Privacy Policy - Gardeners The Hale
This Privacy Policy explains how Gardeners The Hale collects, uses, stores, shares, and protects personal data when providing gardening services to customers in the area. It applies to all Gardeners The Hale customers in the area, including individuals who request quotations, book services, communicate with us, or otherwise engage with our team. We are committed to handling personal data in a lawful, fair, and transparent manner in accordance with applicable data protection law, including the UK GDPR and the Data Protection Act 2018.
We recognise that privacy matters. This policy sets out what information we collect, the reasons we collect it, the lawful basis on which we rely, how long we keep it, the types of processors we may use, and the rights available to you. It is designed to be clear and accessible, while still providing the detailed information expected from a GDPR-compliant privacy notice.
1. Who We Are
Gardeners The Hale provides gardening and related outdoor maintenance services for domestic and commercial customers in the local area. For the purposes of data protection law, we are the data controller in relation to personal information we collect and use about our customers, prospective customers, suppliers, and website or enquiry users where applicable.
As data controller, we determine how and why your personal data is processed, and we take responsibility for ensuring it is handled securely and in line with legal obligations.
2. The Personal Data We Collect
We only collect personal data that is necessary for service delivery, administration, communication, and compliance. The types of data we may collect include:
- Identity details, such as your name and title
- Contact details, such as address, telephone number, and email address
- Service details, such as the nature of the work requested, property access notes, preferences, and instructions
- Billing and payment information, such as invoice details, payment status, and limited transaction records
- Communication records, including emails, phone notes, messages, and service-related correspondence
- Site and scheduling information, such as service dates, visit frequency, and operational arrangements
- Complaint or feedback information, where you contact us with an issue, concern, or review
- Technical data, if you contact us digitally, such as basic device or usage information necessary for security and functionality
We do not intentionally collect special category data unless it is strictly necessary and you have provided it voluntarily, or unless another lawful basis applies and appropriate safeguards are in place. We also do not knowingly collect data relating to children unless it is essential for service delivery and provided by a parent, guardian, or authorised adult.
3. How We Use Your Data
We use personal data only for clear and legitimate purposes. These include:
- Responding to enquiries and providing quotations
- Managing bookings, appointments, and recurring service schedules
- Delivering gardening services and related operational support
- Maintaining customer records and service history
- Issuing invoices and recording payments
- Handling complaints, queries, and customer feedback
- Carrying out internal administration, accounting, and record-keeping
- Meeting legal, tax, insurance, and regulatory obligations
- Protecting our business, staff, customers, and property
We may also use data in limited cases to improve service quality, monitor performance, and ensure appropriate standards are maintained. Where feasible, we use data minimisation and only access information that is necessary for the task being performed.
4. Lawful Basis for Processing
We process personal data only when we have a lawful basis under data protection law. Depending on the context, we may rely on one or more of the following:
Contract
We process data where it is necessary to enter into or perform a contract with you. This includes managing quotations, bookings, service delivery, billing, and related communications.
Legal Obligation
We may process and retain information where required to comply with legal duties, such as tax rules, accounting requirements, health and safety obligations, or to respond to lawful requests.
Legitimate Interests
We may process data where it is necessary for our legitimate interests and where those interests are not overridden by your rights and freedoms. This may include business administration, record keeping, service quality control, fraud prevention, network and system security, and handling customer correspondence. When relying on this basis, we ensure the processing is proportionate and relevant.
Consent
In limited cases, we may rely on your consent, for example for optional communications or specific uses not covered by another lawful basis. If consent is used, it will be informed, freely given, specific, and easy to withdraw.
Vital Interests
In rare circumstances, we may process information to protect someone’s vital interests, such as in an emergency involving health or safety.
5. Retention of Personal Data
We keep personal data only for as long as necessary to fulfil the purpose for which it was collected, including any legal, accounting, or reporting requirements. Retention periods vary depending on the type of information and the reason it is held.
- Customer and service records are normally retained for the period needed to manage the relationship and for a reasonable time afterwards for administration or dispute resolution
- Financial records are retained for the period required by tax and accounting law
- Complaints and correspondence may be retained for a period necessary to resolve issues and evidence decisions
- Consent-based records are retained until consent is withdrawn or the purpose ends
When personal data is no longer required, we securely delete, anonymise, or archive it in line with our retention practices. We do not keep data indefinitely.
6. Processors and Third Parties
We may share personal data with trusted third parties who act as processors on our behalf, or in some cases as independent controllers. These third parties are only used where necessary and subject to appropriate contractual and security safeguards.
Examples of processors may include:
- Accounting and bookkeeping providers
- IT and cloud storage providers
- Email, messaging, and communication service providers
- Scheduling or customer management software providers
- Payment processing services
- Professional advisers, such as legal or insurance advisers where necessary
We require processors to handle data securely, only on our instructions, and in accordance with applicable data protection law. We do not sell personal data. If data is disclosed to an independent controller, such as a public authority or insurer, it will only be for a legitimate and lawful purpose.
7. International Transfers
Where any processor stores or accesses data outside the UK, we ensure appropriate safeguards are in place, such as adequacy regulations, standard contractual clauses, or other approved mechanisms. We take steps to ensure your data receives a level of protection that is consistent with UK data protection standards.
8. Security of Personal Data
We use reasonable technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration, or destruction. These measures may include access controls, secure storage, staff confidentiality practices, and regular review of systems and procedures.
Although no system can be guaranteed completely secure, we are committed to maintaining appropriate safeguards and reviewing them where needed. If a personal data breach were to occur, we would assess the risk and take appropriate action in line with legal requirements.
9. Your Rights
You have a number of rights in relation to your personal data. These rights may be subject to conditions and exemptions under data protection law. They include:
- Right of access – to request a copy of the personal data we hold about you
- Right to rectification – to ask us to correct inaccurate or incomplete information
- Right to erasure – to request deletion of your data in certain circumstances
- Right to restriction – to ask us to limit how we process your data in certain cases
- Right to data portability – to receive certain data in a structured, commonly used format where applicable
- Right to object – to object to processing based on legitimate interests or direct marketing
- Right to withdraw consent – where processing is based on consent
We will respond to valid requests within the timeframe required by law, unless the request is complex or numerous, in which case we may extend the response period where permitted. We may need to verify your identity before acting on a request to protect your data.
10. Marketing and Communications
We only send marketing messages where we are permitted to do so by law. If we rely on consent, you can withdraw it at any time. If we rely on legitimate interests, we will always respect your right to object. Operational messages, such as appointment updates or invoices, are not marketing and may still be sent when necessary to provide services.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the law, our services, or our data handling practices. The most current version will apply to your personal data. We encourage customers to review the policy periodically so they remain informed about how their information is used.
12. How This Policy Applies
This Privacy Policy applies to all Gardeners The Hale customers in area and to individuals who interact with us in connection with our gardening services. By providing personal data to us, you acknowledge that it may be processed in accordance with this policy and applicable law. We aim to keep processing limited, secure, and proportionate at every stage.
Last updated: This policy should be reviewed regularly to ensure ongoing compliance and accuracy.