GDPR Compliance

How Cinderella Clean Academy meets its obligations under the EU General Data Protection
Regulation across the Client and Provider mobile applications.

This notice explains how Schwarzschild Group Limited (“we”, “us”, “our”),
registered at 58 New Bedford Road, LUTON – LU1 1SH, United Kingdom (GB), email: office@schwarzschildgroup.com, complies with Regulation (EU) 2016/679 — the General Data Protection Regulation (“GDPR”), in relation to both the Cinderella Client App and the Cinderella Provider App.

For a full description of the personal data we collect and the purposes for which we process it, please read our Privacy Policy. This notice focuses on the compliance framework: the principles we follow, the safeguards we apply.

01Our GDPR principles

We design and operate both Apps around the seven principles set out in Article 5 GDPR.

Art. 5(1)(a) — Lawfulness, fairness & transparency

Every processing operation has a documented legal basis; we disclose what we do in the Privacy Policy and inside the Apps at the point of collection.

Art. 5(1)(b) — Purpose limitation

Personal data is collected for the specific purposes described in the Privacy Policy and is not reused for incompatible purposes.

Art. 5(1)(c) — Data minimisation

We ask only for the data needed to deliver a booking, match a provider, verify identity or bill you – nothing more.

Art. 5(1)(d) — Accuracy

You can view and correct your account data at any time inside the App; we honour rectification requests promptly.

Art. 5(1)(e) — Storage limitation

We keep personal data only as long as needed for the stated purpose or required by law.

Art. 5(1)(f) — Integrity & confidentiality

Data is encrypted in transit and at rest, and access is restricted to authorised personnel.

Art. 5(2) — Accountability

We maintain records of processing activities, review our processors and can demonstrate compliance on request from supervisory authorities.

02Lawful bases we rely on

Under Article 6 GDPR we rely on the following lawful bases; a full mapping to purposes is in section 2 of the Privacy Policy.

Art. 6(1)(b) — Contract

Delivering the service you signed up for: booking, matching, chat, subscription billing.

Art. 6(1)(c) — Legal obligation

Identity verification, VAT invoicing, statutory tax-record retention, anti-fraud.

Art. 6(1)(f) — Legitimate interests

Diagnosing crashes, protecting the service from abuse, maintaining assignment audit logs.

Art. 6(1)(a) — Consent

Push notifications, precise location, camera, photo library and calendar access — each granted at the OS prompt and revocable at any time in device settings.

03Response timelines

  • We acknowledge every data-subject request in writing.
  • We respond within one month of receipt, as required by Art. 12(3) GDPR.
  • Where the request is complex or we receive several requests, we may extend the period and will inform you within the first month, explaining the reason for the extension.
  • Requests are handled free of charge. We may charge a reasonable fee, or refuse to act, only if a request is manifestly unfounded or excessive (Art. 12(5)).

04Sub-processors

We use the following processors to operate the Apps. Each is bound by a written data-processing agreement complying with Art. 28 GDPR. Where processing takes place outside the European Economic Area, it is governed by the European Commission’s Standard Contractual Clauses.

Google LLC — Firebase Authentication, Cloud Messaging, Firestore, Crashlytics

Authentication, push delivery, chat storage and crash reporting.

Google LLC — Maps SDK, Places API

Map display and address autocomplete.

Stripe

Subscription and card payment processing.

Microsoft Azure

Hosting of our backend, databases and file storage.

Gateway API

Delivery of phone-verification SMS.

05Technical measures

  • All communication between the Apps and our backend uses HTTPS with modern TLS.
  • Access tokens (JWT) and refresh tokens on the device are stored using the operating system’s secure enclave (iOS Keychain / Android Keystore).
  • Passwords are stored on the server as salted hashes; plaintext passwords never leave the device other than over TLS at sign-in.
  • Identity documents and other sensitive files are stored on the backend with restricted access and are not served publicly.
  • Payment card data is handled only by our PCI-DSS-compliant payment processor; card numbers do not touch our infrastructure.

06Personal-data breach handling

If we become aware of a personal-data breach, we act in accordance with Articles 33 and 34 GDPR:

  • We investigate the breach and assess the risk to the rights and freedoms of affected individuals.
  • Where the breach is likely to result in a risk, we notify the competent supervisory authority without undue delay.
  • Where the breach is likely to result in a high risk to affected individuals, we also notify them directly and in clear language, in-App or by email.
  • We document every breach – the facts, the effects and the remedial action taken – regardless of whether notification was required.