Privacy and Cookie Policy
| Entity | Registration No. | Jurisdiction |
| JLA Limited | 01094178 | England and Wales |
| JLA Fire & Security Limited | 06486921 | England and Wales |
| JLA Total Care Limited | 02951461 | England and Wales |
| JLA HVAC Limited | 07886444 | England and Wales |
| DCSW Limited | 09882844 | England and Wales |
| Direct Catering Products Limited | 05086006 | England and Wales |
| Proton (Southern) Limited | 05096198 | England and Wales |
| TFS Facilities Services Limited | 12058482 | England and Wales |
| Circuit Launderette Services Limited | 02944540 | England and Wales |
| Circuit Launderette Services (Ireland) Limited | 343956 | Republic of Ireland |
| Reliance Equipment Limited | 589614 | Republic of Ireland |
| Entity | Registration No. | Jurisdiction |
| Brodericks Food Equipment South Limited | 563904 | Republic of Ireland |
| Brodericks Bros. Limited | 11182 | Republic of Ireland |
| Laundry Total | 80490867 | Netherlands |
| LDL Group Holding & Benelux Subsidiaries | 0682.868.320 | Belgium & EU |
1. Purposes of Processing and Data Categories
A. Delivering Goods, Installation & Equipment Servicing
Data used:
• Identity and contact details
• Address and account information
• Service/maintenance history
• Health & Safety information
Purpose:
To deliver equipment, schedule engineer visits, install products, maintain equipment, and meet safety obligations.
B. Managing Customer Accounts (Billing, Portals, MyJLA)
Data used:
• Identity and login details
• Portal or system usage data
• Service and billing history
• Call recordings and communications
Purpose:
To create and manage accounts, authenticate users, manage billing, and provide customer support.
C. Marketing & Customer Communications
Data used:
• Contact information
• Preference/sector data
• Cookie and browsing activity
• Purchase or enquiry history
Purpose:
To send relevant updates, offers, sector information and product recommendations.
Marketing is conducted under Legitimate Interests (B2B) or Consent, depending on channel.
D. Website Analytics, Cookies & Optimisation
Data used:
• IP address
• Device identifiers
• Cookie identifiers
• User behaviour analytics
Purpose:
To improve website performance, understand usage patterns, and maintain security.
Non essential cookies operate on consent.
E. Legal, Regulatory, Fraud Prevention & Security
Data used:
• Identity and financial details
• Transaction and credit data
• CCTV/dashcam footage
• Incident logs and H&S information
Purpose:
To comply with legislation, detect and prevent fraud, support investigations, ensure health and safety, and meet regulatory duties.
F. Complaints, Investigations & Claims Handling
Data used:
• Identity and contact details
• Service history
• Correspondence and evidence
• Photographs, recordings, including call recordings, or other supporting documents
Purpose:
To investigate and resolve complaints, manage insurance, defend claims, and maintain records.
G. Information Received from Third Parties
Possible sources:
• Credit reference agencies
• Subcontractors and installation partners
• Public databases (e.g., Companies House)
• Analytics and advertising partners
• Payment processors
Purpose:
To verify information, support service delivery, manage risk, and enhance customer insights.
1.1 Telephone Communications and Call Recording
We may record inbound and outbound telephone calls for purposes including quality assurance, staff training, dispute resolution, fraud prevention, and to protect both our business and our customers when communicating with us by telephone.
Call recordings are retained for a defined and limited period in accordance with our retention policies, after which they are securely deleted or anonymised, unless a longer retention period is required for legal or regulatory reasons. Access to call recordings is restricted to authorised personnel only and subject to appropriate technical and organisational safeguards.
Where payment card details are provided by a customer over the telephone, call recording is temporarily paused to ensure that cardholder data is not recorded. This is done in compliance with the Payment Card Industry Data Security Standard (PCI DSS) and supports the secure handling of payment information.
1.2 Special Category Data
Some of the personal data we process may constitute special category data, such as health and safety information, accident reports, or CCTV/dashcam footage.
Where we process special category data, we do so only where necessary and in accordance with applicable data protection law, including where:
• processing is required to carry out obligations in the field of health and safety or employment law;
• processing is necessary for the establishment, exercise or defence of legal claims; or
• another lawful condition under Article 9 GDPR applies.
1.3 Children’s Data
Our websites, products and services are not directed at children, and we do not knowingly collect personal data relating to children.
2. Lawful Bases for Processing
| Activity | Lawful Basis |
| Delivering goods, installation, servicing | Contract; Legitimate Interests |
| Managing customer accounts (billing, service portal, MyJLA) | Contract; Legitimate Interests |
| Marketing (email, post, telephone) | Legitimate Interest (B2B); Marketing preferences defined and PECR-compliant. |
| Website analytics and cookies | Consent for non-essential cookies; Legitimate Interest for site functionality and security. |
| Legal, regulatory and fraud prevention | Legal Obligation; Legitimate Interests |
| Complaints, investigations and claims | Legal Obligation; Legitimate Interests |
Legitimate Interests
Where we rely on legitimate interests as our lawful basis, we have carried out an assessment to ensure that our interests are not overridden by your rights and freedoms.
Our legitimate interests include:
- operating and improving our business and services;
- maintaining customer relationships and providing relevant B2B communications;
- ensuring network and information security;
- preventing fraud and protecting our business, customers and staff.
In each case, we ensure that our processing is necessary, proportionate, and subject to appropriate safeguards. You have the right to object to processing based on legitimate interests at any time (see Section 8).
3. Recipients of Personal Data
- JLA Group companies
- Delivery and installation partners
- Engineers and subcontractors
- IT hosting providers and CRM suppliers
- Marketing automation and analytics vendors
- Regulators and law enforcement
- Insurers and legal advisers
- Credit reference agencies (CRAs)
All suppliers are subject to appropriate contractual safeguards, including DPAs and security requirements.
4. Who we share your personal information with
We share your personal information;
With any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006.
Controllers and Processors – Depending on the circumstances, JLA Group companies may act as independent controllers, joint controllers, or processors.
Where we engage third‑party service providers to process personal data on our behalf, they act as processors and are subject to contractual obligations to process personal data securely and only in accordance with our instructions. Specified third-parties include: Business partners, suppliers, delivery companies and sub-contractors for the performance of any contract we enter into with them or you; professional or legal advisors, financial or fraud investigation authorities, relevant regulatory authorities, debt collection agencies, organisation we’re legally obliged to share information with.
Website hosts and analytics and search engine providers that assist us in the operation, improvement and optimisation of our site; and
Organisations that help us focus our marketing activities on businesses that share similar characteristics as our customers;
In order to enter into a contract with you, we will supply your personal information to credit reference agencies (CRAs) and they will give us information about you/your business, such as about your financial history. We do this to assess creditworthiness and product suitability, check your identity, manage your account, trace and recover debts and prevent criminal activity. We will also continue to exchange information about you/your business with CRAs on an ongoing basis, including about your settled accounts and any debts not fully repaid on time. CRAs will share your information with other organisations. The identities of the CRAs, and the ways in which they use and share personal information, are explained in more detail at http://www.experian.co.uk/crain/index.html
We only allow our service providers to handle your personal information if we are satisfied they take appropriate measures to protect your personal information. We also impose contractual obligations on service providers relating to ensure they can only use your personal information to provide services to us and to you.
In the event that we sell or buy any business or assets, in which case we will disclose your personal data to the prospective seller or buyer of such business or assets. The recipient of the information will be bound by confidentiality obligations.
4.1 Use of Artificial Intelligence (AI)
We make limited use of artificial intelligence technologies to support certain internal business activities, such as productivity, document management, and administrative assistance. Any use of AI tools is subject to prior risk assessment, internal approval, and ongoing monitoring to ensure compliance with applicable data protection and information security requirements.
We have approved the use of Microsoft Copilot for commercial purposes, as it operates within a controlled enterprise environment and is designed to process data in accordance with Microsoft’s contractual, security, and data protection commitments. In contrast, publicly accessible generative AI tools (such as general‑purpose AI chat services) are subject to different deployment models and risk considerations and are not approved for routine business use where personal data may be involved.
The use of AI within the JLA Group is governed by internal policies and oversight mechanisms. AI tools are not used to make automated decisions producing legal or similarly significant effects on individuals. Customer personal data is not routinely input into or processed using artificial intelligence systems, and where exceptional use may be required, this will be subject to appropriate safeguards, minimisation, and access controls.
5. Our marketing
We may use your personal information to send you updates (by email, text message, telephone or post) about our products or services, including exclusive offers, promotions or new products or services.
We have a legitimate interest in processing your personal information for promotional purposes. This means we do not usually need your consent to send you promotional communications. Please note that such marketing communications are aligned with your established business interest and will only be processed on occasions where we believe they will be of interest to you. You can opt-out and change your marketing preferences at any time.
We will always treat your personal information with the utmost respect and never sell or share it with other organisations outside JLA Group for marketing purposes.
You have the right to opt out of receiving promotional communications at any time by:
Contacting us at dataprotection@jla.com
Using the “unsubscribe” link in emails or “STOP” number in text messages
Updating your marketing preferences on our preference centre
6. Where we store your personal data and the international transfer of personal data
Information may be held at our offices and those of our group companies, third party agencies, service providers, representatives and agents as described above. (See above “Who we share your personal information with”)
The data that we collect from you may be transferred to, and stored at, and processed by staff operating outside the EEA who work for us or for one of our suppliers. These transfers are subject to special rules under the applicable data protection laws as some non-EEA countries (such as the United States of America) do not have the same level of data protection laws as the United Kingdom and EEA. We will ensure that any transfer to one of these countries complies with data protection law.
Our standard practice is to use standard data protection “model” clauses that have been approved by the European Commission. Where required under Applicable Data Protection Laws, we may also use International Data Transfer Agreements (IDTAs) together with appropriate transfer risk assessments.
In all cases where such transfers occur, a thorough risk assessment will be carried out in advance to ensure that the recipient has appropriate organisational and technical measures in place to provide a level of security proportionate to the risks associated with processing personal data.
If you would like further information on this, please contact us.
All information you provide to us is stored on our secure servers. Any payment transactions will be encrypted using SSL technology. Where we have given you (or where you have chosen) a password which enables you to access certain parts of our site, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
7. How long we keep your information for
We will keep your personal information while you have a contract with us or we are providing products and services to you. Thereafter, we will keep your personal information for as long as is necessary:
To respond to any questions, complaints or claims made by you or on your behalf;
To show that we treated you fairly;
To keep you updated about new products and services that we think will be of interest to you and your business;
To keep records as required by law.
We only retain your personal information for as long as it is needed to fulfil the purposes outlined in this policy. Different categories of personal information may be kept for different lengths of time. Once your information is no longer required, we will delete it or anonymise it. Anonymised data can no longer be used to identify any individual and may be retained for purposes such as statistical analysis.
Please see the retention table below;
| Record | Recommended retention period | Storage format |
Information relating to customers – Name – Address – Email address – Account and payment details – Copy contracts | 6 years from either the date that the customer contract terminated or last known transaction (whichever is the latter). | Paper/electronic |
| Information relating to customers DD instructions and bank details | 1 month following the date that the customer contract terminated or last known transaction (whichever is the latter) | Paper/electronic |
Circuit Information relating to end users (ie students) of the facilities – Name – Email address – Circuit card details | 1 year from the date of last account activity | Paper/electronic |
Circuit Information relating to end users (ie students) bank account details | For duration necessary to perform specific purpose then deleted | Paper/electronic |
8. Your rights
You have the following rights, which you can exercise free of charge:
| Your right of access | You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for. |
| Your right to rectification | You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete. |
| Your right to erasure/to be forgotten | You have the right to ask us to delete your personal information. (this only applies in specific circumstances) |
| Your right to restriction of processing | The right to require us to restrict processing of your personal information, in certain circumstances, e.g., if you contest the accuracy of the data. |
| Your right to data portability | The right to receive the personal information your provided to us, in a structured, commonly used and machine-readable format and/or transmit that data to a third-party, in certain circumstances. |
| Your right to object to processing | The right to object: You have the right to object at any time to the processing of your personal information where we rely on legitimate interests as our lawful basis. This includes an absolute right to object to the use of your personal information for direct marketing purposes, including any profiling related to direct marketing. You also have the right to object to other processing carried out on the basis of our legitimate interests where you believe that your rights and freedoms outweigh our interests. |
| Your right to withdraw consent | In most cases, we do not rely on consent as the lawful basis for processing your personal data, particularly where we have an established business relationship with you. Where consent is used (for example, in relation to non‑essential cookies or certain marketing communications), you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing carried out before consent was withdrawn. |
| Automated decision-making | We do not make decisions about you that are based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. Where we use automated tools to support activities such as credit checks or fraud prevention, these are subject to appropriate human oversight. |
For further information on each of those rights, including the circumstances in which they apply, please contact us or see the Guidance from the UK Information Commissioner’s Office (ICO) on individuals’ rights under Applicable Data Protection Laws. If you would like to exercise any of those rights, please contact our Data Protection Manager:
You have the right to ask us not to process your personal data for marketing purposes. You can exercise your right to prevent such processing by checking certain boxes on the forms we use to collect your data. You can also exercise the right at any time by contacting us at dataprotection@jla.com or by visiting our preference centre, or by opting-out on the electronic marketing communication which you have received.
9. Cookies
| Cookie | Domain | Description | Duration | Type |
| _ga_* | .dcproducts.co.uk; reliancelaundryequipment.ie; .laundrytotal.nl | Google Analytics sets this cookie to store and count page views. | 1 year 1 month 4 days | Analytics |
| _ga | .dcproducts.co.uk; reliancelaundryequipment.ie; .laundrytotal.nl; .ldlnv.be | The _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site’s analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors. | 1 year 1 month 4 days | Analytics |
| _gcl_au | .dcproducts.co.uk; reliancelaundryequipment.ie; .laundrytotal.nl; .ldlnv.be | Google Tag Manager sets this cookie to experiment advertisement efficiency of websites using their services. | 3 months | Advertisement |
| __Secure-YNID | .youtube.com | YouTube cookie used to protect user security and prevent fraud, especially during the login process. | 6 months | Advertisement |
| YSC | .youtube.com | YouTube cookie is set by YouTube and is used to track the views of embedded videos on YouTube pages. | session | Analytics |
| __Secure-ROLLOUT_TOKEN | .youtube.com | YouTube sets this cookie to manage feature rollout and experimentation. It helps Google control which new features or interface changes are shown to users as part of testing and staged rollouts, ensuring consistent experience for a given user during an experiment. | 6 months | Advertisement |
| VISITOR_INFO1_LIVE | .youtube.com | A cookie set by YouTube to measure bandwidth that determines whether the user gets the new or old player interface. | 6 months | Functional |
| VISITOR_PRIVACY_METADATA | .youtube.com | YouTube sets this cookie to store the user’s cookie consent state for the current domain. | 6 months | Necessary |
| wpEmojiSettingsSupports | .dcproducts.co.uk; reliancelaundryequipment.ie | WordPress sets this cookie when a user interacts with emojis on a WordPress site. It helps determine if the user’s browser can display emojis properly. | session | Necessary |
| rc::c | google.com | This cookie is set by the Google recaptca service to identify bots to protect the website against malicious spam attacks | session | Necessary |
| wpml_browser_redirect_test | circuit-go.com | This cookie is set by WPML WordPress plugin and is used to test if cookies are enabled on the browser. | Session | Functional |
| _icl_visitor_lang_js | .circuit-go.com | WPML sets this cookie to store the redirected language. | 1 day | Functional |
| wp-wpml_current_language | circuit-go.com | WordPress multilingual plugin sets this cookie to store the current language/language settings. | session | Functional |
| _hjSessionUser_* | circuit-go.com | Hotjar sets this cookie to ensure data from subsequent visits to the same site is attributed to the same user ID, which persists in the Hotjar user ID, which is unique to that site. | 1 year | Analytics |
| _hjSession_* | .circuit-go.com | Hotjar sets this cookie to ensure data from subsequent visits to the same site is attributed to the same user ID, which persists in the Hotjar user ID, which is unique to that site. | 1 hour | Analytics |
| ssr-caching | www.brodericks.ie | The ssr-caching cookie is set by WIX and indicates how a site was rendered. | Less than a minute | Necessary |
| XSRF-TOKEN | www.brodericks.ie | This cookie enhances visitor browsing by preventing cross-site request forgery. | session | Necessary |
| hs | www.brodericks.ie | WIX platform sets this cookie for security purposes. | session | Necessary |
| svSession | www.brodericks.ie | WIX platform sets this cookie to identify unique visitors and track a visitor’s session on a site. | 1 year 1 month 4 days | Necessary |
| _wixAB3 | wix.com | The _wixAB3 cookie is used by the hosting provider at the start of a session. It collects information on website traffic, duration and location. | 6 months | Necessary |
| lidc | .linkedin.com | LinkedIn sets the lidc cookie to facilitate data centre selection | 1 day | Functional |
| bcookie | .linkedin.com | LinkedIn sets this cookie to track the use of embedded services. | 1 year | Advertisement |
| li_gc | .linkedin.com | LinkedIn set this cookie for storing visitor’s consent regarding using cookies for non-essential purposes. | 6 months | Functional |
| _fbp | .laundrytotal.nl; .ldlnv.be | Facebook sets this cookie to store and track interactions | 3 months | Advertisement |
| _ga_RYQ4689SZS | .ldlnv.be | This cookie is used by Google Analytics to persist session date. | 1 year 1 month | Analytics |
| _cfuvid | .vimeo.com | This cookie is used for purposes of tracking users across sessions to optimise user experience by maintaining session consistency and providing personalised services. | session | Functional |
| laundry_equipment_session | .ldlnv.be | Used to manage the user session after cookies have been accepted. This cookie enables core website functionality such as session continuity and security during navigation. It does not collect personal data or track users. | 12 hours | Functional |
10. Changes to our privacy policy
| Supervisory Authority in United Kingdom (UK/GB) | Supervisory Authority in Ireland (IE/IRL) |
| Information Commissioner’s Office (ICO) Wycliffe House Water Lane Wilmslow SK9 5AF United Kingdom Web: www.ico.org.uk Email: icocasework@ico.org.uk Telephone: +44 (0) 303 123 1113 | Data Protection Commission (DPC) 6 Pembroke Row Dublin 2 D02 X963 Ireland Web: www.dataprotection.ie Email: info@dataprotection.ie Telephone: + 353 (57) 868 4800 |
| Supervisory Authority for Belgium (BEL) | Supervisory Authority in The Netherlands (NL/NLD) |
| Data Protection Authority (APD-GBA) Authorité de protection des données Gegevensbeschermingsautoriteit Rue de la Presse 35 / Drukpersstraat 35 1000 Bruxelles / 1000 Brussel Web: www.dataprotectionauthority.be Email: contact@apd-gba.be Telephone: +32 (0) 2274 4800 | Autoriteit Persoonsgegevens (AP) Postbus 93374, 2509 AJ DEN HAAG. Visiting Address: Hoge Nieuwstraat 8, 2514 EL Den Haag. Web: www.autoriteitpersoonsgegevens.nl Email: info@autoriteitpersoonsgegevens.nl Telephone: +31 70 888 8500 |
11. Changes to our privacy policy
This Privacy and Cookie Policy is reviewed regularly to ensure it remains accurate and compliant with Applicable Data Protection Laws. We may update this Policy from time to time to reflect changes in our processing activities or legal requirements. Any changes will be posted on this page and, where appropriate, notified to you by email. We encourage you to check this page periodically to stay informed of any updates.
This Policy was last reviewed and amended in April 2026.
[VERSION 10.0]