Privacy Policy - Gardeners Leytonstone
This Privacy Policy explains how Gardeners Leytonstone collects, uses, stores, shares, and protects personal data when providing gardening and related services. It applies to all Gardeners Leytonstone customers in the area, including individuals, households, landlords, tenants, and business clients who request or receive services. We are committed to handling personal information in a fair, lawful, and transparent way, in line with the UK GDPR and the Data Protection Act 2018.
This policy is designed to help you understand what information may be processed, why it is needed, how long it is kept, and what rights you have over your data. By using our services, making an enquiry, or otherwise interacting with Gardeners Leytonstone, you acknowledge the practices described here.
1. Information We Collect
We only collect personal data that is necessary for legitimate business purposes. The types of information we may process include:
- Identity details, such as your name and, where relevant, business name.
- Contact details, such as address, email address, and telephone number.
- Service details, including the type of gardening work requested, property information, access notes, and scheduling preferences.
- Payment and billing information, where needed to issue invoices, record payments, or manage accounts.
- Communication records, such as emails, messages, notes from calls, and feedback provided about our services.
- Site and property information, including relevant instructions about gardens, outdoor access, or safety considerations.
- Technical and usage data, if you interact with digital systems used to manage bookings or enquiries.
We do not seek to collect unnecessary personal data. If any special category data is ever provided to us unintentionally, it will be handled with additional care and only where there is a lawful reason to do so.
2. How We Use Personal Data
Gardeners Leytonstone uses personal data for the following purposes:
- To respond to enquiries and provide quotations.
- To arrange, deliver, and manage gardening services.
- To communicate about bookings, changes, or service updates.
- To prepare invoices, process payments, and manage accounts.
- To maintain records of work completed and customer preferences.
- To handle complaints, disputes, or customer support requests.
- To comply with legal and regulatory obligations.
- To improve our services, administration, and customer experience.
We only use personal information in ways that are relevant to the service relationship and consistent with your expectations. Gardeners Leytonstone does not sell personal data.
3. Lawful Basis for Processing
We process personal data under one or more lawful bases permitted by UK GDPR. These may include:
Contract
We rely on the performance of a contract where processing is necessary to provide gardening services, complete bookings, issue invoices, or carry out agreed work.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided your rights and freedoms do not override those interests. This may include service administration, record keeping, fraud prevention, and internal quality control.
Legal Obligation
Some data must be retained or processed to meet legal, tax, accounting, or regulatory requirements.
Consent
In limited situations, we may ask for your consent, for example where it is required for optional communications or certain types of processing. Where consent is used, you may withdraw it at any time.
We will always use a lawful basis that matches the purpose of processing and will not process data in a way that is unfair or unexpected.
4. Data Sharing and Processors
We may share personal data with trusted third parties who help us operate efficiently and deliver services. These organisations act as processors or, in some cases, independent controllers. They are only given access to the information necessary to perform their role and must handle it securely.
Examples of processors may include:
- Accounting and bookkeeping providers used for invoicing, tax, and financial administration.
- IT and cloud service providers used to store records, manage systems, or secure business data.
- Communication service providers used to support email, telephone, or messaging functions.
- Payment service providers used to process transactions securely.
- Operational contractors or subcontractors who assist with service delivery where needed.
All processors are expected to follow appropriate confidentiality and security measures. We do not permit them to use personal data for their own unrelated purposes.
We may also disclose data where necessary to comply with law, enforce our agreements, protect our rights, or respond to lawful requests from public authorities.
5. Data Retention
We retain personal data only for as long as necessary for the purpose for which it was collected, including any legal, accounting, or reporting requirements. Retention periods depend on the type of information and the context in which it was provided.
In general:
- Customer and service records are kept for the period needed to manage the relationship and resolve any follow-up queries.
- Financial and tax records are kept for the period required by law.
- Correspondence and support records are retained for a reasonable period to manage service quality and potential disputes.
- Consent-based records are kept only until consent is withdrawn or no longer relevant.
When data is no longer needed, it is securely deleted, anonymised, or otherwise disposed of in a safe manner.
6. Data Security
We take reasonable technical and organisational measures to protect personal data from unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, secure storage, staff awareness, and careful management of third-party systems.
While no method of transmission or storage is completely risk-free, we work to keep data protected and to reduce the likelihood of misuse. If a personal data incident were to occur, we would assess it promptly and take appropriate action in line with legal requirements.
7. Your Rights
As a data subject, you have rights under GDPR in relation to your personal data. These rights may include:
- Right of access – to request a copy of the personal data we hold about you.
- Right to rectification – to ask us to correct inaccurate or incomplete information.
- Right to erasure – to request deletion of your data in certain circumstances.
- Right to restrict processing – to limit how we use your data in specific situations.
- Right to object – to object to processing based on legitimate interests.
- Right to data portability – to request transfer of data you provided, where applicable.
- Right to withdraw consent – where processing is based on consent.
You also have the right to lodge a complaint with the Information Commissioner’s Office if you believe your data has been handled improperly. Before doing so, we encourage you to raise any concerns so that we can address them appropriately.
8. Children’s Data
Our services are generally intended for adults responsible for a property or garden. We do not knowingly collect personal data from children unless it is required incidentally in the course of service delivery and there is a lawful basis for doing so. If we become aware that we have collected data inappropriately, we will take steps to remove it.
9. International Transfers
Where personal data is transferred outside the United Kingdom, we will only do so where appropriate safeguards are in place and where such transfers are lawful. This may include standard contractual protections or other recognised safeguards required by law.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, business practices, or service operations. Any revised version will apply from the date it is made available. We encourage customers to review this policy periodically so they remain informed about how their information is handled.
11. Summary of Our Commitment
Gardeners Leytonstone is committed to using personal data responsibly, transparently, and only where necessary to deliver reliable gardening services. We collect only the information needed to manage customer relationships, carry out work safely and efficiently, and meet legal obligations. We keep data secure, share it only with appropriate processors, and respect the rights of every customer in the area.
Privacy matters to us, and we aim to ensure that all personal data is treated with care, confidentiality, and respect.