Privacy Policy - Gardeners Bounds Green
This Privacy Policy explains how Gardeners Bounds Green collects, uses, stores, shares, and protects personal data belonging to customers in the Bounds Green area. It applies to all Gardeners Bounds Green customers in the area, including prospective customers, active customers, and anyone who communicates with us about our services. We are committed to handling personal data in a lawful, fair, transparent, and secure manner in accordance with the UK GDPR and the Data Protection Act 2018.
This policy is intended to help you understand what information we collect, why we collect it, how long we keep it, who may process it on our behalf, and what rights you have in relation to your personal data. By using our services, you acknowledge that your personal data may be handled in line with this policy.
1. Data We Collect
We only collect personal data that is relevant and necessary for providing gardening services, managing customer relationships, and meeting our legal obligations. The types of information we may collect include:
- Identity information: name, title, and any preferred form of address.
- Contact information: address, email address, telephone number, and service location details.
- Service information: details of requested work, property access notes, garden preferences, appointment history, quotations, invoices, and records of completed services.
- Communication records: emails, messages, notes from phone calls, feedback, complaints, and service updates.
- Payment and billing information: limited payment-related data needed to issue invoices, record payments, and maintain accurate accounting records. We do not store unnecessary financial details.
- Technical data: basic website or device information if you interact with our digital systems, such as IP address or browser type, where applicable.
We do not intentionally collect special category data unless it is strictly necessary and lawful. If such information is ever required, for example in relation to accessibility needs or health-related access arrangements, it will be handled with additional care and only where appropriate legal conditions are met.
2. How We Use Your Personal Data
We use personal data only for specified and legitimate purposes. These may include:
- providing quotations and arranging gardening services;
- delivering and managing ongoing work at customer properties;
- responding to enquiries, complaints, and service requests;
- maintaining accurate customer records;
- processing payments and issuing invoices;
- meeting tax, accounting, and regulatory obligations;
- improving service quality and customer experience;
- protecting against fraud, misuse, or security incidents;
- keeping records of consent or preferences where required;
- communicating essential service updates or changes.
We will not use your personal data for purposes that are incompatible with the reasons for which it was collected, unless we have a lawful basis to do so and it is otherwise permitted under data protection law.
3. Lawful Basis for Processing
Under GDPR, we must have a lawful basis before processing personal data. Gardeners Bounds Green relies on the following lawful bases depending on the context:
Contract
We process personal data when it is necessary to enter into or perform a contract with you. This includes providing quotes, carrying out agreed gardening services, managing appointments, and handling billing.
Legal Obligation
We may process personal data where we are required to do so by law. This may include keeping accounting records, tax records, or information needed to comply with official requests or legal duties.
Legitimate Interests
We may process personal data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. Examples include maintaining customer records, preventing fraud, managing service quality, and ensuring safe and efficient business operations.
Consent
In limited situations, we may rely on your consent, particularly where the law requires it. If we ask for consent, it will be informed, specific, and freely given. You may withdraw consent at any time, and this will not affect the lawfulness of processing carried out before withdrawal.
4. Retention of Personal Data
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. The retention period depends on the type of record and the reason for holding it.
In general:
- customer and service records are retained for the duration of the customer relationship and for a reasonable period afterwards;
- financial and invoice records are kept for the period required by tax and accounting laws;
- communication records are retained only as long as needed to resolve queries or maintain service history;
- data held on the basis of consent is kept until consent is withdrawn or it is no longer needed;
- information no longer required is securely deleted, anonymised, or archived where appropriate.
We regularly review the data we hold to ensure it is not kept longer than necessary. Data minimisation is an important principle in our approach, and we aim to avoid retaining excessive or outdated information.
5. Processors and Data Sharing
We may use trusted third-party service providers, known as data processors, to help us operate our business. These processors only act on our instructions and are required to protect your data and use it only for agreed purposes.
Examples of processors may include:
- IT and cloud storage providers that support secure data storage and backup;
- accounting or bookkeeping services that help manage invoices and financial records;
- communication tools used for email or customer messaging;
- payment-related providers used to facilitate transactions, where applicable;
- administrative support services that assist with scheduling or record keeping.
We may also share personal data where required by law, to protect our rights or property, or to prevent fraud or security issues. Where data is shared, we limit disclosure to what is necessary and ensure appropriate safeguards are in place.
We do not sell your personal data. We also do not share your information with third parties for their own marketing purposes without a lawful basis and, where required, your consent.
6. Data Security
We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, alteration, disclosure, or destruction. These measures may include access controls, secure storage, restricted permissions, password protection, and staff awareness of data protection responsibilities.
While we work to protect all personal data, no method of transmission or storage is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will assess the situation and take appropriate action in line with applicable law.
7. Your Rights Under GDPR
You have a number of rights in relation to your personal data. These rights may be subject to conditions, exemptions, or legal limitations, but we will always consider requests carefully and respond appropriately.
- Right of access: you may request a copy of the personal data we hold about you.
- Right to rectification: you may ask us to correct inaccurate or incomplete information.
- Right to erasure: you may request deletion of your data where there is no valid reason for us to keep it.
- Right to restrict processing: you may ask us to limit how your data is used in certain circumstances.
- Right to object: you may object to processing based on legitimate interests or direct marketing.
- Right to data portability: you may request certain data in a structured, commonly used format.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
If you exercise any of these rights, we may need to verify your identity before responding. This helps protect your information and ensures requests are handled securely.
8. International Transfers
Where personal data is transferred outside the UK, we will ensure that appropriate safeguards are in place so that your information remains protected to a standard consistent with UK data protection law. Such safeguards may include adequacy regulations or contractual protections.
9. Children's Data
Our services are generally directed at adult customers. We do not knowingly collect personal data from children unless it is necessary and lawful in connection with a service request or property access arrangement made by an adult customer. If we become aware that data has been collected inappropriately, we will take steps to delete or correct it as required.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any revised version will apply from the date it is published or otherwise communicated. We encourage customers to review this policy periodically so they remain informed about how their personal data is handled.
11. Summary of Our Commitment
Gardeners Bounds Green is committed to respecting your privacy and using personal data responsibly. We only collect what we need, use it for legitimate purposes, retain it for no longer than necessary, and protect it through appropriate safeguards. We also recognise your rights and will work to respond to requests in a clear and fair manner.
By engaging our services, you trust us with information that helps us provide reliable and professional gardening support. We take that trust seriously and aim to handle your personal data with care, transparency, and respect.
This Privacy Policy applies to all Gardeners Bounds Green customers in the Bounds Green area.