UK and EU GDPR Compliance Statement
Priceguide Ltd Effective date: 26 April 2026 Last updated: 26 April 2026 Version: 1.1
About this statement
Priceguide Ltd is a UK-incorporated company providing an AI-powered pricing estimator platform to home service contractors. This statement explains how we comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and where applicable the EU General Data Protection Regulation (Regulation (EU) 2016/679).
This statement is a summary. Authoritative detail is set out in our Privacy Policy, Data Processing Agreement, Sub-processor List, and Records of Processing Activities.
Our role under GDPR
We act in two roles, depending on the data:
| Data | Our role | Customer’s role |
|---|---|---|
| Customer (contractor) account data | Controller | n/a |
| Marketing site visitor data | Controller | n/a |
| Estimator submissions from end users (homeowners) | Processor | Controller (the contractor) |
For estimator submissions, the contractor decides who receives leads, what questions are asked, how long data is retained, and how leads are followed up. We process this data only on the contractor’s documented instructions, set out in our DPA.
Lawful bases for processing
Where we are the controller, we rely on the following lawful bases under Article 6 UK GDPR:
| Activity | Lawful basis |
|---|---|
| Providing the platform to paying customers | Performance of a contract (Art. 6(1)(b)) |
| Pre-contractual demonstrations and quotations | Pre-contractual steps (Art. 6(1)(b)) |
| Service emails (billing, security, outages) | Performance of a contract (Art. 6(1)(b)) |
| Marketing newsletters | Consent (Art. 6(1)(a)), withdrawable at any time |
| Website analytics (GA4) | Consent via cookie banner (Art. 6(1)(a)) |
| Advertising and retargeting (Meta Pixel) | Consent via cookie banner (Art. 6(1)(a)) |
| Marketing automation and lead capture (ActiveCampaign) | Consent via cookie banner (Art. 6(1)(a)) / Legitimate interests for B2B prospect tracking (Art. 6(1)(f)) |
| Product analytics on customer dashboard (Hotjar) | Legitimate interests in improving the customer-facing product (Art. 6(1)(f)); MFA-authenticated customer users |
| Tax, accounting, statutory record-keeping | Legal obligation (Art. 6(1)(c)) |
| Fraud and security investigation | Legitimate interests (Art. 6(1)(f)) |
We do not process special category data (Article 9) or criminal-offence data (Article 10) in the ordinary course of business.
How we meet the GDPR principles (Article 5)
Lawfulness, fairness, transparency — every processing activity has an identified lawful basis. Our Privacy Policy explains in plain English what we do with personal data.
Purpose limitation — data is collected for specific, explicit, legitimate purposes and is not used for incompatible purposes. AI/LLM providers in our supply chain operate under terms that, as currently in force, do not permit the use of customer API data to train their models.
Data minimisation — estimators are designed to collect only what is needed to generate a price and route a lead. Personally identifying fields are not sent to AI providers.
Accuracy — customers may correct their account data through the product. End users may request correction of estimator submissions through the contractor (controller) or via [email protected].
Storage limitation — default retention for estimator submissions is 24 months, configurable downward by the customer. Customer account data is retained for the contract term plus 6 years (UK statutory limitation period). Detail is set out in our Data Retention and Deletion Policy.
Integrity and confidentiality (security) — see our Security Overview. Encryption in transit and at rest, MFA for administrative access, role-based access control, code review, dependency scanning, and incident response procedures.
Accountability — we maintain written Records of Processing Activities (ROPA), data processing terms with all Sub-processors, this statement, and supporting policies.
Data subject rights
Individuals have the following rights under UK and EU GDPR:
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure / right to be forgotten (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection (Art. 21), including objection to direct marketing
- Not to be subject to automated decision-making with legal or similarly significant effect (Art. 22)
- Withdrawal of consent (Art. 7(3))
To exercise any of these rights, please email [email protected]. We will respond within one calendar month, with a possible two-month extension for complex requests, of which we will notify the requester within the first month.
If you submitted an estimate request through a contractor’s website, the contractor is the controller. Please contact them first; we will assist them in fulfilling the request.
Automated processing and AI (Article 22)
Our estimator generates a price range using a deterministic pricing model configured by the contractor. AI/LLM tools (currently OpenAI) assist with content generation but do not make pricing or qualification decisions.
The estimate is informational and non-binding; it does not produce legal or similarly significant effects on the data subject within the meaning of Article 22.
We do not send personally identifying fields to AI providers. AI providers in our supply chain operate under terms that, as currently in force, do not permit the use of customer API data for model training.
We have assessed AI-assisted content generation and concluded that the processing presents low risk to data subjects, on the basis that no personal data is sent to AI providers, the AI does not make decisions about individuals, and outputs are content rather than determinations.
International transfers (Chapter V)
The majority of our service providers operate primarily in the United States. Personal data is therefore transferred outside the UK and EEA. We rely on the following mechanisms, in order of preference:
- Adequacy decisions, including the EU-US Data Privacy Framework and the UK Extension for certified recipients.
- EU Standard Contractual Clauses (2021/914), Modules 2 (controller-to-processor) and 3 (processor-to-processor).
- UK Addendum to the EU SCCs or the UK International Data Transfer Agreement (IDTA) for transfers from the UK.
We rely on the transfer mechanisms documented in our Sub-processor List and apply supplementary technical measures, including encryption in transit and at rest and access controls.
Records of Processing Activities (Article 30)
We maintain an internal ROPA covering all processing carried out as controller and as processor. The ROPA is reviewed annually and on any material change to processing activities. It is available to supervisory authorities on request.
A summary of the ROPA may be made available to enterprise customers on request, subject to confidentiality.
Data Protection Impact Assessments (Article 35)
Where we identify processing that is likely to result in high risk to data subjects, we will carry out a Data Protection Impact Assessment. We have assessed AI-assisted content generation as set out above and concluded the processing is low risk.
We will support customers with their own DPIAs for processing carried out via Priceguide.
Data Protection Officer (Article 37)
Priceguide is not required to designate a Data Protection Officer because:
- we are not a public authority;
- our core activities do not consist of regular and systematic monitoring of data subjects on a large scale; and
- we do not process special category data or criminal-offence data on a large scale.
Privacy enquiries are handled by Steve Auchettl (co-founder), reachable at [email protected]. We review the need for a Data Protection Officer as our processing scales.
For EU-based data subjects, we will appoint an Article 27 representative if and when our activity in the EU triggers that requirement. Please contact us for current details.
Personal Data Breach response (Articles 33–34)
We maintain an Incident Response Plan with documented severity classification, escalation, and notification timelines.
When acting as controller, we will notify the Information Commissioner’s Office (ICO) within seventy-two (72) hours of becoming aware of a notifiable Personal Data Breach, and affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
When acting as processor, we will notify the customer (controller) without undue delay and in any event within forty-eight (48) hours of becoming aware of a Personal Data Breach affecting their data, providing the information they need to fulfil their own notification obligations.
Children’s data
Priceguide is not directed at children. We do not knowingly collect data from anyone under 16. If you become aware that a child has provided personal data to Priceguide, please contact [email protected] and we will delete it.
Supervisory authority
The lead supervisory authority for Priceguide is the UK Information Commissioner’s Office (ICO):
- Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
- 0303 123 1113
- ico.org.uk
EU/EEA data subjects may also lodge a complaint with their local supervisory authority.
Documents that support this statement
- Privacy Policy — priceguide.ai/priceguide-privacy-policy
- Data Processing Agreement — priceguide.ai/data-processing-agreement
- Sub-processor List — priceguide.ai/sub-processor-list
- Security Overview — priceguide.ai/priceguide-security-overview
- Data Retention and Deletion Policy — available on request
- Records of Processing Activities — available to supervisory authorities and, on request, to enterprise customers under NDA
- Incident Response Plan — summary available on request
Contact
Priceguide Ltd 167-169 Great Portland Street, 5th Floor London W1W 5PF, United Kingdom
Have Any Questions?
We’d love to hear from you.
