Privacy Policy - Gardeners Beddington
Gardeners Beddington is committed to protecting the privacy and personal data of all customers and prospective customers in the Beddington area. This Privacy Policy explains how we collect, use, store, share, and protect personal information when we provide gardening and related services. It applies to all Gardeners Beddington customers in the area, including individuals who enquire about services, request quotations, book appointments, or otherwise interact with us.
1. Who this policy applies to
This policy applies to anyone whose personal data we process in connection with our gardening services in Beddington and surrounding local areas. This includes residential and commercial customers, property managers, tenants arranging work, and people who communicate with us on behalf of another person or organisation. It also applies to people who receive service updates, invoices, or administrative messages from us.
2. Information we collect
We collect only the information needed to provide our services effectively and lawfully. Depending on the type of work requested, we may collect the following categories of personal data:
- Identity details: name and, where relevant, business or property name.
- Contact details: address, email address, telephone number, and preferred communication method.
- Service information: details about the gardening services requested, property access notes, work history, and preferences.
- Billing information: invoice details, payment status, and transaction records.
- Communication records: messages, call notes, complaint details, and feedback.
- Technical data: limited information such as IP address or device data if you interact with us through digital systems, where applicable.
We do not intentionally collect special category data unless it is strictly necessary and you choose to provide it, for example where an access arrangement or vulnerability note is relevant to service delivery. If such information is provided, it is handled with extra care and only for a specific and lawful purpose.
3. How we use personal data
We use personal data to manage enquiries, provide quotations, deliver gardening services, schedule visits, process payments, handle customer service matters, and maintain accurate business records. We may also use it to improve service quality, prevent fraud, and meet legal or regulatory obligations.
Examples of use
- confirming bookings and arranging appointments;
- carrying out agreed gardening work;
- issuing invoices and recording payments;
- responding to questions, complaints, or follow-up requests;
- maintaining internal records for quality control and business administration;
- protecting the security of our staff, customers, and systems.
We only process personal data for purposes that are compatible with the reason it was originally collected. We do not sell personal data.
4. Lawful basis for processing
Under GDPR, we must have a lawful basis for each processing activity. Gardeners Beddington relies on the following lawful bases, depending on the situation:
- Contract: where processing is necessary to provide a quote, arrange services, perform gardening work, or manage payments and service administration.
- Legitimate interests: where processing is necessary for our reasonable business operations, such as maintaining records, improving services, preventing misuse, and handling routine customer communication, provided these interests do not override your rights and freedoms.
- Legal obligation: where we are required to retain information or disclose it for tax, accounting, insurance, or other legal purposes.
- Consent: where we rely on your permission for a specific optional purpose. You can withdraw consent at any time, where applicable.
If we ever need to process special category data, we will only do so where another GDPR condition applies and, where required, we have your explicit consent or another appropriate lawful basis.
5. Data sharing and processors
We may share personal data with trusted third parties who assist us in operating our business. These service providers act as processors when they handle data on our behalf and under our instructions. We require appropriate safeguards and data protection terms from such providers.
Typical processor categories
- IT and hosting providers: for secure storage, email, and system administration.
- Accounting and invoicing providers: for financial administration and tax records.
- Payment processors: for handling card or electronic payments securely.
- Communication tools: for sending appointment confirmations or service updates.
- Professional advisers: such as accountants or legal advisers, where needed.
We may also disclose information to public authorities, insurers, or other third parties where required by law, to protect our legal rights, or to respond to a legitimate request. Any disclosure is limited to what is necessary and proportionate.
6. International transfers
Where a processor stores or accesses personal data outside the UK or EEA, we take steps to ensure appropriate safeguards are in place. This may include approved contractual protections or using providers with recognised transfer mechanisms. We aim to keep data within jurisdictions offering adequate protection wherever practical.
7. Data retention
We keep personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Retention periods vary depending on the type of record and the reason for keeping it.
- Customer service and booking records: retained for a period that supports administration, dispute handling, and continuity of service.
- Financial and tax records: retained for the legally required period.
- Communication records: retained as needed to manage enquiries, complaints, and service history.
- Consent-based records: retained until consent is withdrawn or the purpose ends.
When personal data is no longer needed, we will delete it securely or anonymise it so that it can no longer identify you. Retention is reviewed periodically to ensure data is not kept longer than necessary.
8. Data security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, secure storage, password protection, and limited access on a need-to-know basis. While no system can be guaranteed completely secure, we take reasonable steps to safeguard the information we hold.
9. Your rights under GDPR
Depending on the circumstances, you may have the following rights in relation to your personal data:
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to ask us to correct inaccurate or incomplete data.
- Right to erasure: to request deletion of data in certain situations.
- Right to restriction: to ask us to limit processing in certain circumstances.
- Right to object: to object to processing based on legitimate interests or direct marketing, where applicable.
- Right to data portability: to receive certain data in a structured, commonly used format, where applicable.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
These rights are not absolute and may be subject to legal exceptions. If you exercise a right, we will respond in accordance with GDPR requirements and applicable law.
10. Complaints and supervisory authority
If you are concerned about how we handle personal data, you should first raise the matter with us so that we can review and address it. You also have the right to lodge a complaint with the relevant data protection supervisory authority if you believe your data protection rights have been infringed.
11. Children’s data
Our services are not directed at children, and we do not knowingly collect personal data from children unless it is necessary in a family or household context and provided by an adult with authority to do so. If we learn that we have collected data inappropriately, we will take steps to delete it or otherwise handle it lawfully.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. Any revised version will apply from the date it is published or otherwise communicated. We encourage customers to review the policy periodically to stay informed.
Gardeners Beddington values privacy, transparency, and responsible data handling. By using our services, requesting information, or engaging with us in the Beddington area, you acknowledge that your personal data may be processed as described in this Privacy Policy. We will always aim to process personal data fairly, lawfully, and in a way that respects your rights.