Privacy Policy - Gardeners Covent Garden
Gardeners Covent Garden is committed to protecting personal data and respecting privacy. This Privacy Policy explains how we collect, use, store, share, and protect personal information when providing gardening services. It applies to all Gardeners Covent Garden customers in the area, including individuals, households, landlords, and business clients who request or receive our services.
This policy has been written to meet the standards of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It is intended to be clear, transparent, and easy to understand. By using our services, you should understand what personal data may be processed and why it is needed.
1. Personal Data We Collect
We collect only the information necessary to provide our services effectively, manage our relationship with you, and meet legal and operational requirements. The type of data we collect may include:
- Identity details such as your name and title.
- Contact information such as address, email address, and telephone number.
- Service information such as your gardening preferences, requested work, and property access details.
- Billing information such as invoicing details and payment records.
- Communication records including enquiries, messages, complaints, and service updates.
- Technical information where necessary for website or email security, such as IP address logs or device details.
We generally do not seek to collect special category data. If such information is ever provided to us inadvertently, we will only process it where lawful and necessary, and we will take appropriate safeguards.
2. How We Use Your Data
Personal data is used for specific and legitimate purposes related to our services. These may include:
- responding to enquiries and providing quotations;
- arranging appointments and carrying out gardening work;
- maintaining service records and customer preferences;
- issuing invoices, processing payments, and managing accounts;
- handling complaints, disputes, or service follow-up;
- meeting tax, accounting, and other legal obligations;
- protecting our business, staff, customers, and property;
- improving the quality and efficiency of our services.
We will only use your personal data in ways that are compatible with the purposes described in this policy. We do not sell personal data.
3. Lawful Basis for Processing
Under data protection law, we must have a lawful basis before processing personal data. Depending on the activity, we may rely on one or more of the following:
Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes arranging services, managing bookings, delivering work, and handling payment-related matters.
Legal Obligation
We may process certain data to comply with legal obligations, including accounting, tax, record-keeping, fraud prevention, and regulatory requirements.
Legitimate Interests
We may process data where it is necessary for our legitimate interests, provided that those interests are not overridden by your rights and freedoms. Examples include managing business operations, improving customer service, protecting against misuse, and keeping accurate internal records.
Consent
In limited circumstances, we may ask for your consent before processing certain information. Where consent is used, you can withdraw it at any time. This will not affect processing that has already taken place lawfully.
4. Sharing Your Information
We may share your data with trusted third parties only when necessary for service delivery, compliance, or business administration. These parties act as processors or independent controllers depending on the situation.
Examples of processors may include:
- IT and cloud storage providers;
- accounting and bookkeeping services;
- payment processing providers;
- customer communication and scheduling tools;
- professional advisers who support legal, tax, or compliance obligations.
Processors are required to handle personal data securely, only on our instructions, and in accordance with data protection law. We ensure appropriate contractual safeguards are in place where required.
We may also disclose information if required by law, court order, police request, or other lawful authority, or where disclosure is necessary to protect rights, property, or safety.
5. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Retention periods may vary depending on the type of data and the reason for keeping it.
- Customer service records may be retained for the duration of the relationship and a reasonable period afterwards.
- Financial and tax records are typically retained for the period required by law.
- Enquiry records may be kept for a shorter period if no service is booked.
- Security or complaint records may be kept longer where needed to resolve issues or defend legal claims.
When data is no longer needed, we will delete it securely or anonymise it so it can no longer identify you. Retention is reviewed periodically to make sure we do not keep information for longer than necessary.
6. Data Security
We take appropriate technical and organisational measures to protect personal data from loss, misuse, unauthorised access, alteration, or disclosure. These measures are designed to be proportionate to the nature of the information we hold and the risks involved.
Examples of safeguards may include access controls, secure storage, password protection, staff confidentiality expectations, and limited access to records on a need-to-know basis. While no system can be guaranteed completely secure, we work to reduce risk and respond appropriately to any suspected incident.
7. Your Rights Under Data Protection Law
You have a number of rights in relation to your personal data. These rights may apply in different circumstances and are subject to legal conditions and exemptions.
- Right of access – you can ask for a copy of the personal data we hold about you.
- Right to rectification – you can ask us to correct inaccurate or incomplete information.
- Right to erasure – in some cases, you can request that we delete your data.
- Right to restriction – you can ask us to limit how we use your data in certain situations.
- Right to object – you can object to processing based on legitimate interests or direct marketing.
- Right to data portability – you may request your data in a usable format where applicable.
- Right to withdraw consent – if processing is based on consent, you may withdraw it at any time.
You also have the right to raise concerns about how your data is handled. If you are unhappy with the way your data has been processed, you may contact the relevant data protection authority. In the UK, this is the Information Commissioner’s Office (ICO).
8. Automated Decision-Making
We do not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects on individuals. If this changes in the future, we will update this policy and provide the necessary information and safeguards.
9. Third-Party Services and Links
Where we use third-party tools or services, those providers may process data according to their own privacy terms and lawful bases. We expect them to maintain appropriate standards of security and confidentiality. If you interact with third-party services independently, their own policies will apply. We are not responsible for the privacy practices of external sites or providers outside our control.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, business practices, or service arrangements. Any revised version will apply from the date it is published or otherwise communicated. We encourage you to review the policy periodically so that you remain informed about how your data is handled.
11. Summary of Key Principles
In summary, Gardeners Covent Garden will:
- collect only the data needed to provide and manage services;
- process data under a valid lawful basis;
- share data only where necessary and with appropriate safeguards;
- retain information only for as long as needed;
- respect your rights under data protection law;
- protect your information using reasonable security measures.
This Privacy Policy is intended to provide a clear explanation of our data protection practices for all customers in Covent Garden and the surrounding area. If you continue to use our services, your information will be handled in accordance with this policy and applicable law.