Privacy Policy - Gardeners Blackfen
This Privacy Policy explains how Gardeners Blackfen collects, uses, stores, shares, and protects personal data belonging to our customers in the Blackfen area. It applies to all customers, prospective customers, and anyone who interacts with our gardening services in this area. We are committed to handling personal data in a fair, transparent, and lawful way in accordance with the UK GDPR and the Data Protection Act 2018.
1. Who This Policy Applies To
This policy applies to all Gardeners Blackfen customers in the area, including individuals who request quotations, book services, receive gardening work, or communicate with us about ongoing or completed services. It also applies to people whose data we may need to process in connection with the delivery of our services, such as property owners, tenants, property managers, or authorised representatives.
We only process personal data where we have a lawful basis to do so, and we take care to keep the information relevant, accurate, and limited to what is necessary for the purpose involved.
2. Personal Data We Collect
We may collect and process the following categories of data:
- Identity details such as name and title.
- Contact details such as address, phone number, and email address.
- Service information such as the type of gardening work requested, service history, preferences, and instructions.
- Payment and billing information where needed for invoicing, recordkeeping, and payment processing.
- Communication records such as messages, quotes, complaints, feedback, and service updates.
- Property-related details relevant to the work we are asked to carry out, such as access notes, garden layout, and timing preferences.
- Technical information if we receive data through electronic communications, including limited device or log details where applicable.
We aim to collect only the information that is necessary for the service relationship. We do not intentionally collect special category data unless there is a clear and lawful reason to do so and the individual has provided it voluntarily where appropriate.
3. How We Use Personal Data
We use personal data for the following purposes:
- To provide quotes and respond to service enquiries.
- To arrange, deliver, and manage gardening services.
- To communicate about appointments, changes, and service updates.
- To issue invoices, process payments, and maintain financial records.
- To keep records of work completed and customer preferences.
- To deal with complaints, queries, and follow-up requests.
- To improve our services, processes, and customer experience.
- To comply with legal, tax, accounting, and regulatory obligations.
We use information only in ways that are compatible with the purpose for which it was collected. If we need to use personal data for a new purpose, we will assess whether that use is lawful and inform the individual where required.
4. Lawful Basis for Processing
Under data protection law, we must have a lawful basis for each use of personal data. Gardeners Blackfen may rely on one or more of the following bases:
Contract
We process personal data where it is necessary to enter into or perform a contract with a customer. This includes providing quotes, arranging services, and completing agreed work.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided those interests are not overridden by the individual’s rights and freedoms. This may include managing customer records, improving services, and maintaining secure operations.
Legal Obligation
We process certain information where needed to meet legal obligations, such as tax, accounting, insurance, and recordkeeping requirements.
Consent
Where consent is required, we will ask for it clearly and separately. An individual may withdraw consent at any time, where consent is the lawful basis for processing. Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn.
Vital Interests and Public Tasks
These bases are unlikely to apply in most gardening service situations, but if they do, we will only rely on them where permitted by law.
5. Data Sharing and Processors
We may share personal data with trusted third parties, but only when necessary and only to the extent required for the service or for legal compliance. These third parties may act as processors or independent controllers, depending on the circumstances.
Examples of processors may include:
- Payment service providers who process transactions securely.
- Accounting and bookkeeping providers who help manage financial records.
- IT and cloud storage providers who support secure data storage and communications.
- Administrative service providers who assist with scheduling, documentation, or customer administration.
Where a third party acts as a processor, they are required to process personal data only on our instructions and to keep it secure. We use appropriate contractual safeguards to protect data and ensure that processors comply with data protection requirements.
We may also disclose information where required by law, regulation, court order, or to protect our rights, property, customers, or staff. We do not sell personal data.
6. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. Retention periods may vary depending on the type of data and the reason for processing.
In general, we may retain:
- Customer and service records for the duration of the service relationship and for a reasonable period afterwards.
- Financial and invoicing records for the periods required by tax and accounting law.
- Communication records for as long as needed to manage service queries, disputes, or follow-up matters.
- Technical or security-related records only for as long as needed to maintain system integrity and protection.
When data is no longer required, we will delete it securely or anonymise it so that it can no longer be linked to an individual. Retention is always reviewed against necessity, legal obligations, and proportionality.
7. Data Security
We use appropriate technical and organisational measures to protect personal data from unauthorised access, loss, misuse, alteration, or disclosure. These measures are designed to reflect the nature of the data we handle and the risks involved.
Examples may include restricted access, secure storage, password protection, access controls, and staff awareness of confidentiality obligations. While no system can be guaranteed completely secure, we aim to reduce risk through sensible safeguards and careful handling.
8. International Transfers
If personal data is transferred outside the UK, we will take steps to ensure that an appropriate level of protection is in place. This may include using legally recognised transfer safeguards and checking that the receiving party applies adequate security and privacy controls.
9. Your Rights
Individuals whose personal data we process have certain rights under data protection law. These rights may include:
- Right of access – to request a copy of the personal data we hold about you.
- Right to rectification – to ask us to correct inaccurate or incomplete information.
- Right to erasure – to request deletion of data in certain circumstances.
- Right to restriction – to ask us to limit how we use your data in certain situations.
- Right to object – to object to processing based on legitimate interests or direct marketing, where applicable.
- Right to data portability – to receive certain data in a structured, commonly used format, where applicable.
- Right to withdraw consent – where consent is the basis for processing.
These rights are not absolute and may depend on the legal basis for processing and the nature of the request. We will review each request carefully and respond in accordance with applicable law.
10. Children’s Data
Our services are intended for adults. We do not knowingly collect personal data from children unless it is necessary in a limited and lawful way, such as where a parent or guardian provides relevant details for service-related reasons. If we become aware that we have collected data improperly, we will take appropriate steps to delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. Any updates will apply from the date they take effect. We encourage customers to review this policy periodically so they remain informed about how their information is handled.
12. Summary of Our Commitment
Gardeners Blackfen is committed to respecting privacy and handling personal data responsibly. We collect only what we need, use it for clear and lawful purposes, keep it no longer than necessary, and protect it with suitable safeguards. We also recognise the importance of transparency and individual rights, and we aim to maintain trust through fair and lawful data practices.
In short: we process personal data carefully, securely, and only for genuine service, legal, and operational purposes connected with customers in the Blackfen area.