Privacy Policy - Gardeners Dalston
This Privacy Policy explains how Gardeners Dalston collects, uses, stores, shares, and protects personal data when providing gardening services to customers in the Dalston area. It applies to all Gardeners Dalston customers in the area, including prospective clients, current clients, and anyone who communicates with us about our services. We are committed to handling personal information in a lawful, fair, transparent, and secure manner in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We only collect data that is necessary for delivering our services, managing enquiries, maintaining records, meeting legal obligations, and improving our business operations. We do not sell personal information. We also aim to keep all data accurate and up to date, and we retain it only for as long as it is needed for the purpose for which it was collected.
1. Data We Collect
We may collect and process different categories of personal data depending on how you interact with us. This may include:
- Identity information such as your name, title, and, where relevant, business name.
- Contact details such as address, email address, and telephone number.
- Service details such as the type of gardening work requested, preferred dates, property access notes, and instructions you provide.
- Billing and payment information such as invoice records, payment status, and transaction references.
- Communication records such as messages, queries, complaints, feedback, and notes from phone calls or written correspondence.
- Contract and account records such as quotations, service agreements, job history, and administrative notes.
- Technical data that may be collected when you interact with our systems, such as device information or basic usage logs, where applicable.
We do not intentionally collect special category data unless it is strictly necessary and you have chosen to provide it. Special category data may include information about health, religious beliefs, or other sensitive matters. If such information is shared with us, we will handle it with enhanced care and only where a lawful basis exists.
2. How We Use Personal Data
We use personal data for the following purposes:
- To respond to enquiries and provide quotes.
- To arrange, deliver, and manage gardening services.
- To communicate about appointments, schedule changes, and service updates.
- To issue invoices, process payments, and maintain financial records.
- To keep records of work completed and customer preferences.
- To handle complaints, disputes, and service-related queries.
- To comply with legal, tax, and regulatory obligations.
- To improve service quality, efficiency, and customer experience.
- To protect our business, staff, customers, and property from misuse, fraud, or other unlawful activity.
We always aim to ensure our use of personal information is proportionate and relevant to the service we provide. Where possible, we limit access to personal data to people who need it to perform their duties.
3. Lawful Basis for Processing
Under data protection law, we must have a lawful basis for processing personal data. Depending on the circumstances, Gardeners Dalston may rely on one or more of the following lawful bases:
Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes preparing a quotation, arranging a booking, carrying out gardening work, and managing payment or service administration.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include maintaining service records, responding to requests, improving operations, and preventing fraud or misuse. We consider the impact on individuals before relying on this basis.
Legal Obligation
We may need to process and retain personal data to comply with legal obligations, such as accounting, tax, insurance, health and safety, or record-keeping requirements.
Consent
In limited situations, we may rely on your consent, for example where you voluntarily provide information that is not required for a contract or legal obligation. Where consent is used, you have the right to withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, and reporting requirements. Retention periods depend on the nature of the data and the reason we hold it.
- Customer and service records are generally retained for as long as necessary to manage the relationship and address any follow-up queries or disputes.
- Financial and invoice records are retained for the period required by law and good accounting practice.
- Communication records may be retained for an appropriate period to support service continuity, customer care, and dispute resolution.
- Consent-based records are kept only until consent is withdrawn or the information is no longer needed.
When data is no longer required, we will securely delete, anonymise, or archive it where appropriate. We review retained information periodically to ensure it remains necessary and relevant.
5. Processors and Third Parties
We may share personal data with trusted third-party service providers, known as processors, who help us operate our business. These processors only act on our instructions and are required to protect your data appropriately.
Examples of processors and third-party recipients may include:
- Administrative and bookkeeping providers that help manage invoices, records, and accounts.
- IT and system support providers that assist with secure data storage, email systems, or technical maintenance.
- Payment-related service providers that help process transactions or verify payment status.
- Professional advisers such as accountants, insurers, or legal advisers where necessary.
- Public authorities where disclosure is required by law or to protect rights and safety.
Where we use processors, we take reasonable steps to ensure that they provide sufficient guarantees regarding security, confidentiality, and compliance with data protection law. If data is transferred outside the UK, we will ensure appropriate safeguards are in place.
6. Data Security
We use appropriate technical and organisational measures to protect personal data from unauthorised access, loss, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and regular review of our handling procedures.
While no system can be guaranteed to be completely secure, we take data protection seriously and work to reduce risks through careful management and limited access. We also encourage staff and service partners to handle information responsibly and only for legitimate business purposes.
7. Your Rights
Under data protection law, you have several rights in relation to your personal data. These rights may apply depending on the legal basis for processing and the circumstances of your request.
- Right of access – you can ask for a copy of the personal data we hold about you.
- Right to rectification – you can ask us to correct inaccurate or incomplete information.
- Right to erasure – in certain cases, you can ask us to delete your personal data.
- Right to restrict processing – you can request that we limit how we use your data in specific situations.
- Right to object – you can object to processing based on legitimate interests, and in some cases to direct marketing.
- Right to data portability – you can request that certain data be provided to you or another controller in a structured format.
- Right to withdraw consent – where we rely on consent, you may withdraw it at any time.
If you wish to exercise any of these rights, we will consider your request in accordance with applicable law. We may need to verify your identity before responding to protect your privacy and security.
8. Children’s Data
Our services are intended for adult customers and property owners or occupiers. We do not knowingly collect personal data from children unless it is incidentally provided by an adult customer and is necessary for service-related communication. If we become aware that we have collected information inappropriately, we will take steps to delete or correct it.
9. Complaints and Further Information
If you have concerns about how your personal data is handled, we encourage you to raise the issue with us so that we can review and address it. You also have the right to make a complaint to the UK Information Commissioner’s Office (ICO) if you believe your data protection rights have been infringed.
We may update this Privacy Policy from time to time to reflect changes in law, service arrangements, or data handling practices. Any updates will take effect when published and will continue to apply to all Gardeners Dalston customers in area.
Gardeners Dalston is committed to protecting privacy, maintaining trust, and handling personal information responsibly. We collect only what we need, use it fairly, and keep it only for as long as required.