Privacy Policy - Gardeners Seven Sisters
This Privacy Policy explains how Gardeners Seven Sisters collects, uses, stores, shares, and protects personal data relating to all Gardeners Seven Sisters customers in the area. It is designed to be clear and transparent, and to reflect the requirements of the General Data Protection Regulation (GDPR) and applicable UK data protection laws. By using our services, requesting a quotation, making an enquiry, or entering into a service arrangement with us, you acknowledge that your personal data may be processed in line with this policy.
We are committed to handling personal information with care and respect. We only collect data that is necessary for legitimate business purposes, and we apply appropriate technical and organisational measures to protect it. This policy applies whether you contact us by phone, email, written communication, online forms, or through any other service-related interaction.
1. What Personal Data We Collect
We may collect and process different categories of personal data depending on how you interact with us and which services you request. This may include:
- Identity information such as your name, title, and any business or household details you provide.
- Contact details such as address, email address, telephone number, and preferred method of communication.
- Service information such as property access notes, instructions for work, gardening preferences, and service history.
- Financial information such as payment records, invoicing details, and transaction references.
- Communication data such as messages, feedback, complaints, quotations, and notes from conversations.
- Technical data if you interact with digital services, including device identifiers, basic usage logs, and security-related records.
We do not intentionally collect special category data unless there is a clear lawful reason to do so and it is necessary for the service. If any such information is voluntarily provided, we will only process it where permitted by law and where appropriate safeguards are in place.
2. How We Use Personal Data
Gardeners Seven Sisters uses personal data for specific and limited purposes. These include:
- Responding to enquiries and providing quotations.
- Managing bookings, scheduling visits, and delivering gardening services.
- Maintaining customer records and service preferences.
- Processing payments, issuing invoices, and handling account administration.
- Communicating about service changes, updates, or operational matters.
- Handling complaints, disputes, and follow-up requests.
- Meeting legal, tax, accounting, and regulatory obligations.
- Protecting our business, staff, customers, and property from fraud, misuse, or security incidents.
We use a data minimisation approach, which means we aim to collect and use only the information required to carry out the service properly. We do not sell personal data, and we do not use it for unrelated purposes without a lawful basis.
3. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each type of personal data we process. The lawful bases we rely on may include the following:
Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes handling bookings, delivering gardening work, invoicing, and customer account administration.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. Examples include service improvement, maintaining security, internal record keeping, and managing communications related to our services.
Legal Obligation
We may process data where necessary to comply with legal obligations, including tax requirements, accounting duties, record retention rules, and lawful requests from authorities.
Consent
In limited situations, we may rely on your consent. If we do, you will be told clearly what the consent covers, and you may withdraw it at any time. Withdrawing consent will not affect processing carried out before the withdrawal.
Vital Interests and Public Task
These bases are not generally expected to apply to our normal customer services, but they may be relevant in exceptional circumstances where required by law.
4. Retention of Personal Data
We only keep personal data for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements. Retention periods depend on the type of record and the reason it was created.
- Customer and service records are retained while the relationship is active and for a reasonable period afterwards for continuity, dispute resolution, and administration.
- Financial and invoicing records are retained for the period required under tax and accounting law.
- Communication records may be retained for quality assurance, evidence, and customer support purposes.
- Security logs and system records are kept only as long as needed for monitoring, protection, and incident handling.
When data is no longer needed, it is securely deleted, anonymised, or otherwise disposed of in a safe and appropriate manner. We do not keep personal data indefinitely.
5. Processors and Data Sharing
To operate effectively, Gardeners Seven Sisters may use trusted third-party service providers, also known as processors. These processors handle data only on our instructions and are required to protect it appropriately.
Processors may include:
- Payment processing providers.
- Accounting and bookkeeping systems.
- Scheduling, record management, or administrative software providers.
- IT support, security, and data storage providers.
- Communication tools used for email, messaging, or customer administration.
We may also share personal data where necessary with professional advisers, insurers, or public authorities if required by law or to protect our rights, customers, or business operations. Where data is transferred outside the UK or EEA, we will ensure appropriate safeguards are in place, such as adequacy regulations or standard contractual protections.
We require all processors to respect confidentiality, implement reasonable security measures, and process personal data only for the agreed purposes. They are not permitted to use your data for their own independent marketing.
6. Data Security
We take the security of personal data seriously. Measures may include access controls, password protection, restricted permissions, secure storage, staff awareness, and periodic review of handling practices. While no system can be guaranteed to be completely secure, we work to reduce the risk of unauthorised access, accidental loss, disclosure, or misuse.
If a personal data breach occurs and is likely to affect your rights or freedoms, we will act in accordance with legal requirements, which may include notifying the relevant supervisory authority and, where appropriate, affected individuals.
7. Your GDPR Rights
As a data subject, you have a number of rights under GDPR. Depending on the circumstances and legal conditions, these may include:
- Right of access – to request a copy of the personal data we hold about you.
- Right to rectification – to ask us to correct inaccurate or incomplete information.
- Right to erasure – to request deletion of your data in certain situations.
- Right to restriction – to ask us to limit how we use your data in specific cases.
- Right to object – to object to processing based on legitimate interests or direct marketing, where applicable.
- Right to data portability – to request transfer of data you have provided to us, where legally applicable.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
To exercise these rights, you may make a request using the appropriate communication method provided by the service arrangement. We may need to verify your identity before responding. We will respond within the time limits set out by law, usually within one month, unless the request is complex or numerous.
You also have the right to lodge a complaint with a supervisory authority if you believe your data has been handled unlawfully or unfairly. We encourage you to raise concerns with us first so that we can try to resolve them quickly and informally.
8. Children’s Data
Our services are intended for adults and property-related customers. We do not knowingly collect personal data from children except where it is necessary and lawful in a limited context, such as where a customer provides household information that happens to include a child’s name. If we become aware that data has been collected inappropriately, we will take reasonable steps to delete it.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any updated version will apply from the date it is issued. We recommend reviewing it periodically so that you remain informed about how your data is handled.
10. Summary of Our Commitments
Gardeners Seven Sisters is committed to processing personal data fairly, lawfully, and transparently. We collect only the information needed to deliver and manage services, rely on lawful bases under GDPR, retain data only for appropriate periods, use processors responsibly, and respect your rights over your personal information. This policy applies to all Gardeners Seven Sisters customers in area and is intended to ensure that your personal data is handled with care, purpose, and accountability.