necessary for the purposes described in this policy:
- Account and order data. For the life of your account plus the period required by UK tax and accounting law (currently six years from the end of the relevant financial year).
- Payment records. Transaction references are retained for the same statutory period.
- Support records. For up to three years after your last contact with us.
- Cookie preferences. Your consent choice is stored in your browser's local storage until you clear it.
When data is no longer required, it is securely deleted or anonymised.
7. Your rights
Under UK GDPR you have the right to:
- Access. Request a copy of the personal data we hold about you.
- Rectification. Ask us to correct inaccurate or incomplete data.
- Erasure. Ask us to delete your data, subject to legal retention requirements.
- Restriction. Ask us to limit how we use your data in certain circumstances.
- Portability. Receive your data in a structured, machine-readable format.
- Objection. Object to processing based on legitimate interests, and to direct marketing.
- Withdraw consent. Where processing is based on consent, withdraw it at any time without affecting the lawfulness of earlier processing.
To exercise any of these rights, email support@fibrion.co.uk. We respond within one month.
8. Complaints
If you are unhappy with how we handle your personal data, please contact us first so we can put things right. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK regulator for data protection:
- Website: ico.org.uk
- Helpline: 0303 123 1113
9. Security
We use appropriate technical and organisational measures to protect your personal data, including encryption in transit, access controls and regular review of our security practices. If a data breach occurs that is likely to risk your rights and freedoms, we will notify you and the ICO in accordance with UK GDPR.
10. Changes to this policy
We may update this policy from time to time. The date at the top of this page shows when it was last updated. We will notify you of material changes by email or through the portal.
11. Contact us
For any questions about this policy or how we handle your data, contact us at support@fibrion.co.uk.
