Privacy Policy - Gardeners Perivale
Gardeners Perivale is committed to protecting the privacy and personal data of all customers in the Perivale area. This Privacy Policy explains how we collect, use, store, share, and protect personal information when we provide gardening and related services. It also explains the rights available to individuals under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy applies to all Gardeners Perivale customers in the area, including prospective customers, existing customers, household members whose details are provided to us, and any person who communicates with us in connection with our services. By using our services, you acknowledge the practices described in this policy.
1. Information We Collect
We only collect personal data that is relevant and necessary for providing our services, managing customer relationships, and meeting our legal obligations. Depending on the nature of the work requested, we may collect the following categories of information:
- Identity details: name, title, and any relevant household or business contact name.
- Contact details: address, email address, telephone number, and preferred communication method.
- Service details: information about the gardening services requested, site access requirements, property notes, and service preferences.
- Billing and payment information: records relating to invoices, payment status, and transaction details.
- Communication records: emails, messages, call notes, complaints, feedback, and service updates.
- Technical information: limited data such as IP address or browser information if you interact with digital systems used for enquiries or administration.
- Special category data: only where strictly necessary and usually indirectly, for example if a customer shares accessibility needs or health-related information to help us safely arrange services.
We do not intentionally collect more information than needed, and we do not use personal data for unrelated purposes. If sensitive information is provided to us voluntarily, we will handle it with appropriate care and only where there is a valid legal basis.
2. How We Use Personal Data
Gardeners Perivale uses personal data for clear and legitimate purposes connected to our gardening services. These purposes include:
- responding to enquiries and arranging quotations;
- providing gardening, maintenance, and related services;
- managing appointments, work schedules, and site access;
- issuing invoices, processing payments, and maintaining financial records;
- communicating service updates, reminders, and customer support messages;
- handling complaints, disputes, or claims;
- maintaining internal records and service quality;
- meeting legal, tax, accounting, and insurance requirements;
- protecting the security of our staff, customers, systems, and property.
We use personal data only to the extent necessary for these purposes. Where possible, we minimise data use and restrict access to authorised personnel only.
3. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each use of personal data. Gardeners Perivale relies on the following lawful bases where appropriate:
Contract
We process personal data when it is necessary to enter into or perform a contract with you. This includes preparing quotations, confirming bookings, carrying out garden work, and managing payment arrangements.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests and where those interests are not overridden by your rights. Examples include improving service delivery, maintaining accurate records, preventing fraud, and managing customer communications. We consider the impact on individuals before relying on this basis.
Legal Obligation
We process certain information when required by law, including tax, accounting, insurance, health and safety, and record-keeping obligations.
Consent
In limited cases, we may rely on your consent, particularly for optional communications or where special category data is involved and no other lawful basis applies. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Vital Interests
In rare circumstances, personal data may be processed to protect someone’s vital interests, such as in an emergency affecting safety.
4. Data Sharing and Processors
We may share personal data with trusted third parties that help us operate our business. These parties act as data processors or, in some cases, independent controllers. We only share the minimum information necessary and require appropriate safeguards.
Processors may include:
- IT and hosting providers that support email, storage, or administrative systems;
- accounting and invoicing providers used for financial administration;
- payment service providers that handle card or electronic payments;
- customer management tools used to organise bookings and records;
- professional advisers such as insurers, legal advisers, or accountants where necessary;
- subcontractors or workforce partners who assist in service delivery under confidentiality and data protection obligations.
Where a processor handles data on our behalf, we require them to process it only according to our instructions and to apply suitable technical and organisational security measures. We do not sell personal data.
We may also disclose information if required by law, to protect our legal rights, to prevent fraud, or to respond to a lawful request from public authorities.
5. International Transfers
If any personal data is transferred outside the UK, we will ensure that appropriate safeguards are in place. This may include adequacy regulations, standard contractual clauses, or other lawful transfer mechanisms recognised under data protection law. We assess transfer risks and take steps to protect data wherever it is processed.
6. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. Retention periods vary depending on the type of information and the reason it is held.
- Customer and service records: kept for the duration of the service relationship and for a reasonable period afterwards for administration, queries, and legal protection.
- Financial records: retained in line with accounting and tax obligations.
- Communication records: retained as needed to manage the customer relationship, handle complaints, or resolve disputes.
- Consent-based data: kept until consent is withdrawn or the information is no longer needed.
When data is no longer required, it is securely deleted, anonymised, or otherwise disposed of in a safe manner.
7. Data Security
We use reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or disclosure. These measures may include access controls, secure storage, staff confidentiality expectations, and limited data sharing. While no system can be guaranteed completely secure, we regularly review our practices to reduce risk and protect customer information.
8. Your Rights Under GDPR
Individuals whose data we process have a number of rights under data protection law. Subject to legal conditions and exemptions, you may have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data in certain circumstances;
- Restrict how we use your data in certain situations;
- Object to processing based on legitimate interests or direct marketing;
- Data portability, where applicable;
- Withdraw consent where processing is based on consent;
- Complain to the Information Commissioner’s Office if you believe your rights have been infringed.
We will respond to rights requests within the timescales required by law and may need to verify identity before taking action. Some rights may not apply in full if legal obligations or exemptions prevent us from complying.
9. Children’s Data
Our services are directed to adults. We do not knowingly collect personal data from children except where it is incidentally provided by a customer in connection with service arrangements. If we become aware that we have collected data unlawfully or without proper basis, we will take appropriate steps to remove it.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, operational, or service changes. Any revised version will apply from the date it is made available. We encourage customers to review this policy periodically so they remain informed about how their data is used.
11. Summary
Gardeners Perivale processes personal data fairly, lawfully, and transparently in order to provide gardening services to customers in the Perivale area. We collect only the information needed, use it on valid lawful bases, share it carefully with trusted processors, and retain it only for as long as necessary. We respect the rights of every individual and aim to maintain clear, responsible data protection standards at all times.
This Privacy Policy applies to all Gardeners Perivale customers in the area.