Privacy Policy - Gardeners Deptford
This Privacy Policy explains how Gardeners Deptford collects, uses, stores, shares, and protects personal data belonging to all customers in the Deptford area. It applies to every customer who uses our gardening services in this area, whether they contact us for a one-time job, a recurring maintenance visit, a quotation, or any related service. We are committed to handling personal information in a lawful, fair, and transparent way, in line with the UK GDPR and the Data Protection Act 2018.
We believe privacy should be clear and easy to understand. This policy sets out what data we collect, why we collect it, the lawful basis we rely on, how long we keep data, which processors may handle information on our behalf, and the rights available to you as a data subject. By using our services, you acknowledge that your personal information will be handled in accordance with this policy.
1. Data We Collect
We only collect information that is necessary for providing our services, managing bookings, maintaining records, and meeting legal obligations. The categories of data we may collect include:
- Identity information such as your name and, where relevant, business name.
- Contact information such as your telephone number, email address, and property address within the Deptford area.
- Service information including details of the gardening work requested, service preferences, access instructions, appointment history, and notes relating to completed work.
- Billing and payment details such as invoice records, payment status, and transaction references.
- Communication records including messages, quotations, complaints, feedback, and other correspondence.
- Technical data if you interact with our digital systems, such as basic device or usage information used for security and service performance.
We do not intentionally collect special category data unless it is strictly necessary and you choose to provide it. For example, a customer might mention access needs or health-related information to help us carry out services safely. In such cases, we will only use that information where appropriate safeguards are in place and where the law allows us to do so.
2. How We Use Personal Data
Gardeners Deptford uses personal data only for legitimate service-related purposes. These include:
- providing quotes and arranging appointments;
- delivering gardening services and managing customer instructions;
- communicating about bookings, changes, and service updates;
- issuing invoices and handling payments;
- responding to queries, complaints, and customer support requests;
- maintaining business records and service history;
- protecting against fraud, misuse, and security risks;
- meeting legal, tax, insurance, and accounting obligations.
We may also use aggregated or anonymised information to review service quality and improve operational efficiency. Where information has been properly anonymised, it is no longer personal data.
3. Lawful Basis for Processing
Under GDPR, we must have a lawful basis before processing your personal data. Depending on the context, Gardeners Deptford may rely on the following bases:
Contract
We process your data when it is necessary to enter into or perform a contract with you. This includes taking bookings, preparing quotations, providing gardening services, and managing payments.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided your rights and freedoms do not override those interests. Examples include keeping service records, improving customer experience, preventing fraud, and ensuring security. We carefully consider any impact on privacy before relying on this basis.
Legal Obligation
We may process and retain certain information to comply with legal requirements such as tax laws, accounting rules, insurance obligations, and record-keeping duties.
Consent
In limited cases, we may rely on your consent, especially where the law requires it. If consent is used, you may withdraw it at any time. Withdrawing consent will not affect the lawfulness of processing carried out before the withdrawal.
Important: we do not sell personal data, and we do not use it for unrelated purposes without a valid legal basis.
4. Data Sharing and Processors
We may share personal data with trusted third parties that help us operate our business. These organisations act as processors or, in some cases, separate controllers. We only share the minimum information necessary and require appropriate protections.
Examples of processors may include:
- booking and scheduling providers used to manage appointments;
- accounting or invoicing software providers used for financial administration;
- payment service providers used to process transactions securely;
- IT support and cloud storage providers used for data hosting and backup;
- professional advisers such as accountants, insurers, or legal advisers where necessary.
All processors are expected to handle data securely, follow our instructions, and process information only for authorised purposes. Where data is transferred outside the UK, we will ensure suitable safeguards are in place, such as approved contractual protections or adequacy decisions, as required by law.
We may also disclose personal data if required by law, court order, regulatory request, or to protect our rights, property, staff, customers, or the public.
5. Data Retention
We keep personal data only for as long as necessary to fulfil the purposes described in this policy. Retention periods depend on the type of record and the reason it is held.
- Customer service records are generally kept for the duration of the relationship and for a reasonable period afterwards to manage follow-up queries or service history.
- Financial and invoice records are retained for the period required by tax and accounting law.
- Communication records may be kept for as long as needed to resolve disputes, improve service, or maintain evidence of instructions.
- Security and system logs are retained only for a short period unless an issue requires longer investigation.
When personal data is no longer needed, we will delete it securely or anonymise it so that it can no longer identify you. In some cases, we may retain information for a longer period if necessary for legal claims, regulatory duties, or insurance matters.
6. Data Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or alteration. These measures may include secure storage, controlled access, password protection, staff confidentiality obligations, and regular review of our systems and procedures.
Although no system can be guaranteed to be completely secure, we work to minimise risk and respond promptly if a security incident occurs. Where legally required, we will notify affected individuals and relevant authorities.
7. Your Rights Under GDPR
As a customer of Gardeners Deptford in the Deptford area, you have a number of rights regarding your personal data. These rights may be exercised subject to certain legal conditions and exceptions.
- Right of access - you may request a copy of the personal data we hold about you.
- Right to rectification - you may ask us to correct inaccurate or incomplete information.
- Right to erasure - you may request deletion of your data where there is no lawful reason to continue holding it.
- Right to restriction - you may ask us to limit how we use your data in certain situations.
- Right to object - you may object to processing based on legitimate interests, including direct marketing where applicable.
- Right to data portability - you may request certain information in a structured, commonly used format where the law allows.
- Right to withdraw consent - where we rely on consent, you may withdraw it at any time.
If you believe your rights have not been respected, you also have the right to raise a concern with the UK Information Commissioner's Office. We encourage customers to contact us first so we can try to resolve any issue fairly and quickly.
8. Children’s Data
Our services are intended for adult customers and property owners or authorised representatives. We do not knowingly collect personal data from children unless it is necessary for a specific service request and handled appropriately in line with the law.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the law, our services, or our data handling practices. When changes are made, the revised version will apply to all Gardeners Deptford customers in the area from the date it takes effect. We encourage customers to review this policy periodically to stay informed about how we protect personal data.
In summary: Gardeners Deptford collects only the data needed to provide gardening services, relies on lawful bases such as contract, legitimate interests, consent, and legal obligation, retains data for appropriate periods, works with carefully selected processors, and respects your GDPR rights. We are committed to privacy, security, and responsible data handling for every customer in the Deptford area.