Privacy Policy - Gardeners Morden
Gardeners Morden is committed to protecting personal data and respecting privacy. This Privacy Policy explains how we collect, use, store, share, and protect information relating to our customers, prospective customers, and anyone who interacts with our gardening services. It applies to all Gardeners Morden customers in the area, including individuals, households, landlords, tenants, and business clients who engage us for garden maintenance, landscaping, lawn care, planting, clearance, and related services.
This policy has been written in line with the UK General Data Protection Regulation and the Data Protection Act 2018. It sets out the information we collect, the lawful basis we rely on, how long we keep data, the processors we may use, and the rights available to you. We aim to keep our practices fair, transparent, and limited to what is necessary for the delivery of our services.
1. Information We Collect
We only collect personal data that is relevant to providing and managing our services. Depending on how you interact with us, the information may include:
- Identity details such as your name or business name.
- Contact details such as address, email address, and telephone number.
- Service information including your property details, garden requirements, instructions, appointment preferences, and service history.
- Payment-related information where needed to process invoices and payments.
- Communication records such as emails, messages, notes from phone calls, and service updates.
- Technical data if you interact with our digital systems, including basic device and usage information where applicable.
We do not seek to collect special category data unless it is strictly necessary and you have provided it voluntarily, or unless there is another lawful reason to process it. We ask that you avoid sharing sensitive information unless it is directly relevant to your service request.
2. How We Use Your Data
Gardeners Morden uses personal data only for clear and legitimate purposes. These include:
- Providing quotes and responding to enquiries.
- Scheduling and delivering gardening services.
- Managing customer accounts, invoices, and payments.
- Keeping records of completed work, preferences, and service notes.
- Handling customer support, complaints, or follow-up requests.
- Meeting legal, tax, accounting, and insurance obligations.
- Improving the quality, safety, and efficiency of our services.
We process data in a way that is adequate, relevant, and limited to what is necessary. We do not use your personal data for unrelated purposes without a valid reason and, where required, appropriate notice or consent.
3. Lawful Basis for Processing
Under data protection law, we must have a lawful basis for each use of personal data. Gardeners Morden relies on the following lawful bases:
Contract
We process your data where it is necessary to enter into or perform a contract with you. This includes preparing quotes at your request, carrying out agreed garden work, managing bookings, and issuing invoices.
Legitimate Interests
We may process data where it is necessary for our legitimate business interests, provided that your rights and freedoms do not override those interests. This may include maintaining service records, managing customer relationships, improving services, preventing fraud, and ensuring safe operations.
Legal Obligation
Some records must be retained or processed to comply with tax law, accounting rules, health and safety obligations, or other legal requirements.
Consent
In limited cases, we may rely on your consent, for example if we need to use certain optional data or send particular communications. Where consent is used, you may withdraw it at any time. Withdrawal does not affect processing already carried out before it was withdrawn.
We do not process personal data in a manner that is unfair, excessive, or incompatible with the original purpose.
4. Data Sharing and Processors
We may share personal data with trusted third parties where necessary to operate our business and deliver services. These third parties act as processors or independent controllers depending on the service they provide. Examples may include:
- Payment processors for handling secure transactions.
- Accounting and bookkeeping providers for tax and financial administration.
- IT and cloud storage providers for secure record management and communications.
- Scheduling or administration software providers used to organise appointments and customer records.
- Professional advisers such as accountants, insurers, or legal advisers where needed.
When we use processors, we ensure they are bound by appropriate confidentiality and data protection obligations. They may only process data on our instructions and for the agreed purpose. We take reasonable steps to confirm that processors apply suitable technical and organisational safeguards.
We may also disclose information if required by law, court order, regulatory request, or to protect our rights, property, staff, or customers. Any such disclosure is limited to what is necessary and lawful.
5. Data Retention
We keep personal data only for as long as necessary for the purpose it was collected, including any legal, accounting, or reporting requirements. Retention periods depend on the type of information and the reason for holding it.
- Customer enquiry records are usually kept for a limited period if no service is booked.
- Contract and service records are kept for the duration of the relationship and for a reasonable period afterwards.
- Invoice and payment records are kept for the period required by tax and accounting law.
- Communications and complaints may be retained for as long as needed to resolve issues and evidence service history.
When data is no longer required, we delete it securely or anonymise it so that it can no longer identify you. We review retention regularly to ensure information is not kept longer than necessary.
6. Security of Your Data
We take the protection of personal data seriously and use reasonable technical and organisational measures to reduce the risk of unauthorised access, loss, alteration, or disclosure. These measures may include access controls, secure storage, password protection, limited internal access, and staff awareness procedures.
No system can be guaranteed completely secure, but we work to maintain a high standard of protection. If a personal data incident occurs that is likely to result in a risk to your rights and freedoms, we will respond in accordance with legal obligations.
7. Your Rights
As a data subject, you have rights over your personal information. Subject to legal limits, you may have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete information.
- Erase your data in certain circumstances.
- Restrict how we process your data in some situations.
- Object to processing based on legitimate interests or direct marketing.
- Data portability for information you provided to us, where applicable.
- Withdraw consent where processing is based on consent.
You also have the right to receive clear information about how your data is used and the right to lodge a complaint with the relevant supervisory authority if you believe your data protection rights have been infringed.
We may need to verify your identity before acting on a request. This is to protect your privacy and ensure that data is only disclosed to the correct person.
8. Children’s Data
Our services are directed at adults responsible for homes, gardens, or business premises. We do not knowingly collect personal data from children unless it is incidentally included in communications and is necessary for service delivery or safety. If we become aware that we have collected data from a child inappropriately, we will take steps to delete it where required.
9. International Transfers
Where data is processed by service providers outside the United Kingdom, we take steps to ensure appropriate safeguards are in place. These may include adequacy regulations, standard contractual protections, or equivalent legal mechanisms designed to protect your rights.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or internal practices. Any updated version will apply from the date it is published or otherwise communicated. We encourage customers to review this policy periodically so they remain informed about how their information is handled.
11. Summary of Our Commitment
Gardeners Morden is committed to handling personal data responsibly, lawfully, and with care. We collect only what is needed, use it for clear business and legal purposes, retain it for a sensible period, and work only with processors that can support secure and compliant processing. We respect your privacy rights and aim to make our data practices transparent and trustworthy.
This Privacy Policy applies to all Gardeners Morden customers in the area. By using our services, you acknowledge that your personal data may be handled in the ways described above, always in accordance with applicable data protection law.