Privacy Policy - Gardeners Spitalfields
Gardeners Spitalfields is committed to protecting the privacy and personal data of all customers in the Spitalfields area. This Privacy Policy explains how we collect, use, store, share, and safeguard personal information in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It applies to all Gardeners Spitalfields customers in the area, including individuals who enquire about, book, receive, or manage gardening services with us.
We aim to be transparent about the information we handle and to ensure that any processing of personal data is lawful, fair, and limited to what is necessary. By using our services, you acknowledge that your data may be processed in accordance with this policy.
1. Data We Collect
We may collect and process the following categories of personal data:
- Identity information: name, title, and any relevant business or household contact details.
- Contact information: address, email address, telephone number, and preferred communication method.
- Service information: details about the gardening services requested, property access notes, appointment history, and job instructions.
- Payment information: billing details and payment records, where needed to manage invoices and transactions.
- Communication records: correspondence by phone, email, message, or written notes relating to enquiries, bookings, complaints, feedback, or service updates.
- Technical data: limited data such as device or browser information if you interact with our digital systems or forms.
- Special category data: only in exceptional circumstances, and only where necessary, for example if a customer voluntarily provides health-related access needs or safety information relevant to service delivery.
We only collect personal data that is relevant to providing our services, handling administration, or meeting legal obligations. We do not seek unnecessary personal details.
2. How We Use Personal Data
Gardeners Spitalfields uses personal data for the following purposes:
- to respond to enquiries and provide quotations;
- to arrange and deliver gardening services;
- to manage bookings, schedules, and service notes;
- to send invoices, process payments, and maintain financial records;
- to communicate with customers about appointments, changes, or service issues;
- to maintain internal records and improve service quality;
- to comply with tax, accounting, insurance, and legal requirements;
- to resolve disputes, complaints, or claims;
- to protect our business, staff, customers, and property;
- to prevent fraud and misuse of our services.
We do not use personal data for automated decision-making that produces legal or similarly significant effects on customers.
3. Lawful Basis for Processing
Under data protection law, we must have a lawful basis for each type of processing. Gardeners Spitalfields may rely on one or more of the following:
Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes taking bookings, delivering services, issuing invoices, and managing service-related communication.
Legal Obligation
We may process and retain certain records where needed to meet legal obligations, including tax, accounting, and record-keeping requirements.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests and where those interests are not overridden by your rights and freedoms. This may include managing customer relationships, improving our services, maintaining security, and defending legal claims.
Consent
In limited cases, we may ask for your consent, for example where you voluntarily provide optional information that is not required to deliver the service. Where consent is used, you may withdraw it at any time.
Vital Interests
In rare situations, we may process personal data to protect someone’s vital interests, such as urgent safety-related information during an emergency.
4. Sharing Personal Data and Processors
We may share personal data with trusted third parties where necessary to run our business and provide services. These third parties act as processors when they process data on our behalf and under our instructions.
Examples of processors may include:
- IT and hosting providers that store records or support our communication systems;
- payment service providers that process transactions securely;
- accounting or bookkeeping providers that help maintain financial records;
- administrative service providers that support scheduling, invoicing, or record management;
- professional advisers such as insurers, auditors, or legal advisers, where necessary;
- subcontractors or team members engaged to deliver services on our behalf.
All processors are required to handle personal data securely, lawfully, and only for the agreed purpose. Where a third party acts as an independent controller, they are responsible for their own privacy practices.
We may also disclose personal data where required by law, court order, government authority, or to protect rights, safety, or property. We do not sell personal data.
5. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, and in accordance with legal, tax, accounting, and business requirements.
- Customer service records are typically retained for the period needed to manage the relationship and address any follow-up matters.
- Invoices and financial records may be retained for the legally required period for tax and accounting purposes.
- Correspondence and complaints may be retained for a reasonable period to evidence communications and resolve disputes.
- Marketing consent records are retained only while needed to demonstrate consent status or until consent is withdrawn.
When data is no longer required, we will securely delete, anonymise, or archive it where appropriate. Retention periods may vary depending on the nature of the record and applicable legal obligations.
6. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and restricted use of personal information.
While we take data security seriously, no system can be guaranteed to be completely secure. If a data breach occurs and is likely to result in a high risk to your rights and freedoms, we will take appropriate steps in accordance with data protection law.
7. Your Rights
Under UK GDPR, you have a number of rights in relation to your personal data. These may include:
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to ask us to correct inaccurate or incomplete information.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to ask us to limit how we use your data in certain situations.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to data portability: to receive certain data in a structured, commonly used format where applicable.
- Right to withdraw consent: where we rely on consent, you may withdraw it at any time.
These rights are not absolute and may be subject to legal exceptions. If you exercise a right, we may need to verify your identity before responding.
8. International Transfers
If any processor or service provider stores or accesses data outside the UK, we will ensure that appropriate safeguards are in place, such as adequacy regulations or approved contractual protections, to keep your data protected.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, operational needs, or service practices. Any updated version will apply from the date it is issued. We encourage customers to review this policy periodically so they remain informed about how their data is handled.
10. Scope of This Policy
This Privacy Policy applies to all Gardeners Spitalfields customers in the area, including existing customers, new enquiries, and anyone who receives or requests our gardening services. By engaging with us, you confirm that you understand how your personal data may be collected and used for the purposes described above.
Gardeners Spitalfields is dedicated to handling personal information with care, accountability, and respect. We believe that good privacy practice supports trust and helps ensure a professional service experience for every customer.