Privacy Policy - Gardeners Manor Park
Gardeners Manor Park is committed to protecting the privacy of all customers in our area. This Privacy Policy explains how we collect, use, store, share, and protect personal data when we provide gardening and related services. It applies to all Gardeners Manor Park customers in the area, whether you contact us by phone, email, form, or in person, and whether services are one-off or ongoing.
1. Who we are
For the purposes of data protection law, Gardeners Manor Park acts as the data controller for personal data that we collect and process in connection with our services. This means we decide why and how your personal data is used. We are responsible for ensuring that your information is handled lawfully, fairly, and transparently.
2. Personal data we collect
We only collect data that is relevant and necessary for delivering our services, managing our customer relationship, and meeting legal obligations. The categories of personal data we may collect include:
- Identity details such as your name and, where relevant, the name of a household member or authorised contact.
- Contact details such as address, email address, and telephone number.
- Service information such as the services requested, appointment preferences, garden access notes, and job history.
- Payment and billing information such as invoice records, payment status, and accounting references.
- Communication records including emails, messages, call notes, complaints, feedback, and service updates.
- Technical data such as basic website or device information if you interact with digital booking or enquiry systems.
- Special instructions that help us carry out work safely and effectively, for example access arrangements or hazards on site.
We do not intentionally collect more information than needed. We also avoid collecting special category data unless it is necessary and permitted by law. If such data is ever provided to us, we will only process it where there is a valid legal basis and appropriate safeguards.
3. How we use personal data
We use personal data for the following purposes:
- To provide, manage, and complete gardening services.
- To communicate with you about quotes, bookings, schedules, changes, or follow-up work.
- To issue invoices, receive payments, and manage our accounts.
- To respond to enquiries, feedback, and complaints.
- To keep records of services provided and customer preferences.
- To maintain safety, quality, and service standards.
- To comply with legal, tax, accounting, and regulatory obligations.
We use personal data only when there is a lawful reason to do so, and we take care to limit use to what is necessary.
4. Lawful basis for processing
Under the UK GDPR and Data Protection Act 2018, we must have a lawful basis for each type of processing. Gardeners Manor Park may rely on the following lawful bases:
Contract
We process your data when it is necessary to enter into or perform a contract with you. This includes providing quotes, arranging services, carrying out work, and administering payments.
Legal obligation
We process certain information when required by law, such as retaining tax records, accounting documents, or other mandatory business records.
Legitimate interests
We may process personal data for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include managing customer records, improving service quality, preventing fraud, and resolving disputes. Where we rely on legitimate interests, we consider the impact on your privacy carefully.
Consent
In limited cases, we may ask for your consent, for example where optional marketing communication is involved or where specific processing is not covered by another lawful basis. If we rely on consent, you may withdraw it at any time.
5. Sharing personal data and processors
We may share personal data only when necessary and appropriate. This may include sharing data with trusted processors who act on our instructions and support our services. Examples may include:
- IT and cloud service providers that store or help manage records securely.
- Accounting or invoicing providers that help us manage billing and financial records.
- Communication service providers that support email, messaging, or booking administration.
- Payment service providers that process transactions securely.
- Professional advisers such as accountants, insurers, or legal advisers where needed.
We require processors to keep data secure, use it only for the agreed purpose, and comply with data protection law. We do not sell personal data. We may also disclose information if required by law, by court order, or to protect our rights, property, customers, or staff.
6. Data retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including for legal, accounting, and reporting requirements. Retention periods depend on the nature of the data and the reason it is held.
- Customer service records are generally kept for the duration of the customer relationship and for a reasonable period afterwards.
- Financial and tax records are retained for the period required by law.
- Communication records may be kept for as long as needed to manage enquiries, resolve disputes, or maintain accurate service history.
- Data collected with consent is kept until consent is withdrawn, unless we have another lawful basis to retain it.
When data is no longer required, we will delete it securely or anonymise it so it can no longer identify you.
7. Data security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and regular review of our data handling practices.
However, no method of transmission or storage is completely secure. While we work hard to protect your information, we cannot guarantee absolute security. If a personal data breach occurs, we will act in line with legal requirements.
8. Your rights
You have a number of rights under data protection law, subject to certain conditions and exceptions. These include:
- Right of access – to request a copy of the personal data we hold about you.
- Right to rectification – to ask us to correct inaccurate or incomplete data.
- Right to erasure – to request deletion of your data in certain circumstances.
- Right to restrict processing – to ask us to limit how we use your data in certain situations.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to data portability – to receive certain data in a structured, commonly used format.
- Right to withdraw consent – where processing is based on consent, you can withdraw it at any time.
If you wish to exercise any of these rights, we will respond in accordance with data protection law. We may need to verify your identity before acting on your request.
9. Marketing preferences
Where we send optional marketing communications, we will do so only where permitted by law. You may object to direct marketing at any time. If you opt out, we will stop using your data for that purpose.
10. International transfers
Where personal data is transferred outside the UK, we will ensure that appropriate safeguards are in place. This may include transfer mechanisms approved under data protection law and contractual protections designed to keep your data secure and protected.
11. Children’s data
Our services are intended for adult customers or authorised representatives. We do not knowingly collect children’s personal data unless it is necessary for a service arrangement and lawfully provided by an adult with responsibility for the relevant household or property.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data processing practices. Any updated version will apply from the date it is published or otherwise communicated. We encourage customers to review it periodically.
13. Summary of our commitments
Gardeners Manor Park collects only the personal data needed to deliver gardening services, manage customer relationships, and meet legal obligations. We process data on lawful bases such as contract, legal obligation, legitimate interests, and consent where applicable. We keep data only as long as necessary, share it only with trusted processors or when legally required, and respect your rights under data protection law.
This Privacy Policy applies to all Gardeners Manor Park customers in the area.