Privacy Policy - Gardeners New Southgate
This Privacy Policy explains how Gardeners New Southgate collects, uses, stores, shares, and protects personal data. It applies to all Gardeners New Southgate customers in the area, including anyone who requests a quotation, books a service, receives maintenance support, or otherwise engages with our gardening services. We are committed to handling personal information in a lawful, fair, and transparent way, in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Gardeners New Southgate provides local gardening and grounds maintenance services for residential and commercial customers in and around New Southgate. For the purposes of data protection law, we are the data controller for the personal data we collect and use in connection with our services. This means we decide why and how your personal data is processed, and we are responsible for ensuring that processing remains compliant with applicable data protection requirements.
2. Personal data we collect
We collect only the information necessary to provide and manage our services. Depending on how you interact with us, we may collect the following categories of data:
- Identity data such as your name, title, and any account or reference identifier used for service administration.
- Contact data such as your address, email address, and telephone number.
- Service data such as property access instructions, service preferences, booking details, and records of work carried out.
- Billing data such as invoices, payment status, and transaction records.
- Communication data such as enquiries, feedback, complaints, and correspondence.
- Technical data if you interact with digital systems, including basic device or browser information needed for security or troubleshooting.
We do not intentionally collect special category data unless it is provided voluntarily and is strictly necessary for a specific service-related reason. If such data is ever required, it will be processed only where a lawful basis exists and additional safeguards are in place.
3. How we collect personal data
We may collect personal data directly from you when you make an enquiry, request a service, communicate with us, or provide information during a booking or service visit. We may also receive data from third parties where necessary to perform a service, manage a payment, or administer a business relationship. In some cases, we may collect limited information automatically from systems used to secure or operate our services.
4. Why we use your data
We use personal data for clearly defined and legitimate purposes, including:
- responding to enquiries and providing quotations;
- arranging, delivering, and managing gardening services;
- keeping service records and scheduling future visits;
- processing invoices, payments, and account administration;
- communicating updates, changes, or service-related notices;
- handling complaints, disputes, and customer support requests;
- maintaining business records for legal, tax, and insurance purposes;
- improving service quality, security, and operational efficiency.
We only use your data in ways that are relevant to the relationship we have with you. We do not sell personal data, and we do not use it for unrelated purposes without a lawful basis.
5. Lawful basis for processing
Under UK GDPR, we must have a lawful basis to process personal data. Gardeners New Southgate relies on the following lawful bases, depending on the circumstances:
Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes preparing quotations, managing bookings, delivering gardening services, issuing invoices, and handling customer account administration.
Legal obligation
We may process data where required to comply with legal or regulatory duties, such as tax records, accounting obligations, fraud prevention, or record retention requirements.
Legitimate interests
We may process data where it is necessary for our legitimate business interests, provided those interests do not override your rights and freedoms. Examples include maintaining business records, improving customer service, ensuring site safety, and managing routine communications.
Consent
In limited situations, we may rely on your consent. Where consent is used, it will be specific, informed, and freely given, and you may withdraw it at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal.
6. Sharing and processors
We may share personal data with trusted third parties where necessary for service delivery, administration, or legal compliance. These organisations act as processors when they handle data on our instructions, or as independent controllers where they determine their own purposes.
Typical processors may include:
- IT and hosting providers that support secure data storage and system operation;
- accounting or bookkeeping services that assist with invoicing and compliance;
- payment processors used to complete transactions;
- communication and scheduling tools used to manage bookings and customer correspondence;
- professional advisers such as insurers, auditors, or legal advisers where required.
We require processors to act only on our documented instructions, keep personal data secure, and implement appropriate technical and organisational measures. Where personal data is shared with other parties, we ensure that such sharing is limited, necessary, and lawful.
7. Data retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements. Retention periods vary depending on the type of data and the reason for processing.
- Customer and service records are generally kept for the duration of the service relationship and for a reasonable period afterwards to manage follow-up queries or disputes.
- Financial and tax records are retained for the period required by law and accounting obligations.
- Communication records may be retained for a period needed to resolve enquiries, monitor quality, or maintain evidence of instructions.
When data is no longer required, it will be securely deleted, anonymised, or otherwise disposed of in a safe and appropriate manner. We review retention regularly to avoid holding data for longer than necessary.
8. Data security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and careful handling of records. Although no system can be guaranteed completely secure, we take reasonable and proportionate steps to reduce risk and protect your information.
9. Your rights
Under data protection law, you have a number of rights in relation to your personal data. These rights may be subject to limitations and exceptions depending on the circumstances.
- Right of access – you can request a copy of the personal data we hold about you.
- Right to rectification – you can ask us to correct inaccurate or incomplete data.
- Right to erasure – you can ask us to delete your data in certain situations.
- Right to restriction – you can ask us to limit how we use your data in certain circumstances.
- Right to data portability – you can request transfer of certain data in a structured, commonly used format.
- Right to object – you can object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
If you wish to exercise any of these rights, we will respond in accordance with data protection law. We may need to verify your identity before acting on your request. If we are unable to comply fully, we will explain the reason, unless the law prevents us from doing so.
10. International transfers
If personal data is transferred outside the United Kingdom, we will only do so where appropriate safeguards are in place and the transfer complies with applicable data protection law. Where required, these safeguards may include adequacy regulations, standard contractual clauses, or equivalent protections.
11. Cookies and similar technologies
If we use websites or digital tools in connection with our services, they may use basic cookies or similar technologies for security, functionality, or performance. Where consent is required, we will seek it before placing non-essential cookies. Any such tools are used only to support the service experience and not to intrude unnecessarily into your privacy.
12. Children’s data
Our services are not directed at children as a primary audience. We do not knowingly collect personal data from children unless it is necessary in the context of a customer relationship and provided by an adult or lawful guardian. Where children’s data is involved, it is handled carefully and only for legitimate service-related reasons.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. The latest version will apply from the date it is made available. We encourage customers to review it periodically so they remain informed about how their personal data is handled.
14. Summary of our commitment
Gardeners New Southgate is committed to respecting privacy and protecting personal data at every stage of the customer relationship. We collect only what we need, use it for clear and lawful purposes, keep it only as long as necessary, and share it only with trusted processors or where required by law. Your information matters to us, and we aim to handle it with care, transparency, and accountability.