Legal

Privacy Policy

UK GDPR & Data Protection Act 2018 Compliant

Effective Date: July 2026 · Last Updated: July 2026

Welcome to ARO MultiServices. Your privacy is important to us. This Privacy Policy explains how we collect, use, store, disclose, and protect your personal information when you access or use our online booking platform, website, and related services.

By using our platform, you agree to the practices described in this Privacy Policy.

1. Who We Are

ARO MultiServices ("ARO", "we", "our", or "us") provides an online booking platform that enables businesses and customers to schedule appointments and manage bookings efficiently.

ARO acts as the Data Controller for information collected through our website and as a Data Processor where we process customer information on behalf of businesses using our platform.

2. Information We Collect

Depending on how you use our platform, we may collect:

Personal Information

  • Full Name
  • Email Address
  • Telephone Number
  • Billing Address
  • Company Name
  • Job Title

Booking Information

  • Appointment Details
  • Booking History
  • Notes submitted during booking
  • Service Preferences
  • Assigned Staff Member

Account Information

  • Username
  • Password (encrypted)
  • Login History
  • Profile Settings

Payment Information

Payments are processed securely through third-party payment providers. ARO never stores full credit or debit card information.

Technical Information

We automatically collect:

  • IP Address
  • Browser Type
  • Device Information
  • Operating System
  • Cookies
  • Time Zone
  • Usage Statistics
  • Pages Visited
  • Referral URLs

3. How We Collect Information

Information may be collected when:

  • You create an account
  • You make a booking
  • You submit forms
  • You contact customer support
  • You subscribe to newsletters
  • You browse our website
  • You use our services

4. How We Use Your Information

We use your information to:

  • Provide our booking services
  • Process appointments
  • Manage customer accounts
  • Process payments
  • Send booking confirmations
  • Provide customer support
  • Improve platform performance
  • Prevent fraud
  • Detect security incidents
  • Comply with legal obligations
  • Maintain platform security

5. Legal Basis for Processing

Under the UK GDPR, we process personal data under one or more of the following lawful bases:

  • Contractual necessity
  • Legal obligation
  • Legitimate interests
  • User consent
  • Protection of vital interests

6. Sharing Information

We do not sell your personal information.

We may share information with:

  • Payment providers
  • Cloud hosting providers
  • Email service providers
  • Analytics providers
  • IT support providers
  • Government authorities where legally required
  • Professional advisers including lawyers and accountants

All third parties are contractually required to protect your information.

7. Data Security

We implement appropriate technical and organisational measures, including:

  • SSL Encryption
  • Secure Cloud Infrastructure
  • Password Encryption
  • Access Controls
  • Firewalls
  • Routine Security Monitoring
  • Malware Protection
  • Backup Systems
  • Security Updates

Although no online system can be guaranteed completely secure, we continuously work to protect your information using industry-recognised practices.

8. International Transfers

Where personal data is transferred outside the United Kingdom, we ensure appropriate safeguards are in place, including:

  • UK International Data Transfer Agreements (IDTA)
  • Standard Contractual Clauses where applicable
  • Transfers to countries recognised as providing an adequate level of data protection

9. Data Retention

We retain personal information only for as long as necessary to:

  • Provide our services
  • Comply with legal obligations
  • Resolve disputes
  • Enforce agreements
  • Maintain business records

When data is no longer required, it is securely deleted or anonymised.

10. Your Rights

Under UK GDPR, you may have the right to:

  • Access your personal data
  • Correct inaccurate information
  • Delete personal information
  • Restrict processing
  • Object to processing
  • Withdraw consent
  • Receive a copy of your data (data portability)
  • Lodge a complaint with the Information Commissioner's Office (ICO)

Requests may be submitted using the contact information below.

11. Cookies

Our platform uses cookies to:

  • Maintain user sessions
  • Remember preferences
  • Improve website functionality
  • Measure website performance
  • Analyse visitor behaviour

For further information, please refer to our Cookie Policy.

12. Children's Privacy

Our services are not directed toward individuals under the age of 16. We do not knowingly collect personal information from children.

13. Automated Decision Making

ARO does not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.

14. Third-Party Services

Our platform may contain links or integrations with third-party services. ARO is not responsible for the privacy practices of third-party websites or services.

15. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be available on our website.

16. Contact

For any questions regarding this Privacy Policy or your personal information, please contact:

ARO MultiServices

Email: info@aromultiservices.co.uk

Website: app.aromultiservices.co.uk