OptiTech Automation · Last updated: 17 July 2026
> Reviewed against current UK law; under ongoing internal review. Not formal legal advice.
Last updated: 17 July 2026This notice is provided in accordance with Article 14 of the UK General Data Protection Regulation (UK GDPR). It explains how OptitechAutomation and the trade business ("Business") whose booking page you have visited handle your personal data.
When you make a booking through the OptitechAutomation platform, two organisations receive your personal data:
OptitechAutomation (a UK sole trader — the personal business of Cristian Moise-Putanu, Torquay, Devon, United Kingdom) acts as a data processor on behalf of the Business. We operate the booking technology and store your booking records on the Business's behalf. The Business (the trade business whose page you are booking through) acts as the data controller for your personal data. They determine the purpose of your appointment and have the primary relationship with you as a customer.When you submit a booking enquiry or confirm a booking, the following personal data is collected and shared:
Payment card data is processed directly by Stripe and is not shared with the Business or stored on our servers.
We collect this data directly from you when you complete the booking form on the Business's booking page.
| Purpose | Lawful Basis |
|---|---|
| --------- | ------------- |
| Processing and confirming your booking | Article 6(1)(b) — contract performance |
| Sending appointment reminders and status updates | Article 6(1)(b) — contract performance |
| Fraud prevention and platform security | Article 6(1)(f) — legitimate interests |
| Retaining financial records (HMRC compliance) | Article 6(1)(c) — legal obligation |
Your personal data is retained as follows:
Your data may be shared with:
We do not sell your data or use it for advertising purposes.
Under UK GDPR, you have the right to:
To exercise any of these rights, contact us at privacy@optitechautomation.co.uk or contact the Business directly.
Your data is mainly stored in the European Economic Area (Dublin, Ireland). UK law treats the EEA as providing adequate protection (UK adequacy regulations under UK GDPR Article 45), so no extra paperwork is needed for that.
A few of our technology providers are based in the United States. When data goes to them, we use a lawful UK transfer mechanism: the UK Extension to the EU-US Data Privacy Framework (the "UK-US Data Bridge") where the provider is certified, or otherwise the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. The full list of providers and the safeguard used for each is at /legal/sub-processors.
privacy@optitechautomation.co.uk
Torquay, Devon, United Kingdom
The Business (controller)Contact details available on their booking page.