Privacy Policy - Gardeners Elmstead
This Privacy Policy explains how Gardeners Elmstead collects, uses, stores, and protects personal data belonging to its customers in the Elmstead area. It applies to all Gardeners Elmstead customers in the area, including individuals who enquire about services, request quotations, book appointments, receive gardening work, or otherwise interact with us in connection with our services.
We are committed to handling personal information in a lawful, fair, and transparent manner, in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy sets out what data we collect, why we collect it, how long we keep it, who may process it on our behalf, and what rights you have in relation to your personal data.
1. Who We Are
Gardeners Elmstead provides gardening and related outdoor property services to customers in the Elmstead area. In the context of this policy, “we”, “us”, and “our” refer to Gardeners Elmstead as the data controller for the personal data described below. As controller, we determine the purposes and means of processing personal data when offering and delivering our services.
We take data protection seriously and aim to ensure that any personal information we collect is limited to what is necessary for operating our business, meeting legal obligations, and providing a reliable customer experience.
2. Personal Data We Collect
We may collect and process the following categories of personal data:
- Identity data such as your name and, where relevant, the name of a business or property contact.
- Contact data such as your address, email address, and telephone number.
- Service-related data such as details of the gardening or maintenance services requested, property access notes, service preferences, and appointment history.
- Communication data such as enquiries, complaints, feedback, and records of correspondence.
- Billing and payment data such as invoice details, payment status, and transaction references. We do not store full card details where payments are processed by third-party providers.
- Technical data such as limited website or device information if you interact with us through digital channels, where applicable.
- Legal and compliance data such as records needed for tax, insurance, accounting, or dispute resolution purposes.
We do not intentionally collect special category data unless it is strictly necessary and you have provided it, or another lawful basis applies. Special category data includes information such as health details, religious beliefs, or political opinions. If such data is ever shared with us accidentally, we will handle it carefully and in accordance with applicable law.
3. How We Use Your Data
We use personal data for the following purposes:
- To provide quotations, schedule visits, and deliver gardening services.
- To manage customer accounts, service records, and property instructions.
- To respond to enquiries, requests, and complaints.
- To issue invoices, record payments, and maintain financial records.
- To improve our services, including internal training and service planning.
- To meet legal, tax, insurance, and regulatory obligations.
- To protect our business, customers, and staff from fraud, misuse, or other unlawful activity.
We only use your data where we have a valid legal reason to do so and where the use is proportionate to the purpose for which the data was collected.
4. Lawful Basis for Processing
Under data protection law, we must have a lawful basis for each activity involving personal data. The main lawful bases we rely on are set out below:
Contract
We process personal data when it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This includes preparing a quotation, arranging a service visit, and carrying out agreed work.
Legitimate Interests
We may process personal data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. Examples include managing customer relationships, maintaining service records, improving operations, and defending against claims.
Legal Obligation
We may process data where needed to comply with legal requirements, including accounting, tax, and record-keeping duties.
Consent
In limited cases, we may rely on your consent, for example where specific optional communications or uses are involved. Where consent is used, you may withdraw it at any time.
We will always assess the appropriate lawful basis before processing data and will not use information in a way that is incompatible with the original purpose.
5. Data Sharing and Processors
We may share personal data with trusted third parties where necessary for service delivery, administration, or compliance. These third parties act either as independent controllers or as processors acting on our instructions.
Processors may include:
- Payment service providers that process transactions securely.
- Accounting and bookkeeping providers that help manage financial records.
- IT and system support providers that maintain secure data storage or business software.
- Scheduling or administration tools used to organise appointments and service records.
- Professional advisers such as insurers, legal advisers, or tax specialists where necessary.
We only use processors that provide suitable guarantees regarding data protection and confidentiality. They are required to process personal data only on our instructions and to implement appropriate security measures.
We may also disclose personal data if required by law, court order, or a lawful request from a public authority. Where possible, we will limit disclosure to what is necessary.
6. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, or for as long as required by law. Retention periods vary depending on the type of data and the reason it is held.
- Customer service records are generally retained for the duration of the business relationship and for a reasonable period afterwards in case of follow-up or dispute.
- Financial and invoicing records are kept for the period required by tax and accounting law.
- Correspondence and complaint records may be retained for the time needed to resolve issues and demonstrate how matters were handled.
- Consent-based records are kept until consent is withdrawn or the purpose no longer applies.
When data is no longer needed, we will delete it securely or anonymise it so it can no longer identify you. We regularly review retention practices to ensure data is not kept longer than necessary.
7. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or alteration. These measures may include access controls, secure storage, password protection, and restricted internal access on a need-to-know basis.
While no system can be guaranteed to be completely secure, we work to maintain a level of protection appropriate to the nature of the data we hold and the risks involved.
8. Your Rights
As a data subject under UK GDPR, you have a number of rights in relation to your personal data. These rights may apply depending on the circumstances and the lawful basis for processing.
- Right of access – you may request a copy of the personal data we hold about you.
- Right to rectification – you may ask us to correct inaccurate or incomplete data.
- Right to erasure – you may request deletion of your data in certain situations.
- Right to restrict processing – you may ask us to limit how we use your data in certain cases.
- Right to object – you may object to processing based on legitimate interests or direct marketing, where applicable.
- Right to data portability – you may request transfer of certain data in a structured, commonly used format where the law requires it.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
We may need to verify your identity before responding to any rights request. We will aim to respond within the time limits required by law.
9. Children’s Data
Our services are generally aimed at property owners, occupiers, and adult customers. We do not knowingly collect personal data from children unless it is necessary and lawful in a specific context. If we become aware that we have collected such data without proper authority, we will take appropriate steps to delete it.
10. International Transfers
Where personal data is transferred outside the UK, we will ensure appropriate safeguards are in place so that the data continues to receive a level of protection consistent with UK data protection law. Any such transfer will be limited to what is necessary and carried out only where suitable protections exist.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. Any updated version will apply from the date it is published or otherwise communicated. We encourage customers in the Elmstead area to review this policy periodically to stay informed about how their data is handled.
12. Summary of Our Commitment
Gardeners Elmstead is committed to using personal data responsibly, lawfully, and only where necessary to provide services and manage our business. We limit data collection to relevant information, rely on appropriate lawful bases, retain data only as long as needed, and use trusted processors under suitable safeguards. We also respect your rights and will act on valid requests in accordance with applicable data protection law.
By using our services or making an enquiry, you acknowledge that your personal data may be processed as described in this Privacy Policy and that it applies to all Gardeners Elmstead customers in the area.