Privacy Policy - Gardeners Tower Hill
This Privacy Policy explains how Gardeners Tower Hill collects, uses, stores, shares, and protects personal data relating to all customers in the Tower Hill area and surrounding local service area. It applies to all individuals who contact us, request a quotation, book gardening work, receive services, or otherwise interact with Gardeners Tower Hill as a customer in the area. We are committed to handling personal information in a way that is lawful, fair, transparent, and secure, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Gardeners Tower Hill provides gardening and outdoor maintenance services to residential and commercial customers in Tower Hill and the nearby area. For the purposes of data protection law, we act as the data controller in relation to the personal data we collect and process for the running of our services, customer management, invoicing, communications, and administration.
2. Information We Collect
We only collect personal data that is relevant and necessary for our business operations and the delivery of services. Depending on how you interact with us, we may collect the following categories of information:
- Identity information such as your name, title, and any business or household name you provide.
- Contact details including address, email address, and telephone number.
- Service information such as details about your garden, property access, service preferences, requested work, and instructions relevant to the gardening services we provide.
- Billing and payment information required to issue invoices and process payments.
- Communication records including enquiries, feedback, complaints, and notes from conversations.
- Technical information that may be collected when you communicate electronically, such as limited device or usage information, if applicable to our systems.
We do not collect more information than is reasonably needed. Where possible, we use the minimum data necessary to deliver services effectively and responsibly.
3. How We Use Personal Data
We process personal data for the following purposes:
- To respond to enquiries and provide quotations.
- To schedule, deliver, and manage gardening services.
- To maintain service records and customer history.
- To issue invoices, manage payments, and keep financial records.
- To communicate with customers about appointments, service updates, and relevant administrative matters.
- To handle complaints, disputes, and service follow-up.
- To meet legal, accounting, tax, and insurance obligations.
- To improve our services, operations, and customer experience.
We will never use your personal data in a way that is incompatible with the purpose for which it was collected unless we have a valid legal basis to do so.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each processing activity. Gardeners Tower Hill relies on the following lawful bases:
Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes managing your booking, carrying out gardening services, and processing payments.
Legal Obligation
We may process and retain certain records to comply with legal requirements, including tax, accounting, and record-keeping obligations.
Legitimate Interests
We may process personal data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include maintaining service records, managing customer relationships, preventing fraud, protecting our business, and improving our operations. We always balance our interests against your privacy rights.
Consent
In limited situations, we may rely on your consent, for example where you have asked us to communicate with you in a specific way or where consent is required by law. If consent is used, you may withdraw it at any time.
5. Sharing and Processors
We may share personal data with trusted third parties who help us operate our business. These recipients act as processors or, in some cases, as independent controllers. We only share data where necessary and always under appropriate safeguards. The types of processors we may use include:
- Administrative and bookkeeping providers who assist with invoicing, accounts, and financial records.
- IT and hosting providers that support data storage, communication systems, and secure business operations.
- Payment service providers that process payments securely.
- Professional advisers such as accountants, insurers, or legal advisers where necessary.
- Delivery and operational partners where needed to arrange or complete services.
We require processors to handle data securely, to use it only for authorised purposes, and to respect confidentiality. Where data is transferred outside the UK, we take steps to ensure appropriate protection is in place.
6. Data Retention
We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by law. Retention periods may vary depending on the type of data and the purpose for which it is used.
- Customer service records are generally retained for the period needed to manage the relationship and resolve issues.
- Invoices and accounting records are usually retained for the legally required financial retention period.
- Communication records may be kept for a reasonable time to support service administration and dispute handling.
- Consent-based data is kept only until consent is withdrawn or the purpose ends.
When data is no longer needed, it is securely deleted or anonymised. We apply a data minimisation approach and do not keep personal information indefinitely.
7. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and regular review of data handling practices.
While no system can be guaranteed completely secure, we work to maintain a high standard of protection and handle sensitive information with care and discretion.
8. Your Rights
Under data protection law, you have a number of rights regarding your personal data. Subject to legal limits and verification of identity, these rights may include:
- Right of access – to obtain a copy of the personal data we hold about you.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of your data in certain circumstances.
- Right to restriction – to ask us to limit how we use your data in some situations.
- Right to object – to object to processing based on legitimate interests.
- Right to data portability – to receive certain data in a structured, commonly used format where applicable.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
You also have the right to raise concerns with the UK Information Commissioner’s Office if you believe your data protection rights have been breached. We encourage customers to contact us first so that we can try to resolve concerns promptly and fairly.
9. Children’s Data
Our services are generally intended for adult customers. We do not knowingly collect personal data from children except where it is incidentally provided in the context of a household or property booking and is necessary for legitimate business administration. Where such data is collected, it is handled carefully and only for the relevant purpose.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. Any updated version will apply to all Gardeners Tower Hill customers in the area from the date it is issued. We encourage you to review this policy periodically so that you remain informed about how we process personal information.
11. Summary of Our Commitment
Gardeners Tower Hill is committed to protecting your privacy and processing personal data responsibly. We collect only the information we need, use it for clear and lawful purposes, retain it for appropriate periods, share it only with trusted processors where necessary, and respect your rights at every stage. Our approach is built on transparency, accountability, and respect for your personal information.