Privacy Policy - Gardeners Earlsfield
Effective for all Gardeners Earlsfield customers in the area. This Privacy Policy explains how personal data is collected, used, shared, and protected when you use our gardening services in Earlsfield and the surrounding area. We are committed to handling personal information in a lawful, fair, and transparent manner in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy applies to all customers, prospective customers, and service users of Gardeners Earlsfield in the area. It covers information collected through enquiries, bookings, service delivery, billing, correspondence, and any related administrative activity. By engaging our services, you acknowledge that your personal data may be processed as described below.
1. Data We Collect
We collect only the information that is necessary for providing and managing our gardening services. The types of personal data we may process include:
- Identity details such as your name and title.
- Contact details such as your address, email address, and telephone number.
- Service details including property access notes, garden preferences, requested services, appointment history, and job instructions.
- Billing and payment information where needed to issue invoices, process payments, or maintain financial records.
- Communication records such as emails, messages, complaint details, feedback, and call notes.
- Technical data if you interact with our digital systems, such as IP address or browser-related information, where applicable.
We do not intentionally collect special category data unless it is necessary and you have provided it voluntarily, or unless another lawful condition applies. Special category data may include health information or other sensitive personal information. If such data is ever required, it will be handled with additional care and only for a legitimate and lawful purpose.
2. How We Use Your Data
Your personal data is used to deliver, manage, and improve our services. Common purposes include:
- responding to enquiries and providing quotations;
- managing bookings and scheduling visits;
- delivering gardening services and maintaining service records;
- processing invoices, payments, and refunds;
- communicating about your appointment or service changes;
- handling complaints, disputes, and customer support requests;
- meeting legal, tax, accounting, and regulatory obligations;
- protecting our business, staff, and customers against fraud or misuse;
- improving service quality and internal administration.
We will only use your data in ways that are compatible with the purpose for which it was collected. If we need to use personal information for a new and unrelated purpose, we will explain this and ensure we have a valid lawful basis.
3. Lawful Basis for Processing
We process personal data only where permitted under UK GDPR. The lawful bases we rely on may include:
Contract
We process data where it is necessary to enter into or perform a contract with you. This includes taking bookings, carrying out gardening work, issuing invoices, and managing service arrangements.
Legal obligation
Some data must be retained and processed to comply with legal duties, including tax, accounting, insurance, and record-keeping requirements.
Legitimate interests
We may process data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include customer administration, service improvement, safeguarding, and fraud prevention. We always balance our interests against your privacy rights.
Consent
In limited situations, we may rely on your consent, for example where you voluntarily provide additional information or agree to receive certain communications. Where consent is used, you may withdraw it at any time.
Vital interests and legal claims
In rare cases, processing may be necessary to protect someone’s vital interests or to establish, exercise, or defend legal claims.
4. Data Sharing and Processors
We do not sell your personal information. We may share data with trusted third parties who act as processors on our behalf or with independent controllers where required. These parties may include:
- payment service providers who handle card or electronic payments;
- accountants and bookkeeping providers for financial administration;
- IT, hosting, and data storage providers that support secure systems;
- customer communication tools used for emails, scheduling, or administration;
- professional advisers such as legal or insurance advisers;
- public authorities, regulators, or law enforcement where required by law.
All processors are expected to safeguard personal data, act only on our instructions, and maintain appropriate security measures. Where a processor is used, we seek to ensure there is a written contract in place that meets data protection requirements.
We may also disclose information if necessary to prevent fraud, protect rights and property, or comply with a court order or other legal requirement.
5. Data Retention
We keep personal data only for as long as necessary to fulfil the purposes described in this policy, including legal, accounting, or reporting obligations. Retention periods depend on the type of record and the reason it was collected.
As a general approach:
- Customer and service records are retained for the period needed to manage the relationship and address any follow-up issues.
- Financial records are kept for the period required by law for tax and accounting purposes.
- Correspondence and complaint records are stored for a reasonable period in case of dispute resolution or service review.
- Consent-based data is kept until consent is withdrawn or the data is no longer needed.
When information is no longer required, we will securely delete, anonymise, or archive it in accordance with our retention procedures.
6. Data Security
We take appropriate technical and organisational measures to protect personal data from unauthorised access, loss, alteration, or disclosure. These measures are designed to reflect the nature of the data we process and the risks involved.
Security controls may include restricted access, password protection, secure storage, staff confidentiality expectations, and careful selection of trusted processors. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute protection. If a data breach occurs that is likely to result in a risk to your rights and freedoms, we will respond in accordance with applicable law.
7. Your Rights
Under data protection law, you have a number of rights regarding your personal information. Subject to legal limits, these rights include:
- Right of access – to request a copy of the personal data we hold about you;
- Right to rectification – to ask us to correct inaccurate or incomplete information;
- Right to erasure – to request deletion of your data in certain circumstances;
- Right to restriction – to ask us to limit how we use your data in some situations;
- Right to data portability – to receive certain information in a structured format where applicable;
- Right to object – to object to processing based on legitimate interests or direct marketing;
- Right to withdraw consent – where processing is based on consent, you can withdraw it at any time;
- Right to complain – to raise concerns with the UK Information Commissioner’s Office if you believe your data rights have been infringed.
Exercising these rights may require us to verify your identity. Some requests may be limited where the law allows or requires us to keep certain information.
8. Children’s Data
Our services are intended for adults or individuals acting on behalf of a property owner or occupier. We do not knowingly collect personal data from children for marketing or routine service purposes. If we become aware that we have inadvertently collected such information without a valid legal basis, we will take reasonable steps to delete it.
9. International Transfers
Where personal data is processed outside the UK, we will take steps to ensure it is protected by appropriate safeguards. These safeguards may include adequacy regulations, standard contractual clauses, or other approved transfer mechanisms, as required by law.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, our services, or our data handling practices. Any updates will apply from the date they are posted or otherwise communicated. We encourage customers to review the policy periodically to stay informed about how personal information is handled.
11. Summary of Our Commitment
Gardeners Earlsfield respects your privacy and is committed to protecting the information you share with us. We collect only what is needed, use it for clear and lawful purposes, retain it only for as long as necessary, and work with trusted processors who are required to safeguard your data. Our approach is based on transparency, accountability, and data minimisation, ensuring that all Gardeners Earlsfield customers in the area are treated fairly and lawfully.