Privacy Policy - Gardeners Chase Cross
Gardeners Chase Cross is committed to protecting the privacy and personal data of all customers in the Chase Cross area. This Privacy Policy explains how we collect, use, store, share, and protect personal information in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It applies to all Gardeners Chase Cross customers in the area, including prospective customers, current customers, and anyone who interacts with our services in connection with garden maintenance, landscaping, planting, lawn care, hedge trimming, seasonal tidy-ups, and related services.
We aim to keep this policy clear, transparent, and easy to understand. By using our services or providing us with your information, you acknowledge that your personal data may be processed as described below. This policy is designed to explain what information is collected, why it is collected, how long it is kept, who may process it on our behalf, and what rights you have over it.
1. Information We Collect
We collect only the information needed to provide our services effectively, manage our business, and meet legal obligations. The types of personal data we may collect include:
- Identity details such as your name and any preferred title.
- Contact details such as your address, telephone number, and email address.
- Service details such as the type of gardening service requested, job instructions, property access notes, and service preferences.
- Billing and payment information such as payment status, invoice records, and transaction references.
- Communication records including messages, call notes, and correspondence about quotes, bookings, or service updates.
- Site and property information relevant to carrying out the work safely and accurately, such as garden size, access conditions, or scheduling requirements.
We may also collect limited technical information when you contact us through digital means, such as device identifiers or basic usage data if it is necessary for security or service delivery. We do not intentionally collect special category data unless it is required and lawful to do so. If any such data is ever needed, we will only process it with appropriate safeguards and a valid legal basis.
2. How We Use Personal Data
We use personal data for specific and legitimate purposes connected to our services. These include:
- Providing quotations, arranging appointments, and delivering gardening services.
- Managing customer accounts and service records.
- Communicating about bookings, service changes, or follow-up information.
- Processing payments, invoices, and financial administration.
- Maintaining operational records for quality, safety, and business management.
- Meeting legal, tax, accounting, and regulatory requirements.
- Handling complaints, disputes, or service queries.
We only use your information in ways that are compatible with the purposes for which it was collected. Where necessary, we may also use data to improve our services, monitor customer satisfaction, or prevent fraud and misuse. Any such use will be limited and proportionate.
3. Lawful Basis for Processing
Under data protection law, we must have a lawful basis for processing your personal data. Gardeners Chase Cross relies on the following bases depending on the nature of the activity:
Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes preparing quotations, confirming bookings, carrying out garden services, and handling payment-related administration.
Legal obligation
We may process data where required to comply with legal duties such as tax recordkeeping, accounting obligations, insurance matters, or responding to lawful requests from authorities.
Legitimate interests
We may process personal data where it is reasonably necessary for our legitimate business interests, provided those interests do not override your rights and freedoms. This may include maintaining service records, improving customer service, managing scheduling, ensuring security, and resolving disputes.
Consent
Where required by law, we will seek your consent before processing personal data. If consent is used as the basis for processing, you may withdraw it at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before it was withdrawn.
We carefully assess the lawful basis for each processing activity and only use personal data in ways permitted by law.
4. Sharing Your Data and Processors
We do not sell personal data. However, we may share information with trusted third parties who act as processors or service providers on our behalf. These parties are only permitted to use personal data according to our instructions and for defined purposes.
Examples of processors may include:
- Payment processors who handle card or electronic payment transactions.
- Accounting or bookkeeping providers who support invoicing and financial records.
- IT and data storage providers who help secure and maintain business systems.
- Scheduling or communications tools that assist with appointment management and customer correspondence.
- Professional advisers such as insurers, auditors, or legal advisers where necessary.
In all cases, we aim to ensure that appropriate data processing agreements are in place and that processors provide suitable security and confidentiality safeguards. We may also disclose personal information if required by law, court order, regulatory duty, or to protect our legal rights and the safety of our business, staff, customers, or the public.
5. Data Retention
We keep personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law. Retention periods are based on several factors, including the type of data, the reason it was collected, legal obligations, and whether the information may be needed for recordkeeping or dispute resolution.
Typical retention practices may include:
- Customer service and booking records retained for a reasonable period after the last interaction.
- Invoice and accounting records kept for the time required by tax and financial laws.
- Correspondence and complaints retained long enough to resolve issues and demonstrate compliance.
- Technical or security logs kept only for a limited period unless needed for investigation.
When data is no longer required, we will take appropriate steps to delete, anonymise, or securely destroy it. We do not retain personal data indefinitely.
6. Your Data Protection Rights
As a customer or individual whose data we process, you may have the following rights under data protection law:
- Right of access – to request a copy of the personal data we hold about you.
- Right to rectification – to ask us to correct inaccurate or incomplete information.
- Right to erasure – to request deletion of your data in certain circumstances.
- Right to restrict processing – to ask us to limit how we use your information in certain situations.
- Right to object – to object to processing based on legitimate interests or direct marketing where applicable.
- Right to data portability – to request transfer of certain data to you or another organisation.
- Right to withdraw consent – where consent is the lawful basis, you may withdraw it at any time.
These rights are not absolute and may be subject to conditions or exceptions under the law. If you exercise any of these rights, we may need to verify your identity before responding. We will aim to respond within the timeframes required by law.
7. Data Security
We take data security seriously and use appropriate technical and organisational measures to protect personal information from unauthorised access, loss, misuse, alteration, or disclosure. These measures may include restricted access controls, secure storage, password protection, staff confidentiality obligations, and careful management of paper and electronic records.
While we do our best to safeguard information, no system can be completely secure. We therefore encourage customers to share only the information necessary for service provision and to notify us promptly if they believe any data may have been compromised.
8. Children’s Data
Our services are intended for adult customers and property-related service arrangements. We do not knowingly collect personal data from children for marketing or service management purposes. If we become aware that we have collected a child’s personal data without a valid legal basis, we will take steps to delete it where appropriate.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. Any updates will apply from the date of publication unless stated otherwise. We encourage customers to review this policy periodically so they remain informed about how personal data is handled.
10. Scope of This Policy
This Privacy Policy applies to all Gardeners Chase Cross customers in the area, including individuals who request quotes, arrange work, receive services, or communicate with us in relation to gardening and outdoor maintenance. By engaging with our services, you acknowledge that your personal data may be processed in accordance with this policy and applicable data protection law.
In summary, Gardeners Chase Cross processes personal data lawfully, fairly, and transparently. We collect only what is necessary, keep it secure, share it only with appropriate processors, retain it for limited periods, and respect your rights as a data subject. Our approach is designed to ensure that privacy remains an integral part of the service we provide.