Privacy Policy - Gardeners East Sheen
Gardeners East Sheen is committed to protecting the privacy of all customers in the area and handling personal data in a lawful, fair, and transparent way. This Privacy Policy explains how personal information is collected, used, shared, stored, and protected when services are arranged or delivered. It applies to all Gardeners East Sheen customers in the area, whether contact is made by phone, email, online enquiry, referral, or through any other service arrangement.
We respect the importance of privacy and aim to keep data handling limited to what is necessary for providing gardening services, managing bookings, responding to enquiries, and meeting legal and operational obligations. By using our services, customers can expect their personal information to be treated with care and in accordance with applicable data protection laws, including the UK GDPR and the Data Protection Act 2018.
1. Data We Collect
We collect only the information needed to provide and manage services effectively. This may include:
- Identity details such as name and, where relevant, the name of a household member or property manager.
- Contact details such as telephone number, email address, and service address.
- Service information such as job requests, gardening preferences, access notes, scheduling information, and service history.
- Billing and payment information where required to issue invoices, record payments, or manage accounting.
- Communication records including emails, messages, call notes, and feedback.
- Technical information if an enquiry is made through digital systems, such as basic device or usage information, where applicable.
We do not intentionally collect more information than is necessary. We also avoid collecting special category data unless it is strictly required and a valid legal condition applies. For example, if a customer voluntarily provides information relevant to site access, safety, or vulnerability, it will only be used for service delivery and safeguarding purposes.
2. How We Use Personal Data
Personal data is used for the following purposes:
- To respond to enquiries and provide quotations.
- To arrange, deliver, and manage gardening services.
- To maintain records of services carried out and customer preferences.
- To issue invoices, process payments, and manage account administration.
- To communicate about scheduling, updates, changes, or follow-up matters.
- To handle complaints, disputes, and service-related queries.
- To meet legal, tax, accounting, and insurance obligations.
- To improve service quality, operational planning, and internal record keeping.
We only use personal information for legitimate business purposes connected with our services. We do not sell personal data, and we do not use it for unrelated marketing unless appropriate permission has been given where required by law.
3. Lawful Basis for Processing
Under data protection law, we must have a lawful basis for processing personal data. Gardeners East Sheen relies on the following bases:
Contract
We process data when it is necessary to prepare for, enter into, or perform a contract. This includes managing bookings, carrying out agreed work, invoicing, and communicating about the service.
Legitimate Interests
We may process data where it is reasonably necessary for our legitimate business interests, provided these interests do not override the rights and freedoms of the individual. This includes managing customer records, improving service administration, protecting our business from fraud, and ensuring efficient operations.
Legal Obligation
Some information must be kept or used to comply with legal requirements, such as tax, accounting, insurance, or regulatory duties.
Consent
Where consent is required, such as for optional communications or specific uses not covered by other lawful bases, it will be requested clearly. Consent can be withdrawn at any time, although this will not affect processing already carried out lawfully before withdrawal.
4. Data Sharing and Processors
We may share personal data with trusted third parties only where necessary for business operations, legal compliance, or service delivery. These third parties act as processors or independent controllers depending on the service they provide.
Examples of processors may include:
- Payment providers that handle card or electronic payments.
- Accounting or bookkeeping services used for invoicing and financial administration.
- IT and data storage providers that support email, file storage, and system management.
- Scheduling or customer management tools used to organise bookings and service records.
- Professional advisers such as insurers, legal advisers, or auditors where necessary.
All processors are required to handle data securely and only in accordance with our instructions, unless they are acting as independent controllers. We take reasonable steps to ensure that any third party receiving personal data provides appropriate safeguards and complies with data protection law.
In some situations, data may need to be disclosed to public authorities, law enforcement, or regulators if required by law. We may also share limited information where it is necessary to protect rights, property, safety, or to prevent fraud or misuse.
5. Data Retention
We keep personal data only for as long as necessary for the purpose it was collected, including for legal, accounting, tax, insurance, and operational requirements. Retention periods depend on the type of data and the reason for processing.
- Customer and service records are retained for the period needed to manage ongoing relationships and resolve queries.
- Financial records are kept for the period required by tax and accounting law.
- Communication records may be retained for a reasonable period to support continuity, quality control, and dispute handling.
- Inactive data is deleted or securely anonymised when it is no longer needed.
Where it is possible and appropriate, we will securely delete personal data once the retention period ends. In some cases, records may be retained longer if required to establish, exercise, or defend legal claims, or to meet a binding regulatory obligation.
6. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, misuse, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and limited access to records on a need-to-know basis.
Although no system can be guaranteed completely secure, we take data protection seriously and review our practices periodically to maintain a high standard of security.
7. User Rights
Individuals whose personal data we hold have a number of rights under data protection law. These may include:
- Right of access - to request a copy of the personal data held about them.
- Right to rectification - to request correction of inaccurate or incomplete data.
- Right to erasure - to request deletion of data in certain circumstances.
- Right to restriction - to ask us to limit how data is used in specific cases.
- Right to object - to object to processing based on legitimate interests or direct marketing.
- Right to data portability - to request transfer of certain data where legally applicable.
- Right to withdraw consent - where processing is based on consent.
Requests will be handled in line with legal requirements and may require identity verification before a response is provided. Some rights are subject to exceptions and may not apply in every situation.
8. Cookies and Similar Technologies
If digital tools are used for enquiries or service management, basic cookies or similar technologies may be used to improve functionality and understand usage patterns. Where consent is required, it will be requested in a clear manner. Customers can manage browser settings to limit or block cookies, although this may affect website performance where relevant systems are used.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, service arrangements, or internal practices. The latest version will apply from the date it is made available. Customers are encouraged to review the policy periodically to remain informed about how personal data is handled.
10. Summary of Our Commitment
Gardeners East Sheen processes personal data only when there is a valid lawful basis, keeps it for no longer than necessary, and uses trusted processors under suitable safeguards. We aim to ensure that every customer’s data is treated with respect, confidentiality, and care. Our approach is designed to be transparent, proportionate, and compliant with GDPR requirements, while supporting reliable gardening services across the East Sheen area.
This policy applies to all Gardeners East Sheen customers in the area.