Privacy Policy - Gardeners Woodside Park
Gardeners Woodside Park is committed to protecting the privacy and personal data of all customers in the Woodside Park area. This Privacy Policy explains how we collect, use, store, share, and protect personal information when providing gardening and related services. It applies to all Gardeners Woodside Park customers in the area, including prospective customers, current customers, and individuals who have previously used our services.
1. Who We Are
Gardeners Woodside Park provides gardening services to residential and commercial customers in Woodside Park and surrounding local areas. For the purposes of data protection law, we act as the data controller for the personal data we process. This means we decide how and why your personal data is used.
We are committed to handling personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We also take appropriate steps to ensure all personal information is processed fairly, lawfully, and transparently.
2. Information We Collect
We may collect and process the following types of personal data:
- Identity details such as your name and title
- Contact details such as address, email address, and phone number
- Service details including the type of gardening service requested, property access notes, and appointment preferences
- Billing and payment information where needed to process invoices and payments
- Communication records such as messages, booking notes, and service-related correspondence
- Site information relevant to carrying out services safely and effectively, such as garden layout, access instructions, and service history
- Technical information if you interact with our digital systems, including basic device or usage data where applicable
We only collect data that is necessary for providing our services, managing customer relationships, meeting legal obligations, and improving our operations. We do not intentionally collect more information than is needed.
3. How We Use Personal Data
Your personal data may be used for the following purposes:
- To respond to enquiries and provide quotations
- To schedule, deliver, and manage gardening services
- To issue invoices and process payments
- To maintain service records and customer preferences
- To communicate about appointments, changes, or service updates
- To meet legal, tax, and accounting obligations
- To improve service quality, operational planning, and customer experience
- To handle complaints, queries, or disputes
We will always use personal information only for specific, legitimate purposes and in ways that are compatible with those purposes.
4. Lawful Basis for Processing
Under data protection law, we must have a lawful basis for processing personal data. Gardeners Woodside Park relies on the following lawful bases, depending on the situation:
Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes arranging services, managing bookings, communicating about work, and processing payments.
Legal Obligation
We may process personal data when required to comply with legal duties, such as accounting, tax, record-keeping, or regulatory requirements.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided these interests are not overridden by your rights and freedoms. Examples include service management, fraud prevention, internal administration, and improving operations. We always consider the potential impact on your privacy before relying on this basis.
Consent
In some limited situations, we may rely on your consent, for example if specific optional communications or uses of data require it. Where consent is used, you may withdraw it at any time.
5. Data Sharing and Processors
We may share personal data with trusted third parties who help us run our business. These organisations act as processors and only process data on our instructions and under appropriate safeguards.
Examples of processors may include:
- IT and cloud storage providers that support data storage, security, and communication systems
- Payment service providers that help process card or electronic payments
- Accounting and bookkeeping providers who support financial administration
- Administrative service providers who assist with scheduling, customer records, or operational support
We may also share information where required by law, court order, or lawful request from public authorities. We do not sell personal data. Any sharing is limited to what is necessary and proportionate.
6. Data Retention
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, and reporting requirements. Retention periods depend on the type of information and the reason it was collected.
In general:
- Customer service records are kept for the duration of the relationship and for a reasonable period afterwards
- Financial and tax-related records are kept for the period required by law
- Communication records are retained as needed to manage service history, queries, or disputes
- Data no longer needed is securely deleted, anonymised, or destroyed
We review retention periods regularly to ensure data is not kept for longer than necessary.
7. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration. These measures may include access controls, secure storage, staff awareness procedures, and restricted use of personal data where appropriate.
While we take data protection seriously, no system can be guaranteed to be completely secure. We therefore continue to review and improve our safeguards to reduce risk.
8. Your Rights
Under data protection law, you have important rights regarding your personal data. These rights may include:
- The right of access to request a copy of the personal data we hold about you
- The right to rectification to correct inaccurate or incomplete data
- The right to erasure in certain circumstances, also known as the right to be forgotten
- The right to restrict processing in certain situations
- The right to object to processing based on legitimate interests or direct marketing
- The right to data portability where applicable
- The right to withdraw consent where processing is based on consent
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you are unhappy with how your data has been handled. We encourage you to contact us first so we can try to resolve any concerns.
9. Special Categories of Data
We do not usually collect special category data such as health information, political opinions, or religious beliefs. If such information is ever provided to us incidentally, we will only process it where there is a lawful basis to do so and where it is relevant and necessary for the service or legal compliance.
10. Children’s Data
Our services are intended for adults or for properties managed by adults. We do not knowingly collect personal data from children unless it is necessary in a limited and lawful context, such as where a customer provides information relevant to access or property arrangements. If we become aware that data has been collected inappropriately, we will take appropriate steps to delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, operations, or data practices. Any updated version will apply from the date it is published or otherwise communicated. We recommend reviewing this policy periodically to stay informed.
12. Summary of Our Commitment
Gardeners Woodside Park respects your privacy and handles personal data responsibly. We collect only the information needed to provide and manage our gardening services, use it for clear and lawful purposes, keep it only as long as necessary, and protect it with appropriate safeguards. We are committed to transparency, accountability, and compliance with data protection law for all customers in the Woodside Park area.
In short: your data is used carefully, retained appropriately, shared only with necessary processors, and protected with your rights fully recognised.