Privacy Policy – Protyre (Micheldever Tyre Services Limited)

This page details our privacy policy. The key points to note are:

  • We will never sell your data.

  • Your data will be kept secure.

  • You can request access to your data at any time.

  • You can stop all processing of your personal data at any time.


1. Introduction

Micheldever Tyre Services Limited, trading as Protyre (“Protyre”, “we”, “us”, “our”), is committed to protecting your personal data and respecting your privacy.

This Privacy Policy explains how we collect, use, store and protect your personal data when you interact with us, including through our website, in-centre services, and communications.

We process personal data in accordance with:

  • UK General Data Protection Regulation (UK GDPR)

  • Data Protection Act 2018

  • Privacy and Electronic Communications Regulations (PECR)


2. Data Controller

Micheldever Tyre Services Limited
Micheldever Station, Winchester, Hampshire, SO21 3AP
Company Number: 01817398

Data Protection Officer (DPO):
Email: dpo@micheldever.co.uk

Telephone: 01926 816 799


3. Personal Data We Collect

We may collect the following categories of personal data:

3.1 Information you provide

  • Name

  • Address and postcode

  • Email address

  • Telephone numbers

  • Vehicle registration, make and model

3.2 Technical data

  • IP address

  • Browser type and version

  • Operating system

  • Website usage data (e.g. pages visited, referring URLs)

3.3 Data from third parties

We may obtain limited personal data from trusted third‑party providers such as Experian Limited for marketing prospecting purposes. This data typically includes:

  • Name

  • Postal address

We do not obtain payment or financial data from these sources.

Experian acts as an independent data controller. You can find their privacy information here:
https://www.experian.co.uk/privacy/consumer-information-portal/


4. How We Use Your Personal Data

We use personal data only where permitted by law, and always on a valid lawful basis.

4.1 Contractual necessity

To:

  • Process and fulfil orders

  • Provide services and reminders (e.g. MOT, tyres, servicing)

  • Manage warranties and safety recalls

4.2 Legal obligation

To comply with:

  • Accounting and tax requirements

  • Regulatory or legal requests

4.3 Legitimate interests

We process data where it is necessary for our legitimate business interests, including:

  • Improving our services and website

  • Fraud prevention and security

  • Customer insight and analytics

  • Marketing relevant products and services

Balancing test:
We carefully assess that our use of personal data is proportionate, expected, and does not override your rights and freedoms. You have the right to object at any time (see Section 10).

4.4 Consent

We rely on consent where required, particularly for:

  • Email and SMS marketing (where PECR applies)

  • Optional communications or preferences

You may withdraw consent at any time.


5. Marketing Communications

We will send electronic marketing (e.g. email and SMS) only in accordance with PECR, and we will send postal marketing in accordance with UK GDPR.

You can object to postal marketing at any time by contacting us or using the opt-out methods we provide, and we maintain suppression lists to ensure we respect your preferences.

Your controls

You can:

  • Opt out using unsubscribe links

  • Contact us directly to stop all marketing

We may still send essential service communications (e.g. bookings, safety notices).


6. Profiling and Personalisation

We may analyse your data (such as service history or vehicle type) to:

  • Provide tailored reminders

  • Recommend relevant services

This does not involve automated decisions with legal or significant effects.

You have the right to object to profiling at any time.


7. Data Sharing

We may share your personal data with trusted third parties where necessary, including:

  • Payment processors

  • CRM and IT system providers

  • Marketing platforms (e.g. email providers)

  • Analytics providers (e.g. Google Analytics)

  • Credit reference agencies (e.g. Experian)

  • Logistics and service partners

  • Legal and regulatory authorities

All third parties are contractually required to:

  • Process data only on our instructions

  • Maintain appropriate security

  • Comply with data protection law

We do not sell your personal data.


8. International Transfers

Where personal data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place, such as:

  • UK adequacy regulations

  • Standard Contractual Clauses (SCCs)

  • Transfers under recognised frameworks (where applicable)


9. Data Retention

We retain personal data only as long as necessary:

  • Customer and transaction data: up to 7 years (legal and accounting obligations)

  • Marketing data: up to 7 years from last interaction

  • Technical logs: up to 7 years

  • Fraud prevention: variable depending on risk

We regularly review retention periods.


10. Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data

  • Correct inaccurate data

  • Request deletion (“right to be forgotten”)

  • Restrict processing

  • Object to processing (including marketing and profiling)

  • Data portability

  • Withdraw consent at any time

To exercise your rights, contact: dpo@micheldever.co.uk

You also have the right to complain to the Information Commissioner’s Office (ICO):
https://www.ico.org.uk


11. Data Security

We implement appropriate technical and organisational measures, including:

  • Encryption of data in transit and at rest

  • Access controls and role-based permissions

  • Secure system architecture (e.g. cloud infrastructure)

  • Monitoring and logging of access

  • Staff training and confidentiality obligations

While we take all reasonable steps, transmission over the internet is not completely secure.


12. CCTV

Some of our service centres use fixed CCTV to help protect customers, colleagues and our premises, deter and detect crime, and investigate incidents.

Lawful basis: Legitimate interests (site and people security, fraud and crime prevention). Where relevant, we may also process footage to comply with legal obligations or to establish, exercise or defend legal claims.

Retention: Footage is usually kept for up to 30 days (and may be shorter depending on system settings). If needed for an incident, request or legal matter, we may retain relevant footage for longer for as long as necessary.

Sharing and access requests: We may share relevant footage with insurers, professional advisers, law enforcement or regulators where lawful. To request access to footage relating to you, contact our DPO (see Section 2). We may verify your identity and protect others’ rights (for example by redacting third parties).


13. Cookies and Tracking

Our website uses cookies and similar technologies to:

  • Enable functionality

  • Analyse usage

  • Improve user experience

For full details, see our Cookie Policy.

You can manage cookie preferences through your browser settings.


14. Third-Party Websites

Our website may contain links to third-party sites. We are not responsible for their privacy practices and encourage you to review their policies.


15. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted on our website and, where appropriate, notified to you.