Privacy Policy - Gardeners Thornton Heath

Gardeners Thornton Heath is committed to protecting the privacy and personal data of every customer and prospective customer in the Thornton Heath area. This Privacy Policy explains how we collect, use, share, store, and protect personal information in accordance with the UK GDPR and the Data Protection Act 2018. It applies to all Gardeners Thornton Heath customers in the area, including anyone who makes an enquiry, requests a quotation, books a service, or otherwise interacts with us.

We aim to be transparent, fair, and careful with the information we handle. This policy is designed to help you understand what information we process, why we process it, how long we keep it, and what rights you have over it.

1. Information We Collect

We only collect personal data that is necessary to provide and manage our gardening services, respond to enquiries, and meet legal or operational obligations. Depending on how you interact with us, we may collect the following categories of data:

  • Identity details such as your name.
  • Contact details such as your address, email address, and telephone number.
  • Service information including details about your property, garden requirements, preferred service dates, and instructions relevant to the work.
  • Payment and billing information where necessary to process invoices or payments.
  • Communication records such as emails, messages, notes from calls, and service-related correspondence.
  • Technical information that may be collected when you visit a digital service we use, such as IP address, browser type, or usage data, if applicable.
  • Marketing preferences where you have chosen to receive updates or information from us.

We do not intentionally collect special category data unless it is strictly necessary and you have provided it voluntarily, or we are required to handle it for a lawful reason. We encourage you not to share sensitive information unless it is relevant to the service.

2. How We Use Your Personal Data

We process personal information only where there is a valid lawful basis under the UK GDPR. The purposes for which we may use your data include:

  • responding to enquiries and providing quotations;
  • managing bookings, site visits, and gardening services;
  • issuing invoices, processing payments, and maintaining business records;
  • communicating important service updates or changes;
  • handling complaints, disputes, or service follow-up;
  • maintaining internal records and service quality;
  • meeting tax, accounting, insurance, and legal obligations;
  • sending marketing communications where lawful and appropriate.

Gardeners Thornton Heath will never use your data in a way that is incompatible with the reasons it was collected. If we need to use your information for a new purpose, we will make sure that purpose is permitted by law and, where required, we will seek your consent.

3. Lawful Basis for Processing

Under the UK GDPR, we rely on one or more lawful bases to process personal data. These include:

Contract

We process your data when it is necessary to enter into or perform a contract with you. For example, we need your contact details and service instructions to provide gardening services and manage your appointment.

Legal Obligation

We may be required to retain and use certain information to comply with tax, accounting, and other legal requirements.

Legitimate Interests

We may process some information because it is in our legitimate business interests, provided those interests do not override your rights and freedoms. Examples include improving customer service, maintaining records, preventing fraud, and managing business operations.

Consent

Where required, we rely on your consent, especially for certain types of electronic marketing. You may withdraw consent at any time, and doing so will not affect the lawfulness of processing carried out before withdrawal.

Vital Interests and Public Task

These bases are unlikely to apply in ordinary service provision, but if a rare situation requires them, we will only process information where legally permitted.

4. Sharing Your Information with Processors

We may share personal data with trusted third parties who act as data processors on our behalf. These processors only handle data under our instructions and are required to protect it appropriately. Examples may include:

  • payment processing providers;
  • accounting or bookkeeping services;
  • IT, cloud storage, and software providers;
  • customer administration tools;
  • professional advisers such as accountants or insurers;
  • service partners who help us deliver work, if necessary.

We may also disclose information where required by law, regulation, court order, or to protect our legal rights. If a processor or service provider is used, we take reasonable steps to ensure that appropriate contractual and security measures are in place.

We do not sell your personal data. We also do not share it for unrelated third-party marketing without a lawful basis.

5. Retention of Personal Data

We keep personal data only for as long as necessary for the purpose for which it was collected, and to meet legal, accounting, or reporting requirements. Retention periods may vary depending on the nature of the information and the reason we hold it.

  • Enquiry records may be kept for a reasonable period in case you decide to proceed later or to help us manage follow-up communications.
  • Service and invoicing records are typically retained for the period required by tax and accounting law.
  • Correspondence and complaints may be retained to evidence what happened and how issues were resolved.
  • Marketing preferences are retained until you opt out or your details are no longer needed.

When data is no longer needed, we will securely delete, anonymise, or archive it in line with our retention practices. We review retention regularly to avoid keeping information longer than necessary.

6. Data Security

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, secure storage, staff awareness, and limited data sharing.

Although no system can be guaranteed completely secure, we take data protection seriously and aim to maintain a high standard of care when handling all personal information.

7. Your Rights Under GDPR

You have a number of rights regarding the personal data we hold about you. These rights may apply depending on the circumstances and the legal basis for processing. They include:

  • Right of access – you can ask for a copy of the personal data we hold about you.
  • Right to rectification – you can ask us to correct inaccurate or incomplete information.
  • Right to erasure – in some cases, you can request deletion of your data.
  • Right to restriction – you can ask us to limit how we use your data in certain situations.
  • Right to object – you can object to processing based on legitimate interests or direct marketing.
  • Right to data portability – you may request a copy of certain data in a structured format.
  • Right to withdraw consent – where processing is based on consent, you can withdraw it at any time.

If you wish to exercise any of these rights, we will respond in accordance with GDPR requirements and may need to verify your identity before acting on the request. In some situations, legal exceptions may apply.

8. Cookies and Similar Technologies

If we use digital tools that place cookies or similar technologies, these may be used to support site functionality, analyse usage, or improve user experience. Where required, we will seek consent before using non-essential cookies. You can manage cookie settings through your browser or device preferences.

9. International Transfers

Where personal data is transferred outside the UK, we will ensure appropriate safeguards are in place to protect it, such as approved contractual protections or other lawful transfer mechanisms. We only permit transfers where the level of protection is adequate and compliant with applicable data protection law.

10. Children’s Data

Our services are intended for adults and property-related customers. We do not knowingly collect personal data from children except where it is incidental and necessary for legitimate service-related purposes. If we become aware that we have collected information improperly, we will take appropriate steps to delete or secure it.

11. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in the law, our services, or our data handling practices. When we do so, the updated version will apply from the date of publication or implementation. We encourage you to review this policy periodically so you remain informed about how your information is used.

12. How This Policy Applies

This Privacy Policy applies to all customers, prospective customers, and service users of Gardeners Thornton Heath in the Thornton Heath area. By engaging with our services, you acknowledge that personal data may be processed as described in this policy and in accordance with applicable data protection law.

Gardeners Thornton Heath remains committed to handling personal information respectfully, securely, and lawfully. We believe privacy is an essential part of providing a professional and trustworthy service, and we will continue to apply best practices to safeguard the data you share with us.

Gardeners Thornton Heath

Gardeners Thornton Heath is committed to protecting the privacy and personal data of every customer and prospective customer in the Thornton Heath area.

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.