Privacy Policy - Gardeners Isleworth
Effective for all Gardeners Isleworth customers in the area. This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when you use gardening services provided by Gardeners Isleworth. It is written to reflect the core requirements of the UK GDPR and the Data Protection Act 2018, and it applies to all customers, prospective customers, and anyone who communicates with us in relation to our services in the Isleworth area.
1. Who We Are
Gardeners Isleworth provides gardening and outdoor maintenance services to residential and commercial customers in the local area. For the purposes of data protection law, we act as the data controller for the personal information we collect and use in connection with our services. This means we decide why and how your personal data is processed, and we are responsible for ensuring that processing is lawful, fair, transparent, and secure.
2. Information We Collect
We only collect personal data that is necessary to manage our services, respond to enquiries, carry out work, and meet our legal obligations. The types of information we may collect include:
- Identity information, such as your name and title.
- Contact details, such as address, email address, and telephone number.
- Service details, including the type of gardening services requested, property access information, and job instructions.
- Billing and payment information, where required to process invoices and payments.
- Communication records, such as emails, messages, notes from phone calls, and service preferences.
- Technical data, such as limited device or usage information if you interact with our digital systems, where applicable.
- Photographs or site records, where needed to document work carried out, provided, or requested.
We do not intentionally collect special category data unless it is strictly necessary and you have provided it voluntarily or the law allows us to process it. If such information is ever shared with us, it will be handled with extra care and only for a clear and lawful purpose.
3. How We Use Your Data
We use personal data for the following purposes:
- To respond to enquiries and provide quotations.
- To arrange and deliver gardening services.
- To manage appointments, work schedules, and access to properties.
- To issue invoices, process payments, and maintain business records.
- To communicate about changes, updates, or issues relating to a service.
- To keep records of work completed and customer preferences.
- To handle complaints, disputes, or follow-up requests.
- To comply with legal, tax, insurance, and regulatory obligations.
- To improve the quality, safety, and efficiency of our services.
We will only use your personal data for the purpose for which it was collected, unless we reasonably believe another compatible purpose applies or the law requires otherwise.
4. Lawful Basis for Processing
Under UK GDPR, we must have a lawful basis before processing your personal data. Gardeners Isleworth may rely on one or more of the following lawful bases:
Contract
We process data when it is necessary to enter into or perform a contract with you. This includes preparing quotes, arranging services, carrying out agreed gardening work, and managing invoices or payments.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This can include maintaining records, improving service delivery, managing customer relations, preventing fraud, and ensuring security.
Legal Obligation
We may process personal data where required to comply with legal duties, including tax, accounting, health and safety, and insurance obligations.
Consent
In limited situations, we may rely on your consent, for example if you voluntarily provide information that is not required for a service. Where consent is used, you may withdraw it at any time.
Important: Where processing is based on legitimate interests, we assess the impact on your privacy and balance our interests against your rights. We do not use personal data in ways that would be unexpected or unfair.
5. Data Sharing and Processors
We do not sell your personal data. We may share it only where necessary and proportionate for business operations, legal compliance, or service delivery. Some trusted third parties may process data on our behalf as processors. These processors act only under our instructions and are required to protect your data.
Examples of processors may include:
- IT and hosting providers that support email, data storage, or system security.
- Payment service providers that process card or electronic payments.
- Accounting or bookkeeping services that assist with financial records and tax compliance.
- Scheduling or administration tools used to manage appointments and job records.
- Professional advisers, such as legal or insurance advisers, where necessary.
We may also disclose information to public authorities, regulators, law enforcement, or courts when required by law, or when it is necessary to protect our rights, property, staff, customers, or the public.
6. Data Retention
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Retention periods depend on the nature of the data and the reason it was collected.
- Customer and service records are typically retained for the duration of the business relationship and for a reasonable period afterwards.
- Financial and tax records are usually kept for the period required by law.
- Communication records may be kept for as long as needed to resolve queries, evidence work completed, or maintain service continuity.
- Photographs and site notes are retained only where they serve a valid business or legal purpose.
When personal data is no longer needed, it is securely deleted, anonymised, or disposed of in a controlled manner. We review retention regularly to ensure data is not kept longer than necessary.
7. Data Security
We use appropriate technical and organisational measures to protect personal data from unauthorised access, loss, misuse, alteration, or disclosure. These measures may include password protection, access controls, secure storage, staff awareness, and minimising the amount of data processed.
Although no system can be guaranteed to be completely secure, we take reasonable steps to safeguard the information entrusted to us. If a personal data breach occurs, we will assess the risk and take action in line with applicable legal requirements.
8. Your Rights
As a data subject under UK GDPR, you have several rights regarding your personal data. These rights do not always apply in every case, but we will respond to all valid requests in accordance with the law.
- Right of access – you may request a copy of the personal data we hold about you.
- Right to rectification – you may ask us to correct inaccurate or incomplete data.
- Right to erasure – you may request deletion of data in certain circumstances.
- Right to restriction – you may ask us to limit processing in certain situations.
- Right to object – you may object to processing based on legitimate interests or direct marketing, where applicable.
- Right to data portability – you may request certain data in a structured, commonly used format where the law allows.
- Right to withdraw consent – if processing is based on consent, you may withdraw it at any time.
You also have the right to raise a concern with the relevant supervisory authority if you believe your data has been handled unlawfully. We encourage you to contact us first so we can try to resolve the issue directly and fairly.
9. Children’s Data
Our services are aimed at adults and property owners, occupiers, landlords, tenants, and business clients. We do not knowingly collect personal data from children except where it is unavoidable in the course of providing a service, and then only with appropriate safeguards and lawful grounds.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data protection practices. Any revised version will apply from the date it becomes current. We encourage customers in the Isleworth area to review this policy periodically so they remain informed about how their information is handled.
11. Summary of Our Commitment
Gardeners Isleworth is committed to handling personal data responsibly, transparently, and in line with data protection law. We collect only the information needed to provide gardening services, use it for clear and lawful purposes, retain it for no longer than necessary, and protect it with appropriate safeguards. We also respect your rights and aim to make every data request straightforward and fair. This policy applies to all Gardeners Isleworth customers in the area.