Privacy Policy - Gardeners Lisson Grove
Last updated: This Privacy Policy explains how Gardeners Lisson Grove collects, uses, stores, shares, and protects personal data. It applies to all Gardeners Lisson Grove customers in the area, including individuals who enquire about, purchase, or receive gardening services from us.
We are committed to handling personal information in a lawful, fair, and transparent way in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy is designed to help you understand what data we collect, why we collect it, how long we keep it, who may process it on our behalf, and what rights you have over your personal information.
1. Who We Are
Gardeners Lisson Grove provides gardening and related outdoor maintenance services to customers in the local area. For the purposes of data protection law, we are the data controller of the personal data we collect from customers, suppliers, prospects, and website or service users where relevant.
We decide how and why your personal data is used, and we are responsible for ensuring that any processing is carried out in compliance with applicable data protection laws.
2. Personal Data We Collect
We only collect personal data that is necessary for operating our services, managing customer relationships, and meeting legal obligations. The type of information we may collect includes:
- Identity information: name, title, and any preferred form of address.
- Contact details: postal address, email address, and telephone number.
- Service information: details about the gardening services requested, service preferences, property access notes, and appointment history.
- Payment information: billing details, payment status, and transaction records. We do not store full card details unless a secure payment provider requires limited information for processing.
- Communication records: emails, call notes, messages, quotes, complaints, feedback, and correspondence relating to our services.
- Technical information: limited information such as device or browser details if collected through digital systems used to manage enquiries or bookings.
- Legal and compliance data: records needed for tax, accounting, insurance, or dispute resolution purposes.
We do not intentionally collect special category data unless it is necessary and lawful to do so. If such information is ever provided to us, for example where it is relevant to access arrangements or health-related concerns affecting service delivery, we will only process it where a valid condition under data protection law applies.
3. How We Use Personal Data
We use personal data for the following purposes:
- to respond to enquiries and provide quotations;
- to arrange, deliver, and manage gardening services;
- to communicate about appointments, changes, and service updates;
- to process invoices, payments, refunds, or credits;
- to maintain internal records and service history;
- to handle complaints, disputes, or insurance-related matters;
- to comply with legal, accounting, and regulatory requirements;
- to improve our services, customer experience, and operational efficiency;
- to protect against fraud, misuse, and unauthorized access.
We only use your data for purposes that are compatible with the reason it was collected. If we need to use it for a new purpose, we will make sure there is a lawful basis for doing so and, where required, inform you appropriately.
4. Lawful Basis for Processing
Under the UK GDPR, we must have a lawful basis for processing personal data. Gardeners Lisson Grove relies on the following lawful bases, depending on the situation:
Contract
We process your data where it is necessary to enter into or perform a contract with you. This includes arranging services, delivering work, sending invoices, and communicating about the service you have requested.
Legitimate Interests
We may process personal data where it is necessary for our legitimate business interests and where those interests are not overridden by your rights and freedoms. Examples include record-keeping, service administration, managing customer enquiries, improving our operations, and protecting our business from misuse or fraud.
Legal Obligation
We may process and retain personal data where required to comply with legal obligations, such as tax, accounting, insurance, and other regulatory responsibilities.
Consent
In limited cases, we may rely on your consent, for example for certain optional communications or where required for specific processing activities. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
Vital Interests
Although uncommon in our service, we may process personal data where necessary to protect someone’s vital interests, such as in an emergency.
5. Sharing Your Data and Processors
We do not sell your personal data. However, we may share it where necessary and lawful with trusted third parties who help us operate our business. These parties act as processors or independent controllers depending on the service they provide.
Processors may include:
- Accounting and bookkeeping providers who assist with invoices, tax records, and financial administration;
- IT and cloud service providers who host data, maintain systems, or provide secure storage and communication tools;
- Payment service providers who process card or electronic payments on our behalf;
- Customer management and scheduling providers who help us organise bookings and track service delivery;
- Professional advisers such as accountants, insurers, legal advisers, or auditors where necessary;
- Regulatory or public authorities where disclosure is required by law or is necessary to establish, exercise, or defend legal claims.
We only share the minimum amount of personal data required for the relevant purpose. Any processor we use must handle your information securely, act only on our instructions, and comply with applicable data protection requirements.
6. International Transfers
Where any service provider stores or accesses data outside the UK, we will take appropriate safeguards to protect your information. This may include the use of adequacy regulations, standard contractual clauses, or other approved transfer mechanisms.
7. Retention of Personal Data
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, reporting, or insurance requirements. Retention periods depend on the type of data and the reason for holding it.
- Customer and service records: retained for the duration of the customer relationship and for a reasonable period afterward to manage follow-up, disputes, and service history.
- Financial and tax records: retained for the period required by applicable law and accounting standards.
- Communication records: retained as needed to manage enquiries, complaints, and contractual matters.
- Legal claims or dispute records: retained for longer where necessary to defend or establish legal claims.
When data is no longer needed, we will delete it securely or anonymise it so it can no longer identify you.
8. Data Security
We use reasonable technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration, or disclosure. These measures may include access controls, secure storage, restricted permissions, and staff awareness procedures.
However, no system can be guaranteed to be completely secure. We therefore encourage you to take care when sharing information and to notify us promptly if you believe your data has been compromised.
9. Your Rights
You have a number of rights under data protection law in relation to your personal data. These include the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete information;
- erase your data in certain circumstances;
- restrict how we process your information in certain situations;
- object to processing based on legitimate interests or direct marketing;
- data portability where processing is based on consent or contract and carried out by automated means;
- withdraw consent at any time where we rely on consent;
- complain to the UK Information Commissioner’s Office if you believe your rights have been breached.
Some rights are subject to legal limits. For example, we may need to retain certain records to comply with tax or contractual obligations even where you request deletion.
10. Automated Decision-Making
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. If this changes, we will provide appropriate information about the logic involved and your rights.
11. Children’s Data
Our services are not directed at children. We do not knowingly collect personal data from children unless it is necessary in connection with a service arrangement and the information is provided by a parent, guardian, or authorised adult where appropriate.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. Any updates will take effect when published in the revised version. We encourage customers to review this policy periodically to stay informed.
13. Summary of Key Commitments
In summary, Gardeners Lisson Grove collects only the personal data needed to provide reliable gardening services, administer customer relationships, and comply with legal duties. We process information under lawful bases such as contract, legitimate interests, legal obligation, and, where relevant, consent. We keep data only as long as necessary, share it only with trusted processors or when legally required, and respect your rights over your personal information.
By using Gardeners Lisson Grove services in the area, you acknowledge that this Privacy Policy applies to your personal data. We aim to handle all information with care, transparency, and respect.