Privacy Policy - Gardeners Sands End
Gardeners Sands End is committed to protecting the privacy and personal data of all customers in the Sands End area. This Privacy Policy explains how we collect, use, store, share, and protect personal information when we provide gardening services to residential and commercial customers locally. It also explains your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy applies to all Gardeners Sands End customers in the Sands End area, including current, past, and prospective customers, as well as individuals who contact us about our services, request quotations, or receive gardening work at their property.
1. Information We Collect
We only collect personal data that is relevant and necessary for delivering our gardening services, managing customer relationships, and meeting legal or contractual obligations. The types of data we may collect include:
- Identity details such as your name and title.
- Contact details such as address, email address, and telephone number.
- Service details including property access notes, service preferences, garden instructions, and appointment history.
- Billing and payment information such as invoice records, payment confirmations, and transaction references.
- Communication records such as messages, emails, call notes, and complaints or feedback.
- Technical data if you visit any online booking or contact system, such as IP address, browser type, and device information.
- Special category data only where necessary and only in limited circumstances, for example if you voluntarily provide accessibility information that helps us safely carry out a service.
We do not knowingly collect more data than is required. Where possible, we keep information limited and relevant to the purpose for which it was provided.
2. How We Use Personal Data
We use personal information for the following purposes:
- To provide gardening services, quotations, and customer support.
- To arrange visits, manage schedules, and complete work safely and efficiently.
- To process payments, issue invoices, and maintain financial records.
- To communicate with customers regarding service updates, rescheduling, or queries.
- To handle complaints, disputes, or service issues.
- To meet our legal, accounting, and tax obligations.
- To improve our services, internal processes, and customer experience.
- To protect our business, staff, customers, and property from fraud, abuse, or misuse.
We will never use your personal data in a way that is unfair, excessive, or unexpected. Any use of data is limited to what is necessary for the purposes described in this policy.
3. Lawful Basis for Processing
Under data protection law, we must have a valid lawful basis for processing personal data. Gardeners Sands End relies on the following lawful bases:
Contract
We process personal data when it is necessary to enter into or perform a contract with you. This includes preparing quotations, delivering gardening work, managing appointments, and processing payments.
Legal Obligation
We process certain information where we must comply with legal requirements, including tax, accounting, record-keeping, and other regulatory duties.
Legitimate Interests
We may process personal data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include customer administration, service improvement, fraud prevention, and maintaining secure business records.
Consent
In some situations, we may rely on your consent, particularly where processing is optional and not required for a contract or legal duty. If consent is used, you may withdraw it at any time.
Where we process special category data, we will do so only when there is a lawful basis and additional legal condition permitting that processing.
4. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements. Retention periods may vary depending on the type of information and the reason for holding it.
- Customer service records are generally kept for the duration of the service relationship and for a reasonable period afterwards.
- Financial and invoicing records are retained for the period required under tax and accounting law.
- Communications and complaints may be retained for a limited time to help resolve issues and improve service quality.
- Job-related notes and access instructions are kept only as long as needed for service delivery.
When data is no longer needed, we take appropriate steps to securely delete, anonymise, or dispose of it. Retention is always based on necessity, proportionality, and compliance obligations.
5. Data Processors and Sharing
We may share personal data with trusted third parties who help us run our services. These parties act as processors or, in some cases, independent controllers. We only share what is necessary and ensure appropriate data protection safeguards are in place.
Examples of processors and service providers may include:
- Accounting and bookkeeping providers for financial management and tax compliance.
- Payment service providers for handling transactions securely.
- IT and cloud storage providers for secure data hosting, backup, and communications.
- Scheduling or customer management systems used to organise service appointments and records.
- Professional advisers such as legal or insurance advisers where needed.
We require processors to protect personal data, use it only on our instructions where applicable, and maintain appropriate security standards. We do not sell your personal information.
We may also disclose data if required by law, court order, regulatory authority, or where necessary to protect our legal rights, customers, staff, or business operations.
6. Data Security
We take reasonable and appropriate technical and organisational measures to protect personal data from loss, misuse, unauthorised access, disclosure, alteration, or destruction. These measures may include access controls, secure storage, password protection, and limiting access to information to authorised personnel only.
While no system can be guaranteed completely secure, we aim to maintain a high standard of data protection and regularly review our practices to reduce risk.
7. Your Rights
Under data protection law, you have rights in relation to your personal data. These rights may apply depending on the circumstances and the legal basis for processing.
- Right of access – you can request a copy of the personal data we hold about you.
- Right to rectification – you can ask us to correct inaccurate or incomplete data.
- Right to erasure – you can ask us to delete your data in certain situations.
- Right to restriction – you can ask us to limit how we use your data in some cases.
- Right to object – you can object to processing based on legitimate interests.
- Right to data portability – you can request certain data in a structured, commonly used format.
- Right to withdraw consent – where we rely on consent, you may withdraw it at any time.
Important: some rights may not apply in full where we must keep information for legal, contractual, or legitimate business reasons. We will always assess requests in line with applicable law.
8. How to Exercise Your Rights
If you wish to exercise any of your data protection rights, please make a clear request with enough information for us to identify you and understand the nature of your request. We may need to verify your identity before responding, to protect your privacy and security.
We will respond within the time limits required by law and provide information about any action taken. If we cannot comply fully with your request, we will explain why.
9. Complaints
If you are concerned about how your personal data has been handled, you have the right to raise a complaint with the relevant data protection authority. We encourage you to contact us first so we can try to resolve the matter promptly and fairly.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or data protection practices. Any updated version will apply from the date it is published or communicated. We encourage customers to review this policy periodically.
11. Summary of Our Commitment
Gardeners Sands End respects your privacy and is committed to handling personal data lawfully, fairly, and transparently. We collect only what we need, use it for clear and legitimate purposes, keep it only as long as necessary, and protect it with appropriate safeguards. This policy applies to all customers in the Sands End area and is designed to ensure that your information is managed in line with GDPR principles of lawfulness, fairness, transparency, minimisation, accuracy, storage limitation, integrity, and confidentiality.