Privacy Policy - Gardeners Surbiton
This Privacy Policy explains how Gardeners Surbiton collects, uses, stores, and protects personal data when providing gardening services. It applies to all Gardeners Surbiton customers in the area, including residential and commercial clients who request quotes, make bookings, receive garden maintenance, or otherwise interact with our services. We are committed to handling personal information in a lawful, fair, and transparent manner, in line with the UK GDPR and the Data Protection Act 2018.
1. Who We Are and Scope of This Policy
For the purposes of data protection law, Gardeners Surbiton is the organisation responsible for deciding how and why your personal data is used. This policy applies whenever you use our services, contact us about a job, request an estimate, arrange a visit, or become a customer. It also applies to information collected through messages, forms, notes taken during site visits, and records created as part of our service delivery.
We aim to keep your data secure and to use it only for legitimate business and service-related reasons. We do not sell personal data, and we do not use it for purposes that are unrelated to the gardening services we provide.
2. Information We Collect
We may collect and process the following categories of personal data:
- Identity details: your name, title, and any business name you use.
- Contact details: address, phone number, and email address.
- Service information: details about the gardens, outdoor areas, or properties where work is requested or carried out.
- Booking and communication records: messages, appointment notes, service requests, and correspondence.
- Payment and billing information: payment status, invoices, and transaction records. We do not retain full card details where a payment processor handles them securely.
- Technical information: limited data such as device or browser details if you interact with us electronically.
- Feedback and complaint records: reviews, queries, service concerns, and any follow-up notes.
In some cases, we may also collect limited special category data if it becomes necessary for service reasons, for example, where access arrangements or health-related considerations affect how we work on a site. If this occurs, we will only process such information where permitted by law and only to the extent needed.
3. How We Use Your Data
We use personal data for the following purposes:
- to provide gardening services, quotations, and schedule arrangements;
- to communicate about your booking, service updates, or follow-up actions;
- to manage invoicing, payments, and account administration;
- to maintain records of work completed, customer preferences, and property-specific instructions;
- to handle complaints, claims, or service queries;
- to meet legal, accounting, tax, and insurance obligations;
- to improve the quality, safety, and efficiency of our services;
- to prevent fraud, misuse, or unauthorised access to our records.
We will only use your information in ways that are compatible with the purpose for which it was collected. Gardeners Surbiton keeps processing limited to what is necessary and relevant to the service relationship.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis to process personal data. Depending on the situation, we rely on one or more of the following:
Contract
We process data when it is necessary to deliver services you have requested, respond to enquiries, prepare quotations, schedule work, or manage invoices and payment arrangements.
Legitimate Interests
We may process personal information where it is reasonably necessary for our legitimate business interests, provided your rights and freedoms do not override those interests. This includes record-keeping, service management, quality control, and protecting our business from fraud or disputes.
Legal Obligation
We may retain and use data where necessary to comply with legal requirements, such as tax, accounting, insurance, or regulatory obligations.
Consent
Where required, we will ask for your consent, for example, before sending certain types of optional marketing messages. You can withdraw consent at any time without affecting any processing already carried out lawfully before withdrawal.
5. Data Retention
We keep personal data only for as long as needed for the purpose for which it was collected, or as required by law. Retention periods may vary depending on the type of record and the reason for keeping it.
- Customer and service records: retained for the duration of the business relationship and for a reasonable period afterwards.
- Invoices, payment, and tax records: kept for the period required by accounting and tax law.
- Correspondence and service notes: retained as long as necessary to manage ongoing or future service needs, disputes, or warranties.
- Complaint or claim records: retained for as long as required to resolve the matter and for any applicable limitation period.
When information is no longer needed, we will delete it securely or anonymise it so that it can no longer identify you. We review retained records periodically to ensure they are not kept longer than necessary.
6. Sharing Data with Processors
We may share personal data with trusted third parties who help us operate our services. These organisations act as data processors or independent controllers depending on the service they provide. Where they act as processors, they are only permitted to use your data on our instructions and must keep it secure.
Examples of processors may include:
- IT and cloud service providers: for secure storage, email, and record management;
- Accounting and invoicing providers: for financial administration and compliance;
- Payment service providers: for processing payments securely;
- Scheduling or administration tools: for managing appointments and work orders;
- Professional advisers: such as accountants, insurers, or legal advisers when necessary.
We may also disclose data where required by law, court order, or to protect our rights, property, staff, or customers. If a service provider is based outside the UK or EEA, we will ensure appropriate safeguards are in place where required by law.
7. Data Security
We take appropriate technical and organisational measures to protect personal data from unauthorised access, loss, misuse, alteration, or destruction. These measures may include access controls, secure storage, limited staff access, password protection, and careful handling of paper or electronic records.
Although no system can be guaranteed to be completely secure, we work to maintain a level of protection appropriate to the sensitivity of the data we process. If a data breach occurs that is likely to pose a risk to your rights and freedoms, we will act in accordance with legal requirements.
8. Your Rights
Under data protection law, you have several rights in relation to your personal data. These may include:
- Right of access: you may request a copy of the personal data we hold about you;
- Right to rectification: you may ask us to correct inaccurate or incomplete information;
- Right to erasure: in certain circumstances, you may request that we delete your data;
- Right to restriction: you may ask us to limit the use of your data in some situations;
- Right to object: you may object to processing based on legitimate interests or direct marketing;
- Right to data portability: you may ask for certain data in a structured, commonly used format;
- Right to withdraw consent: where processing is based on consent, you can withdraw it at any time.
These rights are not absolute and may be subject to legal exemptions or limitations. If you exercise a right, we may need to verify your identity before responding.
9. Marketing Preferences
We will only send marketing communications where permitted by law. If you receive optional marketing messages, you can choose to stop them at any time. Your request will be respected promptly, and we will not use your information for that purpose once you have opted out.
10. Complaints and Further Information
If you have concerns about how your personal data is handled, we encourage you to raise them so they can be reviewed. You also have the right to make a complaint to the UK Information Commissioner’s Office if you believe your data protection rights have been breached. We aim to resolve concerns fairly and transparently.
11. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. Any updated version will apply from the date it is made available. We recommend checking this policy occasionally to stay informed about how your data is protected.
12. Summary of Our Commitment
Gardeners Surbiton is committed to processing personal data responsibly, securely, and lawfully. We collect only what is necessary, use it for clear service-related purposes, retain it for appropriate periods, and rely on lawful bases under GDPR. We also ensure that our processors are selected carefully and that your rights are respected. This policy applies to all customers in the Surbiton area who use our gardening services, and it reflects our ongoing commitment to privacy, transparency, and trust.