Privacy Policy - Gardeners Gidea Park
This Privacy Policy explains how Gardeners Gidea Park collects, uses, stores, shares, and protects personal data when providing gardening services. It applies to all Gardeners Gidea Park customers in the area, including people who enquire about our services, request quotes, book appointments, receive ongoing maintenance, or otherwise interact with us in connection with our work. We are committed to handling personal data lawfully, fairly, and transparently in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We believe privacy matters, and we aim to keep data collection limited to what is necessary for delivering our services, managing customer relationships, meeting legal obligations, and improving the way we operate. This policy should be read carefully so you understand what information we process, why we process it, and what rights you have.
1. Who We Are
For the purposes of data protection law, Gardeners Gidea Park acts as the data controller for the personal data described in this policy. This means we decide how and why your personal data is used in connection with our gardening services. In some cases, third parties may act as independent controllers or processors, depending on the service they provide.
This policy covers personal data relating to customers, prospective customers, and other individuals whose information we receive during the normal course of business in the Gidea Park area.
2. Information We Collect
We only collect personal data that is relevant to our services and business operations. The types of information we may collect include:
- Identity details such as your name and title.
- Contact details such as phone number, email address, and service address.
- Service information including details about the gardening work requested, property access notes, preferences, and scheduled appointments.
- Billing and payment information such as invoicing details, transaction records, and payment status.
- Communication records including emails, messages, call notes, and records of complaints or feedback.
- Technical data where relevant, such as basic website usage information or device details if you interact with digital services.
- Special instructions you provide that are necessary for service delivery, for example garden access arrangements or timing preferences.
We do not intentionally collect more information than we need. We also do not seek to collect special category data unless it is strictly necessary and you have provided it to us, or another lawful condition applies.
3. How We Use Your Data
We use personal data for the following purposes:
- To respond to enquiries and provide quotes.
- To arrange and deliver gardening services.
- To manage bookings, schedules, and service records.
- To process payments and issue invoices.
- To communicate about service updates, changes, or follow-up work.
- To manage customer relationships and resolve issues.
- To keep appropriate business and financial records.
- To comply with legal, tax, accounting, and regulatory obligations.
- To improve our services, operations, and customer experience.
We use your information only where there is a valid legal reason to do so and only for the purpose for which the data was collected, unless we reasonably need to use it for a compatible purpose.
4. Lawful Basis for Processing
Under UK GDPR, we must have a lawful basis for processing personal data. Depending on the situation, Gardeners Gidea Park may rely on one or more of the following lawful bases:
Contract
We process your data when it is necessary to take steps at your request before entering into a contract, or to perform a contract with you. This includes preparing quotes, scheduling services, completing work, and handling payments.
Legal Obligation
We may process personal data where required to comply with legal duties, such as tax, accounting, fraud prevention, and record-keeping requirements.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided your interests and rights do not override those interests. Examples include managing customer enquiries, maintaining service quality, preventing misuse, and protecting our business from loss or fraud. We always consider whether the processing is proportionate and respectful of your privacy.
Consent
In limited cases, we may rely on your consent, for example where it is required for certain communications or optional services. If we rely on consent, you may withdraw it at any time.
5. Data Sharing and Processors
We may share personal data only when necessary and only with trusted third parties who support our business operations. These recipients may include:
- IT and hosting providers that store or help manage business systems.
- Payment service providers that process card or electronic payments.
- Accounting or bookkeeping providers that assist with financial records and tax compliance.
- Customer management or communication tools used for scheduling and service administration.
- Professional advisers such as accountants, insurers, or legal advisers, where necessary.
- Public authorities where disclosure is required by law or to protect legal rights.
Where these parties process data on our behalf, they act as processors and may only use the data according to our instructions. We take reasonable steps to ensure processors are contractually bound to protect your information, maintain confidentiality, and implement appropriate security measures.
We do not sell personal data. We also do not share it for unrelated marketing purposes without an appropriate lawful basis.
6. International Transfers
If any processor stores or accesses data outside the United Kingdom, we will ensure that appropriate safeguards are in place. This may include using approved contractual protections or relying on other lawful transfer mechanisms recognised by data protection law.
7. Retention of Personal Data
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including meeting legal, accounting, and reporting requirements. Retention periods vary depending on the type of information and the reason we hold it.
In general:
- Customer enquiry records may be retained for a limited period after the enquiry ends.
- Service and contract records may be kept for the duration of the relationship and for a reasonable period afterwards.
- Invoice and payment records are usually kept for the period required by tax and accounting law.
- Records relating to complaints, disputes, or claims may be retained for longer where necessary to establish or defend legal rights.
When personal data is no longer needed, we will delete it securely or anonymise it so it can no longer identify you.
8. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and careful selection of service providers. While no system is completely risk-free, we take data security seriously and review our safeguards where appropriate.
9. Your Rights
Under data protection law, you have a number of rights in relation to your personal data. These may include:
- Right of access – to request a copy of the personal data we hold about you.
- Right to rectification – to ask us to correct inaccurate or incomplete information.
- Right to erasure – to ask us to delete your data in certain circumstances.
- Right to restriction – to ask us to limit how we use your data in certain situations.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to data portability – to receive certain information in a structured, commonly used format.
- Right to withdraw consent – where we rely on consent, you can withdraw it at any time.
You also have the right to raise concerns with the UK Information Commissioner's Office if you believe your data protection rights have been breached. We encourage you to raise any concerns with us first so we can try to resolve the matter promptly and fairly.
10. Children’s Data
Our services are not directed at children, and we do not knowingly collect personal data from children except where it is necessary in the context of property access, household arrangements, or where provided by an adult customer for service administration. If we become aware that we have collected data inappropriately, we will take steps to delete it where required.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. The latest version will apply from the date it is made available. We encourage customers in the Gidea Park area to review this policy periodically so they remain informed about how their data is used.
12. Summary of Our Commitment
Gardeners Gidea Park is committed to treating personal data with care, responsibility, and transparency. We collect only the information needed to provide reliable gardening services, use it for clear and lawful purposes, store it securely, and retain it only for as long as necessary. We also respect your rights and aim to make our privacy practices straightforward and fair.
By engaging with our services, you acknowledge that this policy applies to you as a customer in the Gidea Park area and explains how we handle your personal information.