A laptop repair workshop holds two quite different kinds of information about you. There are the ordinary details you give us when you book a repair, and there is whatever happens to be stored on the machine you hand over. This policy covers both, and it is written to be read rather than skimmed.
It applies to this website, to our nationwide tracked mail-in service and to walk-in repairs at our London workshop. Read it alongside our Cookie Policy, which covers what this site stores in your browser, and our Terms & Conditions, which govern the repair itself.
Who we are and how to contact us
LaptopHaber.com is the data controller for the personal data described here. That means we decide why your data is collected and how it is used, and we are legally answerable for it under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We have been repairing laptops since 2014, and you can read more about the workshop on our about page.
Our workshop and correspondence address is Unit 12, Riverside Workshops, 84 Long Lane, London, SE1 4AU, United Kingdom. For anything to do with your data, email hello@laptophabers.com marked for the attention of the Data Protection Lead, or call 020 7946 0958 during workshop hours.
We are not required to appoint a statutory Data Protection Officer. We are not a public authority, and our core activity is repairing hardware rather than large-scale monitoring or processing of special category data. Responsibility for data protection instead sits with a named member of the management team, and the buck stops there.
What personal data we collect
We collect only what a repair actually needs. In practice that falls into five groups.
Enquiry and booking data
When you complete the form on our contact page, call us or send an email, we record your name, email address, telephone number, the make and model of your laptop, your description of the fault and, for mail-in jobs, the collection and return address. If you send photographs of the damage, we keep those with the enquiry.
Repair intake records
Once a machine reaches the bench we open a job record. It holds the device serial number or service tag, the MAC address where a network fault is involved, photographs of the condition on arrival, the diagnostic findings, the parts fitted, the engineer who carried out the work and the date of every stage. Serial numbers matter to us for three reasons: warranty claims with suppliers, matching the correct part, and proving that the laptop we hand back is the one you left.
Payment data
Card payments run through our payment provider's terminal and gateway. We see the amount, the card type, the last four digits and an authorisation reference. We never see or store your full card number, its expiry date or the security code. Bank transfers show us your account name and the reference you used.
Website data
Our server logs record IP addresses, browser and device type, the pages requested and the time of each request. Anything beyond that, including analytics, is set only if you have agreed to it. The Cookie Policy lists every cookie by name.
Data stored on your device
This is the group that matters most, and the one most repair shops skip over. Repairing a laptop often requires an engineer to power it on, sign in, run diagnostics and confirm that the fix holds. That necessarily gives the engineer the ability to reach the files, photographs, emails, browser history and saved passwords on the storage device. We do not go looking through your data, but we would be misleading you if we claimed a machine could be properly tested without that access being possible.
How a repair workshop actually handles your data
Rather than promise vaguely that your data is safe, here is what the workshop actually does with it.
- A sector-level image before board-level work. Before any microsoldering, board replacement or drive swap, we take a full sector-level image of the storage device onto a dedicated workshop array. That gives us a copy which predates anything we do, so a repair can always be rolled back. Be aware that such an image copies everything on the drive, including deleted files that have not yet been overwritten.
- We work on the copy, not the original. On data recovery jobs the original drive is read once and then set aside. Every recovery attempt runs against the image, so nothing we try can make your original worse.
- Locked storage. Customer drives and drive images are kept in a locked cabinet in a restricted area of the workshop. The imaging array is encrypted at rest and is not connected to the office network or the public internet.
- Logged access. Each of our 14 engineers works under a named account. Opening a job record, mounting a customer image or connecting a customer drive is logged against that account with a timestamp and a job number. Access is granted per job, not by default.
- A deletion schedule we keep to. Drive images are securely erased 30 days after your laptop is collected or returned, and 90 days on data recovery jobs where you may need a second copy. Erasure means a verified overwrite, not a file deletion. Ask us to wipe your image earlier and we will do it the same working day and confirm in writing.
- No browsing, no copying, no sharing. Engineers open your files only where the fault requires it, for example to check that a recovered user profile loads. Copying customer material to personal storage is a dismissible offence, and every engineer signs a confidentiality undertaking on joining.
Two things reduce what we ever see. Back up and sign out of your cloud accounts before you hand the machine over, and tell us at intake if the laptop holds legally privileged, medical or commercially sensitive material so the job can be flagged for restricted handling. If the drive is encrypted with BitLocker or FileVault, keep the recovery key yourself and share it only if the repair genuinely needs it. Our repair guides walk through backing up before a repair.
Our lawful bases under UK GDPR
Article 6 of the UK GDPR requires a lawful basis for every purpose we process data for. Ours are set out below.
| What we do with your data | Lawful basis |
|---|---|
| Quote for, carry out and return a repair you have asked for | Contract, Article 6(1)(b) |
| Access the contents of a storage device where the repair requires it | Contract, Article 6(1)(b), limited to what the job needs |
| Take payment and issue a receipt or invoice | Contract, Article 6(1)(b) |
| Keep job records so we can honour the 12-month parts-and-labour warranty | Legitimate interests, Article 6(1)(f) |
| Website security, fraud prevention and server logging | Legitimate interests, Article 6(1)(f) |
| Analytics and other non-essential cookies | Consent, Article 6(1)(a), and PECR regulation 6 |
| Marketing emails about repair services | Consent, Article 6(1)(a), with an unsubscribe link in every message |
| Accounting, VAT and statutory record keeping | Legal obligation, Article 6(1)(c) |
Where we rely on legitimate interests we have weighed our interest against your rights and concluded that you benefit directly. We could not settle a warranty claim a year from now without the job record that proves what we fitted. You can object to that processing at any time, and we explain how below.
We do not ask for special category data. A repair can still expose it, for example a medical letter sitting in a documents folder. We do not read, use or retain such material. It is incidental to the repair and is covered by the confidentiality and deletion rules above. If a machine in our possession is reported stolen, or an engineer encounters material we are legally obliged to report, we will comply with the law. That is rare, and we will not volunteer your data in any other circumstances.
How long we keep each category, and why
| Category | Retention | Reason |
|---|---|---|
| Enquiries that never become a repair | 12 months | So we can pick up the thread if you come back, and evidence what was quoted |
| Repair job records | 6 years | The 12-month warranty plus the six-year limitation period for contract claims |
| Invoices, receipts and VAT records | 6 years after the accounting period ends | HMRC and Companies Act 2006 requirements |
| Sector-level drive images | 30 days after return, 90 days for data recovery | Long enough to roll a repair back, then destroyed |
| Uncollected customer drives and devices | 90 days after written notice | Then securely erased and recycled under our terms |
| Marketing consent records | Until you unsubscribe, plus 2 years | To prove that consent existed if it is ever questioned |
| Website server logs | 30 days | Security monitoring and abuse investigation |
| Workshop CCTV covering goods-in and the benches | 31 days | Security of customer property and stock |
When a retention period ends, records are deleted or anonymised. Where a copy survives inside an encrypted backup we put it beyond use, which means nobody can access it for any purpose, and it is destroyed on the next backup rotation.
Who we share your data with
We do not sell your personal data. We do not rent it, and we do not pass it to data brokers or advertising networks. The only third parties who see any of it are the ones needed to complete your repair or to keep us lawful.
- Our payment processor handles card authorisation. Your card details go to them directly; we receive only the confirmation and the last four digits.
- Couriers used for mail-in repairs receive your name, address, telephone number and email so they can collect and deliver. They are told nothing about the fault or the contents of the machine.
- Parts suppliers and manufacturers receive the model and, for warranty or recall parts, the serial number. They are not given your name or address unless a manufacturer claim requires it, and we ask you before we make one.
- Our accountants see invoices and payment records while preparing statutory accounts and VAT returns.
- Hosting, email and job-management suppliers may have incidental access while maintaining the systems those records sit in.
- Insurers, solicitors or the police only where the law requires it, or where a claim is made and we have to defend it.
Every supplier that processes data on our behalf does so under a written contract meeting Article 28 of the UK GDPR. They act only on our documented instructions, keep the data confidential, apply appropriate security, and delete or return it when the contract ends.
International transfers
Job records, drive images and customer devices stay in the United Kingdom. Some everyday services we rely on, such as website hosting, email and analytics, are supplied by companies whose infrastructure or support teams sit outside the UK, usually in the European Economic Area or the United States.
Where personal data does leave the UK we rely on a safeguard permitted by Chapter V of the UK GDPR: either a UK adequacy decision, which covers the EEA, or the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. Customer drive images are never transferred abroad. Ask us in writing and we will tell you which supplier holds what, and which safeguard applies.
Your rights under UK GDPR
These rights are free to exercise, and using them will never affect the price, priority or quality of your repair.
- Access. Ask for a copy of the personal data we hold about you, and an explanation of what we do with it.
- Rectification. Have inaccurate data corrected and incomplete data completed.
- Erasure. Ask us to delete data we no longer have a reason to hold.
- Restriction. Ask us to pause processing while an accuracy dispute or an objection is resolved.
- Portability. Receive the data you gave us in a structured, commonly used, machine-readable format, or have it sent to another provider, where the processing is automated and based on consent or contract.
- Objection. Object to processing based on legitimate interests. For direct marketing the right is absolute and we must stop immediately.
- Withdraw consent. Withdraw it at any time, which does not affect the lawfulness of anything done beforehand.
The right to erasure is not absolute. We cannot delete an invoice HMRC requires us to keep, or a job record we need in order to defend a claim within the limitation period. Where that happens we will tell you plainly which parts we can delete, which we cannot, and why.
To exercise any right, email hello@laptophabers.com or write to the workshop address above. We may ask for proof of identity, because releasing a device history to the wrong person would itself be a breach. We respond within one month of receiving a valid request. If a request is unusually complex, or you have made several, we may extend by up to two further months, and we will tell you inside the first month if we do.
Automated decision-making and profiling
We carry out no automated decision-making that produces legal or similarly significant effects, and we do not profile you. Diagnostic software reports symptoms; a qualified engineer decides what the fault is and what it will cost. The figures on our pricing page are published ranges, and the quote you receive is written by the person who examined your machine.
Children's data
Our services are sold to adults and we do not market to children. We do not knowingly collect personal data from anyone under 16. Where a laptop belongs to a child we deal with the parent, guardian or school who brought it in, and the contents are treated with the same confidentiality as any other job. If you believe we hold a child's data that we should not, tell us and we will delete it.
How we keep your data secure
- TLS encryption on this website and on every enquiry form submission.
- Full-disk encryption on engineer workstations and on the imaging array, which stays off the public network.
- Named accounts, multi-factor authentication on email and job management, and access granted job by job rather than across the board.
- Access control on the workshop door, locked cabinets for customer devices, and CCTV covering goods-in and the benches.
- Verified secure erasure of any drive before disposal, followed by certified recycling.
- Confidentiality clauses in every contract of employment, with data protection training at induction and refreshed each year.
- Encrypted, tested backups and a written incident response plan.
No system is perfect and we will not pretend otherwise. If a breach occurs that is likely to risk your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and we will tell you directly, without undue delay, where the risk to you is high.
Complaints and the Information Commissioner's Office
If you are unhappy with how we have handled your data, tell us first. Most problems turn out to be a misunderstanding we can fix the same week. Email hello@laptophabers.com with "Data protection complaint" in the subject line. We acknowledge within five working days and aim to resolve within one month.
You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office, at any time and without coming to us first. The ICO is at ico.org.uk, on 0303 123 1113, or by post at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Complaining costs nothing and does not affect your other legal remedies, including the right to seek compensation through the courts.
Changes to this policy
We update this policy when the way we work changes, when the law changes, or when a section turns out not to be clear enough. The current version is dated 23 September 2026. Material changes, such as a new category of data, a new supplier with access to customer files, or a different retention period, will be flagged at the top of this page for at least 30 days, and we will email you directly if you have an open job with us at the time.
Previous versions are archived and we will send you one on request, so you can see what applied when you booked. Read this policy together with our Terms & Conditions, which set out the repair contract, our Cookie Policy, and the service descriptions on our services page.
Questions about this page? Write to hello@laptophabers.com or post to Unit 12, Riverside Workshops, 84 Long Lane, London SE1 4AU, United Kingdom. We reply to every written enquiry within five working days.