Privacy Policy - Gardeners Botany Bay
This Privacy Policy explains how Gardeners Botany Bay collects, uses, stores, shares, and protects personal data when providing gardening-related services. It applies to all Gardeners Botany Bay customers in the area, including people who request quotations, make bookings, receive garden maintenance services, or otherwise interact with us in connection with our work. We are committed to handling personal data lawfully, fairly, and transparently in line with the UK GDPR and the Data Protection Act 2018.
1. Who we are
Gardeners Botany Bay is a service provider offering gardening and outdoor maintenance services to local customers. For the purposes of data protection law, we act as a data controller for the personal information we determine the purpose and means of processing. This means we decide what data is needed to manage enquiries, deliver services, maintain records, and comply with legal obligations.
2. Information we collect
We only collect personal data that is relevant and necessary for our business operations and service delivery. Depending on how you interact with us, we may collect the following categories of information:
- Identity details such as your name and title.
- Contact information such as address, phone number, and email address.
- Service details including property access instructions, gardening preferences, and requested work.
- Billing and payment records such as invoices, transaction references, and payment status.
- Communication records including emails, messages, call notes, and complaint correspondence.
- Technical data if you visit digital services connected to our business, such as basic device or browser information.
- Special category data only where strictly necessary and where you choose to provide it, for example if you share information relevant to access needs or health-related considerations for service delivery.
We do not seek to collect more data than is needed. If you provide information about another person, you should ensure that you have permission to do so.
3. How we use personal data
We use personal data for clear and limited purposes connected to our services. These include:
- responding to enquiries and providing quotations;
- arranging appointments and delivering gardening services;
- managing customer records and service history;
- issuing invoices, taking payments, and maintaining accounts;
- handling complaints, queries, and follow-up communication;
- meeting legal, regulatory, accounting, and tax obligations;
- protecting our business, staff, customers, and property;
- improving service quality and operational efficiency.
We will not use your personal data in a way that is incompatible with the purposes explained in this policy unless we have a lawful basis to do so and, where required, provide you with notice.
4. Lawful basis for processing
We process personal data only where we have a valid lawful basis under data protection law. Depending on the circumstances, we rely on the following bases:
Contract
We process your personal data where it is necessary to enter into or perform a contract with you. This includes providing quotes you requested, carrying out gardening work, managing bookings, and handling payments.
Legal obligation
We may process and retain certain information to comply with legal requirements, including tax, accounting, insurance, and record-keeping duties.
Legitimate interests
We may process data where it is necessary for our legitimate business interests and where those interests are not overridden by your rights and freedoms. This can include managing customer relationships, improving our services, preventing fraud, and protecting our business.
Consent
In limited cases, we may rely on your consent, for example if you opt in to receive certain types of communication not required for service delivery. Where consent is used, you can withdraw it at any time.
Vital interests and public task
These lawful bases are unlikely to be relied upon in ordinary service delivery, but may be used in rare circumstances if necessary to protect a person’s life or in relation to a legal public function.
5. Sharing data and processors
We may share personal data with trusted third parties where necessary for business operations, legal compliance, or service delivery. When these third parties process personal data on our behalf, they act as processors and are required to follow our instructions and protect the information appropriately.
Examples of processors or service providers may include:
- IT and cloud service providers used to store business records or manage communications.
- Accounting and bookkeeping providers that help prepare invoices, tax records, and financial reports.
- Payment service providers that process transactions securely.
- Scheduling or administration tools used to manage bookings and service coordination.
- Professional advisers such as insurers, auditors, or legal advisers where required.
We may also disclose personal data if required by law, court order, or to protect the rights, safety, or property of Gardeners Botany Bay, our customers, or others. We do not sell personal data.
6. International transfers
Where any processor stores or accesses personal data outside the United Kingdom, we will ensure that appropriate safeguards are in place. These safeguards may include adequacy regulations, standard contractual clauses, or equivalent legal mechanisms designed to protect your information to the required standard.
7. Data retention
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including the purposes of satisfying legal, accounting, or reporting requirements. Retention periods depend on the type of data and the reason it was collected.
- Customer enquiry records are normally kept for a limited period after the enquiry is closed.
- Service and booking records may be retained for the period needed to manage customer relationships and resolve issues.
- Financial and tax records are retained for the period required by law.
- Complaints or dispute records may be retained longer where needed to defend legal claims or manage investigations.
When data is no longer needed, we will securely delete, anonymise, or archive it in line with our retention practices. Retention is reviewed regularly to ensure data is not held for longer than necessary.
8. Your rights
Under data protection law, you have a number of rights regarding your personal data. These rights may apply in different ways depending on the legal basis for processing and the context of your request.
- Right of access – you can request a copy of the personal data we hold about you.
- Right to rectification – you can ask us to correct inaccurate or incomplete information.
- Right to erasure – you can ask us to delete your data in certain circumstances.
- Right to restriction – you can ask us to limit how we use your data in certain situations.
- Right to object – you can object to processing based on legitimate interests, including direct marketing where relevant.
- Right to data portability – you can request your data in a structured, commonly used format where applicable.
- Right to withdraw consent – where we rely on consent, you may withdraw it at any time.
- Right to complain – you may raise concerns with the relevant supervisory authority if you believe your rights have been infringed.
To protect privacy, we may need to verify your identity before responding to a request. We aim to respond within the time limits set by law.
9. Data security
We use appropriate technical and organisational measures to protect personal data from unauthorised access, alteration, loss, or disclosure. These measures are proportionate to the nature of the information we handle and may include restricted access, password protection, secure storage, and staff confidentiality obligations. While no system can be guaranteed completely secure, we work to reduce risks and respond appropriately to any suspected breach.
10. Children’s data
Our services are generally intended for adults. We do not knowingly collect personal data from children unless it is necessary in connection with a customer’s property, access arrangements, or another lawful reason. If we become aware that we have collected data from a child without an appropriate basis, we will take steps to delete it or handle it lawfully.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in law, business practice, or the way we process personal data. Any updates will take effect when published or otherwise communicated. We encourage customers to review this policy periodically so they remain informed about how their data is handled.
12. Summary of our commitments
Gardeners Botany Bay is committed to using personal data responsibly, keeping it secure, and respecting the rights of every customer in the area. We collect only what we need, use it for clear purposes, retain it only for as long as necessary, and share it only with trusted processors or where the law requires it. If you interact with our services, your information will be handled with care, confidentiality, and in accordance with GDPR principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity, and accountability.