Privacy Policy - Gardeners Old Coulsdon
Gardeners Old Coulsdon is committed to protecting the privacy of all customers in the Old Coulsdon area and to handling personal data in a lawful, fair, and transparent manner. This Privacy Policy explains how we collect, use, store, and share personal information when we provide gardening services to customers in this area. It also sets out the rights available to you under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy applies to all Gardeners Old Coulsdon customers in the area, including current, former, and prospective customers whose personal data we process in connection with our services. By using our services, making an enquiry, or communicating with us, you acknowledge that your personal data may be processed in accordance with this policy.
1. Personal Data We Collect
We only collect personal data that is necessary for running our services, managing customer relationships, and meeting legal obligations. The information we may collect includes:
- Identity details such as your name and, where relevant, the name of a business or property owner.
- Contact details such as an address, telephone number, and email address.
- Service details including information about your garden, property access, service preferences, and requested work.
- Billing and payment information needed to process invoices, payments, and account records.
- Communication records including messages, notes from calls, and details of enquiries or complaints.
- Technical information such as basic device or usage details if you interact with us through online systems used for administration.
We do not seek to collect special category data unless it is strictly necessary and you have provided it voluntarily or a lawful basis applies. Special category data includes information relating to health, religious beliefs, political views, biometric data, or similar sensitive categories. If such information is ever shared with us incidentally, we will handle it with extra care and only where appropriate safeguards are in place.
2. How We Use Personal Data
We use personal data for specific purposes connected to our gardening services. These include:
- providing quotations and responding to enquiries;
- delivering gardening and related property services;
- managing appointments, site visits, and service schedules;
- issuing invoices, processing payments, and maintaining records;
- communicating important updates about services or bookings;
- dealing with complaints, disputes, or service issues;
- meeting legal, accounting, and tax obligations;
- protecting our business, staff, customers, and property;
- improving service quality and maintaining internal administration.
We only use personal information where it is relevant to the service provided and where we have a valid legal reason to do so. We will not use your data in a way that is incompatible with the original purpose for which it was collected.
3. Lawful Basis for Processing
Under UK GDPR, every use of personal data must have a lawful basis. We rely on the following lawful bases where appropriate:
Contract
We process data where it is necessary to enter into or perform a contract with you. This includes preparing quotations, delivering gardening services, managing bookings, and handling payments.
Legal Obligation
We may process personal data to comply with legal duties, including record-keeping, tax, accounting, and other regulatory requirements.
Legitimate Interests
We may process certain data for our legitimate business interests, provided your interests and rights do not override those interests. This can include administration, service improvement, fraud prevention, and maintaining secure business records.
Consent
Where consent is required, for example for certain optional communications or the use of specific information beyond the normal service relationship, we will ask for your clear permission. You may withdraw consent at any time where processing is based on consent.
4. Sharing Data and Processors
We may share personal data with trusted third parties when necessary to operate our business and deliver services. These third parties act as processors or independent controllers depending on the service they provide.
Examples of processors may include:
- accounting and invoicing providers used to manage payments and financial records;
- IT and cloud storage providers used to store and protect business data;
- communication service providers used for email, messaging, or administration;
- payment service providers used to facilitate secure transactions;
- professional advisers such as accountants or legal advisers where needed;
- subcontractors or service partners who assist in fulfilling a customer request.
Where processors are used, they are required to process data only on our instructions, keep it secure, and comply with data protection obligations. We do not sell personal data. We also require any third parties that handle data on our behalf to use appropriate technical and organisational measures to protect it.
In limited circumstances, we may also disclose information where required by law, court order, or a public authority exercising lawful powers.
5. Retention of Personal Data
We keep personal data only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required by law. Retention depends on the type of data and the nature of our relationship with you.
- Customer and service records are generally kept for the duration of the service relationship and for a reasonable period afterwards.
- Financial records may be retained for the period required by tax and accounting laws.
- Correspondence and dispute records may be retained for as long as needed to resolve issues or defend legal claims.
- Marketing or optional communication records are kept only while the relevant consent or legitimate basis remains valid.
When personal data is no longer required, we will delete it securely or anonymise it so that it can no longer identify you. We regularly review retention periods to ensure data is not kept longer than necessary.
6. Data Security
We take appropriate measures to protect personal data from accidental loss, misuse, unauthorised access, disclosure, alteration, or destruction. These measures may include secure storage, access controls, staff awareness, and the use of trusted systems and suppliers. Although no method of transmission or storage is completely risk-free, we work to maintain a level of security appropriate to the risks involved.
7. Your Rights
Under data protection law, you have a number of rights in relation to your personal data. These rights may apply depending on the circumstances and the lawful basis for processing.
- Right of access – you can request a copy of the personal data we hold about you.
- Right to rectification – you can ask us to correct inaccurate or incomplete data.
- Right to erasure – you can request deletion of your data in certain situations.
- Right to restrict processing – you can ask us to limit how we use your data in certain cases.
- Right to object – you can object to processing based on legitimate interests, including certain forms of direct communication.
- Right to data portability – you can request transfer of certain data to you or another controller where applicable.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
To exercise your rights, you may submit a request in writing. We may need to verify your identity before responding. We will normally respond within one month, although this may be extended where the request is complex or multiple requests are received.
8. Children’s Data
Our services are directed at adult customers and property-related service arrangements. We do not knowingly collect personal data from children in a way that would require separate handling, and we do not intentionally target children for our services.
9. International Transfers
If any personal data is transferred outside the United Kingdom, we will only do so where appropriate safeguards are in place and the transfer is permitted under data protection law. Such safeguards may include adequacy regulations or approved contractual protections.
10. Changes to This Privacy Policy
We may update this policy from time to time to reflect changes in our services, legal obligations, or data handling practices. The updated version will apply from the date it is published or otherwise made available. We encourage customers to review this policy periodically so they remain informed about how their data is protected.
11. Summary of Our Commitments
Gardeners Old Coulsdon will only collect personal information that is necessary, use it for clear purposes, retain it for no longer than needed, and share it only with trusted processors or where required by law. We are committed to respecting your rights, keeping your information secure, and processing data in a way that is lawful, transparent, and proportionate.
Applies to all Gardeners Old Coulsdon customers in the area.