Privacy Policy - Gardeners Hatch End
This Privacy Policy explains how Gardeners Hatch End collects, uses, stores, shares, and protects personal data when providing gardening services to customers in the Hatch End area. It applies to all Gardeners Hatch End customers in the area, including individuals, households, landlords, tenants, and business clients who request or receive our services. We are committed to processing personal data in a lawful, fair, and transparent way in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using our services, you acknowledge that some personal data may be collected and processed for service delivery, administration, safety, legal compliance, and legitimate business purposes. We only collect data that is relevant and necessary, and we take steps to ensure it is kept secure and used responsibly.
1. Information We Collect
We may collect and process the following categories of personal data:
- Identity data such as your name or company name.
- Contact data such as address details, email address, and telephone number.
- Service information such as property access notes, garden preferences, service instructions, and scheduled appointment details.
- Payment and billing information where needed for invoicing, payment processing, and record-keeping.
- Communication records including messages, service requests, complaints, feedback, and notes relating to customer support.
- Technical data such as basic website or device usage information if you interact with our digital systems, where applicable.
- Security and operational data such as site access information, appointment history, and risk notes relevant to delivering services safely.
We generally collect this information directly from you when you request a quote, book a service, communicate with us, or provide updates about your property or preferences. In some cases, information may also be provided by property managers, landlords, tenants, or other authorised representatives.
2. How We Use Personal Data
Gardeners Hatch End uses personal data for the following purposes:
- To provide, manage, and complete gardening services.
- To arrange appointments and communicate service updates.
- To prepare estimates, invoices, and payment records.
- To record customer preferences and service history.
- To maintain health, safety, and access notes relevant to our work.
- To respond to enquiries, feedback, complaints, and requests.
- To meet legal, accounting, tax, and insurance obligations.
- To improve our services, systems, and customer experience.
- To prevent fraud, misuse, or unauthorised access to our systems or records.
We will only use your data for purposes that are compatible with the reason it was collected, unless we obtain your permission or are otherwise legally permitted to do so.
3. Lawful Basis for Processing
Under data protection law, we must have a lawful basis for each processing activity. Depending on the nature of the interaction, Gardeners Hatch End may rely on one or more of the following lawful bases:
Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes handling bookings, delivering gardening services, managing invoices, and maintaining account information.
Legal Obligation
We may process data to comply with legal obligations, including tax laws, accounting rules, insurance requirements, health and safety obligations, and record-keeping duties.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests and where those interests are not overridden by your rights and freedoms. Examples include managing service records, improving operations, preventing fraud, and protecting our business and customers.
Consent
In limited situations, we may rely on your consent, for example where it is appropriate to contact you for certain non-essential communications. Where we rely on consent, you can withdraw it at any time.
4. Sharing and Processors
We may share personal data only where necessary and only with trusted third parties who support our business operations. These organisations act as data processors or, in some cases, independent controllers. They are required to handle personal data securely and in line with applicable data protection law.
Examples of processors or service providers may include:
- Payment processors for handling card or electronic payments.
- Accounting and bookkeeping providers for invoicing and financial administration.
- IT and cloud service providers for secure storage, backup, and system maintenance.
- Communication platforms used to send messages, reminders, or service updates.
- Professional advisers such as insurers, legal advisers, or accountants where necessary.
We do not sell personal data. We do not share personal data with unrelated third parties for their own marketing purposes without a valid legal basis. If required by law, we may disclose information to public authorities, regulators, law enforcement, or courts.
5. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, and operational requirements. Retention periods may vary depending on the type of data and the reason for processing.
In general:
- Service and contract records are kept for the period needed to manage the customer relationship and resolve any issues.
- Financial and tax records are kept for the period required by applicable law.
- Communication records may be retained for a reasonable period to manage queries, complaints, and service history.
- Health and safety or access notes are retained only as long as necessary for safe service delivery.
When personal data is no longer required, we will delete it securely or anonymise it so that it can no longer identify you.
6. Data Security
We take appropriate technical and organisational measures to protect personal data from loss, misuse, unauthorised access, disclosure, alteration, or destruction. These measures may include access controls, secure storage, password protection, limited staff access, and regular review of data handling practices.
Although we make every reasonable effort to protect information, no method of transmission or storage is completely secure. If a data breach occurs and there is a risk to your rights and freedoms, we will respond in line with legal requirements.
7. Your Rights
As a data subject under UK GDPR, you have a number of rights regarding your personal data. Subject to certain conditions and exemptions, these may include:
- Right of access – to request a copy of the personal data we hold about you.
- Right to rectification – to ask us to correct inaccurate or incomplete information.
- Right to erasure – to request deletion of your data in certain circumstances.
- Right to restriction – to ask us to limit how we use your data in certain situations.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to data portability – to request transfer of certain data in a structured, commonly used format.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
These rights are not absolute, and in some cases we may need to retain or continue processing data where required by law or for legitimate business purposes. We will explain any refusal or limitation where applicable.
8. International Transfers
Where any processors or service providers store or access data outside the UK, we will ensure appropriate safeguards are in place to protect your information in line with applicable data protection laws.
9. Children’s Data
Our services are generally provided to adults and property owners or occupiers. We do not intentionally collect personal data from children. If we become aware that we have collected such data without appropriate authority, we will take reasonable steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, our services, or data handling practices. Any revised version will apply from the date it is made available. We encourage customers to review this policy periodically to stay informed about how personal data is processed.
11. Summary of Our Commitment
Gardeners Hatch End is committed to handling personal data with care, transparency, and respect. We collect only what we need, use it for clear and lawful purposes, retain it only for as long as necessary, and work with trusted processors who are contractually bound to protect it. We also recognise and support your rights under data protection law.
By choosing our services, you understand that we may process your personal information as set out in this policy in order to deliver gardening services safely, efficiently, and lawfully across the Hatch End area.