Privacy Policy - Gardeners The Burroughs
This Privacy Policy explains how Gardeners The Burroughs collects, uses, stores, shares, and protects personal data when providing gardening and related services. It applies to all Gardeners The Burroughs customers in the area, including individuals, households, landlords, tenants, and business clients who request or receive our services. We are committed to handling personal information in a lawful, fair, and transparent manner, in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By engaging our services, making an enquiry, or otherwise providing information to us, you acknowledge that your personal data may be processed as described in this policy. We only collect information that is relevant and necessary for the delivery, administration, and improvement of our services.
1. Information We Collect
We may collect and process the following categories of personal data:
- Identity details such as name and title.
- Contact details such as address, email address, and telephone number.
- Service details relating to the type of gardening work requested, property access notes, scheduling preferences, and project instructions.
- Billing and payment information where applicable, including transaction records and payment status.
- Communication records including emails, messages, service notes, quotations, complaints, and feedback.
- Technical and usage information where relevant, such as enquiry timestamps or limited device data used for communication and website interaction.
We generally do not seek to collect special category data. However, if such information is voluntarily provided and is necessary to deliver a service safely or effectively, it will be handled with additional care and only where a lawful basis applies.
2. How We Use Personal Data
We use personal data for the following purposes:
- To respond to enquiries and provide quotations.
- To arrange and deliver gardening services.
- To manage customer accounts, appointments, and service records.
- To issue invoices, process payments, and maintain financial records.
- To communicate about service updates, scheduling changes, or relevant operational matters.
- To deal with complaints, disputes, or requests for further information.
- To maintain internal records, improve service quality, and support business administration.
- To comply with legal and regulatory obligations.
We do not use personal information for purposes that are incompatible with the original reason it was collected.
3. Lawful Basis for Processing
We process personal data only when permitted by law. Depending on the situation, we rely on one or more of the following lawful bases:
Contract
We process data where it is necessary to enter into or perform a contract with you. This includes providing quotes, scheduling work, delivering services, and managing payments.
Legal Obligation
We may process and retain certain information where required to comply with legal duties, such as tax, accounting, and record-keeping obligations.
Legitimate Interests
We may process personal data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include maintaining service records, improving operations, managing customer relationships, and protecting our business from fraud or misuse.
Consent
In limited cases, we may rely on your consent, for example where you choose to provide optional information that is not required for the service. Where consent is used, you may withdraw it at any time.
4. Sharing and Processors
We may share personal data with trusted third parties who help us operate our business. These parties act as processors when they process data on our instructions, or as independent controllers where they determine their own purposes.
Typical processors or service providers may include:
- Accounting and bookkeeping providers for invoicing and financial administration.
- Payment service providers for handling card or electronic payments.
- IT and cloud service providers for secure storage, communication, and system support.
- Scheduling or business administration tools used to manage appointments and customer records.
- Professional advisers such as accountants or legal advisers where necessary.
We only share data with third parties where there is a lawful basis and where appropriate safeguards are in place. Processors are required to protect personal data, use it only for our instructions, and maintain confidentiality and security.
We may also disclose personal data if required by law, court order, or regulatory authority, or to protect our rights, property, customers, or staff.
5. Retention of Personal Data
We keep personal data only for as long as necessary for the purposes for which it was collected, and to satisfy legal, accounting, or reporting requirements. Retention periods vary depending on the type of information and the reason for processing.
In general:
- Customer and service records are retained for the duration of the working relationship and for a reasonable period afterwards.
- Financial and accounting records are retained for the period required by law.
- Communication records may be retained for as long as needed to manage enquiries, disputes, or ongoing service matters.
When data is no longer required, it is securely deleted, anonymised, or otherwise disposed of in a safe and appropriate manner.
6. Data Security
We take appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, misuse, alteration, or disclosure. These measures are designed to reflect the nature of the data we hold and the risks involved in processing it.
Although we work to protect your information, no system can be guaranteed to be completely secure. We therefore encourage customers to share only the information necessary for the service and to notify us promptly if they believe any data has been compromised.
7. Your Rights Under GDPR
You have several rights in relation to your personal data, subject to legal conditions and exceptions. These include:
- Right of access – to request a copy of the personal data we hold about you.
- Right to rectification – to ask us to correct inaccurate or incomplete data.
- Right to erasure – to request deletion of your data in certain circumstances.
- Right to restrict processing – to ask us to limit how we use your data in certain situations.
- Right to object – to object to processing based on legitimate interests or direct marketing where applicable.
- Right to data portability – to receive data you provided to us in a structured, commonly used, machine-readable format, where applicable.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
You also have the right to lodge a complaint with the relevant data protection supervisory authority if you believe your rights have not been respected.
8. Children’s Data
Our services are not directed at children, and we do not knowingly collect personal data from children except where it is necessary for the provision of services arranged by an adult customer. If we become aware that we have collected data inappropriately, we will take reasonable steps to delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, service practices, or operational requirements. Any revised version will apply from the date it is published or otherwise communicated. We encourage customers to review this policy periodically so they remain informed about how their data is handled.
10. Summary of Key Principles
Gardeners The Burroughs processes personal data only when it is necessary, lawful, and proportionate. We collect only the information needed to provide gardening services, we keep it securely, we share it only with appropriate processors or where legally required, and we retain it only for as long as needed. Customers in the area have clear rights over their personal information, and we aim to respect those rights at every stage of our service.