How D&A Commercial Cleaning Ltd handles personal data in the D&A Manager application.
Last updated: 26 August 2026
D&A Manager is provided by D&A Commercial Cleaning Ltd ("we", "us"), a company registered in England and Wales. We are the data controller for the personal data described here.
D&A Manager is a workforce, site-reporting and fleet management tool for people who work for, or on behalf of, D&A — our own staff and the gangs carrying out work on our contracts. Accounts are created by an administrator; the app is not available to the general public, there is no self-service sign-up, and it is not intended for anyone under 18.
| Data | What it includes | Why |
|---|---|---|
| Account and identity | Name, email address, telephone number, job role, profile picture, and the permissions attached to your account. | To sign you in, show you the records you are entitled to see, and attribute work to the person who did it. |
| Employment records | Leave requests, entitlements and the decisions taken on them, the gang you belong to, and equipment assigned to you. | To administer the employment or engagement relationship. |
| Photographs and files | Images you capture with the camera or select from your photo library, and documents you attach — including images that show people, premises or vehicle registrations. | Evidence for site reports, arrival on site, vehicle checks, defect reports and accident reports. |
| Location | Your device's location at the moment you take a photograph, and while a job requiring location is open. Photographs are stamped with the coordinates and the time they were taken. | To tie a site report or an inspection photograph to the place it was taken. |
| Operational records | Site reports and arrival-on-site records, vehicle checks, defect and defect-report records, maintenance and mileage reports, accident reports, and the times these were created or changed. | To run the business, meet health-and-safety obligations, and keep an auditable record. |
| Document read receipts | Which documents you have opened, and when. | To evidence that required reading has been acknowledged. |
| Security and audit records | Sign-ins and failed sign-in attempts, the email address entered, the IP address and browser or device identifier the attempt came from, and a record of who changed a permission, changed a user, or deleted a record. | To detect and investigate unauthorised access, and to keep an audit trail of changes to who can see what. |
| Notifications | Messages held against your account about work that needs your attention, and whether you have read them. | To tell you about a decision, a document or a report that concerns you. |
| Technical data | Which platform your device runs — iOS or Android — sent when the app asks whether a newer version exists. | To tell you when the app needs updating. |
The app asks for location permission the first time a feature needs it, and iOS and Android will tell you when it is in use. Location is captured to stamp photographs and is stored alongside the record it belongs to. If you decline the permission, or no fix can be obtained, the record is saved without a location rather than with a guessed one. You can withdraw the permission at any time in your device settings.
We do not use your data for advertising. We do not track you across other companies' apps or websites, and the app contains no advertising or analytics software. The app sends us no crash reports, no performance measurements and no diagnostic data of any kind. We do not sell personal data.
We rely on the following bases under the UK GDPR:
So the app works where there is no signal, some data is stored on the device itself: a local database holding site reports and other work waiting to be uploaded, cached copies of photographs and files you have attached, your session, and your most recent location fix. This is held in the app's own private storage and is removed when the app is uninstalled. Anything queued offline is sent to our servers when a connection returns.
We do not share your personal data except as set out below.
Using this app involves personal data being transferred outside the United Kingdom:
Where such a transfer takes place we rely on the safeguards permitted under UK data protection law — the UK Extension to the EU–US Data Privacy Framework where the provider is certified under it, or the International Data Transfer Agreement where it is not.
We keep personal data for as long as it is needed for the purpose it was collected for, and then for as long as we are required to keep it. What sets the period differs by record:
We review what is held periodically and remove what is no longer needed. Where you ask us to erase data and we are not required to keep it, we will. Some records cannot be erased on request — accident reports and statutory inspections have to be retained because the law requires it.
Traffic between the app and our servers is encrypted in transit using HTTPS. Passwords are stored only as a one-way hash, never in a form anyone can read. Access within the app is controlled by role, so you see only the records your permissions allow. Sign-in attempts are rate limited, sessions can be revoked, and links to stored files are short-lived and issued only to someone entitled to the record they belong to. Devices are expected to be protected by a passcode or biometric lock.
Under the UK GDPR you have the right to ask us for a copy of your personal data; to have inaccurate data corrected; to have data erased in certain circumstances; to restrict or object to how we use it; and to receive certain data in a portable form. Where we rely on consent — such as location permission — you may withdraw it at any time without affecting what was done beforehand.
To exercise any of these, write to dan.stanbra@daccs.co.uk or to the address above. If you are not satisfied with our response you may complain to the Information Commissioner's Office at ico.org.uk.
Some records — accident reports, statutory inspections — cannot be erased on request, because we are required to keep them.
You cannot create an account in D&A Manager. Accounts are created, managed and closed by an administrator, and there is no self-service sign-up.
To have your account closed, or your data removed where we are not required to keep it, speak to your administrator or write to dan.stanbra@daccs.co.uk. We will respond within one month, as the UK GDPR requires.
If we change how the app handles personal data we will update this page and change the date at the top. Material changes will be communicated through the app or by your administrator.
D&A Commercial Cleaning Ltd
1st Floor, Castle House, Dawson Road, Milton Keynes, England, MK1 1QT
dan.stanbra@daccs.co.uk · +44 7922 426969