Howard Family Developments Ltd
More
Howard Family Developments Ltd

Privacy Policy

Generated privacy notice - general business

Howard Family Developments Ltd customer privacy notice

This privacy notice tells you what to expect us to do with your personal information.

  • Contact details
  • What information we collect, use, and why
  • Lawful bases and data protection rights
  • Where we get personal information from
  • How long we keep information
  • Who we share information with
  • Sharing information outside the UK
  • How to complain

Contact details

Email

james@howardfamilydevelopmentsltd.co.uk

What information we collect, use, and why

We collect or use the following information to provide services and goods, including delivery:

  • Names and contact details
  • Addresses
  • Purchase or account history
  • Payment details (including card or bank information for transfers and direct debits)
  • Health and safety information
  • Website user information (including user journeys and cookie tracking)
  • Photographs or video recordings
  • Identification documents
  • Information relating to compliments or complaints
  • Vehicle registration numbers, emergency contact details, check-in and check-out information, guest communications (including emails, SMS and messaging through booking platforms), booking preferences, occupancy information, and records relating to property access and security.

We collect or use the following information to prevent, detect, investigate or prosecute crimes:

  • Names and contact information
  • Customer or client accounts and records
  • Video and CCTV recordings of public areas (including indoor and outdoor spaces)

We collect or use the following information for service updates or marketing purposes:

  • Names and contact details
  • Addresses
  • Marketing preferences
  • Purchase or viewing history
  • IP addresses
  • Website and app user journey information
  • Records of consent, where appropriate

We collect or use the following information to comply with legal requirements:

  • Name
  • Contact information
  • Identification documents
  • Financial transaction information
  • Any other personal information required to comply with legal obligations
  • Health and safety information

We collect or use the following personal information for dealing with queries, complaints or claims:

  • Names and contact details
  • Address
  • Payment details
  • Purchase or service history
  • Video recordings of public areas
  • Witness statements and contact details
  • Relevant information from previous investigations
  • Customer or client accounts and records
  • Financial transaction information
  • Information relating to health and safety
  • Correspondence

We collect or use the following information to managing property access, protecting guests and property, and administering bookings.:

  • Names and contact details
  • Purchase or account history
  • Payment details (including card or bank information for transfers and direct debits)
  • Photographs or video recordings
  • Identification documents
  • Customer or client accounts and records
  • Financial transaction information
  • Recorded images, such as photos or videos
  • Vehicle registration numbers; emergency contact details; check-in and check-out dates and times; guest communications (including emails, SMS and messages through booking platforms); booking preferences; occupancy information; and property access and security logs.

Lawful bases and data protection rights

Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.

Which lawful basis we rely on may affect your data protection rights which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:

  • Your right of access - You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for. Read more about the right of access.
  • Your right to rectification - You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete. Read more about the right to rectification.
  • Your right to erasure - You have the right to ask us to delete your personal information. Read more about the right to erasure.
  • Your right to restriction of processing - You have the right to ask us to limit how we can use your personal information. Read more about the right to restriction of processing.
  • Your right to object to processing - You have the right to object to the processing of your personal data. Read more about the right to object to processing.
  • Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you. Read more about the right to data portability.
  • Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent at any time. Read more about the right to withdraw consent.

If you make a request, we must respond to you without undue delay and in any event within one month.

To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.

Our lawful bases for the collection and use of your data

Our lawful bases for collecting or using personal information to provide services and goods are:

  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
  • We collect and use personal information where it is necessary for our legitimate interests in operating a safe, secure and efficient serviced accommodation business. This includes protecting our guests, properties, staff, contractors and business interests; preventing and detecting fraud; managing property access and security; investigating incidents, damage or breaches of booking terms; maintaining service quality; and improving our accommodation services. The use of personal information allows us to provide a safe and reliable service, respond effectively to guest needs, protect against misuse of our properties and resolve issues that may arise during or after a stay. We carefully consider the impact on individuals and only collect and use information that is necessary for these purposes. We do not use personal information in ways that are unexpected or unfair to guests. Access to personal information is restricted to authorised persons, and information is retained only for as long as necessary in accordance with our data retention procedures. This also includes managing secure access to our properties through systems such as key safes or electronic access controls and, where applicable, monitoring security through CCTV in appropriate areas. These measures help protect guests and properties while avoiding unnecessary intrusion into guests’ privacy.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information to prevent, detect, investigate or prosecute crimes are:

  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
  • We have a legitimate interest in processing personal information to protect our guests, staff, contractors and properties, prevent and detect fraud, investigate suspected criminal activity, respond to incidents, enforce our booking terms and protect our business interests. This processing helps maintain a safe environment for guests and prevents misuse of our accommodation. We carefully balance these interests against individuals’ rights and only process information that is necessary and proportionate. We limit access to personal information, apply appropriate security measures and retain information only for as long as required.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information for service updates or marketing purposes are:

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
  • We have a legitimate interest in communicating with guests to improve our services, request feedback about their stay, respond to enquiries and provide information that is relevant to their previous interactions with us. We ensure that any communications are proportionate, expected and do not unfairly impact individuals’ privacy rights.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information for legal requirements are:

  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.

Our lawful bases for collecting or using personal information for dealing with queries, complaints or claims are:

  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
  • We have a legitimate interest in processing personal information to respond to guest enquiries, manage complaints, investigate incidents, resolve disputes, handle damage claims, process refunds where appropriate, improve our services and protect our business interests. This enables us to provide a fair and effective response while maintaining appropriate records. We balance our interests against individuals’ rights and only use information that is necessary and relevant to resolving the query, complaint or claim. Access to information is limited to authorised persons and records are retained only for as long as necessary.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information for managing property access, protecting guests and property, and administering bookings. are:

  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
  • We have a legitimate interest in collecting and using personal information to operate our serviced accommodation safely and efficiently. This includes managing secure property access, protecting guests and our properties, preventing fraud and misuse, maintaining accurate booking and occupancy records, responding to incidents, and ensuring effective communication with guests. We only collect information that is necessary for these purposes and consider the impact on individuals’ privacy rights. We apply appropriate security measures, restrict access to authorised persons and retain information only for as long as necessary.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Where we get personal information from

  • Directly from you
  • CCTV footage or other recordings
  • Insurance companies
  • Suppliers and service providers
  • Third parties:
  • Booking platforms and online travel agents, corporate booking partners, property owners or agents, guest communication platforms, smart lock or access control systems, and other organisations involved in managing accommodation services.
  • We may receive personal information from online booking platforms, travel agents, corporate booking partners, property management platforms and other accommodation intermediaries where guests make reservations through these services. Information may include guest names, contact details, booking details, payment-related information, occupancy information and communications relating to the reservation.

How long we keep information

Type of information

Purpose

Suggested retention period

Guest names, contact details and booking records

Managing reservations and providing accommodation services

6 years after the end of the financial year (for business/accounting records)

Invoices and payment records

Tax and accounting obligations

6 years (or longer if required by tax rules)

Guest communications (email, SMS, booking platform messages)

Managing bookings, queries, complaints and claims

3–6 years depending on purpose

Identification documents (passport/driving licence copies if collected)

Identity verification and security

Delete as soon as no longer required; typically within a short defined period unless a legal reason exists to retain

Vehicle registration details

Parking, access control and security

Duration of stay plus a defined period (e.g. 12 months)

Emergency contact details

Guest safety and emergencies

Duration of stay plus limited retention period (e.g. 12 months)

Smart lock/key safe access records

Property security and incident investigation

30–90 days unless required for an investigation

CCTV footage

Security and crime prevention

Typically 30–90 days unless needed for an incident or claim

Complaints and claims records

Resolving disputes and legal protection

6 years after resolution

Marketing consent records

Demonstrating compliance with marketing rules

Until consent is withdrawn plus a limited audit period

Website analytics/cookie data

Website improvement and marketing analysis

According to your analytics provider settings

For more information on how long we store your personal information or the criteria we use to determine this please contact us using the details provided above.

Who we share information with

Data processors

Guesty

This data processor does the following activities for us: Guesty provides property management software that stores and manages guest booking information, including guest names, contact details, reservation details, communications, occupancy information, check-in and check-out details, and property management records. Guesty helps us manage reservations, guest communications, operational tasks and accommodation services.

Online Travel agents: AirBnB, Booking.com, VRBO

These data processors do the following activities for us: Provide online accommodation booking platforms that facilitate reservations between guests and our accommodation business. Processes guest booking information, contact details, payment-related information and communications relating to reservations and stays.

Stripe

Payment processing provider used to securely process booking payments, refunds and transactions.

QuickBooks (Intuit)

Accounting software provider used to manage invoices, financial records and accounting information.

Others we share personal information with

  • Professional or legal advisors
  • Relevant regulatory authorities
  • Organisations we’re legally obliged to share personal information with
  • Suppliers and service providers
  • Other relevant third parties:
  • Insurance providers and claims handlers, Professional advisers including legal advisers, accountants and business consultants, Emergency services, law enforcement and regulatory authorities, Property owners and authorised property representatives

Sharing information outside the UK

Where necessary, we will transfer personal information outside of the UK. When doing so, we comply with the UK GDPR, making sure appropriate safeguards are in place.

Organisation name: Guesty

Category of recipient: Property Management System

Country the personal information is sent to: United States and Israel (and other countries where Guesty or its authorised sub-processors operate).

How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

Organisation name: Airbnb

Category of recipient: Online accommodation booking platform and travel marketplace

Country the personal information is sent to: United States and other countries where Airbnb or its service providers operate

How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

Organisation name: Booking.com

Category of recipient: Online accommodation booking platform and travel services provider

Country the personal information is sent to: The Netherlands and other countries where Booking.com or its authorised service providers operate.

How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

Organisation name: Vrbo (Expedia Group)

Category of recipient: Online accommodation booking platform

Country the personal information is sent to: United States and other countries where Expedia Group and its service providers operate.

How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

Organisation name: Stripe

Category of recipient: Payment processing and financial technology provider

Country the personal information is sent to: United States and other countries where Stripe or its service providers operate.

How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

Organisation name: QuickBooks (Intuit)

Category of recipient: Accounting software and financial record management provider

Country the personal information is sent to: United States and other countries where Intuit or its authorised service providers operate.

How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

Where necessary, our data processors may share personal information outside of the UK. When doing so, they comply with the UK GDPR, making sure appropriate safeguards are in place.

Organisation name: Amazon Web Services (AWS)

Category of recipient: Cloud hosting and data storage provider

Country the personal information is sent to: United States and\/or other countries where AWS infrastructure used by Guesty is located

How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

Organisation name: Airbnb service providers and technology partners

Category of recipient: Cloud hosting, technology, security, payment and operational service providers

Country the personal information is sent to: United States and other countries where Airbnb or its service providers operate

How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

Organisation name: Booking.com group companies and service providers

Category of recipient: Technology infrastructure, cloud hosting, payment, security and operational service providers

Country the personal information is sent to: Netherlands, United States and other countries where Booking.com or its service providers operate

How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

Organisation name: Expedia Group service providers

Category of recipient: Cloud hosting, technology, payment, security and operational service providers

Country the personal information is sent to: United States and other countries where Expedia Group or its service providers operate

How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

Organisation name: Stripe service providers and infrastructure providers

Category of recipient: Payment processing, financial technology, cloud hosting and fraud prevention providers

Country the personal information is sent to: United States and other countries where Stripe or its service providers operate

How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

Organisation name: Intuit service providers and technology partners

Category of recipient: Cloud hosting, accounting software infrastructure and IT service providers

Country the personal information is sent to: United States and other countries where Intuit or its service providers operate

How the transfer complies with UK data protection law: Addendum to the EU Standard Contractual Clauses (SCCs)

How to complain

If you have any concerns about our use of your personal information, you can make a data protection complaint to us:

Email: james@howardfamilydevelopmentsltd.co.uk

If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO. 

The ICO’s address:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline number: 0303 123 1113
Website: https://www.ico.org.uk/make-a-complaint

  • Privacy Policy

Howard Family Developments Ltd

Copyright © 2026 Howard Family Developments Ltd - All Rights Reserved.

Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept