Privacy Policy - Gardeners Newington
This Privacy Policy explains how Gardeners Newington collects, uses, stores, shares, and protects personal data in connection with its gardening services. It applies to all Gardeners Newington customers in the area, including individuals who enquire about services, receive quotations, make bookings, request ongoing maintenance, or otherwise interact with our team. We are committed to handling personal information in a lawful, fair, and transparent manner in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We recognise that privacy matters. When you choose our services, you trust us with information that may identify you directly or indirectly. This policy sets out what data we collect, why we collect it, the legal bases on which we rely, how long we keep it, the third parties who may process it on our behalf, and the rights available to you. We aim to keep our practices clear and proportionate, collecting only what is necessary for the purposes described below.
1. Data We Collect
Gardeners Newington may collect personal data in several ways, depending on how you interact with us. The information we collect may include:
- Identity information such as your name and, where relevant, the name of a business or property manager.
- Contact details such as your address, email address, and telephone number.
- Service details such as the type of gardening work requested, property access notes, preferred appointment times, and service history.
- Billing and transaction information such as invoice details, payment status, and records of services provided.
- Communication records including emails, messages, call notes, complaints, and feedback.
- Technical information such as limited website or device data if you contact us online, for example IP address or browser information, where this is collected automatically for security and service functionality.
We do not intentionally collect special category data, such as health information, unless you choose to provide it for a specific reason and it is necessary for the service. For example, a customer may tell us about an access need or a safety concern that is relevant to arranging work at a property. In such cases, any information shared will be used carefully and only for the stated purpose.
2. How We Use Personal Data
We use personal data to operate our services efficiently and to meet our obligations to customers and regulators. Typical uses include:
- responding to enquiries and preparing quotations;
- arranging visits, providing gardening services, and managing ongoing maintenance;
- issuing invoices, processing payments, and keeping financial records;
- managing customer relationships and service updates;
- handling complaints, disputes, and insurance-related matters;
- improving service quality, training, and internal administration;
- protecting against fraud, misuse, or unlawful activity;
- meeting legal, tax, accounting, and regulatory obligations.
We do not sell personal data. Any sharing is limited to what is required for service delivery, legal compliance, or legitimate operational purposes.
3. Lawful Basis for Processing
Under UK GDPR, we must have a lawful basis to process personal data. Gardeners Newington relies on the following grounds:
a) Contract
We process personal data when it is necessary to enter into or perform a contract with you. This includes preparing a quote at your request, scheduling gardening work, managing service delivery, and processing payment.
b) Legal Obligation
We may process and retain certain information to comply with legal duties, including accounting requirements, tax rules, and record-keeping obligations. This may also include responding to lawful requests from authorities where required.
c) Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided your rights and freedoms do not override those interests. Examples include managing customer relationships, preventing fraud, improving services, maintaining internal records, and protecting our operations. Where we rely on legitimate interests, we consider necessity and balance carefully.
d) Consent
In limited cases, we may rely on your consent, for example for optional communications or where special category data is provided and consent is the most appropriate basis. Where consent is used, you can withdraw it at any time.
4. Sharing and Processors
We may share personal data with trusted third parties, known as processors, who act on our instructions and support our operations. These may include:
- Payment providers who process card or electronic payments securely;
- Accounting and bookkeeping providers who help us manage invoices, tax records, and financial administration;
- IT and cloud service providers who store data securely and support email, document management, or system maintenance;
- Customer administration tools used to manage bookings, service schedules, and communications;
- Professional advisers such as accountants, insurers, or legal advisers where necessary;
- Public authorities where disclosure is required by law or needed to establish, exercise, or defend legal claims.
All processors are expected to protect data appropriately and to process it only for the agreed purposes. We seek to use providers with suitable technical and organisational safeguards, including access controls and encryption where appropriate.
5. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Retention periods vary depending on the type of data and the context in which it is used.
- Customer and service records are typically retained for the duration of the working relationship and for a reasonable period afterwards to manage queries, warranties, disputes, or follow-up services.
- Financial and tax records are retained for the period required by law, which is commonly up to six years for accounting purposes.
- Communication records may be kept for a shorter or longer period depending on whether they are needed to evidence instructions, resolve issues, or maintain continuity of service.
When data is no longer needed, we will securely delete or anonymise it. Retention is reviewed regularly to ensure information is not kept for longer than necessary.
6. Data Security
We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration, or destruction. These measures may include access restrictions, secure storage, staff confidentiality obligations, and careful management of third-party systems. While no system can be guaranteed completely secure, we work to reduce risk and respond promptly to suspected incidents.
7. International Transfers
Where a processor or service provider stores or accesses data outside the UK, we take steps to ensure an adequate level of protection in line with applicable data protection law. This may involve approved contractual safeguards or use of service providers in jurisdictions with suitable protections.
8. Your Rights
As a data subject, you have rights under UK GDPR in relation to your personal data. Depending on the circumstances, you may have the right to:
- Access the personal data we hold about you;
- Rectification of inaccurate or incomplete data;
- Erasure of data in certain situations;
- Restriction of processing in certain situations;
- Object to processing based on legitimate interests or direct marketing;
- Data portability for information you have provided to us where processing is based on contract or consent and carried out by automated means;
- Withdraw consent where processing relies on consent;
- Lodge a complaint with the Information Commissioner’s Office if you believe your rights have been infringed.
We may need to verify your identity before acting on a request. Some rights are subject to exceptions or limits under law. For example, we may need to retain certain records to comply with legal obligations or defend a legal claim.
9. Children’s Data
Our services are aimed at adults and property-related customers. We do not knowingly collect personal data from children in the ordinary course of business. If we become aware that information has been collected from a child without appropriate authority, we will take reasonable steps to delete it unless we are legally required to keep it.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. Any updated version will apply from the date it is published or otherwise communicated. We encourage customers to review the policy periodically so they remain informed about how their information is handled.
11. Summary of Our Approach
Gardeners Newington handles personal data responsibly and only for legitimate, specified purposes. We collect the minimum information needed to provide gardening services, keep records, comply with law, and maintain quality standards. Our processing is based on contract, legal obligation, legitimate interests, or consent where appropriate. We retain data only as long as required, share it carefully with trusted processors, and respect the rights of every customer in the area. This policy is intended to give you clear, transparent information about how your personal data is used and protected.