Three unrelated things get muddled together on most pages like this one, so they are kept apart here: the contact details you type into a form, the physical media you hand over to a recovery lab, and the technical exhaust any web browser produces simply by loading a page. Written to be read rather than scrolled past. Current version dated August 2026.
For everything set out below, the controller in the UK GDPR sense is Bracknell Data Recovery — the trading name this lab's work is sold under to households, sole traders, professional practices and companies across Bracknell, Berkshire and Surrey, into London, and anywhere else a parcel will reach. No premises are kept in Bracknell itself. Bench, imaging hardware, donor stock and job records all live at one address — Guildford Data Recovery, Building 2, Ground Floor, Guildford Business Park, Guildford GU2 8XH — around forty minutes away by way of the A322 and the A3. Anything on this page can be raised on 0800 689 0668 during Mon–Fri 9:00am–5:30pm, or in writing to support@guildforddatarecovery.co.uk, and it will be answered by somebody who works on the jobs rather than by a ticketing system.
Two forms exist. The callback request lives on the contact page; the second closes the free diagnostic once a device, a manufacturer and a symptom have been chosen. Both carry the same four fields — the name to greet you by, a number to ring, an address for the written quote, and a free-text box for your own account of what went wrong. The diagnostic form attaches the three answers you clicked, so that whoever rings already knows whether the subject is a ticking 3.5-inch disk or a BitLocker volume nobody can open. Nothing else is gathered. One further field sits in the markup deliberately hidden and marked to be left blank: automated form-fillers complete it, people never see it, and any submission with text in that box is dropped without being read.
Date of birth is never asked. A postal address is asked for only at the point a parcel genuinely has to go back to you. Card details are never typed into this website at all, since no part of it takes payment; invoicing details are collected separately when a job is going ahead, and they sit with the accounts rather than in any marketing tool.
Two of the six UK GDPR bases carry almost all of this. Replying to an enquiry, quoting for work, taking a device into custody and performing the recovery are steps taken on your instruction, either before a contract exists or in delivering one, which is Article 6(1)(b). Retaining invoices and job records afterwards for as long as HMRC requires is a legal obligation, Article 6(1)(c). The one remaining case is legitimate interest, Article 6(1)(f): where an engineer notes down how an unusual fault behaved so the next example of it goes better, and that note concerns hardware, not the person who owned it.
Consent to marketing is not relied on anywhere, because no marketing goes out. Completing a form buys an answer to the question you asked and nothing further. There is no newsletter here and no list quietly collecting names.
Freephone calls are not recorded. Whatever an engineer notes during one amounts to the same short set of facts a form would have gathered, filed against the job so that the next person to answer is not starting from nothing. The chat window in the corner of the screen comes from Olark. Whatever you type there is what it carries, and it gets handled on the same footing as an email.
Reception opens the box, records what is inside it against a job number and passes the media through to the lab. Only the engineers working on it handle it from that point. It is never sub-contracted, never forwarded to another lab, and never carried home in a bag to be looked at over a weekend. Any drive needing to be opened is opened under filtered air in the same building it arrived at.
Almost every job begins with a sector-level image, and the work that follows is done against that image rather than the original. This is why a fragile drive can sit untouched on a shelf while the difficult part goes on elsewhere — and it is also why the two sections below exist, because that image is a full copy of everything you sent.
Three parts of the work need contents visible in some form: reading the file system, rebuilding directory trees, and proving the returned files actually open. The boundary sits exactly there. A document gets opened to establish it is undamaged, not to learn what it says; a picture gets checked as a thumbnail, which is enough to show the image data survived. None of it is copied out for any purpose of ours, none of it is displayed outside the lab, and none of it is discussed with anybody but the engineers on the job and the contact whose name is on it.
Two exceptions apply, and they are stated rather than buried. A court order or statutory demand from a UK authority will be complied with. Material whose mere possession is a criminal offence would be reported, a duty carried by every lab in the country.
Forensic instructions work differently, since examining content and reporting on it is the whole purpose. The instructing party — a solicitor, an employer, an insurer — defines the scope, and the written report is delivered to them. A chain-of-custody record tracks who held the media and when; far from being incidental, it exists precisely so that it can be produced and challenged later. Exported CCTV footage is treated the same way. Where you are the subject of an investigation rather than the party who commissioned it, your rights over that material run through whoever did commission it.
Wiping, in that list, means a multi-pass overwrite of whatever storage held the image — or, where a disk is being taken out of service, physical destruction of its platters. It does not mean dropping a folder into a recycle bin.
On the physical side, the lab is a controlled building, the recovery area sits behind a further door, and media is stored rather than left on desks. Nothing goes out to a third party. On the technical side, working storage is encrypted, recovered files are returned on encrypted media with the passphrase sent separately, and only the engineers on a job can reach its storage. This website keeps no customer database because none is ever created: the forms pass straight to mail and retain nothing themselves.
No honest page can promise that traffic across the internet is impossible to intercept, and this one will not try. What it can say is that the forms carry contact details only and never the data being recovered, and that recovered data travels home physically, on encrypted media, rather than over a wire.
Recovery work, the media and the job records remain in the United Kingdom. The two exceptions are the third-party scripts already named. Olark and Google Fonts both run from outside the UK, so loading a page here does send a request abroad, under whatever transfer safeguards those suppliers publish. Both are avoidable if it matters to you: ring the freephone number instead of opening the chat window, and a browser configured to block third-party font requests will simply render this site in a system typeface with nothing else changed.
Web servers write down an IP address, a timestamp, the page asked for and the browser string, which is what any server needs in order to deliver a page and to recognise abuse. Those logs rotate and are discarded on a short cycle. Google Fonts sees a comparable request record while delivering typefaces. As for cookies: none of them here advertise, track across sites or feed an analytics suite. The only one you are likely to encounter comes from the Olark chat window and exists to remember a conversation already in progress so you are not asked to start again. Refuse it and nothing about the site changes.
UK GDPR gives you rights over personal information held about you. Each is honoured here without argument:
Ring 0800 689 0668 or write to support@guildforddatarecovery.co.uk naming which of these you want. Identification may be requested first, for the single reason that information must not go to the wrong person.
Bring it here first, by telephone or in writing, and it will be taken seriously. If the outcome still does not satisfy you, the supervisory authority for the United Kingdom is the Information Commissioner's Office, which accepts complaints through ico.org.uk or on its helpline. Approaching the ICO is free and has no bearing on how your recovery is handled.
This service is bought by adults. Nothing here is directed at children and no age information is gathered. Where the device belonged to a child, the parent or guardian who commissioned the recovery is the person dealt with throughout.
The date in the opening paragraph identifies the current version. Any change that materially alters how information is handled is written into this page, and where such a change touches a job already in progress the customer is told directly rather than left to spot an edit to a website.
Freephone 0800 689 0668, Mon–Fri 9:00am–5:30pm. Email support@guildforddatarecovery.co.uk. Post to Guildford Data Recovery, Building 2, Ground Floor, Guildford Business Park, Guildford GU2 8XH. Commercial terms are in the terms and conditions (PDF), and the contact page covers how to get a device here undamaged.