Privacy Policy - Gardeners Bexley

Effective for all Gardeners Bexley customers in the area. This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when you use our gardening services. We are committed to handling personal information in a lawful, fair, and transparent manner in accordance with the UK GDPR and the Data Protection Act 2018.

1. Who This Policy Applies To

This Privacy Policy applies to all Gardeners Bexley customers in the area, including individuals who request quotes, make bookings, receive garden maintenance services, or communicate with us about current or future work. It also applies to people whose information is provided to us by a customer, such as a property owner, tenant, landlord, neighbour, or authorised representative, where that information is needed to deliver our services.

2. Personal Data We Collect

We collect only the information needed to provide our services, manage customer relationships, fulfil legal duties, and improve our operations. Depending on your interaction with us, we may collect the following categories of personal data:

  • Identity details: name, title, and, where relevant, business name.
  • Contact details: address, email address, telephone number, and service location.
  • Service information: details about the gardening work requested, property access notes, scheduling preferences, and service history.
  • Financial information: payment status, invoices, and transaction records. We do not store full card details if a third-party payment provider handles the transaction.
  • Communication records: emails, messages, call notes, complaints, feedback, and booking confirmations.
  • Technical data: limited information collected through our systems, such as IP address or device details, where necessary for security and performance purposes.
  • Special category data: in normal circumstances, we do not intentionally collect special category personal data. If such data is provided inadvertently, we will process it only where a lawful basis exists and appropriate safeguards are in place.

3. How We Use Personal Data

We use personal data to run our gardening services efficiently and responsibly. Typical uses include:

  • providing quotations and confirming bookings;
  • delivering gardening and maintenance services;
  • managing customer accounts and service records;
  • handling billing, payments, and refunds;
  • responding to questions, complaints, and service updates;
  • maintaining security, preventing fraud, and protecting our systems;
  • meeting legal, tax, accounting, and insurance obligations;
  • improving our customer service and operational planning.

We do not sell personal data. We only use it for the purposes described in this policy or for purposes that are compatible with those purposes.

4. Lawful Basis for Processing

Under the UK GDPR, we must have a lawful basis to process personal data. We rely on the following bases depending on the context:

Contract

We process personal data where it is necessary to enter into or perform a contract with you. This includes preparing estimates, arranging appointments, carrying out gardening work, and managing payments.

Legitimate Interests

We may process data where it is necessary for our legitimate interests and where those interests are not overridden by your rights and freedoms. This may include service administration, record keeping, customer support, internal quality control, and protecting our business from misuse or fraud.

Legal Obligation

We may process and retain certain information where required to comply with legal obligations, such as tax rules, accounting standards, insurance requirements, or requests from public authorities.

Consent

Where we rely on consent, we will make that clear at the time it is requested. You may withdraw consent at any time, although this will not affect processing already carried out before the withdrawal.

Vital Interests and Public Task

These bases are unlikely to apply to our routine services, but may be used in exceptional circumstances if necessary to protect life or where required by law.

5. Data Sharing and Processors

We may share personal data with trusted third parties who act as data processors or independent controllers, but only where necessary and appropriate. All processors are required to handle data securely and only in accordance with our instructions or their own legal obligations.

Examples of processors or third-party service providers may include:

  • accounting and bookkeeping services;
  • payment processing providers;
  • IT and cloud storage providers;
  • customer communication and scheduling tools;
  • professional advisers such as insurers, legal advisers, or auditors;
  • delivery, logistics, or subcontracted service partners where needed to complete work.

We may also disclose personal data where required by law, court order, regulatory authority, or to protect our legal rights, staff, customers, or property.

Where a processor is used, we take reasonable steps to ensure there is an appropriate data processing agreement in place. These agreements require the processor to implement suitable technical and organisational security measures, limit use of the data, and assist us in meeting our GDPR obligations where relevant.

6. Data Retention

We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. Retention periods vary depending on the type of data and the reason for processing.

  • Service records: kept for the duration of the customer relationship and for a reasonable period afterwards.
  • Financial and tax records: retained for the period required by applicable law, typically several years.
  • Communication records: kept for as long as needed to manage queries, disputes, or service continuity.
  • Website or system logs: retained for a limited period for security, troubleshooting, and performance monitoring.

When data is no longer required, we will delete it securely or anonymise it so that it can no longer identify you.

7. Data Security

We take appropriate technical and organisational measures to protect personal data from unauthorised access, accidental loss, alteration, or disclosure. These measures may include access controls, password protection, secure storage, and limiting access to only those who need the information for their work.

However, no method of transmission or storage is completely secure. While we work hard to protect personal information, we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will respond in line with applicable law and notify affected individuals and regulators where required.

8. Your Rights Under GDPR

You have a number of rights regarding your personal data. Depending on the circumstances and applicable law, these may include:

  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: ask us to correct inaccurate or incomplete data.
  • Right to erasure: request deletion of your data in certain situations.
  • Right to restrict processing: ask us to limit how we use your data in certain cases.
  • Right to object: object to processing based on legitimate interests or direct marketing.
  • Right to data portability: receive certain data in a structured, commonly used format where technically feasible.
  • Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office if you believe your data protection rights have been breached. We encourage you to raise concerns with us first so we can try to resolve the issue promptly.

9. Children’s Data

Our services are intended for adults and property-related customers. We do not knowingly collect personal data from children except where it is incidental to service delivery and only when appropriate consent or lawful authority exists. If we become aware that we have collected children’s data without the correct basis, we will take steps to delete or secure it as required.

10. International Transfers

Where personal data is transferred outside the UK, we will ensure appropriate safeguards are in place, such as adequacy regulations or approved contractual protections. We only use international transfers where necessary and where the protection of your data is maintained to a lawful standard.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. Any updated version will apply from the date it is published or otherwise communicated. We recommend reviewing this policy periodically so you remain informed about how your data is handled.

12. Summary of Our Commitment

Gardeners Bexley is committed to respecting privacy, using personal data responsibly, and keeping information secure. We collect only what is needed, use it for clear and lawful purposes, retain it for no longer than necessary, and work with processors who meet appropriate data protection standards. This policy applies to all Gardeners Bexley customers in the area and is designed to support transparent, compliant, and trustworthy service delivery.

Gardeners Bexley

This Privacy Policy explains how Gardeners Bexley collects, uses, stores, shares, and protects personal data for customers in the area.

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.