Privacy Policy - Gardeners Temple
Effective date: This Privacy Policy explains how Gardeners Temple collects, uses, stores, shares, and protects personal data in connection with our services. It applies to all Gardeners Temple customers in area and should be read carefully to understand your rights and our responsibilities under applicable data protection law, including the UK GDPR and the Data Protection Act 2018.
We are committed to handling personal information fairly, lawfully, and transparently. This policy covers personal data we receive from customers, prospective customers, suppliers, and other individuals who interact with our services. By using our services or providing personal data to us, you acknowledge the practices described in this Privacy Policy.
1. Information We Collect
We may collect and process the following categories of personal data:
- Identity information: name, title, and relevant identification details.
- Contact information: address, email address, telephone number, and service location details.
- Service information: property preferences, booking details, job notes, service history, and communications relating to garden services.
- Payment information: payment status, billing records, and transaction details. We do not store full card information unless required by a secure payment provider.
- Technical information: device information, IP address, browser type, and limited usage data where applicable to our systems.
- Marketing preferences: choices about receiving promotional communications and service updates.
- Special category data: in normal circumstances, we do not intentionally collect special category data. If such data is provided to us incidentally, we will process it only where permitted by law and necessary for a specific purpose.
We collect data directly from you when you make an enquiry, request a quote, book a service, communicate with us, or complete forms. We may also receive information from third parties such as payment processors, scheduling platforms, or publicly available sources where appropriate and lawful.
2. How We Use Personal Data
Gardeners Temple uses personal data to provide and manage our services, including:
- responding to enquiries and preparing quotations;
- arranging appointments and delivering services;
- processing payments and maintaining records;
- managing customer accounts and service relationships;
- improving service quality and operational efficiency;
- carrying out administrative, accounting, and legal obligations;
- sending service-related updates, where necessary;
- with consent, sending marketing communications;
- protecting our business, customers, staff, and premises;
- resolving complaints, disputes, or claims.
We only use personal data for specified, explicit, and legitimate purposes. We do not sell personal data.
3. Lawful Basis for Processing
Under data protection law, we must have a lawful basis for each processing activity. Depending on the situation, we rely on one or more of the following lawful bases:
Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes providing quotations, scheduling work, delivering services, processing payments, and managing service records.
Legal Obligation
We may process data where required to comply with legal duties, such as tax recordkeeping, accounting obligations, fraud prevention, or responding to lawful requests from authorities.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Examples include managing and improving our services, maintaining internal records, preventing misuse, and ensuring business security.
Consent
Where required, we rely on consent, for example for certain marketing communications or optional data uses. When we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before consent was withdrawn.
Vital Interests and Public Task
These bases are unlikely to apply in normal customer service activity, but if they do, we will only use them where permitted by applicable law.
4. How We Share Data
We may share personal data with trusted third parties only when necessary for the purposes described in this policy. These may include:
- Service providers and processors: businesses that support our operations, such as payment processors, accounting services, scheduling systems, IT support, cloud storage providers, and communications platforms.
- Professional advisers: accountants, insurers, legal advisers, and auditors.
- Public authorities: where disclosure is required by law, regulation, court order, or lawful request.
- Business transferees: in connection with a merger, sale, restructuring, or transfer of business assets, subject to appropriate safeguards.
When we use processors, they act only on our instructions, are bound by confidentiality obligations, and must implement suitable security measures. They are not permitted to use personal data for their own purposes.
5. Data Retention
We retain personal data only for as long as necessary for the purpose for which it was collected, unless a longer retention period is required or permitted by law. Retention periods are determined by factors such as:
- the nature of the data and the service provided;
- contractual and legal requirements;
- accounting and tax obligations;
- the need to resolve disputes or enforce agreements;
- our legitimate need to maintain business records.
In general, customer and transaction records are kept for a period necessary to satisfy legal, accounting, and operational requirements, after which they are securely deleted, anonymised, or archived where appropriate. If data is no longer required, we will take reasonable steps to erase it securely.
6. Data Security
We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality duties, and limited access on a need-to-know basis.
No method of transmission or storage is completely secure. While we work to protect personal data, we cannot guarantee absolute security. If a data breach occurs that presents a risk to your rights and freedoms, we will handle it in accordance with applicable legal requirements.
7. International Transfers
If personal data is transferred outside the UK or European Economic Area, we will ensure that appropriate safeguards are in place, such as adequacy regulations, approved contractual clauses, or equivalent lawful transfer mechanisms. We take steps to ensure that any such transfer provides an adequate level of protection.
8. Your Rights
Subject to conditions and exemptions under data protection law, you have the following rights in relation to your personal data:
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to ask us to correct inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restrict processing: to ask us to limit how we use your data in certain cases.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to data portability: to receive certain data in a structured, commonly used format where applicable.
- Right to withdraw consent: where processing is based on consent, to withdraw it at any time.
You may also have the right to challenge decisions based solely on automated processing, although we do not normally use fully automated decision-making in our standard services. If we ever do, we will provide appropriate information and safeguards.
9. Exercising Your Rights
If you wish to exercise your rights, we may ask for information to verify your identity and protect your personal data. We will respond within the time limits required by law, usually within one month, unless your request is complex or numerous.
We aim to handle all requests fairly and promptly. In some cases, legal exceptions may apply, and we may not be able to comply fully with a request. If that happens, we will explain our decision where permitted to do so.
10. Cookies and Similar Technologies
If we use cookies or similar technologies on our digital systems, they are used only where necessary for functionality, security, analytics, or improving user experience, and where required, with appropriate consent or notice. Any such use will be handled in line with applicable privacy rules and our internal controls.
11. Children’s Data
Our services are intended for adults. We do not knowingly collect personal data from children without proper authority from a parent, guardian, or other lawful basis. If we become aware that we have collected data from a child without appropriate permission, we will take steps to delete it or otherwise handle it lawfully.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, our services, or our processing practices. Any updates will take effect when published or otherwise communicated, as appropriate. Please review this policy periodically to stay informed about how we protect personal data.
13. Summary of Our Commitment
Gardeners Temple is committed to processing personal data with care, transparency, and respect. We collect only what we need, use it for clear and lawful purposes, keep it only for as long as necessary, and protect it with suitable safeguards. We also respect your rights and aim to ensure that your information is handled in a lawful, fair, and secure manner.
By using our services, you confirm that you have read and understood this Privacy Policy.