Privacy Policy - Gardeners Heston

Gardeners Heston is committed to protecting personal data and handling it in a lawful, fair, and transparent way. This Privacy Policy explains how we collect, use, store, share, and protect personal information relating to our customers, including all Gardeners Heston customers in the area. It also explains the rights individuals have under the UK GDPR and the Data Protection Act 2018.

This policy applies when you request services, make an enquiry, receive a quotation, book a visit, communicate with us, or otherwise interact with Gardeners Heston. It covers personal data collected through direct contact, service delivery, administrative processes, and any related communications.

1. Information We Collect

We only collect data that is relevant and necessary for providing gardening services, managing customer relationships, and meeting legal obligations. The personal data we may collect includes:

  • Identity information such as your name and title.
  • Contact details such as address, email address, and phone number.
  • Service information such as details of requested work, property access notes, preferences, and appointment history.
  • Billing and payment information such as invoicing details and payment status, where needed for administration.
  • Communication records including emails, messages, call notes, and complaint details.
  • Technical and usage data if you interact with digital tools connected to our services, such as basic device or browser information where applicable.

In limited cases, we may also process special category data if it is provided voluntarily and is necessary for service delivery, for example information about mobility needs or access requirements. We do not seek unnecessary sensitive information, and we only process it when there is a valid legal basis and additional protection in place.

2. How We Use Personal Data

We use personal data to operate our business and provide services efficiently. Typical purposes include:

  • responding to enquiries and preparing quotations;
  • arranging appointments and delivering gardening services;
  • managing customer accounts and records;
  • processing invoices and payments;
  • maintaining service history and communication logs;
  • meeting legal, tax, accounting, and insurance requirements;
  • improving service quality and customer experience;
  • handling complaints, disputes, or claims;
  • protecting against fraud, misuse, or security incidents.

We do not use personal data for unrelated purposes. Where we need to process data in a way that is not covered by this policy, we will explain the new purpose and, if necessary, seek further permission or rely on another lawful basis.

3. Lawful Basis for Processing

Under data protection law, we must have a lawful basis for processing personal data. Gardeners Heston relies on the following lawful bases depending on the context:

Contract

We process personal data when it is necessary to enter into or perform a contract with you. This includes booking services, delivering work, sending invoices, and communicating about scheduled appointments.

Legal Obligation

We may process data to comply with legal duties, such as accounting, tax record keeping, health and safety obligations, and responding to lawful requests from authorities.

Legitimate Interests

We may process data where it is reasonably necessary for our legitimate interests and where your rights do not override those interests. This may include service administration, business planning, record keeping, quality monitoring, and protecting our business from fraud or misuse. We always consider whether the processing is proportionate and respectful of privacy.

Consent

In some situations, we may rely on consent, particularly where the law requires it or where processing is optional. If we rely on consent, you can withdraw it at any time. Withdrawal of consent will not affect processing already carried out before it was withdrawn.

Vital Interests and Public Task

These bases are unlikely to apply in ordinary gardening services, but if they ever do, we will only rely on them when the law permits.

4. Data Sharing and Processors

We may share personal data with trusted third parties who help us run our business. These organisations act as processors or independent data controllers depending on the service they provide. Where a third party acts as a processor, they only process data on our instructions and must protect it appropriately.

Examples of processors and service providers may include:

  • accounting and bookkeeping providers;
  • invoice or payment processing services;
  • IT support and data storage providers;
  • customer communication tools such as email systems;
  • professional advisers, including legal or insurance advisers where needed.

We may also share personal data where required by law, to enforce our rights, to protect the safety of staff or customers, or to respond to valid legal requests. We do not sell personal data.

Whenever we use processors, we take reasonable steps to ensure they are subject to proper confidentiality, security, and data protection obligations. We aim to work only with providers that maintain appropriate safeguards.

5. Data Retention

We keep personal data only for as long as necessary for the purposes for which it was collected, including the fulfilment of service obligations, legal compliance, and dispute resolution. Retention periods vary depending on the type of data and the reason for holding it.

In general:

  • customer enquiry records may be kept for a limited period if no service is booked;
  • service and invoicing records may be retained for the period required by tax and accounting rules;
  • communication records may be retained where needed to manage ongoing service issues or complaints;
  • supporting operational records may be kept for business administration and legal protection purposes.

When data is no longer needed, we will delete it securely or anonymise it so that it can no longer identify an individual. If records must be retained longer due to a legal claim, insurance matter, or regulatory requirement, we will keep them only for that specific purpose.

6. Data Security

We take data security seriously and use reasonable technical and organisational measures to protect personal data from loss, misuse, unauthorised access, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and limited access to information on a need-to-know basis.

Although no system can be guaranteed completely secure, we work to reduce risks and to respond promptly if an incident occurs. If a personal data breach is likely to result in a risk to your rights and freedoms, we will handle it in line with legal requirements.

7. Your Rights Under GDPR

Individuals whose data we process have rights under the UK GDPR. These rights may not apply in every situation, but we will always review requests carefully and respond within the required timeframe.

  • Right of access – you can request confirmation of whether we process your data and obtain a copy of it.
  • Right to rectification – you can ask us to correct inaccurate or incomplete data.
  • Right to erasure – you can request deletion of your data in certain circumstances.
  • Right to restriction – you can ask us to limit processing in certain cases.
  • Right to data portability – you may request data you provided to us in a structured, commonly used format where applicable.
  • Right to object – you can object to processing based on legitimate interests or direct marketing.
  • Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
  • Right to complain – you can raise concerns with the Information Commissioner’s Office if you believe your data rights have been infringed.

We may need to verify your identity before responding to a rights request, to ensure that data is only disclosed to the correct person.

8. Children’s Data

Our services are aimed at adults and property owners, and we do not knowingly collect personal data from children unless it is incidental and necessary for service-related communication. If we become aware that we have collected data from a child without a valid reason, we will take appropriate steps to delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect legal, operational, or service changes. Any revised version will continue to apply to all Gardeners Heston customers in area. Where changes are significant, we will take reasonable steps to make them known.

10. Fair Processing Statement

We aim to be transparent about what data we collect and why. Our approach is based on data minimisation, purpose limitation, and accountability. We only process what is relevant, we use it for defined purposes, and we maintain records to show compliance where required.

If you provide information to Gardeners Heston, you can expect it to be handled carefully, kept secure, and used only for legitimate service and legal purposes. We respect privacy and will continue to review our practices so that they remain aligned with GDPR principles and best practice.

Gardeners Heston

Gardeners Heston is committed to protecting personal data and handling it in a lawful, fair, and transparent way for all customers in area.

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.