Privacy Policy - Gardeners Grahame Park

Gardeners Grahame Park is committed to protecting the privacy and personal data of all customers in the Grahame Park area. This Privacy Policy explains how we collect, use, store, share, and protect personal information when you use our gardening services. It applies to all Gardeners Grahame Park customers in the area, including prospective customers, current customers, and former customers whose information we retain for legitimate business purposes.

1. Who We Are

For the purposes of data protection law, Gardeners Grahame Park acts as the data controller for the personal data described in this policy. This means we decide how and why your personal information is processed in connection with our gardening services, customer support, quotations, scheduling, invoicing, and related operations.

This policy is written to be clear, fair, and transparent, so that you understand what happens to your data and what rights you have under the UK GDPR and the Data Protection Act 2018.

2. Information We Collect

We only collect personal data that is relevant to providing our services, managing customer relationships, and operating our business effectively. Depending on your interaction with us, we may collect the following categories of information:

  • Identity details such as your name and title.
  • Contact details such as phone number, postal address, and email address.
  • Service details such as information about your garden, property access, preferred service times, requested tasks, and service history.
  • Billing details such as invoice information, payment status, and transaction records.
  • Communication records including enquiries, messages, feedback, complaints, and notes relating to our dealings with you.
  • Technical data such as limited website or device information if you contact us through digital channels, where applicable.
  • Special category data only where strictly necessary and usually only if you choose to provide it, for example information about accessibility needs that helps us deliver services safely and appropriately.

We do not intentionally collect more information than is needed. If we ever need to collect sensitive data, we will only do so where it is lawful, necessary, and appropriate.

3. How We Use Your Data

We use personal data for several legitimate business and service-related purposes, including:

  • providing gardening services and managing bookings;
  • preparing quotations and estimates;
  • communicating with you about appointments, updates, and service changes;
  • issuing invoices and managing payments;
  • maintaining customer records and service histories;
  • handling complaints, queries, and service issues;
  • meeting legal, accounting, and regulatory obligations;
  • improving the quality, efficiency, and safety of our services;
  • protecting against fraud, misuse, and security incidents.

We only process data in ways that are necessary, proportionate, and relevant to these purposes.

4. Lawful Basis for Processing

Under data protection law, we must have a lawful basis for using personal data. Gardeners Grahame Park relies on the following lawful bases, depending on the situation:

Contract

We process personal data when it is necessary to enter into or perform a contract with you. This includes arranging services, carrying out gardening work, sending invoices, and managing customer accounts.

Legal Obligation

We process certain data to comply with legal requirements, including tax, accounting, and record-keeping obligations.

Legitimate Interests

We may process data where it is in our legitimate interests to do so and where those interests are not overridden by your rights and freedoms. Examples include managing customer relationships, improving our services, maintaining internal records, and protecting our business from fraud or misuse.

Consent

Where consent is required, we will ask for it clearly and separately. For example, if we ever need to use information for optional communications or certain types of processing, you will be given a genuine choice. You may withdraw consent at any time.

Vital Interests and Public Interest

These lawful bases are unlikely to apply in most customer situations, but they may be used where necessary to protect someone’s life or in limited circumstances required by law.

5. Sharing and Processors

We may share personal data with trusted third parties who act as processors on our behalf. These providers only handle data according to our instructions and are required to protect it appropriately. Typical processors may include:

  • IT and cloud storage providers used to securely store business records and communications;
  • accounting and bookkeeping providers used for invoicing, payments, and compliance;
  • customer administration tools used for scheduling and record management;
  • email and communication providers used to send service-related messages;
  • professional advisers such as accountants, insurers, or legal advisers, where necessary.

We may also disclose data to authorities, regulators, or law enforcement where required by law or where disclosure is necessary to protect our legal rights.

We do not sell your personal data. We do not share information with third parties for their own marketing purposes unless you have expressly agreed and lawfully permitted us to do so.

6. International Transfers

If any processor stores or accesses data outside the UK, we will take appropriate safeguards to ensure your information remains protected. These safeguards may include adequacy decisions, standard contractual clauses, or equivalent legal mechanisms approved under applicable data protection law.

7. Data Retention

We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, and reporting obligations. Retention periods may vary depending on the type of record and the reason for holding it.

  • Customer and service records are generally retained for the duration of the service relationship and for a reasonable period afterwards.
  • Financial and tax records are retained for the period required by law.
  • Communication records may be kept for as long as needed to resolve disputes, manage service quality, or maintain accurate business records.
  • Consent-based records are kept only until consent is withdrawn or the purpose no longer applies.

When data is no longer needed, we securely delete, anonymise, or archive it in line with our retention practices.

8. Data Security

We use appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures may include access controls, secure storage, password protection, and staff awareness practices. While no system can be guaranteed completely secure, we take reasonable steps to safeguard all information entrusted to us.

9. Your Rights

Under data protection law, you have a number of rights in relation to your personal data. These rights may be subject to legal exceptions and limitations.

  • Right of access – you may ask for a copy of the personal data we hold about you.
  • Right to rectification – you may ask us to correct inaccurate or incomplete data.
  • Right to erasure – in certain circumstances, you may ask us to delete your data.
  • Right to restriction – you may ask us to limit how we use your data in some situations.
  • Right to object – you may object to processing based on legitimate interests or direct marketing.
  • Right to data portability – where applicable, you may request your data in a structured format.
  • Right to withdraw consent – where we rely on consent, you can withdraw it at any time.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office if you believe your data protection rights have been infringed.

10. Cookies and Similar Technologies

If we use cookies or similar tools in connection with digital services, they are only used where lawful and appropriate. Any such technologies would be limited to necessary site functionality, performance, or user experience improvement. Where consent is required, we will request it clearly.

11. Children’s Data

Our services are intended for adults who arrange gardening work for residential or commercial premises. We do not knowingly collect personal data from children. If we become aware that such data has been collected inadvertently, we will take appropriate steps to remove it unless we are legally required to retain it.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, our services, or our data handling practices. The most current version will apply from the date it is published or otherwise communicated. We encourage you to review it periodically so that you remain informed.

13. Summary of Our Commitment

Gardeners Grahame Park is committed to handling personal data lawfully, fairly, and transparently. We collect only what we need, use it for clear and legitimate purposes, keep it only as long as necessary, and apply safeguards when sharing it with trusted processors. This policy applies to all Gardeners Grahame Park customers in area, and we treat every customer’s privacy with care and respect.

By using our services, you acknowledge that you have read and understood this Privacy Policy.

Gardeners Grahame Park

Gardeners Grahame Park is committed to protecting the privacy and personal data of all customers in the Grahame Park area.

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.