Privacy Policy - Gardeners St Pauls Cray

Gardeners St Pauls Cray is committed to protecting the privacy of every customer in the area we serve. This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when you use our gardening services. It applies to all Gardeners St Pauls Cray customers in the area, including people who enquire about our services, receive a quotation, book work, or communicate with us in any way.

We aim to handle personal data fairly, transparently, and in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy is intended to help you understand what information we hold, why we hold it, and what rights you have in relation to it.

1. Information We Collect

We only collect personal data that is necessary for providing gardening services, managing enquiries, and running our business effectively. The information we may collect includes:

  • Identity details: your name and, where relevant, the name of your household or business.
  • Contact details: address, email address, and telephone number.
  • Service details: information about the type of gardening work requested, preferred dates, property access notes, and instructions relevant to the service.
  • Communication records: messages, emails, call notes, and other correspondence related to enquiries, bookings, and completed work.
  • Payment-related information: records needed to process payments, issue invoices, and maintain accounts.
  • Website or device data: limited technical information such as IP address or browser details if you contact us through digital channels, where applicable.

We do not intentionally collect special category data unless it is strictly necessary and you choose to provide it. If any such information is shared with us, it will be handled carefully and only where a valid legal reason exists.

2. How We Use Your Data

We use personal data to operate our services and manage our relationship with you. The main uses include:

  • responding to enquiries and providing quotations;
  • arranging appointments and delivering gardening services;
  • managing customer records and service history;
  • processing payments and maintaining financial records;
  • handling complaints, queries, or follow-up requests;
  • improving our services and customer experience;
  • meeting legal, tax, and insurance obligations;
  • protecting our business, staff, contractors, and customers from fraud or misuse.

We only use your data for purposes that are compatible with the original reason it was collected. If we need to use it for a new purpose, we will ensure that there is a valid lawful basis under data protection law.

3. Lawful Basis for Processing

Under UK GDPR, we must have a lawful basis for processing personal data. Gardeners St Pauls Cray relies on the following lawful bases depending on the situation:

Contract

We process your data when it is necessary to take steps before entering into a contract or to perform a contract with you. This includes creating quotations, booking work, delivering services, and managing related customer communications.

Legal Obligation

We may process and retain certain records because we are required to do so by law. This can include tax records, accounting information, and records needed to comply with statutory or regulatory requirements.

Legitimate Interests

We may process data where it is in our legitimate interests and your rights do not override those interests. Examples include managing our business operations, maintaining service records, improving customer service, preventing fraud, and ensuring safe and efficient scheduling of work. We always balance our interests against your privacy rights.

Consent

In limited situations, we may rely on your consent, for example where you ask us to send optional marketing updates or agree to a specific use of your information. Where consent is used, you may withdraw it at any time.

4. Data Sharing and Processors

We do not sell personal data. We may share information with trusted third parties only when necessary to operate our services, comply with legal obligations, or protect legitimate business interests. These third parties may act as data processors on our behalf or, in some cases, as independent data controllers.

Typical processors may include:

  • Payment providers: used to process transactions securely.
  • Accounting and bookkeeping providers: used to manage invoices, records, and financial compliance.
  • IT and cloud storage providers: used to store communications, schedules, and business records securely.
  • Communication service providers: used to send emails, messages, or service updates.
  • Professional advisers: such as accountants, legal advisers, or insurers where needed.

All processors are expected to handle personal data securely and only in accordance with our instructions and applicable law. Where data is shared with independent controllers, such as tax authorities or law enforcement, they will be responsible for their own use of the information.

We take reasonable steps to ensure that any third party handling personal data provides adequate security and confidentiality safeguards.

5. Data Retention

We keep personal data only for as long as necessary to fulfil the purpose for which it was collected, including any legal, accounting, or reporting requirements. Retention periods may vary depending on the type of data and the reason it is held.

In general:

  • customer enquiry records may be kept for a limited period after the enquiry ends;
  • service and invoicing records may be retained for several years to meet financial and legal obligations;
  • communication records may be stored for as long as needed to manage the customer relationship or resolve disputes;
  • data no longer required will be securely deleted or anonymised.

We regularly review our records to ensure that information is not kept longer than necessary. When data is no longer required, it is disposed of in a secure manner.

6. How We Protect Your Information

We use appropriate technical and organisational measures to safeguard personal data. These measures may include access controls, secure storage, password protection, restricted permissions, and careful management of physical and digital records. While no system can be guaranteed to be completely secure, we work to reduce the risk of unauthorised access, loss, or misuse.

Only authorised personnel and approved processors may access personal data where necessary for the performance of their duties. We also expect anyone handling data on our behalf to follow strict confidentiality and security standards.

7. Your Rights

Under data protection law, you have important rights regarding your personal data. Subject to certain conditions and exceptions, these rights may include:

  • Right of access: you can request a copy of the personal data we hold about you.
  • Right to rectification: you can ask us to correct inaccurate or incomplete data.
  • Right to erasure: in some circumstances, you can ask us to delete your personal data.
  • Right to restrict processing: you can request limited use of your data in certain situations.
  • Right to data portability: you may ask for data you provided to us in a structured, commonly used format where applicable.
  • Right to object: you can object to processing based on legitimate interests or direct marketing.
  • Right to withdraw consent: if we rely on consent, you can withdraw it at any time.

You also have the right to raise concerns with the Information Commissioner’s Office if you believe your data has been handled improperly. We encourage you to contact us first so we can try to resolve the matter promptly and fairly.

8. Children’s Data

Our services are not directed at children, and we do not knowingly collect data from children as part of ordinary gardening services. If any information relating to a child is incidentally provided in connection with a service request, it will be treated with appropriate care and used only where necessary.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. Any changes will take effect when the revised policy is made available. We encourage customers to review this policy periodically so they remain informed about how their information is handled.

10. Summary of Our Commitment

Gardeners St Pauls Cray only processes personal data where it is necessary, lawful, and proportionate. We aim to be transparent about what we collect, why we collect it, how long we keep it, and who may process it on our behalf. We respect your rights and will always work to handle your information in a fair, secure, and responsible manner.

By using our services, you acknowledge that this Privacy Policy applies to all Gardeners St Pauls Cray customers in the area.

Gardeners St Pauls Cray

Gardeners St Pauls Cray is committed to protecting customer privacy and handling personal data fairly under UK GDPR.

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.