Avanti Doors Policy
1Our role and scope
Controller
Avanti Doors Ltd, Unit 19, East Coast Business Park, West Lynn, Norfolk, PE34 3LW, is the controller for personal information it collects through this website and uses to manage enquiries and services.
Applicable framework
Our approach is based on the UK General Data Protection Regulation, the Data Protection Act 2018 as amended, and applicable rules on electronic communications and cookies.
Detailed notice
Our Website Privacy Policy gives the fuller information about categories of data, purposes, lawful bases, recipients, international processing, retention criteria and individual rights.
2Data-protection principles
We apply the following principles to website enquiries and related records:
Lawfulness, fairness and transparency
We identify and document an appropriate lawful basis for each purpose, explain our uses in plain language and do not use website enquiry information for an incompatible hidden purpose.
Purpose limitation
We collect website enquiry information to respond, quote, provide requested services, maintain security and meet applicable legal obligations. A form submission is not treated as marketing consent.
Data minimisation
Forms ask for information relevant to the requested work. The website stores the enquiry source and a random submission identifier, but does not retain the raw request IP address or full user-agent string in the enquiry database.
Accuracy
We take reasonable steps to keep operational and customer records accurate and provide a route for people to request corrections.
Storage limitation
Retention is based on the purpose of the enquiry, whether work is instructed, warranty and customer-record needs, and applicable legal or claims periods. Information is deleted or anonymised when it is no longer needed.
Integrity and confidentiality
We use proportionate technical and organisational controls, including access restrictions, encrypted connections, private upload storage, file validation and form-abuse controls.
Accountability
We review our purposes, suppliers and security arrangements and update our public privacy information when material practices change.
3Lawful bases
Contract and pre-contract steps
When someone asks for a quotation, requests work or reports an issue under an existing customer relationship, we use information that is necessary to take the requested steps or perform a contract.
Legitimate interests
For proportionate general-enquiry administration and website security, we may rely on legitimate interests in responding to people who contact us, maintaining business records, preventing abuse and operating a reliable service. We consider necessity, reasonable expectations and the effect on individual rights.
Legal obligation and legal claims
We may process information where required by law, regulation, accounting or taxation duties, or where needed to establish, exercise or defend legal claims.
Consent
Consent is used for optional website analytics, heatmaps and privacy-masked session recordings. These tools are denied by default and are not a condition of using the website or submitting a form. They can be rejected or withdrawn through Cookie settings.
4Systems and suppliers
Enquiry workflow
Cloudflare Workers processes form submissions, Cloudflare D1 stores the durable enquiry record, and private Cloudflare R2 storage holds accepted uploads. Resend sends internal notification email and Zendesk provides the service-team ticketing workflow.
Security checks
Cloudflare Turnstile is used when configured to assess whether a submission appears automated. A honeypot, minimum submission time, field limits, upload limits and duplicate-submission identifiers provide additional practical abuse controls.
Optional analytics
Google Analytics measures website visits and configured interaction events, including successful enquiry outcomes. Microsoft Clarity provides heatmaps and session recordings with Strict masking, so page text and form contents are masked before transmission. Both services load only after analytics consent; advertising storage and personalisation are not enabled by this website.
Supplier oversight
We limit each provider to a defined operational purpose and review relevant contractual, security, retention and international-transfer arrangements. Supplier failure does not remove a successfully stored D1 enquiry record.
5Individual rights
Requests
Depending on the circumstances, individuals may have rights of access, rectification, erasure, restriction, objection and portability, and the right to withdraw consent where consent applies. Rights are subject to the conditions and exemptions in data-protection law.
Right to object
Individuals may object to processing based on legitimate interests. The right to object to direct marketing is absolute; website enquiry forms do not enrol people into marketing by default.
Contact and complaints
Requests or questions can be sent to service@avantidoors.co.uk or made by calling 01553 615608. Individuals can also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or on 0303 123 1113.
6Review and updates
Keeping information current
We review this summary and the Website Privacy Policy when website forms, processors, analytics settings, retention practices or legal requirements materially change. The detailed Privacy Policy records its last-updated date.





