Privacy Policy - Gardeners Eastcote
This Privacy Policy explains how Gardeners Eastcote collects, uses, stores, shares, and protects personal data when providing gardening services. It applies to all Gardeners Eastcote customers in the area, including prospective customers, existing customers, and individuals who enquire about our services. We are committed to handling personal information fairly, lawfully, and transparently in line with the UK GDPR and the Data Protection Act 2018.
1. Who This Policy Applies To
This policy applies to anyone who uses or requests services from Gardeners Eastcote, including household customers, business customers, property managers, tenants, landlords, and anyone else who interacts with us for service enquiries, bookings, quotes, scheduling, invoicing, or aftercare. It also covers personal data collected when you visit our premises, communicate with us, or allow us to carry out work at a property.
We only collect the information we need to provide our services effectively, manage customer relationships, meet legal obligations, and improve our operations.
2. Data We Collect
We may collect the following types of personal data:
- Identity data, such as your name and title.
- Contact data, such as your address, email address, and telephone number.
- Service details, such as the type of gardening work requested, property access instructions, preferred appointment times, and service history.
- Billing and payment data, such as invoice details, payment records, and transaction references.
- Communication data, such as messages, call notes, emails, and feedback.
- Technical data, where relevant, such as basic website usage information or device details if you interact with our online systems.
- Operational data, such as attendance records, quotations, job notes, and photographs taken to document completed work where necessary for service delivery or quality control.
We do not seek to collect special category data unless it is strictly necessary and you voluntarily provide it, or there is a lawful reason to do so. If such information is ever collected, it will be handled with heightened care and only for a specific, legitimate purpose.
3. How We Use Your Data
Gardeners Eastcote uses personal data for the following purposes:
- to respond to enquiries and provide quotations;
- to arrange and deliver gardening services;
- to manage customer accounts and service records;
- to communicate about appointments, changes, and follow-up matters;
- to issue invoices, process payments, and maintain accounting records;
- to improve service quality, training, and customer experience;
- to meet legal, tax, insurance, and regulatory requirements;
- to prevent fraud, misuse, or security incidents;
- to resolve disputes and handle complaints.
We will never use your data in a way that is incompatible with the reason it was collected. Where possible, we apply data minimisation by collecting only what is necessary for the relevant task.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis to process personal data. Gardeners Eastcote relies on the following lawful bases:
Contract
We process data where it is necessary to enter into or perform a contract with you. This includes preparing quotes you have requested, scheduling work, delivering services, and managing payments.
Legal Obligation
We process certain data to comply with legal obligations, including tax, accounting, insurance, safeguarding, and record-keeping requirements.
Legitimate Interests
We may process data where it is necessary for our legitimate interests and where your rights do not override those interests. This may include maintaining internal records, improving services, preventing fraud, ensuring security, and handling routine business administration. We always consider the impact on your privacy before relying on this basis.
Consent
In limited situations, we may rely on your consent, for example where you choose to receive certain types of marketing or where consent is required for specific optional processing. You may withdraw consent at any time if processing is based on consent.
5. Sharing Your Data and Processors
We may share personal data with trusted third parties who support our business operations. These parties act as processors when they process data on our behalf and only according to our instructions. Examples may include:
- accounting and bookkeeping providers;
- payment service providers;
- IT and cloud storage providers;
- customer management or scheduling software providers;
- email and communication service providers;
- professional advisers such as insurers, auditors, or legal advisers where needed;
- subcontractors or service partners who assist in delivering work at a property.
We require processors to take appropriate security measures and to process personal data only for the purposes we specify. We do not sell personal data. We may disclose data to public authorities, regulators, or courts where required by law or where necessary to protect our legal rights.
6. Retention of Personal Data
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. The retention period depends on the type of information and how it is used.
- Customer and service records are typically retained for the duration of the relationship and for a reasonable period afterwards.
- Invoice and payment records are retained for the period required by tax and accounting laws.
- Correspondence and complaints are retained for as long as needed to manage the matter and support record keeping.
- Consent records are retained until consent is withdrawn or no longer needed.
When data is no longer required, it is securely deleted, anonymised, or otherwise disposed of in a safe and appropriate manner.
7. Data Security
We take reasonable technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures may include access controls, password protection, secure storage, restricted access on a need-to-know basis, and staff awareness of data protection responsibilities.
Although we work to protect your information, no method of transmission or storage is completely secure. We therefore cannot guarantee absolute security, but we continually review our practices to maintain a high standard of protection.
8. International Transfers
If any processor or service provider stores or accesses data outside the UK, we will ensure appropriate safeguards are in place to protect your personal information in accordance with applicable data protection law. This may include approved contractual protections or adequacy arrangements where relevant.
9. Your Rights
Under data protection law, you have a number of rights in relation to your personal data. Subject to legal limits, these include:
- The right to be informed about how your data is used;
- The right of access to request a copy of the personal data we hold about you;
- The right to rectification if your data is inaccurate or incomplete;
- The right to erasure in certain circumstances, sometimes called the “right to be forgotten”;
- The right to restrict processing where specific conditions apply;
- The right to data portability in certain cases;
- The right to object to processing based on legitimate interests or to direct marketing;
- The right to withdraw consent where processing is based on consent;
- Rights related to automated decision-making, where applicable, although we do not عادة use solely automated decisions that have legal or similarly significant effects.
If you wish to exercise any of these rights, we will respond in accordance with applicable law. We may need to verify your identity before acting on a request. In some cases, we may not be able to comply fully if the law requires us to retain certain data or if an exemption applies.
10. Marketing Preferences
If we send any marketing communications, they will only be sent where permitted by law. You can object to direct marketing at any time, and we will respect that choice. Where consent is required, you may withdraw it whenever you like.
11. Children’s Data
Our services are generally intended for adults responsible for properties and gardening arrangements. We do not knowingly collect children’s personal data unless it is incidentally provided by an adult customer and is necessary for the service or compliance purpose described in this policy.
12. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, business practices, or service operations. Any updated version will apply from the date it takes effect. We encourage customers to review this policy periodically to stay informed about how personal data is handled.
13. Summary of Our Approach
Gardeners Eastcote is committed to lawful, fair, and transparent processing of personal data. We collect only what is needed, use it for clear purposes, protect it with appropriate safeguards, and retain it only as long as necessary. This policy is designed to give customers confidence that their information is handled responsibly throughout the service relationship.
By engaging with Gardeners Eastcote, requesting a quote, or using our services, you acknowledge that your personal data may be processed as described in this policy and in accordance with applicable data protection laws.