Privacy Policy - Gardeners Sidcup
This Privacy Policy explains how Gardeners Sidcup collects, uses, stores, shares, and protects personal data relating to all Gardeners Sidcup customers in the area. It is intended to meet the requirements of the UK GDPR and the Data Protection Act 2018. By using our services, requesting a quotation, making an enquiry, or entering into a service agreement, you acknowledge that your personal data may be processed in the ways described below.
1. Who We Are
Gardeners Sidcup provides gardening and outdoor maintenance services to customers in Sidcup and the surrounding area. For the purposes of data protection law, we act as a data controller when we determine why and how personal data is used. In some limited cases, we may act as a data processor where we handle information on behalf of another organisation. This policy applies to personal data collected from customers, prospective customers, suppliers, and other individuals whose information we process in connection with our services.
2. Personal Data We Collect
We only collect data that is relevant and necessary for providing services, managing enquiries, meeting legal obligations, and improving our business operations. The categories of information we may collect include:
- Identity data such as your name, title, and property or business details.
- Contact data such as address, email address, telephone number, and preferred communication method.
- Service data such as service requests, garden specifications, appointment details, job notes, and customer preferences.
- Financial data such as billing details, payment records, and transaction information.
- Technical data such as basic device, browser, and usage information when you interact with digital systems we may use for administration.
- Communications data such as records of correspondence, complaints, feedback, or service updates.
We do not seek to collect special category data unless there is a clear lawful reason to do so and it is relevant to a specific request or legal obligation. Where such data is provided accidentally, we will handle it carefully and only process it where permitted by law.
3. How We Use Personal Data
We process personal data for the following purposes:
- to respond to enquiries and provide quotations;
- to deliver gardening and maintenance services;
- to schedule visits and manage customer accounts;
- to issue invoices, process payments, and manage financial records;
- to maintain service history and operational records;
- to communicate about appointments, changes, or service matters;
- to comply with legal, regulatory, tax, and accounting obligations;
- to prevent fraud, misuse, or unauthorised access;
- to improve service quality and customer experience.
We will only use your data in ways that are compatible with the purpose for which it was collected, unless we have a lawful basis for further processing.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each type of processing. Gardeners Sidcup relies on the following legal bases:
Contract
We process personal data when it is necessary to enter into or perform a contract with you. This includes handling enquiries, preparing quotations, arranging service visits, carrying out gardening work, and managing payments.
Legal Obligation
We may process personal data when required to comply with legal duties, including accounting, tax, record-keeping, and regulatory obligations.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. Examples include managing customer relationships, preventing fraud, maintaining business records, and improving our operations. Where we rely on legitimate interests, we assess the impact of processing carefully.
Consent
In some situations, we may rely on your consent, for example where you choose to receive certain types of communications or where optional information is requested for a specific purpose. You may withdraw consent at any time, and this will not affect the lawfulness of processing carried out before withdrawal.
5. Data Retention
We keep personal data only for as long as necessary for the purpose for which it was collected, and in line with legal and operational requirements. Retention periods may vary depending on the type of record and the reason for processing.
- Customer service records are generally retained for the duration of the service relationship and for a reasonable period afterwards.
- Financial and tax records are kept for the period required by law.
- Communications and job notes may be retained to support customer service, dispute handling, and continuity of service.
- Inactive or unnecessary data is securely deleted or anonymised once it is no longer needed.
Retention decisions are based on necessity, legal requirements, and the need to maintain accurate business records. We do not store personal data indefinitely. When information is no longer needed, we take appropriate steps to remove it securely.
6. Processors and Third Parties
We may share personal data with trusted processors and service providers who help us operate our business. These parties only process data on our instructions and are required to protect it appropriately. Examples may include:
- bookkeeping and accounting providers;
- payment service providers;
- IT, software, and data storage providers;
- administrative support services;
- professional advisers such as accountants or legal advisers;
- other contractors assisting with service delivery where necessary.
We may also disclose personal data where required by law, by a court order, or to respond to lawful requests by public authorities. Where we use processors, we ensure there is a written agreement in place requiring them to keep personal data secure, use it only for permitted purposes, and support our compliance obligations.
7. Data Security
We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include controlled access, secure storage, staff awareness, and limiting data access to those who need it for legitimate business purposes. While no system can be guaranteed to be completely secure, we aim to maintain a level of protection appropriate to the nature of the data and the risks involved.
8. International Transfers
Where personal data is transferred outside the United Kingdom, we will only do so where appropriate safeguards are in place and the transfer complies with applicable data protection law. This may include transfers to service providers using standard contractual protections or comparable lawful safeguards.
9. Your Rights
Individuals whose personal data we process have several rights under GDPR. These rights may apply depending on the circumstances and legal basis for processing:
- Right of access – you can request a copy of the personal data we hold about you.
- Right to rectification – you can ask us to correct inaccurate or incomplete data.
- Right to erasure – you can request deletion of your data in certain cases.
- Right to restriction – you can ask us to limit how we use your data in some circumstances.
- Right to data portability – you can request transfer of certain information to you or another provider.
- Right to object – you can object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
To protect privacy, we may need to verify your identity before responding to a request. We will respond within the timescales required by law unless an extension is permitted.
10. Complaints and Supervisory Authority
If you have concerns about how your personal data is handled, you have the right to raise a complaint with the relevant data protection supervisory authority. We encourage you to first raise any concerns through the usual service communication route so that we can try to resolve the matter promptly. This does not affect your legal rights.
11. Children’s Data
Our services are intended for adults and property-related customers. We do not knowingly collect personal data from children unless it is necessary and lawful in a specific situation. If we become aware that we have collected information inappropriately, we will take steps to delete it or otherwise handle it lawfully.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, business practices, or service arrangements. Any updated version will apply from the date it is published or otherwise made available. We encourage customers to review this policy periodically so they remain informed about how personal data is processed.
13. Scope of This Policy
This Privacy Policy applies to all Gardeners Sidcup customers in the area and to personal data processed in connection with our gardening services, administration, billing, communications, and legal compliance. It is designed to be clear, fair, and transparent. By continuing to use our services or engaging with us, you acknowledge the terms described in this policy.
In summary, Gardeners Sidcup is committed to handling personal data responsibly, lawfully, and securely. We collect only what we need, use it for clear purposes, retain it for appropriate periods, and respect your rights at every stage of the process.