Privacy Policy - Gardeners Tokyngton
Gardeners Tokyngton is committed to protecting the privacy and personal data of all customers in the area. This Privacy Policy explains how we collect, use, store, share, and protect personal information when we provide gardening services. It also explains the rights available to individuals under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy applies to all Gardeners Tokyngton customers in area, including anyone who enquires about our services, receives a quotation, books work, or uses our gardening services. By engaging with our services, customers should understand how their information is handled in a lawful and transparent way.
1. Information We Collect
We only collect personal data that is relevant and necessary for the provision of gardening services, administration, communication, and legal compliance. The types of information we may collect include:
- Identity details: name, title, and, where necessary, company or property name.
- Contact details: postal address, email address, telephone number, and preferred communication method.
- Service details: information about the gardens, outdoor areas, access arrangements, service preferences, and instructions provided by the customer.
- Payment and billing data: transaction records, invoice details, and limited financial information required to process payments.
- Communication records: emails, messages, notes from calls, complaint details, and service feedback.
- Technical information: basic website or device information if a customer contacts us through digital channels, such as IP address or browser type, where applicable.
We do not intentionally collect special category data unless it is strictly necessary and there is a valid legal reason to do so. If such data is ever needed, it will be handled with additional safeguards and only where permitted by law.
2. How We Use Personal Data
Gardeners Tokyngton uses personal data for the following purposes:
- to respond to enquiries and provide quotations;
- to arrange and deliver gardening services;
- to manage appointments, schedules, and site access;
- to issue invoices, process payments, and maintain business records;
- to communicate service updates, reminders, and important notices;
- to handle complaints, disputes, and requests for follow-up work;
- to comply with legal, accounting, and tax obligations;
- to protect our legitimate business interests, including service quality and fraud prevention.
We use personal data in a way that is fair, limited, and proportionate to the service being provided.
3. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for processing personal data. Depending on the purpose, Gardeners Tokyngton relies on one or more of the following lawful bases:
Contract
We process personal data when it is necessary to perform a contract with a customer or to take steps before entering into a contract. This includes quoting, booking, carrying out garden work, and issuing invoices.
Legal Obligation
We may process and retain certain information to comply with legal duties, such as accounting rules, tax requirements, or record-keeping obligations.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided those interests are not overridden by the rights and freedoms of the individual. This may include service administration, maintaining records, managing customer communications, improving service delivery, and protecting our business from misuse or fraud.
Consent
In limited situations, we may rely on consent, for example for specific optional communications or where the law requires consent. Where consent is used, it may be withdrawn at any time.
We do not rely on unlawful or unnecessary processing. Each activity is reviewed to ensure it has a valid basis and is aligned with GDPR principles.
4. Sharing Personal Data and Processors
We do not sell personal data. However, we may share information with trusted third parties where necessary for business operations or legal compliance. These third parties act as processors or independent controllers depending on their role.
Examples of processors may include:
- IT and cloud storage providers used to securely store records and communications;
- accounting and bookkeeping providers used for invoicing and financial administration;
- payment service providers used to process card or electronic payments;
- customer communication systems used for sending messages or managing appointments;
- professional advisers such as legal or insurance advisers, where necessary.
Where processors are used, we require them to handle personal data securely and only in accordance with our instructions and applicable law. We take reasonable steps to ensure they provide appropriate technical and organisational safeguards.
We may also disclose data if required by law, to regulators, law enforcement, courts, or other public authorities. Any such disclosure will be limited to what is necessary and lawful.
5. Retention of Personal Data
We keep personal data only for as long as necessary for the purpose for which it was collected, or as required by law. Retention periods vary depending on the type of data and the reason for processing.
- Customer and service records: kept for the duration of the customer relationship and for a reasonable period afterwards for administration, dispute resolution, and service history.
- Financial and tax records: retained for the period required by law and accounting rules.
- Communication records: retained for as long as needed to manage the service, respond to queries, or evidence decisions.
- Inactive or unnecessary records: securely deleted or anonymised when no longer required.
When personal data is no longer needed, we will take appropriate steps to ensure it is securely destroyed, deleted, or anonymised.
6. Data Security
We take data security seriously and use reasonable technical and organisational measures to protect personal information from unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and careful management of records.
Although no system can be guaranteed completely secure, we work to keep data protected and to reduce the risk of accidental or unlawful processing.
7. International Transfers
If any of our processors store or access data outside the United Kingdom, we ensure that appropriate safeguards are in place, such as lawful transfer mechanisms and security measures required under data protection law.
8. Your Rights Under GDPR
Individuals whose personal data is processed by Gardeners Tokyngton have rights under GDPR. These include:
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to ask us to correct inaccurate or incomplete information.
- Right to erasure: in certain cases, to request deletion of your personal data.
- Right to restriction: to ask us to limit the way we use your data in certain circumstances.
- Right to data portability: to receive certain data in a structured, commonly used format where applicable.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
These rights are not absolute and may be subject to legal limits. We will assess each request carefully and respond in accordance with GDPR requirements.
9. How We Handle Requests and Complaints
If an individual wishes to exercise a data protection right, we will respond within the timeframe required by law and may ask for information to verify identity before taking action. This is to protect customers and prevent unauthorised disclosure.
We also encourage customers to raise any concerns about data handling so that we can review and address them appropriately. Our aim is to deal with issues in a fair, timely, and respectful manner.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the law, our services, or our data handling practices. Any updated version will apply from the date it is published or made available. Customers are encouraged to review this policy periodically to stay informed about how their data is protected.
11. Summary of Our Commitment
Gardeners Tokyngton treats personal data with care and responsibility. We only collect what we need, use it for clear and lawful purposes, keep it only for as long as necessary, and protect it with appropriate safeguards. We also respect the rights of all customers in area and aim to ensure that our handling of personal information remains transparent, lawful, and secure.
This Privacy Policy applies to all Gardeners Tokyngton customers in area.