Privacy Policy - Gardeners Gipsy Hill
Gardeners Gipsy Hill is committed to protecting the privacy of every customer in the area and to handling personal data in a lawful, fair, and transparent way. This Privacy Policy explains how we collect, use, store, share, and protect personal information when you request, receive, or enquire about gardening services from us. It applies to all Gardeners Gipsy Hill customers in the area, including individuals who contact us for a quotation, arrange a booking, or use our services on an ongoing basis.
We understand that privacy matters. This policy is written to help you understand what information we collect, why we use it, how long we keep it, and what rights you have under the UK General Data Protection Regulation and the Data Protection Act 2018. By making use of our services, you acknowledge that your information may be processed in accordance with this policy.
1. Information We Collect
We collect only the personal data necessary to manage enquiries, provide gardening services, and meet legal obligations. The types of information we may collect include:
- Identity details, such as your name and title.
- Contact details, including your address, email address, and telephone number.
- Service information, such as the type of work requested, garden access details, service preferences, and notes needed to complete the work safely and effectively.
- Billing and payment information, where relevant for invoices, payment records, and transaction confirmation.
- Communication records, including emails, messages, call notes, and instructions relating to bookings or complaints.
- Technical information if you contact us through digital channels, such as basic device or browser details that may be used for security, troubleshooting, or website performance, where applicable.
We do not seek to collect more information than is needed for the service we provide. We also do not intentionally collect special category data unless it is necessary and lawful to do so, for example where it is voluntarily shared and relevant to service delivery, safety, or legal compliance.
2. How We Use Your Data
We use personal data for the following purposes:
- to respond to enquiries and provide quotations;
- to arrange and deliver gardening services;
- to manage customer accounts, invoices, and payments;
- to keep service records and maintain quality standards;
- to communicate about appointments, schedule changes, and work updates;
- to deal with complaints, feedback, and after-service queries;
- to comply with tax, accounting, insurance, and other legal duties;
- to protect our business, staff, and customers from fraud, misuse, or unlawful activity.
We may also use aggregated or anonymised information for business planning, service improvement, and reporting. Anonymised data does not identify you and is not treated as personal data.
3. Lawful Basis for Processing
We only process personal data where we have a valid lawful basis under data protection law. Depending on the circumstances, the lawful basis may be one or more of the following:
Contract
We process personal information when it is necessary to enter into or perform a contract with you. This includes taking bookings, delivering gardening services, sending service updates, and managing payments.
Legitimate Interests
We may process data where it is reasonably necessary for our legitimate business interests, provided your rights and freedoms do not override those interests. Examples include maintaining internal records, improving services, managing customer communication, and preventing misuse or fraud. When relying on legitimate interests, we assess the impact of the processing and aim to keep it proportionate.
Legal Obligation
Some information must be retained or used to satisfy legal and regulatory obligations, such as accounting, tax record-keeping, insurance requirements, or responding to lawful requests from authorities.
Consent
In limited situations, we may rely on your consent, for example where we need permission to send certain marketing communications or to use information for a purpose not covered by another lawful basis. Where consent is used, you may withdraw it at any time.
4. Data Sharing and Processors
We may share personal data with trusted third parties, known as processors, who assist us in running our business. These processors only act on our instructions and are required to protect your data appropriately.
Examples of processors or service providers may include:
- accounting or bookkeeping providers;
- payment processing services;
- email, messaging, and customer administration systems;
- IT support and secure data storage providers;
- professional advisers such as insurers, auditors, or legal advisers where necessary.
We may also disclose data where required by law, court order, or a regulator, or where it is necessary to protect our rights, customers, staff, or property. We do not sell your personal data.
Where a processor handles personal data on our behalf, we ensure that appropriate contractual and security measures are in place. We choose service providers carefully and expect them to meet relevant data protection standards.
5. Data Retention
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, insurance, and reporting requirements. Retention periods can vary depending on the nature of the information and the reason it is held.
- Customer and service records are generally kept for as long as needed to manage the service relationship and resolve any follow-up issues.
- Financial records are retained for the period required by tax and accounting laws.
- Communication records may be kept for a reasonable period to support service history, dispute handling, and quality assurance.
When personal data is no longer required, we take steps to delete it securely or anonymise it so that it can no longer identify you. We do not keep data indefinitely without a valid reason.
6. Data Security
We use appropriate technical and organisational measures to protect personal data from loss, misuse, unauthorised access, disclosure, alteration, or destruction. These measures may include secure storage, access controls, password protection, and limiting access to only those who need the information for legitimate business purposes.
While no system can be guaranteed completely secure, we are committed to maintaining a level of security appropriate to the risks involved. If a personal data breach occurs and it presents a risk to your rights and freedoms, we will handle it in accordance with applicable data protection laws.
7. Your Rights
Under data protection law, you have a number of rights in relation to your personal data. These rights may apply in different situations and may be subject to legal exceptions. They include:
- Right of access – you can ask for a copy of the personal data we hold about you.
- Right to rectification – you can ask us to correct inaccurate or incomplete information.
- Right to erasure – you can request deletion of your personal data in certain circumstances.
- Right to restriction – you can ask us to limit the use of your data in certain situations.
- Right to object – you can object to processing based on legitimate interests or to certain direct marketing activities.
- Right to data portability – you may request that certain information be provided to you or another controller in a structured, commonly used format, where applicable.
- Right to withdraw consent – where processing is based on consent, you can withdraw it at any time.
If you wish to exercise any of these rights, please make a clear request using the details provided in our service communications or records. We may need to verify your identity before acting on your request. We aim to respond within the timeframe required by law.
8. Marketing and Communication Preferences
We will only send marketing communications where permitted by law. If you receive optional marketing messages, you may opt out at any time. Service-related communications, however, may still be sent when they are necessary to manage your booking, deliver the service, or fulfil a legal obligation.
You can also let us know if you prefer communication in a particular format. We will try to accommodate reasonable preferences where possible.
9. Children’s Data
Our services are intended for adult customers or authorised representatives arranging gardening work. We do not knowingly collect personal data from children except where it is incidental and necessary for the provision of a household service, or where it is lawfully provided by an adult responsible for the booking. If we become aware that data has been collected in error, we will take appropriate steps to delete or protect it.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or data handling practices. Any revised version will apply from the date it takes effect. We encourage customers to review this policy periodically so they remain informed about how we process personal data.
11. Summary of Our Commitment
Gardeners Gipsy Hill will only collect and use personal data where there is a clear and lawful reason to do so. We are committed to keeping information accurate, secure, and no longer than necessary. We will process data fairly, respect your rights, and ensure that any processors working on our behalf provide suitable safeguards.
This Privacy Policy applies to all Gardeners Gipsy Hill customers in the area and is designed to reflect a responsible, transparent, and GDPR-compliant approach to data protection.