Privacy Policy - Gardeners Northwood
Gardeners Northwood is committed to protecting the privacy and personal data of everyone who uses our services. This Privacy Policy explains how we collect, use, store, share, and protect personal information in a manner that is consistent with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It applies to all Gardeners Northwood customers in the area, including individuals who enquire about our services, request quotations, book gardening work, or receive ongoing maintenance from us.
We aim to keep this policy clear and transparent so that you understand what happens to your information when you engage with our gardening services. By using our services, you acknowledge that your personal data may be processed as described below.
1. Information We Collect
We collect only the personal data that is necessary for operating our services, managing customer relationships, and meeting legal obligations. The information we may collect includes:
- Identity details such as your name and any business or household name you provide.
- Contact details such as postal address, email address, and telephone number.
- Service details including the type of gardening work requested, property access notes, scheduling preferences, and service history.
- Billing and payment information where needed to issue invoices, record payments, and manage account administration.
- Communication records such as emails, messages, call notes, and feedback relating to quotes, appointments, complaints, or service updates.
- Technical data if you interact with our digital systems, such as basic device or usage information used for security and performance purposes.
We do not intentionally collect special category data unless it is strictly necessary and you have provided it for a specific reason, for example, to help us make reasonable arrangements for access or service delivery. Where such information is processed, we do so with additional safeguards.
2. How We Use Your Personal Data
We use personal data for legitimate operational purposes connected to our gardening services. These include:
- responding to enquiries and preparing quotations;
- booking, delivering, and managing gardening services;
- maintaining customer records and service preferences;
- issuing invoices, processing payments, and keeping financial records;
- handling complaints, disputes, and service-related queries;
- meeting legal, tax, accounting, and regulatory requirements;
- protecting our business, staff, and customers from fraud or misuse; and
- improving service quality and operational efficiency.
We only use your information where there is a valid and lawful reason to do so. We do not sell your personal data to third parties.
3. Lawful Basis for Processing
Under data protection law, we must have a lawful basis for processing personal data. Gardeners Northwood relies on the following lawful bases, depending on the specific activity:
Contract
We process information where it is necessary to enter into or perform a contract with you. This includes arranging services, confirming appointments, handling service instructions, and managing payment obligations.
Legitimate Interests
We may process personal data where it is necessary for our legitimate business interests, provided that those interests are not overridden by your rights and freedoms. Examples include maintaining accurate customer records, managing service delivery, improving our operations, and protecting against fraud or misuse.
Legal Obligation
Some information must be retained and processed to comply with legal requirements, including tax, accounting, insurance, and record-keeping obligations.
Consent
In limited cases, we may rely on your consent, for example if you ask us to use certain information for an optional purpose. Where consent is used, you may withdraw it at any time, although this will not affect processing already carried out lawfully before withdrawal.
4. Sharing Your Information and Processors
We may share personal data with trusted third parties who help us run our services. These organisations act as processors or independent controllers depending on the circumstances. We ensure that appropriate contracts and safeguards are in place before any personal data is shared.
Examples of processors and service providers may include:
- IT and cloud service providers that store records securely and support administrative systems;
- accounting or bookkeeping providers that assist with invoicing, tax, and financial administration;
- payment processing services that handle card or electronic payments;
- communication tools used for email, messaging, or scheduling;
- professional advisers such as accountants, insurers, or legal advisers where required;
- subcontractors or specialist suppliers involved in delivering a requested service.
We may also disclose information where required by law, court order, or regulatory authority. If a third party receives your data, they are only permitted to use it for the agreed purpose and must keep it secure.
5. Retention of Personal Data
We keep personal data only for as long as it is needed for the purpose it was collected, or for as long as required by law. Our retention periods vary depending on the type of information and the reason for holding it.
- Enquiry records may be kept for a reasonable period to manage follow-up communications and service planning.
- Customer service records are kept for the duration of the relationship and a further period where necessary for administration, complaint handling, or legal protection.
- Financial and tax records are retained for the period required by law and accounting rules.
- Communication and dispute records may be held longer if needed to resolve issues or defend legal claims.
When data is no longer required, it is securely deleted, anonymised, or otherwise disposed of using appropriate methods. We review retention practices periodically to ensure we do not keep information longer than necessary.
6. Data Security
We use appropriate technical and organisational measures to protect personal data from unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, secure storage, password protection, staff awareness, and limiting data access to authorised personnel only.
Although no system can be guaranteed to be completely secure, we take reasonable and proportionate steps to safeguard the information we hold. If a personal data breach occurs and there is a risk to your rights and freedoms, we will respond in line with our legal obligations.
7. Your Rights Under Data Protection Law
Depending on the circumstances, you may have the following rights in relation to your personal data:
- Right of access – to request a copy of the personal data we hold about you.
- Right to rectification – to request correction of inaccurate or incomplete information.
- Right to erasure – to request deletion of your data in certain circumstances.
- Right to restrict processing – to ask us to limit how we use your data in certain situations.
- Right to data portability – to receive certain information in a structured, commonly used format where applicable.
- Right to object – to object to processing based on legitimate interests, including direct marketing where relevant.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
To protect privacy, we may need to verify your identity before responding to a rights request. Some rights are subject to legal limits and may not apply in every case. We will explain the outcome of any request clearly and fairly.
8. International Transfers
Where any service provider stores or processes data outside the UK, we ensure appropriate safeguards are in place to protect your information. These safeguards may include approved contractual protections or other lawful transfer mechanisms required under data protection law.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or operational practices. Any revised version will apply from the date it is published or otherwise communicated. We encourage customers to review this policy periodically so they remain informed about how their information is handled.
10. Our Commitment to Privacy
Gardeners Northwood values trust, discretion, and responsible handling of personal information. We aim to process data fairly, lawfully, and transparently, while keeping it secure and only for clearly defined purposes. If you use our services, we will treat your information with care and use it only as necessary to deliver the service, manage our business, and comply with the law.
This policy applies to all Gardeners Northwood customers in the area and forms part of our approach to privacy, accountability, and compliance.