Privacy Policy - Gardeners Blackheath
Gardeners Blackheath is committed to protecting the privacy and personal data of all customers in the Blackheath area. This Privacy Policy explains how we collect, use, store, and share personal information, and sets out the rights available to individuals under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy applies to all Gardeners Blackheath customers in the area, including prospective customers, existing customers, and anyone who has interacted with our services.
1. Who We Are
For the purposes of data protection law, Gardeners Blackheath acts as a data controller in relation to the personal data we collect and use for providing gardening services. This means we determine the purposes and means of processing personal data in connection with service enquiries, bookings, service delivery, invoicing, and customer communications.
We only process personal data where we have a lawful basis to do so, and we do so in a manner that is fair, transparent, and proportionate to the services we provide.
2. Personal Data We Collect
We may collect and process the following categories of personal data:
- Identity details, such as name and title.
- Contact details, such as address, email address, and telephone number.
- Service details, including property access instructions, preferred service times, and gardening requirements.
- Billing and payment details, where needed for invoicing and payment processing.
- Communication records, such as emails, messages, notes from calls, and service feedback.
- Technical information, if you interact with our digital systems, such as device type, IP address, and usage logs.
- Special instructions relevant to the provision of gardening services, including access arrangements or site-specific preferences.
We generally do not seek to collect special category data, such as health information, unless it is strictly necessary and you choose to provide it. If such information is ever provided, it will be handled with additional care and only where a lawful basis exists.
3. How We Use Personal Data
Gardeners Blackheath uses personal data for the following purposes:
- To respond to enquiries and provide quotations.
- To arrange and deliver gardening services.
- To manage customer accounts and service records.
- To issue invoices, process payments, and manage outstanding balances.
- To communicate about appointments, service changes, and relevant updates.
- To maintain internal records and improve service quality.
- To meet legal, accounting, and regulatory obligations.
- To protect our business, staff, and customers from fraud or misuse.
We will not use personal data for purposes that are incompatible with the reasons it was collected, unless we are required or permitted to do so by law.
4. Lawful Basis for Processing
Under UK GDPR, we must identify a lawful basis for each use of personal data. Depending on the context, Gardeners Blackheath may rely on the following bases:
Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes providing quotes, confirming bookings, carrying out garden maintenance, and handling payment-related matters.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include record keeping, service improvement, customer communication, and the prevention of fraud or misuse.
Legal Obligation
We may process personal data to comply with legal obligations, including tax, accounting, and regulatory requirements.
Consent
In limited cases, we may rely on your consent, for example where you have chosen to receive non-essential marketing communications. Where consent is used, you may withdraw it at any time.
5. Sharing Personal Data and Processors
We may share personal data with trusted third parties where necessary for operating our services. These third parties act as processors or independent controllers depending on the service they provide.
Typical processors may include:
- IT and cloud service providers that host or support our records and communications systems.
- Payment processors that handle card or electronic payments.
- Accounting or bookkeeping providers that assist with financial administration.
- Scheduling or administration providers that help manage appointments and service operations.
We require processors to act only on our instructions, to implement appropriate security measures, and to protect personal data in line with data protection law. We do not sell personal data. Any sharing is limited to what is necessary and proportionate for service delivery, compliance, or business administration.
We may also disclose personal data where required by law, court order, or lawful request from a public authority, or where necessary to establish, exercise, or defend legal claims.
6. International Transfers
If any of our processors store or access personal data outside the UK, we will ensure appropriate safeguards are in place. These may include adequacy regulations, standard contractual clauses, or equivalent legal protections designed to maintain a level of protection consistent with UK GDPR requirements.
7. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including legal, accounting, and reporting obligations. Retention periods may vary depending on the type of data and the nature of the customer relationship.
As a general approach:
- Customer service records are kept for the duration of the relationship and for a reasonable period afterwards.
- Financial records are retained for the period required by law.
- Communication records may be retained for customer service, dispute resolution, or audit purposes.
- Marketing data is kept only while consent remains valid or until you opt out.
When data is no longer needed, we will delete it securely or anonymise it so that it can no longer identify you.
8. Data Security
We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration, or disclosure. These measures are designed to reflect the nature of the information we hold and the risks associated with processing it.
Although no system can be guaranteed to be completely secure, we take reasonable steps to safeguard the personal information entrusted to us.
9. Your Rights
Under data protection law, you have a number of rights in relation to your personal data. These rights may apply in full or in part depending on the circumstances:
- Right of access – you can request a copy of the personal data we hold about you.
- Right to rectification – you can ask us to correct inaccurate or incomplete data.
- Right to erasure – in certain cases, you can ask us to delete your data.
- Right to restrict processing – you can ask us to limit how we use your data in certain situations.
- Right to object – you can object to processing based on legitimate interests or direct marketing.
- Right to data portability – in some cases, you can request your data in a structured, commonly used format.
- Right to withdraw consent – where processing relies on consent, you can withdraw it at any time.
These rights are not absolute. We may retain or continue processing data where we have a lawful reason to do so, such as compliance with legal obligations or the defence of legal claims.
10. Marketing Preferences
We will only send marketing communications where permitted by law. If you no longer wish to receive such messages, you may opt out at any time. Once an opt-out is recorded, we will update our systems accordingly and cease non-essential communications subject to any legal exceptions.
11. Children’s Data
Our services are directed to adult customers and property owners or occupiers. We do not intentionally collect data from children. If we become aware that personal data relating to a child has been collected inadvertently, we will take appropriate steps to delete it or handle it lawfully.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any updated version will apply from the date it is made available. We encourage customers to review this policy periodically to remain informed about how their data is handled.
13. Summary of Our Approach
Gardeners Blackheath is committed to processing personal data responsibly, transparently, and securely. We collect only the information needed to provide and manage our services, use it for clear and lawful purposes, retain it only for as long as necessary, and share it only with trusted processors or where the law requires it. All customers in the Blackheath area can expect their personal data to be handled in accordance with UK GDPR principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity, and confidentiality.