Privacy Policy - Gardeners Goddington
Gardeners Goddington is committed to protecting the privacy and personal data of all customers in the area. This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when you use our gardening services. It applies to all Gardeners Goddington customers in area, including prospective clients, existing clients, and anyone who communicates with us about our services.
1. Personal Data We Collect
We only collect personal data that is relevant and necessary for providing gardening services, managing customer relationships, and meeting legal obligations. The type of information we may collect includes:
- Identity data such as your name.
- Contact data such as address, telephone number, and email address.
- Service information such as property access notes, service preferences, requested works, quotations, and scheduling details.
- Billing and payment data such as invoicing details, payment status, and transaction records where applicable.
- Communication data such as messages, queries, complaints, feedback, and records of conversations.
- Technical data in limited circumstances, such as basic device or usage information if you contact us through digital systems that record it.
We do not intentionally collect special category data unless it is necessary and you choose to provide it for a specific reason. If such information is shared, we will handle it carefully and only where there is a lawful basis to do so.
2. How We Use Your Data
We use personal data to deliver services efficiently and professionally. Typical uses include:
- Providing quotations and arranging appointments.
- Delivering gardening, maintenance, and related services.
- Managing customer accounts, invoicing, and payments.
- Responding to enquiries and service requests.
- Keeping records of work completed and follow-up actions.
- Maintaining service quality, training, and internal administration.
- Meeting legal, tax, accounting, and insurance requirements.
We only process personal data for specified, explicit, and legitimate purposes, and we do not use it in a way that is incompatible with those purposes.
3. Lawful Basis for Processing
Under UK GDPR and GDPR principles, we rely on lawful bases for each type of processing. These may include:
Contract
We process personal data when it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This includes providing quotes, arranging services, and carrying out agreed work.
Legal Obligation
We process certain data where it is needed to comply with legal duties, such as tax records, accounting requirements, and regulatory obligations.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided your interests and rights do not override those interests. This may include business administration, record keeping, service improvement, fraud prevention, and protecting our property and operations.
Consent
In limited situations, we may rely on your consent, for example where we need permission to use certain optional data or to communicate in a particular way. Where consent is used, you may withdraw it at any time.
4. Data Sharing and Processors
We may share personal data with trusted third parties only when necessary for the running of our business or the delivery of our services. These third parties act as processors or independent controllers depending on the nature of their role.
Examples of processors may include:
- IT and cloud service providers who store or support our systems.
- Administrative and accounting providers who help manage records, invoicing, or reporting.
- Payment service providers who process transactions securely.
- Communication service providers who help us send messages or manage enquiries.
We require processors to act only on our instructions, to apply appropriate security measures, and to respect confidentiality. We do not sell personal data. If data is transferred outside the UK or EEA, we will ensure appropriate safeguards are in place in line with applicable data protection law.
5. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including any legal, accounting, or reporting requirements. Retention periods may vary depending on the type of record and why it is held.
- Customer and service records are kept for the duration of the business relationship and for a reasonable period afterwards.
- Financial records are kept for the period required by tax and accounting law.
- Communication records are retained as needed to resolve queries, document decisions, or demonstrate service history.
- Consent-based information is kept only until consent is withdrawn or the information is no longer needed.
When data is no longer required, it is securely deleted, anonymised, or otherwise disposed of in a safe manner.
6. Data Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures may include restricted access, secure storage, staff confidentiality obligations, and routine review of our data handling practices.
While we work hard to protect your information, no system is completely risk-free. We therefore maintain proportionate safeguards and review them regularly to reduce risks to personal data.
7. Your Data Protection Rights
As a data subject, you have a number of rights under data protection law. These rights may apply depending on the circumstances and the legal basis for processing.
- Right of access – to request a copy of the personal data we hold about you.
- Right to rectification – to ask us to correct inaccurate or incomplete data.
- Right to erasure – to request deletion of your data in certain situations.
- Right to restrict processing – to ask us to limit how we use your data in some cases.
- Right to data portability – to request your data in a structured, commonly used format where applicable.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
Please note that these rights are not absolute. We may retain or continue processing information where required or permitted by law.
8. Children’s Data
Our services are intended for adult customers and property owners or occupiers. We do not knowingly collect children’s personal data unless it is provided incidentally in the course of service communication and is necessary for a lawful purpose. Where such information is encountered, it is handled with appropriate care and minimisation.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. Any revised version will apply from the date it is made available. We encourage customers to review it periodically so they remain informed about how their personal data is used.
10. Our Commitment to Privacy
Gardeners Goddington values trust, transparency, and accountability. We will only use personal data where we have a proper legal basis, keep it only as long as necessary, and take reasonable steps to protect it. Our approach is designed to support a professional service while respecting the privacy of everyone who uses our gardening services in the area.
In summary, this policy explains what data we collect, why we collect it, how long we keep it, who may process it on our behalf, and what rights you have over your information. It applies to all Gardeners Goddington customers in area.