SKYLARK WINDOWS LIMITED Company number 07397674 - Privacy Policy

Effective Date: 16th October 2025

Our Commitment to Your Privacy Choices

This website is operated by SKYLARK WINDOWS LIMITED Company number 07397674, with its registered address at 673 Romford Road, Manorpark, London, E12 5AD.

We, SKYLARK WINDOWS LIMITED Company number 07397674, located at 673 Romford Road, Manorpark, London, E12 5AD, take the protection of your personal data extremely seriously. Your trust is vital to us. We are committed to processing your personal data fairly, lawfully, and transparently, strictly adhering to the core principles of data protection set out in data protection laws including the General Data Protection Regulation (GDPR-EU and GDPR-UK). Our staff receive regular data protection training to ensure these principles are embedded in our culture. Our leadership team, overseen by our CEO, is accountable for ensuring compliance.

This Privacy Policy explains how we collect, use, share, and protect your personal data. We are committed to transparency and user control. Depending on the specific service you use and your relationship with us, we may rely on different lawful basis for processing your data, including obtaining your explicit consent ('Hard Opt-In'). We will always seek your explicit 'Hard Opt-In' consent for certain activities, particularly before sharing your data with partners for new quotes or conducting processing considered higher risk. Where 'Hard Opt-In' applies, this will be made explicitly clear at the point your data is collected. In other specific, limited circumstances permitted by law (such as marketing similar services to existing contacts), we may operate on an 'opt-out' basis, as detailed further in this policy.

This policy provides clear information on how we request your permission, collect your data, use it, share it, protect it, and how you can exercise your rights.

Data Protection Officer (DPO):

Our appointed Data Protection Officer can be contacted directly with any privacy-related questions or requests:

  • Email: [email protected]

  • Post: Data Protection Officer, SKYLARK WINDOWS LIMITED Company number 07397674, 673 Romford Road, Manorpark, London, E12 5AD

UK ICO Registration:

We are registered as a data controller with the UK Information Commissioner's Office (ICO).


Contents

  1. Definitions

  2. What Personal Data We Collect and Why

  3. Lawful Basis for Processing

  4. Our Roles under GDPR (Controller and Processor)

  5. How We Collect Your Personal Data

  6. Legitimate Interests for Direct Marketing

  7. Special Category Data (Not Currently Collected)

  8. Use of AI (Artificial Intelligence) – Requires Your Opt-In

  9. Cookies and Similar Technologies – Requires Your Opt-In

  10. Automated Decision Making

  11. Data Sharing with Third Parties – Requires Your Explicit Consent for Key Sharing

  12. International Data Transfers – Requires Consent & Safeguards

  13. How Long We Keep Your Information (Data Retention)

  14. Security of Your Personal Information

  15. Data Breach Handling

  16. Data Protection by Design

  17. Children's Information

  18. Your Data Protection Rights

  19. Your Consent and Choices: Opt-In and Opt-Out

  20. Consequences of Not Providing Consent or Information

  21. Change of Control or Sale

  22. Links to Other Websites

  23. Right to Complain

  24. Contact Us

  25. Policy Review and Amendments


1. Definitions

  • Personal Data: Any information relating to an identified or identifiable living individual.

  • Processing: Any operation performed on Personal Data, such as collection, recording, storage, use, disclosure, or erasure.

  • Consent / Explicit Consent ('Hard Opt-In'): Your freely given, specific, informed, and unambiguous agreement, indicated by a clear affirmative action (like ticking an unticked box), to the processing of your Personal Data for a specific purpose.

  • Soft Opt-In Exemption: A specific legal basis under regulations like PECR (UK) allowing marketing of similar products/services via email/SMS to existing contacts whose details were obtained during a sale, provided a clear opt-out was offered then and in every message.

  • Controller: The organisation that determines the purposes and means of processing Personal Data (In this policy, "we", "us", "our", SKYLARK WINDOWS LIMITED Company number 07397674).

  • Processor: An organisation that processes Personal Data on behalf of the Controller.

  • Third Party: Any individual or organisation other than you, the Controller, or authorised Processors. This includes our clients or partners with whom data might be shared (requiring your explicit consent for quote purposes).

  • GDPR: General Data Protection Regulation ((EU) 2016/679) and the UK equivalent (UK GDPR).

  • PECR: The Privacy and Electronic Communications Regulations (UK).

  • ICO: UK Information Commissioner's Office, the data protection regulator.

  • EEA: European Economic Area.


2. What Personal Data We Collect and Why

We collect and process Personal Data for specific purposes, relying on appropriate lawful bases as explained in Section 3. We are transparent about why we need the data at the point of collection. The table below outlines the main categories of data we might collect and typical purposes.

Data Category Example Purposes Notes on Lawful Basis (See Sec 3 for full details)
Identity Data (Name) To identify you when communicating; To personalise communications; To fulfil a service request. Consent / Performance of Contract / Legitimate Interest
Contact Data (Email, Phone, Address) To contact you about services/information you requested; To send marketing communications (see Marketing below); To share with partners for specific quotes (requires explicit opt-in). The postcode submitted for one offer (e.g., windows) is used first to check eligibility for that specific offer. If unsuccessful, the postcode is then used for the secondary purpose of checking eligibility for other relevant energy-saving home improvement offers available in your area. We process your postcode for this secondary check based on our legitimate interest in helping you find relevant energy-saving options; you have the right to object to this processing at any time by contacting us at [email protected] Consent / Performance of Contract / Legitimate Interest
Enquiry/Request Details To understand your needs for a specific product/service; To provide relevant information/quotes; To share with partners for specific quotes (requires explicit opt-in). Consent / Performance of Contract
Marketing Preferences To respect your choices about receiving marketing communications (opt-in or opt-out status). Consent / Legal Obligation / Legitimate Interest
Technical/Usage Data (IP Address, Browser type, page visits etc.) For essential website operation, security monitoring, basic performance analysis (anonymised where possible). Not used for tracking/profiling without explicit consent via Cookie banner. Legitimate Interest (Strictly Necessary) / Consent (for non-essential via Cookies)
AI Interaction Data To facilitate AI chatbot/voice bot interactions you initiate or consent to; To improve AI services (aggregated/anonymised or with consent if linked to you). Consent

Marketing Communications:

  • We will seek your explicit opt-in consent before sending you direct marketing communications if you are a new contact, or if required by law for specific channels or types of marketing.In the specific case of sending marketing via email, SMS or WhatsApp about similar products or services to individuals whose contact details we obtained in the course of a previous interaction or service provision (i.e., existing contacts), we may rely on the 'Soft Opt-In' exemption under PECR where legally permissible. This means we may send such communications unless you opted out at the time your details were collected, and you will always have a clear option to opt-out in every subsequent message. We rely on Legitimate Interest for this specific type of marketing.

  • Sharing data with third parties for their marketing always requires your explicit opt-in consent.


3. Lawful Basis for Processing

We only collect and use Personal Data when the law allows us to. The lawful basis we rely on depends on the specific processing activity and your relationship with us. We will make the basis clear at the point of collection where appropriate. Our potential lawful bases include:

  • Consent (Article 6(1)(a) GDPR): Where you have given us your clear, affirmative agreement ('Hard Opt-In') for processing for a specific purpose. This is our primary basis for:

    • Sharing your data with clients/partners for quotes on additional products/services.

    • Sending direct marketing to new contacts or where otherwise required.

    • Using non-essential cookies and tracking technologies.

    • Processing sensitive data (if ever applicable).

    • Specific AI interactions (e.g., proactive AI calls).

    • International data transfers (in combination with safeguards).

  • Performance of a Contract (Article 6(1)(b) GDPR): Where processing is necessary to fulfil a service you have requested or to perform a contract we have entered into with you (or to take steps at your request before entering a contract).

  • Legal Obligation (Article 6(1)(c) GDPR): Where processing is necessary for compliance with a legal duty to which we are subject (e.g., responding to legal authorities, tax obligations).

  • Legitimate Interests (Article 6(1)(f) GDPR): Where processing is necessary for our legitimate interests (or those of a third party), provided these interests are not overridden by your fundamental rights and freedoms. We use this basis carefully and conduct assessments (LIAs) where appropriate. Examples include:

    • Essential website security monitoring and fraud prevention.

    • Basic server logging for diagnostics.

    • Internal analysis of aggregated/anonymised data to improve services.

    • Marketing similar products/services via email/SMS to existing contacts under the 'Soft Opt-In' exemption (PECR), where applicable and subject to your right to opt-out (see Section 2).

    • Managing our relationship with business clients (e.g., CRM, service updates).

  • We do not rely on legitimate interests for sharing your data with third parties for their marketing, using non-essential tracking cookies, or processing sensitive data.


4. Our Roles under GDPR (Controller and Processor)

Depending on the specific service, SKYLARK WINDOWS LIMITED Company number 07397674 may act as either a 'Controller' or a 'Processor' under GDPR.

  • We act as a Controller for the Personal Data we collect directly from you via our website for our own purposes (like managing your requests or sending marketing you consented to).

  • We may act as a Processor when we handle Personal Data strictly on behalf of and under the instruction of our business clients as part of a contracted service.

This policy primarily addresses our activities as a Controller, but the principles of data protection apply to all processing we undertake.


5. How We Collect Your Personal Data

We collect Personal Data through various methods, depending on the context:

  • Directly from you: When you actively provide it by filling in forms, interacting with consent mechanisms (opt-in boxes), contacting us, or using interactive features.

  • Automatically: Essential technical data is collected when you browse our website. Non-essential data via cookies/trackers is only collected after your explicit opt-in via our consent banner.

  • From Third Parties: We may receive data from:

    • Third-party platforms and sources: We may receive data via platforms such as Facebook, LinkedIn, Instagram, advertising partners (e.g., PPC, SEO, Taboola, Criteo), or affiliates, but only if you have explicitly consented (either via the platform's settings, directly on an advertisement form linked to us, or through other clear means) for your information to be shared with SKYLARK WINDOWS LIMITED Company number 07397674 for a specific purpose.

    • Clients/Partners: (e.g., providing contact details for us to act as a Processor on their behalf, under contract).

    • Publicly available sources: (rarely, and typically only for B2B contact verification, relying on Legitimate Interests where appropriate and compliant).


6. Legitimate Interests for Direct Marketing

We may process your personal data under the lawful basis of Legitimate Interests (Article 6(1)(f) UK GDPR).

Our legitimate interests include promoting and offering home-improvement products and services that are likely to be relevant to you, such as windows, doors, solar panels, insulation, and heat-pump solutions.

When you provide your details to request a quote or further information, we use them to:

  • respond to your enquiry;

  • keep in touch about your request; and

  • contact you by telephone, email, SMS, WhatsApp, or post about related home-improvement offers that may be of interest.

We carefully balance our business interests with your rights and expectations. We only contact you about products that are reasonably connected to your original enquiry, we check numbers against the Telephone Preference Service before calling, and you can object to or opt out of marketing at any time.

If you wish to object to this processing or withdraw from marketing, you can contact us at [email protected]. We have completed a Legitimate Interests Assessment (LIA) which explains how we protect your rights; a summary is available on request.


7. Special Category Data (Not Currently Collected)

We do not currently collect 'special category' data (e.g., health details, ethnicity, political opinions). If we ever need to collect such data for a specific service in the future, we will only do so with your explicit prior consent under the strict conditions of Article 9 GDPR, for a clearly stated purpose.


8. Use of AI (Artificial Intelligence) – Requires Your Opt-In

We may use AI technologies to enhance efficiency and communication. Your control and consent are paramount:

  • AI Chatbots/Messaging: Use of AI bots for web chat, WhatsApp, SMS etc. requires your prior interaction and/or consent. You typically initiate the chat or agree to communicate via that channel knowing AI may assist. AI assistance will be made clear where possible.

  • AI-Powered Calling & Voice Bots: We will only use AI-powered calling or voice bots to contact you (e.g., for confirmations, follow-ups) if you have explicitly consented to this method of communication.

  • AI-Driven Analysis: Analysis of interaction data linked to your Personal Data (beyond aggregated/anonymised statistics for general service improvement) requires your explicit consent.

  • Your Rights: You have the right not to consent or to opt-out of specific AI interactions (like AI calls) at any time without penalty. You can request human intervention. All your standard data rights apply. See Section 18 for details.


9. Cookies and Similar Technologies – Requires Your Opt-In

Our website uses cookies and may use similar technologies (like pixels or scripts).

  • Strictly Necessary Cookies: We only use cookies essential for basic website functionality by default. These do not require your consent but do not collect identifiable tracking information.

  • Non-Essential Cookies & Technologies: For all other cookies and tracking technologies (e.g., analytics, marketing, performance, third-party embeds), we require your explicit, affirmative opt-in consent via our cookie banner/management tool before they are placed or activated on your device.

  • Managing Preferences: You can review the types of cookies used and manage your preferences at any time via our cookie banner/management tool. Refusing non-essential cookies will not prevent you from using the core functionality of our website.

Please see our separate Cookie Policy at for full details.


10. Automated Decision Making

We do not currently use your Personal Data for fully automated decision-making (decisions made solely by machines without human involvement) that produces legal or similarly significant effects on you. If AI assists in initial filtering or qualification for services, significant decisions involve human oversight. Should this change, we would only implement such systems with your explicit prior consent and provide clear information and rights to contest decisions or request human intervention.


11. Data Sharing with Third Parties – Requires Your Explicit Consent for Key Sharing

Your trust is paramount. We are open about how and why your data is shared, with whom, and what we receive in return.

How our business works

SKYLARK WINDOWS LIMITED Company number 07397674 is a lead generation business. When you request a quote or further information about a home improvement product or service, we share your details with companies who provide that product or service in your area. Those companies pay us a fee for the introduction. This is our primary commercial model and we want you to understand it before you submit any details.
We will only share your data in this way if you give us your explicit, granular Hard Opt-In consent for each specific product or service at the point of sharing.

Who we share your data with for quotes

Depending on the product or service you have asked about, your details may be shared with one or more companies in the following categories:

  • Solar PV and battery storage installers (typically MCS certified)
  • Domestic insulation installers (cavity wall, loft, internal/external wall, under floor)
  • Heat pump and renewable heating installers
  • Boiler installation and replacement companies
  • Window, door and conservatory installers (FENSA or CERTASS registered where applicable)
  • Roofing and roof coating contractors
  • Driveway, patio and resin surfacing contractors
  • Home security providers
  • Energy switching and tariff comparison services
  • FCA authorised finance brokers (where finance options are part of the quote)
  • Trade matching and quote comparison platforms acting on behalf of the above categories

A current list of the specific companies in our partner network is available on request by emailing [email protected]. We update this list as our partner network changes.

What partners can and cannot do with your data

Once we share your data with a partner under your consent, that partner becomes an independent Controller of your data. This means:

  • They are responsible for how they use your data from that point on
  • Their use of your data is governed by their own privacy policy, which they are required to provide to you
  • They may only use your data for the specific purpose you consented to (for example, contacting you about a solar quote), unless you separately agree to other uses with them directly
  • They are not permitted under our partner agreements to pass your data on to any further company without obtaining a fresh, specific consent from you first
  • They are required to honour any opt out, erasure request or other data subject right you exercise with them directly

If a partner contacts you outside the scope of your original consent, or passes your details on without your permission, please let us know at [email protected] and we will investigate and take appropriate action, which may include removing that partner from our network.

Service providers (Processors)

We also use trusted third party service providers who process data strictly on our behalf, under written Data Processing Agreements, and only on our instructions. These providers do not become independent Controllers and cannot use your data for their own purposes. Categories include:

  • IT support, cloud hosting and telecommunications providers, primarily located in the UK or EEA
  • Customer Relationship Management (CRM) system providers
  • Email, SMS and messaging platforms used to deliver communications you have consented to or that fall within the soft opt in
  • Analytics providers (for example Google Analytics, only where you have given cookie consent)
  • Telephony, call recording and call quality providers
  • Identity verification, fraud prevention and TPS screening providers
  • Payment processors, where applicable
  • Recruitment platforms, if you apply for a role with us
Marketing service providers

We only share your data with third parties for their own marketing purposes if you have given specific, explicit opt in consent for that sharing.

Legal requirements and vital interests

We may disclose your data where we are legally required to do so (for example, to law enforcement, regulators, courts, or to comply with a statutory obligation), or in rare circumstances to protect the vital interests of you or another person.

What we receive in return

We want to be transparent that we receive a commercial fee from partner companies when we introduce a qualified enquiry to them. This fee does not change the price you pay for any product or service the partner offers, and it does not affect your rights under this policy or under data protection law. The fee is paid for the introduction itself, not for ongoing access to your data.

Your control

At any point you can:

  • Withdraw consent for sharing by emailing [email protected]
  • Ask us for the current list of partner companies
  • Exercise any of your data protection rights set out in Section 18, both with us and directly with any partner who has received your data

Withdrawing consent will not affect any sharing that has already taken place lawfully under your prior consent, but it will prevent any further sharing of your details by us going forward.


12. International Data Transfers – Requires Consent & Safeguards

Your Personal Data is primarily stored and processed within the United Kingdom (UK) and the European Economic Area (EEA).

We will only transfer your Personal Data outside the UK/EEA if:

  • You have explicitly consented to the specific processing activity that necessitates such a transfer, having been informed of the potential risks; AND

  • Appropriate safeguards are in place (e.g., Adequacy Decision, Standard Contractual Clauses/IDTA, BCRs).

Any transfer will be made securely and only for the consented purpose or necessary contractual step.


13. How Long We Keep Your Information (Data Retention)

We retain your Personal Data only for as long as is reasonably necessary to fulfil the specific purpose(s) for which it was collected (based on consent or another lawful basis), or as required by law. Our internal data retention schedule guides specific periods.

  • Consent-Based Data: Kept until consent is withdrawn or purpose fulfilled, then deleted/anonymised (unless legal hold applies).

  • Illustrative Periods:

    • Data for providing a quote/service might be kept for a reasonable period post-interaction.

    • Marketing contact data: Kept while consent is active or soft opt-in applies. Opt-outs are moved to a suppression list (kept indefinitely only to respect the opt-out). Other data deleted/anonymised after a reasonable period of inactivity.

    • Legal Compliance Data: Kept for legally mandated periods

  • Review & Secure Disposal: We periodically review data holdings and have processes for secure disposal when data is no longer required.


14. Security of Your Personal Information

We take protecting your privacy and data security extremely seriously. We implement appropriate technical and organisational measures designed to protect your Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures are based on risk assessment and include:

  • Implementing technical measures like data encryption (in transit and at rest where appropriate), using up-to-date and supported secure software, deploying anti-malware solutions.

  • Applying organisational measures like role-based access controls (limiting access to personnel with a need-to-know), robust password policies, secure deletion procedures for data no longer needed, appropriate backup and disaster recovery solutions, storing physical documents securely (e.g., lockable cabinets), regular staff training on data security and confidentiality, and performing due diligence on our third-party processors.

While we strive for security, no system is 100% impenetrable.


15. Data Breach Handling

We have procedures in place to detect, investigate, and respond to potential personal data breaches. In the event of a breach likely to risk your rights and freedoms, we are committed to notifying the Information Commissioner's Office (ICO) without undue delay (within 72 hours where feasible). Where a breach is likely to result in a high risk to you, we will also aim to inform you directly without undue delay, providing information about the breach and the steps you can take.


16. Data Protection by Design

We are committed to implementing 'Data Protection by Design and by Default'. This means we integrate data protection considerations into the design and operation of our services, processes, and systems from the outset, aiming to minimise data collection and build in privacy safeguards.


17. Children's Information

Our services are not for individuals under 16. We do not knowingly collect their data. Contact our DPO if you believe this has occurred.


18. Your Data Protection Rights

Under GDPR, you have rights including:

  • Be Informed: (This policy aims to do this).

  • Access: Request a copy of your data.

  • Rectification: Correct inaccurate data.

  • Erasure: Request deletion under certain conditions.

  • Restrict Processing: Request temporary halt on processing.

  • Data Portability: Obtain/reuse your data provided under consent/contract.

  • Object: Object to processing based on legitimate interests (absolute right for direct marketing).

  • Withdraw Consent: Withdraw consent easily at any time (see Section 19).

  • Rights re: Automated Decisions: Not be subject to solely automated decisions with significant effects.

Exercising Your Rights: Contact our DPO (Section 24). We aim to respond to all legitimate requests within one calendar month of receipt. We will need to verify your identity before processing your request. Access requests are usually free, but fees or refusals may apply to unfounded, excessive, or repetitive requests.


19. Your Consent and Choices: Opt-In and Opt-Out

We respect your choices about how your data is used.

  • Explicit Consent ('Hard Opt-In'): As stated, this is required for key activities like sharing data for quotes with partners, specific AI uses, non-essential cookies, and generally for marketing to new contacts. Where required, we use clear, unticked opt-in boxes or similar affirmative actions.

  • Soft Opt-In Exemption / Opt-Out: In the limited case of marketing similar products/services via email/SMS to existing contacts (where details obtained during service provision and opt-out offered), we may rely on this exemption (based on Legitimate Interest) unless you opt-out.

  • Withdrawal / Opting Out: You have the absolute right to withdraw your consent or opt-out of marketing at any time. This is designed to be as easy as giving consent/not opting out initially. You can do so via:

    • 'Unsubscribe' links in emails.

    • Replying 'STOP' to SMS messages.

    • Contacting our DPO directly (see Section 24).

Withdrawal/opt-out is effective going forward and does not affect past lawful processing.


20. Consequences of Not Providing Consent or Information

You are not obliged to provide data or consent. However, choosing not to opt-in or provide necessary data may mean:

  • We cannot provide the specific service/information requiring that consent/data (e.g., share details for a quote).

  • We cannot fulfil related contractual elements.

  • We cannot send you marketing communications you haven't opted into (unless the narrow soft opt-in exemption applies and you haven't opted out).

We clarify necessities at the point of collection.


21. Change of Control or Sale

If SKYLARK WINDOWS LIMITED Company number 07397674 is sold or merged, user data may be transferred. The new entity must use your data according to this policy unless you agree otherwise or are notified of changes.


22. Links to Other Websites

Our site may link to third-party sites. We are not responsible for their privacy practices. Review their policies.


23. Right to Complain

Please contact our DPO first (Section 24) with any concerns. You also have the right to complain to the ICO (details below):

  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

  • Website: www.ico.org.uk


24. Contact Us

For questions, rights requests, or more information, contact our Data Protection Officer:

  • Email: [email protected]

  • Post: Data Protection Officer, SKYLARK WINDOWS LIMITED Company number 07397674, 673 Romford Road, Manorpark, London, E12 5AD

  • Phone: +44 20 8514 6978


25. Policy Review and Amendments

This policy is reviewed regularly and may be updated.

Last updated: 16th October 2025.

We will notify you of substantial changes via email/notice on our Service where feasible. Please review periodically.

Copyright 2026 Gliphorax - All Rights Reserved. | Privacy Policy

Company: SKYLARK WINDOWS LIMITED Company number 07397674

Address: 673 Romford Road, Manorpark, London, E12 5AD

Email: [email protected]

Phone: +44 20 8514 6978