Privacy Policy - Gardeners Chessington
This Privacy Policy applies to all Gardeners Chessington customers in the area. It explains how personal data is collected, used, stored, shared, and protected when you enquire about, purchase, or receive gardening services from Gardeners Chessington. We are committed to handling personal information in a lawful, fair, and transparent manner in line with the UK GDPR and the Data Protection Act 2018.
By using our services, requesting a quotation, making an enquiry, or otherwise engaging with Gardeners Chessington, you acknowledge that your personal data may be processed for the purposes described in this policy. We only collect information that is necessary for delivering services, managing customer relationships, meeting legal obligations, and improving the quality of our work.
1. Information We Collect
We may collect and process the following categories of personal data:
- Identity details: your name and, where relevant, business name.
- Contact details: postal address, email address, and telephone number.
- Service information: details about the gardening services requested, site access notes, preferences, and job history.
- Communication records: correspondence between you and Gardeners Chessington, including enquiries, complaints, feedback, and service updates.
- Billing and payment records: invoice details, payment status, and transaction references where applicable.
- Technical data: limited information such as device or browser data if you interact with our digital systems.
- Special instructions or access notes: any information you choose to provide that helps us safely carry out our work.
We aim to collect only what is necessary and relevant. We do not intentionally collect excessive information. Where sensitive data is provided by you voluntarily, we process it only when a lawful basis exists and only to the extent needed.
2. How We Use Personal Data
Gardeners Chessington uses personal data for the following purposes:
- to respond to enquiries and provide quotations;
- to arrange and deliver gardening services;
- to manage bookings, scheduling, and site visits;
- to issue invoices and process payments;
- to keep accurate customer and service records;
- to handle complaints, queries, and aftercare;
- to meet legal, tax, insurance, and accounting obligations;
- to improve service quality, safety, and customer experience;
- to maintain internal administration and business operations.
We do not sell personal data. We also do not use customer information for unrelated purposes without notice or a lawful basis.
3. Lawful Basis for Processing
We process personal data only where permitted under data protection law. Depending on the situation, the lawful basis may include:
Contract
We process data where it is necessary to enter into or perform a contract with you, such as providing gardening services, preparing quotations at your request, managing appointments, and handling payment-related administration.
Legal Obligation
We may process and retain certain records to comply with legal duties, including accounting, tax, insurance, and record-keeping requirements.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided your rights do not override those interests. This may include maintaining service records, improving operations, preventing misuse, and managing customer communications. Where we rely on legitimate interests, we ensure that the processing is proportionate and relevant.
Consent
In limited situations, we may rely on your consent, for example where you provide optional information that is not required for service delivery. You may withdraw consent at any time where consent is the basis for processing.
Vital Interests
In rare circumstances, we may process personal data to protect someone’s vital interests, such as in an emergency affecting safety on site.
4. Retention of Personal Data
We retain personal data only for as long as necessary for the purposes for which it was collected, and to satisfy legal, accounting, or operational requirements. Retention periods may vary depending on the type of information and the reason for holding it.
- Customer and service records: kept for the period needed to manage the relationship and aftercare.
- Financial and invoice records: retained for the period required by law and standard accounting practice.
- Correspondence and complaints: retained long enough to resolve issues and maintain accurate business records.
- Technical or administrative data: kept only as long as necessary for operational purposes.
When personal data is no longer required, we will securely delete, anonymise, or archive it in line with our retention practices. Retention is based on necessity, not convenience.
5. Processors and Third Parties
Gardeners Chessington may use trusted third-party service providers, known as processors, to help operate the business. These processors only act on our instructions and are required to protect personal data appropriately.
Examples of processors may include:
- administrative and bookkeeping service providers;
- payment processing services;
- email, scheduling, or customer management systems;
- IT support and data storage providers;
- professional advisers such as accountants or insurers, where necessary.
We may also disclose personal data where required by law, by a regulatory authority, or to protect our legal rights. Any sharing is limited to what is necessary and proportionate. Where processors are used, we expect them to apply suitable technical and organisational security measures.
6. Data Security
We take reasonable steps to protect personal data from loss, misuse, unauthorised access, disclosure, alteration, or destruction. These steps may include access controls, secure storage, staff awareness, and restricting access to information on a need-to-know basis.
Although we take data protection seriously, no system can be guaranteed completely secure. In the event of a personal data breach, we will assess the risk and take appropriate action in line with legal obligations.
7. User Rights
Under data protection law, you have a number of rights regarding your personal information. These rights may apply depending on the lawful basis used and the circumstances of the request.
Right of Access
You may request confirmation of whether we hold your personal data and ask for a copy of that data.
Right to Rectification
You may ask us to correct inaccurate or incomplete information.
Right to Erasure
In certain cases, you may request deletion of your personal data. This is not always possible where we have a legal obligation to retain records.
Right to Restrict Processing
You may request that we limit how we use your data in certain circumstances.
Right to Object
You may object to processing based on legitimate interests. We will review your objection and stop processing unless we have compelling grounds to continue.
Right to Data Portability
Where processing is based on consent or contract and carried out by automated means, you may ask for certain data in a reusable format.
Right to Withdraw Consent
If we rely on consent, you may withdraw it at any time. This will not affect the lawfulness of processing before withdrawal.
You also have the right to complain to the UK Information Commissioner’s Office if you believe your data has been handled improperly.
8. Children’s Data
Our services are directed to adult customers and property owners or occupiers. We do not knowingly collect personal data from children unless it is necessary and lawful, and only in limited circumstances.
9. International Transfers
Where data is processed by service providers outside the UK, we will take steps to ensure that suitable safeguards are in place to protect your information and maintain an equivalent level of protection.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, services, or business practices. The latest version will apply to all Gardeners Chessington customers in the area from the date it is issued.
Summary: Gardeners Chessington processes customer data lawfully, securely, and only for clear business purposes, with rights, retention limits, and processor safeguards in place.