Privacy Policy - Gardeners Eden Park
Gardeners Eden Park is committed to protecting the privacy of all customers in the area we serve. This Privacy Policy explains how we collect, use, store, share, and protect personal data when we provide our gardening and related services. It also explains your rights under applicable data protection law, including the UK GDPR and the Data Protection Act 2018.
This policy applies to all Gardeners Eden Park customers in the area, including prospective customers, current customers, and anyone who has previously enquired about our services. By engaging with us, requesting a quote, making a booking, or receiving services, you acknowledge that your personal information will be handled in accordance with this policy.
1. Personal Data We Collect
We collect only the information needed to deliver services safely, efficiently, and professionally. The types of personal data we may collect include:
- Identity details such as your name, title, and any business name you use when booking services.
- Contact details such as address, email address, and telephone number.
- Service information such as property access notes, service preferences, garden instructions, and appointment history.
- Payment and billing information where relevant to invoices, receipts, or payment processing.
- Communication records including emails, messages, notes from phone calls, and feedback.
- Technical data if you interact with our digital systems, such as limited device or usage information.
- Security and access information such as gate codes or entry instructions, where necessary and provided by you.
We do not collect more information than necessary. Where possible, we keep personal data limited and relevant to the work we provide. If you choose not to provide information that is required for service delivery, we may be unable to complete your request.
2. How We Use Your Data
We use personal data for clear and legitimate purposes connected to our services. These purposes include:
- responding to enquiries and providing quotations;
- managing customer bookings and scheduling visits;
- delivering gardening services and related support;
- issuing invoices, processing payments, and maintaining financial records;
- recording service preferences and site-specific instructions;
- communicating updates, changes, or important service information;
- handling complaints, follow-up requests, and service quality matters;
- meeting legal, tax, accounting, and insurance obligations;
- protecting our business, staff, and customers from fraud or misuse.
We may also use data to improve our operations, but only in ways that are compatible with the purposes for which the data was originally collected. Where data is used for internal analysis, it will be handled carefully and in a manner that respects privacy.
3. Lawful Basis for Processing
Under data protection law, we must have a lawful basis to process your personal data. Gardeners Eden Park relies on the following lawful bases depending on the context:
Contract
Processing is necessary for the performance of a contract or to take steps at your request before entering into a contract. This applies when we provide quotations, arrange bookings, carry out gardening services, issue invoices, or manage customer accounts.
Legal obligation
We process certain data because we are required to comply with legal obligations, including tax, accounting, record-keeping, and other regulatory requirements.
Legitimate interests
We may process information where it is necessary for our legitimate business interests and where those interests are not overridden by your rights and freedoms. Examples include maintaining service records, improving customer experience, preventing fraud, and managing business administration.
Consent
In limited situations, we may rely on your consent. If we do, you have the right to withdraw that consent at any time. Withdrawing consent will not affect the lawfulness of processing carried out before withdrawal.
Where special category data is involved, we only process it when permitted by law and when necessary for a specific and valid purpose. We avoid collecting such data unless it is genuinely required.
4. Retention of Personal Data
We keep personal data only for as long as necessary to fulfil the purpose for which it was collected, and to meet legal, accounting, or reporting obligations. Retention periods depend on the type of information and the reason for holding it.
- Customer and service records are normally retained for the duration of the service relationship and for a reasonable period afterwards.
- Financial records are generally retained for the period required by tax and accounting law.
- Communication records may be retained for as long as needed to manage queries, disputes, or service history.
- Safety or access notes are kept only while relevant to ongoing service delivery and are reviewed regularly.
When personal data is no longer needed, we securely delete, anonymise, or destroy it. We review records periodically to ensure we are not retaining information for longer than necessary. Retention is based on necessity, not convenience.
5. Data Sharing and Processors
We do not sell personal data. We only share it where necessary and proportionate for the purposes described in this policy. In some cases, we use trusted third-party service providers, known as processors, who act on our instructions and are required to protect your data.
Examples of processors may include:
- Payment processors for secure transaction handling;
- Accounting or bookkeeping providers for invoice and financial record management;
- IT and cloud storage providers for secure data hosting and backup;
- Communication service providers for sending messages and handling customer correspondence;
- Administrative software providers used for scheduling or record management.
We may also disclose personal data where required by law, court order, regulatory request, or to prevent serious harm or unlawful activity. If service partners or subcontractors are involved in delivering work, they may receive only the minimum information needed to complete the task safely and effectively.
Whenever we use processors, we seek to ensure appropriate contractual safeguards, confidentiality, and security measures are in place. All processors are expected to handle data only in accordance with our instructions and applicable law.
6. Data Security
We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration, or disclosure. These measures may include access controls, secure storage, password protection, limited staff access, and careful handling of paper and electronic records.
Although no system can be guaranteed completely secure, we work to reduce risk and respond promptly to any suspected data incident. If a personal data breach occurs and it is necessary to do so, we will act in accordance with legal reporting requirements.
7. Your Rights
You have important rights over your personal data. Depending on the circumstances, these may include:
- Right to be informed about how your data is collected and used;
- Right of access to request a copy of the personal data we hold about you;
- Right to rectification to correct inaccurate or incomplete information;
- Right to erasure in certain situations, sometimes called the right to be forgotten;
- Right to restrict processing in certain cases;
- Right to data portability for data processed by automated means where applicable;
- Right to object to processing based on legitimate interests or direct marketing;
- Rights relating to automated decision-making, where relevant.
If you have given consent for any processing, you may withdraw it at any time. You also have the right to raise concerns with a supervisory authority if you believe your data protection rights have not been respected.
We aim to respond to rights requests within the timeframes required by law. In some cases, we may need to verify your identity before acting on your request to protect your privacy.
8. Children’s Data
Our services are not directed at children, and we do not knowingly collect personal data from children except where it is necessary in a family or household context and provided by a responsible adult. If we become aware that data has been collected inappropriately, we will take steps to delete it where required.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, our services, or the way we process personal data. Any updated version will apply from the date it takes effect. We encourage customers to review this policy periodically so they remain informed about how their information is handled.
10. Summary of Our Commitment
Gardeners Eden Park handles personal data with care, fairness, and transparency. We collect only what we need, use it for legitimate purposes, keep it only as long as necessary, and protect it with appropriate safeguards. We also respect your rights and aim to make privacy practices clear and accountable. If you are a customer in the area, this policy applies to you whenever we collect or use your personal information.